Skip to content

Bump the actions group with 3 updates - #77

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-beabbccdba
Closed

Bump the actions group with 3 updates#77
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-beabbccdba

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 7, 2026

Copy link
Copy Markdown

Bumps the actions group with 3 updates: actions/checkout, plexsystems/container-structure-test-action and aquasecurity/trivy-action.

Updates actions/checkout from 6.0.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

v7.0.1

v7.0.0

v6.0.3

Commits

Updates plexsystems/container-structure-test-action from 0.1.0 to 0.3.0

Release notes

Sourced from plexsystems/container-structure-test-action's releases.

v0.3.0

What's Changed

New Contributors

Full Changelog: plexsystems/container-structure-test-action@v0.2.0...v0.3.0

v0.2.0

Update container structure test to version 0.9

Commits
  • c0a028a Merge pull request #4 from plexsystems/update-version
  • 22109e9 Update container structure test to v1.15.0
  • cb09ec8 Merge pull request #3 from MaxymVlasov/main
  • 6ecb914 Remove Renovate deps update tracikng definition
  • 2f5ce94 Delete renovate.json5
  • ccb4d43 feat: Update deps and add renovate (#2)
  • fc4492b Merge pull request #2 from rbhadti94/upgrading-container-structure-tests-to-1...
  • d1cfe6f upgrading to 1.9
  • See full diff in compare view

Updates aquasecurity/trivy-action from 0.35.0 to 0.36.0

Release notes

Sourced from aquasecurity/trivy-action's releases.

v0.36.0

What's Changed

New Contributors

Full Changelog: aquasecurity/trivy-action@v0.35.0...v0.36.0

Commits
  • ed142fd chore: update action version to v0.36.0 in examples (#563)
  • dea62cf chore(deps): Update trivy to v0.70.0 (#559)
  • 128d9a8 chore: use GitHub Actions as git commit author in bump-trivy workflow (#561)
  • 876cf04 Upgrade Trivy action version from 0.33.1 to 0.35.0 fixes #549 (#548)
  • dada784 Fix typo in GOOGLE_APPLICATION_CREDENTIALS env var name (#547)
  • 4a2deec fix: use portable shebang in entrypoint.sh (#545)
  • 1994662 chore(deps): bump the actions group with 5 updates (#558)
  • 6b36659 chore: add zizmor config (#557)
  • 316aa5a ci: add dependabot config (#556)
  • 264c9c5 test: use pinned digests for trivy-db, trivy-java-db and trivy-checks (#555)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [plexsystems/container-structure-test-action](https://github.com/plexsystems/container-structure-test-action) and [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).


Updates `actions/checkout` from 6.0.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6.0.2...v7.0.1)

Updates `plexsystems/container-structure-test-action` from 0.1.0 to 0.3.0
- [Release notes](https://github.com/plexsystems/container-structure-test-action/releases)
- [Commits](plexsystems/container-structure-test-action@v0.1.0...v0.3.0)

Updates `aquasecurity/trivy-action` from 0.35.0 to 0.36.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.35.0...v0.36.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: plexsystems/container-structure-test-action
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 7, 2026
@abnegate

abnegate commented Aug 7, 2026

Copy link
Copy Markdown
Member

Superseded by #79, which takes all three actions to the same (or newer) releases and additionally pins every uses: to a commit SHA — actions/checkout 7.0.1, container-structure-test-action 0.3.0 and trivy-action 0.36.0 are all included there, alongside docker/login-action 4.6.0 and codeql-action 4.37.6.

A version tag is a mutable pointer, so #79 records the resolved commit with the version as a trailing comment. Dependabot rewrites both together from here on.

@abnegate abnegate closed this Aug 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 7, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-beabbccdba branch August 7, 2026 02:19
abnegate added a commit that referenced this pull request Aug 7, 2026
A version tag is a mutable pointer: whoever controls an action's
repository can repoint v7.0.1 at arbitrary code, and every workflow here
runs with the DockerHub push credentials in scope. Pinning by commit SHA
makes the resolved code immutable, and the trailing version comment keeps
the Dependabot "actions" group able to rewrite both together.

Takes each action to its current release while pinning, superseding the
open Dependabot bump (#77): checkout 6.0.2 -> 7.0.1, login-action
4 -> 4.6.0, container-structure-test-action 0.1.0 -> 0.3.0, trivy-action
0.35.0 -> 0.36.0, codeql-action 4 -> 4.37.6.
abnegate added a commit that referenced this pull request Aug 7, 2026
* (fix): pin GitHub Actions to commit SHAs

A version tag is a mutable pointer: whoever controls an action's
repository can repoint v7.0.1 at arbitrary code, and every workflow here
runs with the DockerHub push credentials in scope. Pinning by commit SHA
makes the resolved code immutable, and the trailing version comment keeps
the Dependabot "actions" group able to rewrite both together.

Takes each action to its current release while pinning, superseding the
open Dependabot bump (#77): checkout 6.0.2 -> 7.0.1, login-action
4 -> 4.6.0, container-structure-test-action 0.1.0 -> 0.3.0, trivy-action
0.35.0 -> 0.36.0, codeql-action 4 -> 4.37.6.

* (fix): pin extension sources by commit and checksum

Extensions were built from `git clone --branch <tag>` and
`pecl install <package>-<version>`, both of which resolve through a
mutable pointer — an upstream tag can be deleted and recreated on a
different commit, and the build would silently compile it into an image
that runs as the base for every Appwrite service. Each git extension now
carries a PHP_*_COMMIT alongside its version and is fetched by that SHA
directly (`git init` + `git fetch --depth 1 <url> <sha>`), so the tag is
never consulted; protobuf carries a PHP_PROTOBUF_CHECKSUM and its PECL
tarball is verified with sha256sum before install. Submodules stay
transitively pinned through the parent commit's gitlinks.

The version is kept beside each reference so the release it was resolved
from stays readable, and so tests.yaml has something to assert against.

Everything moves to its latest compatible release in the same pass, since
a stale pin is now genuinely frozen: base image digest, brotli 0.18.3 ->
0.20.0, lz4 0.6.0 -> 0.7.0, mongodb 2.2.1 -> 2.3.3, protobuf 5.34.0 ->
5.35.1, scrypt 2.0.1 -> 2.0.2, swoole 6.2.0 -> 6.2.2, xdebug 3.5.1 ->
3.5.3, zstd 0.15.2 -> 0.17.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant