chore(deps): update github-actions#613
Conversation
ab4913f to
c7befcc
Compare
c06a650 to
e6b8878
Compare
e6b8878 to
7af9554
Compare
jrusso1020
left a comment
There was a problem hiding this comment.
Verdict
Approve. Clean, low-risk Renovate GitHub Actions digest bump. All 30+ required checks green, and I verified every pinned digest against the upstream repos rather than trusting the comment annotations:
| Action | New SHA | Resolves to | |
|---|---|---|---|
actions/cache |
0057852 |
v4.3.0 (latest v4.x) | ✅ real commit, correct tag |
github/codeql-action/{init,analyze} |
7211b7c |
v4.36.0 | ✅ real commit, correct tag |
marocchino/sticky-pull-request-comment |
7737449 |
v2.9.4 (exact tag object SHA) | ✅ real commit, correct tag |
sticky-pull-request-comment v2.9.1→v2.9.4 is patch-level (transitive dep/security bumps — undici, octokit); it's used only in the continue-on-error Fallow-audit comment step, so no blast radius even on regression.
Nit (non-blocking)
The PR body table advertises codeql-action 8aad20d (= v4.36.2), but the diff actually pins 7211b7c (= v4.36.0) — Renovate rebased the branch since the body was generated and the table went stale. Both are legitimate codeql v4 releases; merging takes v4.36.0 and Renovate's immortal PR will follow up to bump the remaining two patch versions. Worth nothing more than awareness.
|
Closing as stale/unmergeable. Why: This branch's last real commit is 2026-05-22 (409 commits behind Why not just rebase-and-merge: the branch touches Renovate will recreate a fresh PR for these pins on its next healthy run. |
This PR contains the following updates:
1bd1e32→00578529e0d7b8→8aad20dv2.9.1→v2.9.4Release Notes
marocchino/sticky-pull-request-comment (marocchino/sticky-pull-request-comment)
v2.9.4Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.3...v2.9.4
v2.9.3Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.2...v2.9.3
v2.9.2Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.1...v2.9.2
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.