Skip to content

ci: bump the github-actions group across 1 directory with 2 updates#1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-37d7d335b6
Open

ci: bump the github-actions group across 1 directory with 2 updates#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-37d7d335b6

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 24, 2026

Bumps the github-actions group with 2 updates in the / directory: dependabot/fetch-metadata and creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml.

Updates dependabot/fetch-metadata from 2 to 3

Release notes

Sourced from dependabot/fetch-metadata's releases.

v3.0.0

The breaking change is requiring Node.js version v24 as the Actions runtime.

What's Changed

New Contributors

Full Changelog: dependabot/fetch-metadata@v2...v3.0.0

v2.5.0

What's Changed

... (truncated)

Commits
  • 25dd0e3 v3.1.0 (#692)
  • e073f50 Merge pull request #705 from dependabot/dependabot/npm_and_yarn/hono-4.12.14
  • 0670e16 build(deps-dev): bump hono from 4.12.12 to 4.12.14
  • 7a7fe10 Merge pull request #702 from dependabot/dependabot/npm_and_yarn/dependencies-...
  • 5168191 Updating dist build
  • 23882e1 build(deps): bump @​actions/github in the dependencies group
  • 1072469 Merge pull request #701 from dependabot/dependabot/github_actions/actions/cre...
  • 43f8a00 build(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1
  • b4d904a Merge pull request #703 from dependabot/dependabot/npm_and_yarn/globals-17.5.0
  • c8046bb build(deps-dev): bump globals from 17.4.0 to 17.5.0
  • Additional commits viewable in compare view

Updates creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml from 0.1.0 to 0.2.0

Changelog

Sourced from creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml's changelog.

Changelog

All notable changes to oss-security-scan are documented in this file.

The format follows Keep a Changelog and the project adheres to Semantic Versioning.

Commits
  • 8aa8407 fix(osv): treat exit 128 as 'no manifests', not vulnerability
  • 9d6fc88 feat(osv): inline osv-scanner job to unblock callers ahead of Go 1.26.2
  • ce81d40 fix: harden tier-1 checkouts against transient github auth flake
  • 6d491a1 ci: add Dependabot auto-merge for high-trust updates
  • 8073837 ci: add workflow_dispatch to integration-test.yml
  • bf16446 ci: bump crate-ci/typos in the github-actions group (#1)
  • da1c688 chore: enable dependabot for github-actions + language ecosystem
  • 8ff88bf ci: add workflow_dispatch trigger + OSV-on-manual gating to self-scan
  • 320ab08 feat: rename leakguard references to textleaks
  • 24be6b7 fix(test): install leakguard + oss-twin from git, not PyPI
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels May 24, 2026
Bumps the github-actions group with 2 updates in the / directory: [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) and [creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml](https://github.com/creatornader/oss-security-scan).


Updates `dependabot/fetch-metadata` from 2 to 3
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v2...v3)

Updates `creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml` from 0.1.0 to 0.2.0
- [Changelog](https://github.com/creatornader/oss-security-scan/blob/main/CHANGELOG.md)
- [Commits](creatornader/oss-security-scan@v0.1.0...v0.2.0)

---
updated-dependencies:
- dependency-name: creatornader/oss-security-scan/.github/workflows/oss-security-scan.yml
  dependency-version: 0.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: dependabot/fetch-metadata
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title ci: bump the github-actions group with 2 updates ci: bump the github-actions group across 1 directory with 2 updates May 31, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/github-actions-37d7d335b6 branch from 8cbae67 to c16f009 Compare May 31, 2026 08:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants