Skip to content

chore(deps): bump the github-actions group with 4 updates - #101

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-329d2f1fe2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-329d2f1fe2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 4 updates: actions-rust-lang/setup-rust-toolchain, NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml, crate-ci/typos and taiki-e/install-action.

Updates actions-rust-lang/setup-rust-toolchain from 1.17.0 to 2.0.0

Release notes

Sourced from actions-rust-lang/setup-rust-toolchain's releases.

v2.0.0

What's Changed

  • Use CARGO_BUILD_WARNINGS for enforcing warning free compilations (#98) This is a new variable supported by cargo 1.97+ and sets the build.warnings config. It allows removing the RUSTFLAGS="-D warnings" default, which will improve compatibility with target.*.rustflags and .cargo/config.toml files.

    This adds a new build-warnings input to configure the value for the build.warnings config.

  • Add error matcher for Rust panics This will highlight the location of the panic location during tests.

  • Reuse output of rustc --version --verbose calls (#103 by @​ChihweiLHBird)

New Contributors

Full Changelog: actions-rust-lang/setup-rust-toolchain@v1.17.0...v2.0.0

Changelog

Sourced from actions-rust-lang/setup-rust-toolchain's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

[2.0.0] - 2026-09-07

  • Use CARGO_BUILD_WARNINGS for enforcing warning free compilations (#98) This is a new variable supported by cargo 1.97+ and sets the build.warnings config. It allows removing the RUSTFLAGS="-D warnings" default, which will improve compatibility with target.*.rustflags and .cargo/config.toml files.

    This adds a new build-warnings input to configure the value for the build.warnings config.

  • Add error matcher for Rust panics This will highlight the location of the panic location during tests.

  • Reuse output of rustc --version --verbose calls (#103 by @​ChihweiLHBird)

[1.17.0] - 2026-06-25

  • Add new parameter cache-targets that is propagated to Swatinem/rust-cache as cache-targets (#84). This allows disabling caching of the workspace target directory, e.g. when using sccache, while keeping the rest of the cache enabled.

[1.16.1] - 2026-05-08

  • Renamed internally used variable to avoid clashes with globally existing variables. This fixes the interference of the TOOLCHAIN variable as reported in #91.

[1.16.0] - 2026-04-13

  • Add new parameter cache-save-if that is propagated to Swatinem/rust-cache as save-if (#90 by @​ChanTsune)

[1.15.4] - 2026-03-15

  • Bump Swatinem/rust-cache from 2.8.2 to 2.9.1 (#87 by @​hyperfinitism) This gets rid of the warnings about Node.js 20.

[1.15.3] - 2026-03-01

  • Bump Swatinem/rust-cache from 2.8.1 to 2.8.2

[1.15.2] - 2025-10-04

  • Fix: Run the version detection steps in the selected rust-src-dir directory. This should enable the version selection even without a default toolchain installed. Fixes #74.

[1.15.1] - 2025-09-23

... (truncated)

Commits
  • ecabd13 Prepare changelog for 2.0.0 release
  • dc00391 Add error matcher for Rust panics
  • 70de7eb Merge pull request #103 from ChihweiLHBird/reuse-rustc-verbose-output
  • c420b69 Merge pull request #105 from actions-rust-lang/use-build-warnings
  • d94d10a Use CARGO_BUILD_WARNINGS for enforcing warning free compilations
  • 34430aa Reuse rustc verbose output instead of invoking rustc three times.
  • 0267444 Merge pull request #102 from actions-rust-lang/dependabot/github_actions/Swat...
  • 5fa2882 Bump Swatinem/rust-cache from 2.9.1 to 2.9.2
  • 8439c15 Merge pull request #100 from actions-rust-lang/dependabot/github_actions/acti...
  • c8f944a Bump actions/checkout from 7.0.0 to 7.0.1
  • See full diff in compare view

Updates NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml from a0dc5592333dcfdf2a3d239ed1f2b128899e5482 to c113d4c9b0265bcefeb756489da9a06c8c1b9e5f

Changelog

Sourced from NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml's changelog.

Changelog

Unreleased

  • Provider v0.1.5-nddev.130 is .129 rebuilt on the raised AWS SDK minor and patch releases. No provider behaviour changes; the version moves because the binary does, and the release manifest records which source commit and which bytes. Root go.mod changes cannot ship under the previous derivative version - that is how two hosts once ran different binaries under one name.

  • Observer schema 17 labels the oldest queued waiter per scale set and the oldest assigned waiter with journal job_id. lifecycle_queued_delivery_stall, queue_wait_slow_burn and lifecycle_assigned_stall aggregate max by (job_id, scale_set) so {subject} is that GUID. A cancelled or advanced waiter dropping out of the gauge is a new incident, not a quieter reading of the previous one. The global Telegram template is unchanged. queue_started_wait_slow_burn still names the scale set. Deploy the observer before reconciling OpenObserve: the assigned stall stream is new.

  • GARM v0.2.1-nddev.94 binds stale scale-set job mutation to exact identity: check-run external_id, workflow_job.check_run_url, repository, exact attempt, numeric job ID and source SHA. A job name is never terminal proof. Missing fields, incomplete pagination, omitted or changing page totals, another attempt, a non-Actions producer and no exact match retain the intent. check_run_url and the check URL must share an https origin and repos/{owner}/{repo}/check-runs/{id} path; a missing check URL or a foreign host does not bind. GitHub 404 retains the intent and does not start the 15-minute access-refusal backoff used for 403/429. Scaling uses the latest MESSAGE statistics.TotalAssignedJobs; idle retirement requires a recent MESSAGE with messageID > 0 and re-checks that observation before RemoveRunner. Session-create zeros and 202/nil long-polls are not idle evidence. Start failure deletes the new message session and cancels the listener context. Listener JobCompleted with an empty runner name ends a delivery reservation and is not a REST workflow-job terminal; REST still-queued exact identity can clear that tombstone. A later same-run/name GUID is not aliased onto it. JobStarted of another GUID does not delete or rename an assigned waiter or copy its FIFO clock. A request-less JobAssigned yields occupancy only when a dispatchable JobAvailable would actually fit after that yield, including while that reservation is still unexpired; a quota-blocked available job does not evict a useful foreign bootstrap reservation. The original waiter and FIFO stay in the journal. Same-GUID JobAvailable keeps occupancy. An official build preserves the source tree when container stop is not proven. A replayed MESSAGE with the same session and messageID does not refresh idle-retirement freshness. A late message from a replaced session does not overwrite current demand. golang.org/x/text is v0.39.0. The .92 and .93 patches are unchanged. This is a source/artifact candidate, not a fleet rollout.

... (truncated)

Commits
  • c113d4c Merge pull request #457 from NDDev-OpenNetwork/fix/reconcile-orphaned-queue-i...
  • dbaa4ac fix: reconcile terminal queue orphans and preserve workers during maintenance
  • 3d8b898 build: update the provider network dependency
  • 22bde32 Merge pull request #456 from NDDev-OpenNetwork/fix/refresh-incomplete-incus-i...
  • 966d1b4 chore: record the reproducible provider 132 release and rollout contract
  • 7a82d68 fix(provider): refresh a complete inventory snapshot before retrying
  • deb7eb1 fix(provider): refresh incomplete inventory after lease transitions
  • 68264ad Merge pull request #455 from NDDev-OpenNetwork/chore/ignore-feedback-python-c...
  • e00edfa chore(git): ignore generated feedback Python caches
  • 2e07dce Merge pull request #454 from NDDev-OpenNetwork/chore/benchmark-dependency-con...
  • Additional commits viewable in compare view

Updates crate-ci/typos from 1.50.0 to 1.50.1

Release notes

Sourced from crate-ci/typos's releases.

v1.50.1

[1.50.1] - 2026-09-01

Fixes

  • Don't correct asend in Python code
Changelog

Sourced from crate-ci/typos's changelog.

Change Log

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

[Unreleased] - ReleaseDate

[1.50.1] - 2026-09-01

Fixes

  • Don't correct asend in Python code

[1.50.0] - 2026-08-28

Features

[1.49.1] - 2026-08-27

Fixes

  • Don't correct the brand name HashiCorp

[1.49.0] - 2026-08-03

Features

  • Updated the dictionary with the July 2026 changes

[1.48.0] - 2026-06-30

Features

  • Updated the dictionary with the June 2026 changes

[1.47.2] - 2026-06-04

Fixes

  • Don't correct inferrable
  • Correct unused inferible variant

[1.47.1] - 2026-06-03

Fixes

... (truncated)

Commits
  • d43b6c0 chore: Release
  • 84aa963 docs: Update changelog
  • 79e6746 Merge pull request #1608 from nightcityblade/fix/python-asend
  • aba6985 Merge pull request #1616 from crate-ci/renovate/clap-cargo-0.x
  • 92ed824 chore(deps): Update compatible (#1615)
  • e575a6c chore(deps): Update Rust crate clap-cargo to 0.19.0
  • 5956a26 fix: Allow Python asend identifier
  • f6ce659 test: Capture Python asend behavior
  • See full diff in compare view

Updates taiki-e/install-action from 2.87.2 to 2.87.8

Release notes

Sourced from taiki-e/install-action's releases.

2.87.8

  • Update shfmt@latest to 3.14.1.

  • Update release-plz@latest to 0.3.162.

  • Update protoc-gen-connect-openapi@latest to 0.26.0.

  • Update dprint@latest to 0.57.4.

  • Update cargo-llvm-cov@latest to 0.9.1.

  • Update cargo-crap@latest to 0.5.0.

  • Update cargo-binstall@latest to 1.23.0.

2.87.7

  • Update wasm-bindgen@latest to 0.2.128.

  • Update uv@latest to 0.12.10.

  • Update tombi@latest to 1.5.2.

  • Update rclone@latest to 1.75.1.

2.87.6

  • Update rafn@latest to 0.1.6.

  • Update editorconfig-checker@latest to 3.11.3.

  • Update dprint@latest to 0.57.1.

  • Update convco@latest to 0.7.2.

2.87.5

  • Update vacuum@latest to 0.30.3.

  • Update uv@latest to 0.12.9.

  • Update typos@latest to 1.50.1.

  • Update tombi@latest to 1.5.1.

  • Update release-plz@latest to 0.3.161.

  • Update prek@latest to 0.5.2.

  • Update oxfmt@latest to 1.81.0.

  • Update mise@latest to 2026.9.1.

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

Changelog

All notable changes to this project will be documented in this file.

This project adheres to Semantic Versioning.

[Unreleased]

[2.87.12] - 2026-09-12

  • Update wasmtime@latest to 48.0.2.

  • Update wasm-tools@latest to 1.259.0.

  • Update uv@latest to 0.12.13.

  • Update release-plz@latest to 0.3.165.

  • Update protoc-gen-connect-openapi@latest to 0.27.1.

  • Update mise@latest to 2026.9.5.

  • Update cargo-nextest@latest to 0.9.144.

[2.87.11] - 2026-09-11

  • Update biome@latest to 2.5.13.

  • Update uv@latest to 0.12.12.

  • Update mise@latest to 2026.9.4.

  • Update kache@latest to 0.19.0.

[2.87.10] - 2026-09-10

  • Update zizmor@latest to 1.30.1.

  • Update uv@latest to 0.12.11.

  • Update tombi@latest to 1.5.4.

  • Update release-plz@latest to 0.3.164.

  • Update mise@latest to 2026.9.3.

... (truncated)

Commits
  • d438492 Release 2.87.8
  • cf1fade Update shfmt@latest to 3.14.1
  • 7161449 Update release-plz@latest to 0.3.162
  • 58df4bb Update protoc-gen-connect-openapi@latest to 0.26.0
  • 33e9ffe Update oxfmt manifest
  • 60bf882 Update kache manifest
  • 667469a Update dprint@latest to 0.57.4
  • aa52fd6 Update cargo-llvm-cov@latest to 0.9.1
  • 834d344 Update cargo-crap@latest to 0.5.0
  • 097f1f0 Update cargo-binstall@latest to 1.23.0
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 4 updates: [actions-rust-lang/setup-rust-toolchain](https://github.com/actions-rust-lang/setup-rust-toolchain), [NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml](https://github.com/nddev-opennetwork/github-actions), [crate-ci/typos](https://github.com/crate-ci/typos) and [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `actions-rust-lang/setup-rust-toolchain` from 1.17.0 to 2.0.0
- [Release notes](https://github.com/actions-rust-lang/setup-rust-toolchain/releases)
- [Changelog](https://github.com/actions-rust-lang/setup-rust-toolchain/blob/main/CHANGELOG.md)
- [Commits](actions-rust-lang/setup-rust-toolchain@166cdcf...ecabd13)

Updates `NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml` from a0dc5592333dcfdf2a3d239ed1f2b128899e5482 to c113d4c9b0265bcefeb756489da9a06c8c1b9e5f
- [Release notes](https://github.com/nddev-opennetwork/github-actions/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/github-actions/blob/main/CHANGELOG.md)
- [Commits](NDDev-Archive/github-actions-garm@a0dc559...c113d4c)

Updates `crate-ci/typos` from 1.50.0 to 1.50.1
- [Release notes](https://github.com/crate-ci/typos/releases)
- [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md)
- [Commits](crate-ci/typos@4d9c206...d43b6c0)

Updates `taiki-e/install-action` from 2.87.2 to 2.87.8
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@1ed6d7b...d438492)

---
updated-dependencies:
- dependency-name: actions-rust-lang/setup-rust-toolchain
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: NDDev-OpenNetwork/github-actions/.github/workflows/ci-feedback.yml
  dependency-version: c113d4c9b0265bcefeb756489da9a06c8c1b9e5f
  dependency-type: direct:production
  dependency-group: github-actions
- dependency-name: crate-ci/typos
  dependency-version: 1.50.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: taiki-e/install-action
  dependency-version: 2.87.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added ci dependencies Pull requests that update a dependency file labels Sep 14, 2026
@dependabot
dependabot Bot requested a review from rldyourmnd as a code owner September 14, 2026 06:36
@dependabot dependabot Bot added ci dependencies Pull requests that update a dependency file labels Sep 14, 2026
@rldyourmnd

Copy link
Copy Markdown
Contributor

Superseded: this Dependabot bump pins github-actions/ci-workflows to c113d4c and/or a624689, which predate extra-approval=false on main (6064b7d / 9eb9e07). Closing in favor of chore/pin-reusable-workflows-20260915.

1 similar comment
@rldyourmnd

Copy link
Copy Markdown
Contributor

Superseded: this Dependabot bump pins github-actions/ci-workflows to c113d4c and/or a624689, which predate extra-approval=false on main (6064b7d / 9eb9e07). Closing in favor of chore/pin-reusable-workflows-20260915.

@rldyourmnd rldyourmnd closed this Sep 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-329d2f1fe2 branch September 14, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant