Skip to content

feat: consolidate dependency updates#478

Merged
venkatamutyala merged 1 commit into
mainfrom
chore/consolidate-dependency-updates
Jun 29, 2026
Merged

feat: consolidate dependency updates#478
venkatamutyala merged 1 commit into
mainfrom
chore/consolidate-dependency-updates

Conversation

@venkatamutyala

Copy link
Copy Markdown
Contributor

Consolidates the open Renovate dependency PRs into one branch, validated end-to-end in Docker. Highest version wins where multiple PRs touched the same item.

Included — GitHub Actions (SHA-pinned)

Action File Version Supersedes
actions/checkout image.yml v6 (df4cb1c) #454
docker/setup-qemu-action image.yml v4 (0611638) #467
docker/setup-buildx-action image.yml v4.1.0 #474
docker/login-action image.yml v4.2.0 #472, #461
docker/metadata-action image.yml v6.1.0 #473
docker/build-push-action image.yml v7.2.0 #471, #464
dataaxiom/ghcr-cleanup-action cleanup_images.yaml v1.2.1 #470, #469

Included — Docker base image

Included — npm dependencies (package-lock.json regenerated from scratch → newest-in-range)

Validation (all in Docker — host has no Node toolchain)

  • docker build . (repo Dockerfile, new node digest, npm ci --only=production) — green, 0 vulnerabilities
  • node --check app.js / app-server.jssyntax OK
  • ESM import smoke of all upgraded deps (@slack/bolt, express, axios, winston, dotenv, slack-block-builder, unique-names-generator) — all OK

Excluded (left open)

Not merging — left for review. Superseded bot PRs will be closed with a pointer here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant