Bump the actions group with 15 updates#13814
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps the actions group with 15 updates: | Package | From | To | | --- | --- | --- | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.12.0` | `4.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.7.0` | `4.1.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.19.2` | `7.1.0` | | [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) | `2430c1ec91d04667414e2fa31ecfc36c153ea391` | `b0f9a6e3b6aa912656cbda9f74896eb721d29421` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `6.2.0` | | [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3` | `b0f9a6e3b6aa912656cbda9f74896eb721d29421` | | [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.91` | `1.0.127` | | [huggingface/security-workflows/.github/workflows/codeql-reusable.yml](https://github.com/huggingface/security-workflows) | `1.1.0` | `1.2.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `8.0.1` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.1.0` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.13.0` | `1.14.0` | | [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.94.2` | `3.95.3` | | [crate-ci/typos](https://github.com/crate-ci/typos) | `1.42.1` | `1.46.2` | | [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `9ad2de8582b56c017cb530c1165116d40433f1c6` | `b0f9a6e3b6aa912656cbda9f74896eb721d29421` | Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4.6.2...v7.0.1) Updates `docker/setup-buildx-action` from 3.12.0 to 4.0.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@8d2750c...4d04d5d) Updates `docker/login-action` from 3.7.0 to 4.1.0 - [Commits](docker/login-action@c94ce9f...4907a6d) Updates `docker/build-push-action` from 6.19.2 to 7.1.0 - [Commits](docker/build-push-action@10e90e3...bcafcac) Updates `huggingface/doc-builder/.github/workflows/build_main_documentation.yml` from 2430c1ec91d04667414e2fa31ecfc36c153ea391 to b0f9a6e3b6aa912656cbda9f74896eb721d29421 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Commits](huggingface/doc-builder@2430c1e...b0f9a6e) Updates `actions/setup-python` from 5.6.0 to 6.2.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5.6.0...v6.2.0) Updates `huggingface/doc-builder/.github/workflows/build_pr_documentation.yml` from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to b0f9a6e3b6aa912656cbda9f74896eb721d29421 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Commits](huggingface/doc-builder@90b4ee2...b0f9a6e) Updates `anthropics/claude-code-action` from 1.0.91 to 1.0.127 - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@2ff1acb...1dc994e) Updates `huggingface/security-workflows/.github/workflows/codeql-reusable.yml` from 1.1.0 to 1.2.0 - [Release notes](https://github.com/huggingface/security-workflows/releases) - [Commits](huggingface/security-workflows@dc6ca34...e0d40aa) Updates `actions/download-artifact` from 4.3.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4.3.0...3e5f45b) Updates `actions/labeler` from 5.0.0 to 6.1.0 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...f27b608) Updates `pypa/gh-action-pypi-publish` from 1.13.0 to 1.14.0 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@ed0c539...cef2210) Updates `trufflesecurity/trufflehog` from 3.94.2 to 3.95.3 - [Release notes](https://github.com/trufflesecurity/trufflehog/releases) - [Commits](trufflesecurity/trufflehog@6bd2d14...37b7700) Updates `crate-ci/typos` from 1.42.1 to 1.46.2 - [Release notes](https://github.com/crate-ci/typos/releases) - [Changelog](https://github.com/crate-ci/typos/blob/master/CHANGELOG.md) - [Commits](crate-ci/typos@6512063...aca895b) Updates `huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml` from 9ad2de8582b56c017cb530c1165116d40433f1c6 to b0f9a6e3b6aa912656cbda9f74896eb721d29421 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Commits](huggingface/doc-builder@9ad2de8...b0f9a6e) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/setup-buildx-action dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/login-action dependency-version: 4.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: docker/build-push-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml dependency-version: b0f9a6e3b6aa912656cbda9f74896eb721d29421 dependency-type: direct:production dependency-group: actions - dependency-name: actions/setup-python dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml dependency-version: b0f9a6e3b6aa912656cbda9f74896eb721d29421 dependency-type: direct:production dependency-group: actions - dependency-name: anthropics/claude-code-action dependency-version: 1.0.127 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: huggingface/security-workflows/.github/workflows/codeql-reusable.yml dependency-version: 1.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/labeler dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: trufflesecurity/trufflehog dependency-version: 3.95.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: crate-ci/typos dependency-version: 1.46.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml dependency-version: b0f9a6e3b6aa912656cbda9f74896eb721d29421 dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 15 updates:
4.6.27.0.13.12.04.0.03.7.04.1.06.19.27.1.02430c1ec91d04667414e2fa31ecfc36c153ea391b0f9a6e3b6aa912656cbda9f74896eb721d294215.6.06.2.090b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3b0f9a6e3b6aa912656cbda9f74896eb721d294211.0.911.0.1271.1.01.2.04.3.08.0.15.0.06.1.01.13.01.14.03.94.23.95.31.42.11.46.29ad2de8582b56c017cb530c1165116d40433f1c6b0f9a6e3b6aa912656cbda9f74896eb721d29421Updates
actions/upload-artifactfrom 4.6.2 to 7.0.1Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEUpdates
docker/setup-buildx-actionfrom 3.12.0 to 4.0.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
4d04d5dMerge pull request #485 from docker/dependabot/npm_and_yarn/docker/actions-to...cd74e05chore: update generated contenteee38ecbuild(deps): bump@docker/actions-toolkitfrom 0.77.0 to 0.79.07a83f65Merge pull request #484 from docker/dependabot/github_actions/docker/setup-qe...a5aa967Merge pull request #464 from crazy-max/rm-deprecatede73d53fbuild(deps): bump docker/setup-qemu-action from 3 to 428a438eMerge pull request #483 from crazy-max/node24034e9d3chore: update generated contentb4664d8remove deprecated inputs/outputsa8257denode 24 as default runtimeUpdates
docker/login-actionfrom 3.7.0 to 4.1.0Commits
4907a6dMerge pull request #930 from docker/dependabot/npm_and_yarn/aws-sdk-dependenc...1e233e6chore: update generated content6c24eadbuild(deps): bump the aws-sdk-dependencies group with 2 updatesee034d7Merge pull request #958 from docker/dependabot/npm_and_yarn/lodash-4.18.11527209Merge pull request #937 from docker/dependabot/npm_and_yarn/proxy-agent-depen...d39362abuild(deps): bump lodash from 4.17.23 to 4.18.1a6f092bchore: update generated content60953f0build(deps): bump the proxy-agent-dependencies group with 2 updates62c6885Merge pull request #936 from docker/dependabot/npm_and_yarn/docker/actions-to...102c0e6chore: update generated contentUpdates
docker/build-push-actionfrom 6.19.2 to 7.1.0Commits
bcafcacMerge pull request #1509 from docker/dependabot/npm_and_yarn/vite-7.3.218e62f1Merge pull request #1510 from docker/dependabot/npm_and_yarn/lodash-4.18.146580d2chore: update generated content3f80b25chore(deps): Bump lodash from 4.17.23 to 4.18.1efeec95Merge pull request #1505 from crazy-max/refactor-git-contextddf04b0Merge pull request #1511 from docker/dependabot/github_actions/crazy-max-dot-...db08d97chore(deps): Bump the crazy-max-dot-github group with 2 updatesef1fb96Merge pull request #1508 from docker/dependabot/github_actions/docker/login-a...2d8f2a1chore: update generated content919ac7bfix test since secrets are not written to temp path anymoreUpdates
huggingface/doc-builder/.github/workflows/build_main_documentation.ymlfrom 2430c1ec91d04667414e2fa31ecfc36c153ea391 to b0f9a6e3b6aa912656cbda9f74896eb721d29421Commits
b0f9a6eupdate (#788)093eb65feat: add language-* class to rendered code blocks (#787)8991858fix: preserve angle-bracketed content in code blocks when exporting Markdown ...Updates
actions/setup-pythonfrom 5.6.0 to 6.2.0Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
a309ff8Bump urllib3 from 2.6.0 to 2.6.3 in /tests/data (#1264)bfe8cc5Upgrade@actionsdependencies to Node 24 compatible versions (#1259)4f41a90Bump urllib3 from 2.5.0 to 2.6.0 in /tests/data (#1253)83679a8Bump@types/nodefrom 24.1.0 to 24.9.1 and update macos-13 to macos-15-intel ...bfc4944Bump prettier from 3.5.3 to 3.6.2 (#1234)97aeb3eBump requests from 2.32.2 to 2.32.4 in /tests/data (#1130)443da59Bump actions/publish-action from 0.3.0 to 0.4.0 & Documentation update for pi...cfd55cagraalpy: add graalpy early-access and windows builds (#880)bba65e5Bump typescript from 5.4.2 to 5.9.3 and update docs/advanced-usage.md (#1094)18566f8Improve wording and "fix example" (remove 3.13) on testing against pre-releas...Updates
huggingface/doc-builder/.github/workflows/build_pr_documentation.ymlfrom 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to b0f9a6e3b6aa912656cbda9f74896eb721d29421Commits
b0f9a6eupdate (#788)093eb65feat: add language-* class to rendered code blocks (#787)8991858fix: preserve angle-bracketed content in code blocks when exporting Markdown ...2430c1efeat: pin missing deps + update (#783)37b4351fix(ci): set default shell to bash in build workflow jobs (#784)2f8115ffix(ci): sync to bucket before zip-push to preserve extracted files (#782)8624007feat: make >>> and ... REPL prompts unselectable in code blocks (#781)9ad2de8feat: sync PR docs to HF bucket instead of git dataset (#780)3ffa60ffix(security): sanitize PR data interpolation in upload_pr_documentation work...9a1ab9c🔒 Pin GitHub Actions to commit SHAs (#775)Updates
anthropics/claude-code-actionfrom 1.0.91 to 1.0.127Release notes
Sourced from anthropics/claude-code-action's releases.
... (truncated)
Commits
1dc994eResolve actor account type before applying allowed_bots (#1330)ca89df3chore: bump Claude Code to 2.1.145 and Agent SDK to 0.3.145fd1877dSimplify comment tool instructions in prompt (#1328)2449274chore: bump Claude Code to 2.1.144 and Agent SDK to 0.3.1440345b11Fix prettier formatting in create-prompt (#1325)b020494chore: bump Claude Code to 2.1.143 and Agent SDK to 0.3.143d56f102Strengthen simplified tag-mode prompt (USE_SIMPLE_PROMPT) (#1313)bbad518fix: add parentheses to fix operator precedence in co-author check (#1199)51ea8eachore: bump Claude Code to 2.1.142 and Agent SDK to 0.3.142acfa366chore: bump pinned Bun to 1.3.14 (#1312)Updates
huggingface/security-workflows/.github/workflows/codeql-reusable.ymlfrom 1.1.0 to 1.2.0Release notes
Sourced from huggingface/security-workflows/.github/workflows/codeql-reusable.yml's releases.
Commits
e0d40aaFix typo in workflow namec2d38d6Merge pull request #13 from huggingface/improvments2c91f1edocs: update workflows infosf07172eRename auto-create-release.yml to manual-create-release.yml67fe7b0Merge pull request #12 from huggingface/improvments37c2ec8chore(ci): refactoring workflows3863108Update release workflow name for clarity4a56a03Merge pull request #11 from huggingface/paulinebm-patch-3556dfacfeat: Add support for runner group in CodeQL workflowa36b07eMerge pull request #9 from salmanmkc/upgrade-github-actions-node24Updates
actions/download-artifactfrom 4.3.0 to 8.0.1Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they doUpdates
actions/labelerfrom 5.0.0 to 6.1.0Release notes
Sourced from actions/labeler's releases.
... (truncated)
Commits
f27b608chore: upgrade dependencies (@actions/core,@actions/github, js-yaml, minimat...c5dadc2Add 'changed-files-labels-limit' and 'max-files-changed' configs to allow cap...e52e4fbBump minimatch from 10.0.1 to 10.2.3 (#926)77a4082Fix: Preserve manually added labels during workflow run and refine label sync...25abb3cImprove Labeler Action Documentation and Error Handling for Permissions (#897)395c8cfBump brace-expansion from 1.1.11 to 1.1.12 and document breaking changes in v...634933epublish-action upgrade to 0.4.0 from 0.2.2 (#901)f1a63e8Update Node.js version to 24 in action and dependencies (#891)b0a1180Bump@octokit/request-errorfrom 5.0.1 to 5.1.1 (#846)110d441Update README.md (#871)Updates
pypa/gh-action-pypi-publishfrom 1.13.0 to 1.14.0Release notes
Sourced from pypa/gh-action-pypi-publish's releases.