ci(deps)(deps): bump the github-actions group across 1 directory with 2 updates#4
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
ArrayBolt3
pushed a commit
to ArrayBolt3/developer-meta-files
that referenced
this pull request
May 10, 2026
…scorecard-workflow Add reusable Scorecard workflow (first reusable in developer-meta-files)
d55678e to
4d1368b
Compare
… 2 updates Bumps the github-actions group with 2 updates in the / directory: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) and [github/codeql-action](https://github.com/github/codeql-action). Updates `anthropics/claude-code-action` from 1.0.114 to 1.0.123 - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@62238dd...51ea8ea) Updates `github/codeql-action` from 4.35.3 to 4.35.5 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@e46ed2c...9e0d7b8) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.119 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.35.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
4d1368b to
a83575f
Compare
adrelanos
pushed a commit
that referenced
this pull request
May 15, 2026
Ports #4 (Dependabot grouped update) to the org-ai-assisted mirror, which does not run Dependabot itself per agents/github-policy-canonical-vs-mirror.md. - anthropics/claude-code-action: 62238ddb (v1.0.114) -> 51ea8ea7 (v1.0.123) - github/codeql-action/init: e46ed2cb (v4.35.3) -> 9e0d7b8d (v4.35.5) - github/codeql-action/analyze: e46ed2cb (v4.35.3) -> 9e0d7b8d (v4.35.5) - github/codeql-action/upload-sarif:e46ed2cb (v4.35.3) -> 9e0d7b8d (v4.35.5) All three codeql-action usages move in lockstep to the same SHA so a single run never mixes patch levels.
Contributor
Author
|
Looks like these dependencies are no longer updatable, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 2 updates in the / directory: anthropics/claude-code-action and github/codeql-action.
Updates
anthropics/claude-code-actionfrom 1.0.114 to 1.0.123Release notes
Sourced from anthropics/claude-code-action's releases.
Commits
51ea8eachore: bump Claude Code to 2.1.142 and Agent SDK to 0.3.142acfa366chore: bump pinned Bun to 1.3.14 (#1312)9eb125afix: handle non-user actors (e.g. Copilot) in permission and actor checks (#1...1450f65fix: write execution file when SDK throws (#1255)0756f6efix: exclude .claude-pr snapshot from git staging (#1277)f4d6a11fix: dereference symlinks when snapshotting sensitive paths to .claude-pr/ (#...bf6d40efix: allow , in branch names (#1310)86eb26bchore: bump Claude Code to 2.1.141 and Agent SDK to 0.2.141f4fb5c6chore: bump Claude Code to 2.1.140 and Agent SDK to 0.2.140dde2242chore: bump Claude Code to 2.1.139 and Agent SDK to 0.2.139Updates
github/codeql-actionfrom 4.35.3 to 4.35.5Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
9e0d7b8Merge pull request #3905 from github/update-v4.35.5-d4b4855156d7d599Add changelog entry for #389951f7e38Update changelog for v4.35.5d4b4855Merge pull request #3899 from github/mbg/esbuild/split127de81Merge remote-tracking branch 'origin/main' into mbg/esbuild/split7fde13fUse src + basename in header to avoid issues on Windowsdfa61e7Improve pattern matching and error handling52aafecImport and callrunWrappernormally inanalyzetests0d08c01Auto-generate shared bundle14085a6Auto-generate entry points