Skip to content

build(deps): bump the github-actions group across 1 directory with 9 updates - #5662

Merged
ric-oliv merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-9f7da8261c
Oct 2, 2026
Merged

ric-oliv merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-9f7da8261c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 9 updates in the / directory:

Package From To
getsentry/github-workflows/sentry-cli/integration-test 3.4.0 3.4.1
getsentry/craft/.github/workflows/changelog-preview.yml 2.31.1 2.31.2
github/codeql-action/init 4.38.1 4.38.2
github/codeql-action/analyze 4.38.1 4.38.2
getsentry/github-workflows/danger 3.4.0 3.4.1
gradle/actions/setup-gradle 6.3.0 6.4.0
getsentry/craft 2.31.1 2.31.2
getsentry/github-workflows/updater 3.4.0 3.4.1
getsentry/github-workflows/validate-pr 3.4.0 3.4.1

Updates getsentry/github-workflows/sentry-cli/integration-test from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/sentry-cli/integration-test's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/sentry-cli/integration-test's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Updates getsentry/craft/.github/workflows/changelog-preview.yml from 2.31.1 to 2.31.2

Release notes

Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's releases.

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880
Changelog

Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's changelog.

Changelog

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880

2.31.1

Bug Fixes 🐛

Internal Changes 🔧

Deps

Deps Dev

2.31.0

New Features ✨

  • (config) Top-level workspaces schema + --workspace selector by @​BYK in #848
  • Propagate release workspaces by @​BYK in #872

Bug Fixes 🐛

2.30.1

Bug Fixes 🐛

  • (vercel) Pass prebuilt output directory by @​BYK in #868

2.30.0

New Features ✨

  • (vercel) Allow project ID in target config by @​BYK in #867

... (truncated)

Commits
  • 25028d0 release: 2.31.2
  • bba2a96 fix(deps): remediate open security alerts (#881)
  • 7137f20 fix(github): Filter artifacts by name when fetching revision artifact (#880)
  • 960a1c7 meta: Bump new development version
  • 7dab3b4 Merge remote-tracking branch 'remotes/origin/release/2.31.1'
  • See full diff in compare view

Updates github/codeql-action/init from 4.38.1 to 4.38.2

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.1 to 4.38.2

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

No user facing changes.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates getsentry/github-workflows/danger from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/danger's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/danger's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Updates gradle/actions/setup-gradle from 6.3.0 to 6.4.0

Release notes

Sourced from gradle/actions/setup-gradle's releases.

v6.4.0

Highlights

Gradle version support status in the Job Summary

The actions now report the support status of every Gradle version used in a workflow, as job annotations and in the Job Summary (#1057). Thanks to @​ov7a for the contribution.

version kind job annotation version table below the table
End-of-life — two or more major versions behind the latest release warning ⚠️ expandable section naming the affected release lines, pointing at the Gradle Security Subscription
Out of date — one major behind, or more than two minors behind on the current major notice ℹ️ one-line legend pointing at the Gradle release lifecycle docs
Current none — —

Deliberately not reported: patch releases (being on 9.7.0 when 9.7.1 exists is not flagged) and pre-releases (release candidates, milestones and snapshots never produce annotations). The latest Gradle release is determined from the wrapper checksum data already bundled with the action, so no network access is required.

Note that these annotations are emitted independently of the add-job-summary setting: setting add-job-summary: 'never' suppresses the Job Summary itself, but the warning and notice annotations remain.

Gradle itself is now reported in the dependency graph

The dependency-submission action now applies v1.5.0 of the GitHub Dependency Graph Gradle Plugin (up from v1.4.2) (#1069).

The headline change is that the Gradle Build Tool running the build is now reported as an org.gradle:gradle-core dependency, so that GitHub can surface known vulnerabilities in the version of Gradle used to run your build. These are the coordinates that GitHub advisories for the Gradle Build Tool are published against.

Details worth knowing:

  • The entry is always reported as a direct dependency with development scope.
  • It is not affected by the project, configuration or scope filters, so it appears even in graphs that filter aggressively.
  • Expect dependency graphs to gain this one new entry the first time a build runs after upgrading.

A new Gradle signing key, if you use dependency verification

[!IMPORTANT] If your build has dependency verification enabled, you must add a second trusted key before upgrading, or Dependency Graph generation will fail signature verification.

github-dependency-graph-gradle-plugin 1.5.0 is signed with a new Gradle signing subkey, and the key previously documented in our setup guide has been revoked upstream:

... (truncated)

Commits
  • 3f5f9ad Document the new Gradle signing key for dependency verification (#1071)
  • b031f6d [bot] Update dist directory
  • 5bc4175 Bump dependency-graph-gradle-plugin to 1.5.0 (#1069)
  • f3ff59b Combined automated updates: wrapper checksums, npm dependencies, setup-java (...
  • 7927085 Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 (#1068)
  • c3897a4 [bot] Update dist directory
  • 6b92be1 Update dependencies (#1065)
  • 0d208da [bot] Update dist directory
  • e49d0a3 Report EOL and maintenance status for Gradle versions (#1057)
  • 575435b Use the root-qualified :wrapper task (#1064)
  • Additional commits viewable in compare view

Updates getsentry/craft from 2.31.1 to 2.31.2

Release notes

Sourced from getsentry/craft's releases.

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880
Changelog

Sourced from getsentry/craft's changelog.

Changelog

2.31.2

Bug Fixes 🐛

  • (deps) Remediate open security alerts by @​BYK in #881
  • (github) Filter artifacts by name when fetching revision artifact by @​itaybre in #880

2.31.1

Bug Fixes 🐛

Internal Changes 🔧

Deps

Deps Dev

2.31.0

New Features ✨

  • (config) Top-level workspaces schema + --workspace selector by @​BYK in #848
  • Propagate release workspaces by @​BYK in #872

Bug Fixes 🐛

2.30.1

Bug Fixes 🐛

  • (vercel) Pass prebuilt output directory by @​BYK in #868

2.30.0

New Features ✨

  • (vercel) Allow project ID in target config by @​BYK in #867

... (truncated)

Commits
  • 25028d0 release: 2.31.2
  • bba2a96 fix(deps): remediate open security alerts (#881)
  • 7137f20 fix(github): Filter artifacts by name when fetching revision artifact (#880)
  • 960a1c7 meta: Bump new development version
  • 7dab3b4 Merge remote-tracking branch 'remotes/origin/release/2.31.1'
  • See full diff in compare view

Updates getsentry/github-workflows/updater from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/updater's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/updater's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (#170)
  • c802283 fix(danger): harden extra-install-packages against host-shell interpolation (...
  • b6d9e26 Merge branch 'release/3.4.0'
  • See full diff in compare view

Updates getsentry/github-workflows/validate-pr from 3.4.0 to 3.4.1

Release notes

Sourced from getsentry/github-workflows/validate-pr's releases.

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)
Changelog

Sourced from getsentry/github-workflows/validate-pr's changelog.

Changelog

3.4.1

Fixes

  • Danger - Add skip-checkout to preserve a caller's prepared workspace, including generated custom Dangerfiles. Checkout remains enabled by default. (#175)
  • Updater - Preserve CMake and submodule pins ahead of the selected release, while reporting divergent histories and Git errors (#174)
  • Danger - Harden extra-install-packages handling: pass the package list into the container via env var instead of host-shell string interpolation (defense in depth) (#169)
  • Updater - Avoid cleanup races in temporary ancestry repositories by disabling background Git maintenance; preserve original Git errors if cleanup also fails (#177)
  • Sentry-CLI integration test action - Skip the reverse DNS lookup on server start, which made each start take ~35 s on macOS (#178)

3.4.0

Features

  • Validate PR - Action is advisory: it posts a single friendly comment on community PRs that don't reference an issue with maintainer discussion. PRs are not closed and no labels are applied. Recommended trigger is types: [opened].
  • Validate PR - Skip validation for PRs with fewer than 100 lines changed, excluding common lock files (Cargo.lock, yarn.lock, package-lock.json, Pipfile.lock, etc.). Tiny PRs no longer go through the issue-discussion loop.
  • Add validate-pr composite action for validating non-maintainer PRs against contribution guidelines (#153)

Fixes

  • Complete script injection hardening across all actions: move remaining step outputs to env vars, validate Danger version against semver (#152)
  • Updater - Trigger CI for new PRs without changelog updates (#166)
  • Updater - Select the first branch when multiple branches point at HEAD (#165)

Dependencies

3.3.0

Features

  • Updater - Support CMake GIT_TAG with variable references like ${FOO_REF}, resolving and updating the corresponding set() definition (#149)

3.2.1

Fixes

  • Sentry-CLI integration test action - Accept chunked ProGuard uploads for compatibility with Sentry CLI 3.x (#140)

3.2.0

Features

  • Danger - Add support for repository-specific dangerfiles (#129)
    • Add extra-dangerfile input parameter to run custom Danger checks alongside shared workflow checks

... (truncated)

Commits
  • 959162c release: 3.4.1
  • 573d8af fix(sentry-cli): Skip reverse DNS lookup on dummy server start (#178)
  • 6651df0 fix(updater): prevent maintenance from racing ancestry cleanup (#177)
  • 45c8e3a chore: cleanup changelog (#176)
  • 229617d fix(danger): preserve prepared workspaces with optional checkout (#175)
  • 14b30d6 fix(updater): distinguish newer pins from divergent history (#174)
  • 4013fc6 ci: bump danger tests to Node.js 24 (

…updates

Bumps the github-actions group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [getsentry/github-workflows/sentry-cli/integration-test](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/craft/.github/workflows/changelog-preview.yml](https://github.com/getsentry/craft) | `2.31.1` | `2.31.2` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.1` | `4.38.2` |
| [getsentry/github-workflows/danger](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [gradle/actions/setup-gradle](https://github.com/gradle/actions) | `6.3.0` | `6.4.0` |
| [getsentry/craft](https://github.com/getsentry/craft) | `2.31.1` | `2.31.2` |
| [getsentry/github-workflows/updater](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |
| [getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows) | `3.4.0` | `3.4.1` |



Updates `getsentry/github-workflows/sentry-cli/integration-test` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/craft/.github/workflows/changelog-preview.yml` from 2.31.1 to 2.31.2
- [Release notes](https://github.com/getsentry/craft/releases)
- [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md)
- [Commits](getsentry/craft@b5451aa...25028d0)

Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

Updates `getsentry/github-workflows/danger` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `gradle/actions/setup-gradle` from 6.3.0 to 6.4.0
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@9c97196...3f5f9ad)

Updates `getsentry/craft` from 2.31.1 to 2.31.2
- [Release notes](https://github.com/getsentry/craft/releases)
- [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md)
- [Commits](getsentry/craft@b5451aa...25028d0)

Updates `getsentry/github-workflows/updater` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

Updates `getsentry/github-workflows/validate-pr` from 3.4.0 to 3.4.1
- [Release notes](https://github.com/getsentry/github-workflows/releases)
- [Changelog](https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md)
- [Commits](getsentry/github-workflows@607fed7...959162c)

---
updated-dependencies:
- dependency-name: getsentry/github-workflows/sentry-cli/integration-test
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/craft/.github/workflows/changelog-preview.yml
  dependency-version: 2.31.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/danger
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: gradle/actions/setup-gradle
  dependency-version: 6.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: getsentry/craft
  dependency-version: 2.31.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/updater
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: getsentry/github-workflows/validate-pr
  dependency-version: 3.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added Dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 2, 2026
@dependabot dependabot Bot added Dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 2, 2026
@github-actions github-actions Bot added the risk: medium PR risk score: medium label Oct 2, 2026
@ric-oliv

ric-oliv commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

This bump includes github-workflows #178, which saves us ~20 minutes on the .NET (macos) CI runtime.

@ric-oliv
ric-oliv merged commit ea7fa3a into main Oct 2, 2026
47 checks passed
@ric-oliv
ric-oliv deleted the dependabot/github_actions/github-actions-9f7da8261c branch October 2, 2026 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant