Skip to content

Bump the actions-deps group with 3 updates#18

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions-deps-5e0e850687
Closed

Bump the actions-deps group with 3 updates#18
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions-deps-5e0e850687

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions-deps group with 3 updates: lfreleng-actions/github2gerrit-action, actions/setup-java and lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml.

Updates lfreleng-actions/github2gerrit-action from 1.2.3 to 1.2.4

Release notes

Sourced from lfreleng-actions/github2gerrit-action's releases.

v1.2.4

Downloads for this release

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

Commits
  • 806c001 Merge pull request #284 from modeseven-lfreleng-actions/fix/cryptography-open...
  • 875879a Fix: resolve vulnerable OpenSSL in cryptography
  • 587d4f0 Merge pull request #283 from lfreleng-actions/dependabot/uv/pyjwt-2.13.0
  • 93dff5d Chore: Bump pyjwt from 2.12.1 to 2.13.0
  • 71763aa Merge pull request #282 from modeseven-lfreleng-actions/fix/security-zizmor-c...
  • 309622b Fix: address Zizmor and CodeQL security findings
  • fb35f88 Merge pull request #280 from lfreleng-actions/pre-commit-ci-update-config
  • b2d33e5 Merge pull request #281 from modeseven-lfreleng-actions/fix/gerrit-auth-guard...
  • dbc0a93 Fix: surface Gerrit auth failures without noise
  • 847130b Chore: pre-commit autoupdate
  • Additional commits viewable in compare view

Updates actions/setup-java from 5.2.0 to 5.3.0

Release notes

Sourced from actions/setup-java's releases.

v5.3.0

What's Changed

New Contributors

Full Changelog: actions/setup-java@v5...v5.3.0

Commits
  • ad2b381 Bump @​vercel/ncc from 0.38.1 to 0.44.0 (#1018)
  • b24df5b Make the Adoptopenjdk package type look at the Temurin repo first for latest ...
  • 43120bc Implement pagination with link headers for Adoptium based apis (#1014)
  • ad9d6a6 Bump @​types/node from 24.1.0 to 25.9.3 (#950)
  • 039af37 Bump picomatch, @​types/jest, jest, jest-circus and ts-jest (#1016)
  • 1756ab6 Bump eslint-config-prettier from 8.10.0 to 10.1.8 (#881)
  • 662bb59 Bump @​typescript-eslint/eslint-plugin from 8.35.1 to 8.46.2 (#952)
  • 1071fc1 fix: resolve npm audit vulnerabilities in fast-xml-builder and fast-xml-parse...
  • 576b821 Merge pull request #674 from gdams/alpine
  • 307d3a2 update readme for ubuntu sudo java_home behavior (#1013)
  • Additional commits viewable in compare view

Updates lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml from 0.5.0 to 0.6.0

Release notes

Sourced from lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml's releases.

v0.6.0

Downloads for this release

✨ New Features ✨

🔧 Maintenance 🔧

  • Chore: pre-commit linting updates @pre-commit-ci[bot] (#679)
  • Chore: Bump lfreleng-actions/nexus-publish-action from 0.2.0 to 0.2.1 @dependabot[bot] (#678)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-jjb-verify.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#674)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-packer-verify.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#676)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-sonatype-lifecycle.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#675)
  • Chore: Bump github/codeql-action from 4.36.1 to 4.36.2 @dependabot[bot] (#677)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/gerrit-compose-required-tox-verify.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#673)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#672)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-repo-linting.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#670)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-verify-github-actions.yaml from 0.3.4 to 0.5.0 @dependabot[bot] (#671)

Links

Commits
  • f43b219 Merge pull request #681 from modeseven-lfit/feat/package-hardening-audit
  • 6f57890 Feat: Add package hardening audit workflow
  • f8a4d0a Merge pull request #680 from modeseven-lfit/ci/harden-runner-block-mode
  • 4d5996a Fix: Block egress, silence zizmor on autolabeler
  • 82c150a Feat: Add reusable SHA-pinned actions workflow
  • 96e32b5 Feat: Add reusable autolabeler workflow
  • ce92cf4 Feat: Add reusable zizmor scan workflow
  • e22e915 Style: Refine workflow display names
  • 371b433 Fix: Harden reusable workflow permissions
  • 8b9dd61 CI: Enable harden-runner block egress mode
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions-deps group with 3 updates: [lfreleng-actions/github2gerrit-action](https://github.com/lfreleng-actions/github2gerrit-action), [actions/setup-java](https://github.com/actions/setup-java) and [lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml](https://github.com/lfit/releng-reusable-workflows).


Updates `lfreleng-actions/github2gerrit-action` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases)
- [Changelog](https://github.com/lfreleng-actions/github2gerrit-action/blob/main/docs/RELEASE-v0.2.0.md)
- [Commits](lfreleng-actions/github2gerrit-action@f5891c5...806c001)

Updates `actions/setup-java` from 5.2.0 to 5.3.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@be666c2...ad2b381)

Updates `lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml` from 0.5.0 to 0.6.0
- [Release notes](https://github.com/lfit/releng-reusable-workflows/releases)
- [Commits](lfit/releng-reusable-workflows@b2adc11...f43b219)

---
updated-dependencies:
- dependency-name: lfreleng-actions/github2gerrit-action
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions-deps
- dependency-name: actions/setup-java
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
- dependency-name: lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml
  dependency-version: 0.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 17, 2026
@github-actions

Copy link
Copy Markdown

PR: #18
Mode: squash
Topic: GH-openflowplugin-18
Change-Ids:
I33f96fa2a438d1129beef62d2581fe0c58767f3d
Digest: 8b64bc7b3b7e
GitHub-Hash: baf7801683223962

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://git.opendaylight.org/gerrit/c/openflowplugin/+/123615

odl-github pushed a commit that referenced this pull request Jun 17, 2026
Bumps the actions-deps group with 3 updates: [lfreleng-actions/github2gerrit-action](https://github.com/lfreleng-actions/github2gerrit-action), [actions/setup-java](https://github.com/actions/setup-java) and [lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml](https://github.com/lfit/releng-reusable-workflows).
Updates `lfreleng-actions/github2gerrit-action` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases)
- [Changelog](https://github.com/lfreleng-actions/github2gerrit-action/blob/main/docs/RELEASE-v0.2.0.md)
- [Commits](lfreleng-actions/github2gerrit-action@f5891c5...806c001)
Updates `actions/setup-java` from 5.2.0 to 5.3.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@be666c2...ad2b381)
Updates `lfit/releng-reusable-workflows/.github/workflows/composed-maven-sonar-cloud.yaml` from 0.5.0 to 0.6.0
- [Release notes](https://github.com/lfit/releng-reusable-workflows/releases)
- [Commits](lfit/releng-reusable-workflows@b2adc11...f43b219)

Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: I33f96fa2a438d1129beef62d2581fe0c58767f3d
GitHub-PR: #18
GitHub-Hash: baf7801683223962
Signed-off-by: gh2gerrit <releng+odl-gh2gerrit@linuxfoundation.org>
@github-actions

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Jun 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot dependabot Bot deleted the dependabot/github_actions/actions-deps-5e0e850687 branch June 17, 2026 11:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants