Skip to content

chore(deps): update github-actions - #983

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
astral-sh/setup-uv action minor v10.0.1v10.1.0
docker/build-push-action action minor v7.3.0v7.4.0
docker/setup-buildx-action action minor v4.3.0v4.4.1
docker/setup-qemu-action action minor v4.2.0v4.4.0
github/codeql-action action minor v4.37.9v4.38.0
zizmorcore/zizmor-action action patch v0.6.3v0.6.4

Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v10.1.0: 🌈 New output python-runtime-idand respect NO_PROXY

Compare Source

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 (comment) for details on why this can be useful.

🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
docker/build-push-action (docker/build-push-action)

v7.4.0

Compare Source

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

docker/setup-buildx-action (docker/setup-buildx-action)

v4.4.1

Compare Source

v4.4.0

Compare Source

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

docker/setup-qemu-action (docker/setup-qemu-action)

v4.4.0

Compare Source

Full Changelog: docker/setup-qemu-action@v4.3.0...v4.4.0

v4.3.0

Compare Source

Full Changelog: docker/setup-qemu-action@v4.2.0...v4.3.0

github/codeql-action (github/codeql-action)

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129
zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.6.4

Compare Source

Sponsorship is appreciated!

zizmor 1.30.1 is now the default version.

Release notes: https://docs.zizmor.sh/release-notes/#​1301


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@toolhive-release-app

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ agent-observability-eval-bootstrap

  • Status: Passed
  • Findings: 11
  • Allowed (not blocking): 10
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)

Summary: Scanned 1 skill(s), all passed security checks. ✅

@toolhive-release-app

Copy link
Copy Markdown
Contributor

🔒 MCP Security Scan Results

✅ adb-mysql-mcp-server

  • Status: Passed
  • Tools scanned: 3
  • Result: No security issues detected

✅ agentql-mcp

  • Status: Passed
  • Tools scanned: 1
  • Result: No security issues detected

Summary: Scanned 2 MCP server(s), all passed security checks. ✅

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4e226e9 to d7affe9 Compare September 15, 2026 18:16
@renovate
renovate Bot force-pushed the renovate/github-actions branch from d7affe9 to 74ec52b Compare September 16, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants