Skip to content

Bump the github-actions-updates group with 4 updates - #31

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-1095071b54
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-1095071b54

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-updates group with 4 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml, lfreleng-actions/gerrit-review-action, lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml and lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml.

Updates lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml from 1.4.5 to 2.1.0

Release notes

Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.

v2.1.0

Downloads for this release

✨ New Features ✨

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

Links

v2.0.0

Downloads for this release

💥 Breaking Change 💥

🔧 Maintenance 🔧

Links

Commits
  • 3d548cc Merge pull request #390 from modeseven-lfreleng-actions/feat/fork-approval-gate
  • bfdb90e Fix: Address Copilot review feedback
  • b65bf61 Feat: Gate fork PR transfer on maintainer approval
  • a485b30 Merge pull request #389 from modeseven-lfreleng-actions/fix/pr-command-author...
  • 411afac Fix: Authorise @​github2gerrit comment directives
  • 9d659e2 Merge pull request #388 from lfreleng-actions/pre-commit-ci-update-config
  • da33e11 Chore: pre-commit autoupdate
  • f44ab26 Merge pull request #384 from modeseven-lfreleng-actions/fix/fork-pr-hardening
  • 5f9b6ff Fix: Address Copilot review feedback
  • 1e6e3ab Fix: Ignore fork-supplied .gitreview for Gerrit target
  • Additional commits viewable in compare view

Updates lfreleng-actions/gerrit-review-action from 1.1.2 to 1.1.3

Release notes

Sourced from lfreleng-actions/gerrit-review-action's releases.

v1.1.3

Downloads for this release

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

Commits
  • 1e3eae7 Merge pull request #146 from lfreleng-actions/dependabot/github_actions/step-...
  • cf518f9 Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0
  • c0cf518 Merge pull request #145 from lfreleng-actions/pre-commit-ci-update-config
  • 4ecb804 Chore: pre-commit autoupdate
  • 9658839 Merge pull request #144 from lfreleng-actions/dependabot/github_actions/step-...
  • bd38f6a Merge pull request #143 from lfreleng-actions/dependabot/github_actions/lfit/...
  • ee2e5ae Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1
  • e82f354 Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc...
  • 364f7f6 Merge pull request #142 from lfreleng-actions/pre-commit-ci-update-config
  • 31fb5bd Merge pull request #141 from lfreleng-actions/dependabot/github_actions/relea...
  • Additional commits viewable in compare view

Updates lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.3.0 to 0.5.0

Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.5.0

Downloads for this release

✨ New Features ✨

🐛 Bug Fixes 🐛

Links

v0.4.0

Downloads for this release

✨ New Features ✨

  • Feat: Expose jacoco_mode so callers can share execution data @​askb (#72)

Links

v0.3.1

Downloads for this release

🐛 Bug Fixes 🐛

  • Chore: Bump action pins to their latest releases @​askb (#53)

🔧 Maintenance 🔧

Links

Commits
  • 9219040 Merge pull request #73 from modeseven-lfreleng-actions/fix/lane-parity-and-go...
  • 937e05b Merge pull request #71 from modeseven-lfreleng-actions/feat/audit-examples
  • 4053dba Fix: Address Copilot review feedback
  • 48eb830 Docs: Record what callers set for the dropped inputs
  • f0507f1 Docs: Show the Go path in the Gerrit CLM example
  • 9e05a29 Docs: Name the CLM callers behind the cohesion claim
  • 8ca2d35 Fix: Accept fetch_depth and submodules for CLM
  • 6ee0886 Merge pull request #72 from lfreleng-actions/feat/jacoco-mode-input
  • b224976 Feat: Expose jacoco_mode so callers can share execution data
  • b843e00 Feat: Audit examples/ with actionlint and zizmor
  • Additional commits viewable in compare view

Updates lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.1 to 0.10.3

Release notes

Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases.

v0.10.3

Downloads for this release

🔧 Maintenance 🔧

Links

v0.10.2

Downloads for this release

🔧 Maintenance 🔧

... (truncated)

Commits
  • 87eacd1 Merge pull request #878 from lfit/pre-commit-ci-update-config
  • e80cc27 Merge pull request #877 from lfit/dependabot/github_actions/github/codeql-act...
  • 8cf781e Merge pull request #876 from lfit/dependabot/github_actions/github/codeql-act...
  • 9e5b39e Merge pull request #875 from lfit/dependabot/github_actions/lfreleng-actions/...
  • 3d515a0 Merge pull request #874 from lfit/dependabot/github_actions/lfreleng-actions/...
  • 75daab7 Merge pull request #873 from lfit/dependabot/github_actions/lfreleng-actions/...
  • 7b22cd2 Merge pull request #872 from lfit/dependabot/github_actions/lfreleng-actions/...
  • 3d8ec4f Merge pull request #871 from lfit/dependabot/github_actions/lfreleng-actions/...
  • 685f654 Merge pull request #867 from lfit/dependabot/github_actions/1password/load-se...
  • ecfca7e Merge pull request #870 from lfit/dependabot/github_actions/github/codeql-act...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-updates group with 4 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action), [lfreleng-actions/gerrit-review-action](https://github.com/lfreleng-actions/gerrit-review-action), [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows) and [lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml](https://github.com/lfit/releng-reusable-workflows).


Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.5 to 2.1.0
- [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases)
- [Commits](lfreleng-actions/github2gerrit-action@848115e...3d548cc)

Updates `lfreleng-actions/gerrit-review-action` from 1.1.2 to 1.1.3
- [Release notes](https://github.com/lfreleng-actions/gerrit-review-action/releases)
- [Commits](lfreleng-actions/gerrit-review-action@a1c036a...1e3eae7)

Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.3.0 to 0.5.0
- [Release notes](https://github.com/lfreleng-actions/security-workflows/releases)
- [Commits](lfreleng-actions/security-workflows@5882f13...9219040)

Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.10.1 to 0.10.3
- [Release notes](https://github.com/lfit/releng-reusable-workflows/releases)
- [Commits](lfit/releng-reusable-workflows@f7aae21...87eacd1)

---
updated-dependencies:
- dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions-updates
- dependency-name: lfreleng-actions/gerrit-review-action
  dependency-version: 1.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
- dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml
  dependency-version: 0.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml
  dependency-version: 0.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 1, 2026
@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

PR: #31
Mode: squash
Topic: GH-policy-distribution-31
Change-Ids:
I47acf94e6e8b2e72c1a055e9efcdffab256c8e37
Digest: d7c8716b001f
GitHub-Hash: f200e6f6b205cb6b

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

github-actions Bot commented Sep 1, 2026

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/distribution/+/147304

onap-github pushed a commit that referenced this pull request Sep 2, 2026
Bumps the github-actions-updates group with 4 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml, lfreleng-actions/gerrit-review-action, lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml and lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml.

Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 1.4.5 to 2.1.0
## Release notes

Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.

v2.1.0

✨ New Features ✨

Feat: Gate fork PR transfer on maintainer approval @​ModeSevenIndustrialSolutions (#390)

🐛 Bug Fixes 🐛

Fix: Authorise @​github2gerrit comment directives @​ModeSevenIndustrialSolutions (#389)

🔧 Maintenance 🔧

Chore: pre-commit autoupdate @pre-commit-ci[bot] (#388)

Links

Submit bugs/feature requests

v2.0.0

💥 Breaking Change 💥

Fix!: Harden fork pull request handling @​ModeSevenIndustrialSolutions (#384)

🔧 Maintenance 🔧

Chore: pre-commit autoupdate @pre-commit-ci[bot] (#371)
Chore: Bump astral-sh/setup-uv from 9.0.0 to 10.0.1 @dependabot[bot] (#373)
Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.0.4 to 0.0.5 @dependabot[bot] (#374)
Chore: Bump ruff from 0.16.2 to 0.16.3 @dependabot[bot] (#375)
Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#376)
Chore: Bump mypy from 2.3.0 to 2.3.1 @dependabot[bot] (#377)
Chore: Bump hatchling from 1.31.0 to 1.32.0 @dependabot[bot] (#378)
Chore: Bump lfreleng-actions/pypi-publish-action from 0.1.9 to 0.2.0 @dependabot[bot] (#379)

Links

Submit bugs/feature requests

## Commits

3d548cc Merge pull request #390 from modeseven-lfreleng-actions/feat/fork-approval-gate
bfdb90e Fix: Address Copilot review feedback
b65bf61 Feat: Gate fork PR transfer on maintainer approval
a485b30 Merge pull request #389 from modeseven-lfreleng-actions/fix/pr-command-author
411afac Fix: Authorise @​github2gerrit comment directives
9d659e2 Merge pull request #388 from lfreleng-actions/pre-commit-ci-update-config
da33e11 Chore: pre-commit autoupdate
f44ab26 Merge pull request #384 from modeseven-lfreleng-actions/fix/fork-pr-hardening
5f9b6ff Fix: Address Copilot review feedback
1e6e3ab Fix: Ignore fork-supplied .gitreview for Gerrit target
Additional commits viewable in compare view

Updates `lfreleng-actions/gerrit-review-action` from 1.1.2 to 1.1.3
## Release notes

Sourced from lfreleng-actions/gerrit-review-action's releases.

v1.1.3

🐛 Bug Fixes 🐛

Fix: resolve zizmor auditor persona findings @​ModeSevenIndustrialSolutions (#125)

🔧 Maintenance 🔧

Chore: Bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#117)
Chore: Bump release-drafter/release-drafter from 7.3.1 to 7.4.0 @dependabot[bot] (#118)
Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.3 to 0.1.4 @dependabot[bot] (#119)
Chore: Bump lfreleng-actions/tag-validate-action from 1.0.2 to 1.0.4 @dependabot[bot] (#120)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#121)
Chore: Bump release-drafter/release-drafter from 7.4.0 to 7.5.1 @dependabot[bot] (#123)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#124)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#126)
Chore: Bump step-security/harden-runner from 2.19.4 to 2.20.0 @dependabot[bot] (#127)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.2 to 0.7.4 @dependabot[bot] (#128)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#129)
Chore: Bump actions/checkout from 7.0.0 to 7.0.1 @dependabot[bot] (#130)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.7.4 to 0.8.1 @dependabot[bot] (#131)
Chore: Bump lfreleng-actions/tag-validate-action from 1.0.4 to 1.1.0 @dependabot[bot] (#132)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#133)
Chore: Disable pre-commit.ci autofix PRs @​ModeSevenIndustrialSolutions (#134)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.8.1 to 0.9.1 @dependabot[bot] (#135)
Chore: Bump release-drafter/release-drafter from 7.5.1 to 7.6.0 @dependabot[bot] (#136)
Chore: Bump lfreleng-actions/tag-validate-action from 1.1.0 to 1.1.2 @dependabot[bot] (#137)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#139)
Refactor: Call the shared release workflow @​ModeSevenIndustrialSolutions (#138)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.9.1 to 0.10.0 @dependabot[bot] (#140)
Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#141)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#142)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#143)
Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#144)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#145)
Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#146)

🎓 Code Quality 🎓

CI: Add OpenSSF Scorecard workflow @​ModeSevenIndustrialSolutions (#122)

Links

Submit bugs/feature requests

## Commits

1e3eae7 Merge pull request #146 from lfreleng-actions/dependabot/github_actions/step-
cf518f9 Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0
c0cf518 Merge pull request #145 from lfreleng-actions/pre-commit-ci-update-config
4ecb804 Chore: pre-commit autoupdate
9658839 Merge pull request #144 from lfreleng-actions/dependabot/github_actions/step-
bd38f6a Merge pull request #143 from lfreleng-actions/dependabot/github_actions/lfit/
ee2e5ae Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1
e82f354 Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-sc
364f7f6 Merge pull request #142 from lfreleng-actions/pre-commit-ci-update-config
31fb5bd Merge pull request #141 from lfreleng-actions/dependabot/github_actions/relea
Additional commits viewable in compare view

Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.3.0 to 0.5.0
## Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.5.0

✨ New Features ✨

Feat: Audit examples/ with actionlint and zizmor @​ModeSevenIndustrialSolutions (#71)

🐛 Bug Fixes 🐛

Fix: Close CLM checkout gap and record audit evidence @​ModeSevenIndustrialSolutions (#73)

Links

Submit bugs/feature requests

v0.4.0

✨ New Features ✨

Feat: Expose jacoco_mode so callers can share execution data @​askb (#72)

Links

Submit bugs/feature requests

v0.3.1

🐛 Bug Fixes 🐛

Chore: Bump action pins to their latest releases @​askb (#53)

🔧 Maintenance 🔧

Chore: pre-commit autoupdate @pre-commit-ci[bot] (#52)
CI(actions): Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#62)
CI(actions): Bump github/codeql-action/analyze from 4.37.6 to 4.37.7 @dependabot[bot] (#63)
CI(actions): Bump github/codeql-action/init from 4.37.6 to 4.37.7 @dependabot[bot] (#64)
CI(actions): Bump lfreleng-actions/harden-runner-block-action from 0.2.1 to 0.3.0 @dependabot[bot] (#65)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.0.4 to 0.0.5 @dependabot[bot] (#66)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.0.4 to 0.0.5 @dependabot[bot] (#67)
CI(actions): Bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 @dependabot[bot] (#68)
Chore: Bump harden-runner allow-list to v0.16.0 @​ModeSevenIndustrialSolutions (#69)

Links

Submit bugs/feature requests

## Commits

9219040 Merge pull request #73 from modeseven-lfreleng-actions/fix/lane-parity-and-go
937e05b Merge pull request #71 from modeseven-lfreleng-actions/feat/audit-examples
4053dba Fix: Address Copilot review feedback
48eb830 Docs: Record what callers set for the dropped inputs
f0507f1 Docs: Show the Go path in the Gerrit CLM example
9e05a29 Docs: Name the CLM callers behind the cohesion claim
8ca2d35 Fix: Accept fetch_depth and submodules for CLM
6ee0886 Merge pull request #72 from lfreleng-actions/feat/jacoco-mode-input
b224976 Feat: Expose jacoco_mode so callers can share execution data
b843e00 Feat: Audit examples/ with actionlint and zizmor
Additional commits viewable in compare view

Updates `lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml` from 0.10.1 to 0.10.3
## Release notes

Sourced from lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml's releases.

v0.10.3

🔧 Maintenance 🔧

Chore: Bump harden-runner allow-list to v0.16.0 @​ModeSevenIndustrialSolutions (#879)
Chore: Bump lfreleng-actions/harden-runner-block-action from 0.2.1 to 0.12.1 @dependabot[bot] (#868)
Chore: Bump lfreleng-actions/draft-release-promote-action from 0.1.4 to 0.1.5 @dependabot[bot] (#869)
Chore: Bump lfreleng-actions/tox-run-action from 0.1.2 to 0.1.3 @dependabot[bot] (#866)
Chore: Bump github/codeql-action/upload-sarif from 4.37.7 to 4.37.8 @dependabot[bot] (#870)
Chore: Bump 1password/load-secrets-action from 5.0.0 to 5.0.1 @dependabot[bot] (#867)
Chore: Bump lfreleng-actions/inject-issue-id-action from 0.1.2 to 0.1.3 @dependabot[bot] (#871)
Chore: Bump lfreleng-actions/docker-save-images-action from 0.1.1 to 0.2.0 @dependabot[bot] (#872)
Chore: Bump lfreleng-actions/checkout-gerrit-change-action from 1.0.2 to 1.1.0 @dependabot[bot] (#873)
Chore: Bump lfreleng-actions/tag-push-verify-action from 0.1.2 to 0.1.3 @dependabot[bot] (#874)
Chore: Bump lfreleng-actions/openssf-scorecard-summary-action from 0.1.1 to 0.1.2 @dependabot[bot] (#875)
Chore: Bump github/codeql-action/init from 4.37.7 to 4.37.8 @dependabot[bot] (#876)
Chore: Bump github/codeql-action/analyze from 4.37.7 to 4.37.8 @dependabot[bot] (#877)
Chore: pre-commit linting updates @pre-commit-ci[bot] (#878)

Links

Submit bugs/feature requests

v0.10.2

🔧 Maintenance 🔧

Chore: Bump lfreleng-actions/change-isolation-action from 0.2.0 to 0.2.1 @dependabot[bot] (#835)
Chore: Bump release-drafter/release-drafter/autolabeler from 7.6.0 to 7.7.0 @dependabot[bot] (#833)
Chore: Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 @dependabot[bot] (#838)
Chore: Bump actions/setup-java from 5.6.0 to 5.7.0 @dependabot[bot] (#837)
Chore: Bump lfreleng-actions/gradle-build-action from 0.5.0 to 0.6.0 @dependabot[bot] (#841)
Chore: Bump 1password/load-secrets-action from 4.1.1 to 5.0.0 @dependabot[bot] (#834)
Chore: pre-commit linting updates @pre-commit-ci[bot] (#842)
Chore: Bump lfreleng-actions/credential-load-action from 2.0.2 to 2.0.3 @dependabot[bot] (#845)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/gerrit-compose-required-tox-verify.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#847)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-sonatype-lifecycle.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#846)
Chore: Bump github/codeql-action/init from 4.37.3 to 4.37.6 @dependabot[bot] (#848)
Chore: Bump step-security/harden-runner from 2.20.0 to 2.20.1 @dependabot[bot] (#849)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/compose-jjb-verify.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#851)
Chore: Bump lfreleng-actions/maven-build-action from 0.3.0 to 0.3.1 @dependabot[bot] (#850)
Chore: Bump github/codeql-action/upload-sarif from 4.37.3 to 4.37.6 @dependabot[bot] (#852)
Chore: Bump github/codeql-action/analyze from 4.37.3 to 4.37.6 @dependabot[bot] (#853)
Chore: Bump github/codeql-action/analyze from 4.37.6 to 4.37.7 @dependabot[bot] (#857)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-verify-github-actions.yaml from 0.10.0 to 0.10.1 @dependabot[bot] (#856)
Chore: Bump github/codeql-action/upload-sarif from 4.37.6 to 4.37.7 @dependabot[bot] (#859)
Chore: Bump dorny/paths-filter from 4.0.2 to 4.0.3 @dependabot[bot] (#858)
Chore: Bump step-security/harden-runner from 2.20.1 to 2.21.0 @dependabot[bot] (#862)
Chore: pre-commit linting updates @pre-commit-ci[bot] (#864)

... (truncated)

## Commits

87eacd1 Merge pull request #878 from lfit/pre-commit-ci-update-config
e80cc27 Merge pull request #877 from lfit/dependabot/github_actions/github/codeql-act
8cf781e Merge pull request #876 from lfit/dependabot/github_actions/github/codeql-act
9e5b39e Merge pull request #875 from lfit/dependabot/github_actions/lfreleng-actions/
3d515a0 Merge pull request #874 from lfit/dependabot/github_actions/lfreleng-actions/
75daab7 Merge pull request #873 from lfit/dependabot/github_actions/lfreleng-actions/
7b22cd2 Merge pull request #872 from lfit/dependabot/github_actions/lfreleng-actions/
3d8ec4f Merge pull request #871 from lfit/dependabot/github_actions/lfreleng-actions/
685f654 Merge pull request #867 from lfit/dependabot/github_actions/1password/load-se
ecfca7e Merge pull request #870 from lfit/dependabot/github_actions/github/codeql-act
Additional commits viewable in compare view

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: I47acf94e6e8b2e72c1a055e9efcdffab256c8e37
GitHub-PR: #31
GitHub-Hash: f200e6f6b205cb6b
Signed-off-by: onap.gh2gerrit <releng+onap-gh2gerrit@linuxfoundation.org>
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Sep 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-updates-1095071b54 branch September 2, 2026 10:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants