Skip to content

chore(deps): Bump the github-actions group across 1 directory with 4 updates - #22

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-85f0130962
Closed

chore(deps): Bump the github-actions group across 1 directory with 4 updates#22
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-85f0130962

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2025

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 4 updates in the / directory: actions/checkout, actions/setup-go, helm/kind-action and docker/build-push-action.

Updates actions/checkout from 4 to 5

Release notes

Sourced from actions/checkout's releases.

v5.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

Full Changelog: actions/checkout@v4...v5.0.0

v4.3.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v4...v4.3.0

v4.2.2

What's Changed

Full Changelog: actions/checkout@v4.2.1...v4.2.2

v4.2.1

What's Changed

New Contributors

Full Changelog: actions/checkout@v4.2.0...v4.2.1

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

V5.0.0

V4.3.0

v4.2.2

v4.2.1

v4.2.0

v4.1.7

v4.1.6

v4.1.5

v4.1.4

v4.1.3

... (truncated)

Commits

Updates actions/setup-go from 4 to 6

Release notes

Sourced from actions/setup-go's releases.

v6.0.0

What's Changed

Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

New Contributors

Full Changelog: actions/setup-go@v5...v6.0.0

v5.5.0

What's Changed

Bug fixes:

Dependency updates:

New Contributors

Full Changelog: actions/setup-go@v5...v5.5.0

v5.4.0

What's Changed

Dependency updates :

... (truncated)

Commits

Updates helm/kind-action from 1.10.0 to 1.12.0

Release notes

Sourced from helm/kind-action's releases.

v1.12.0

What's Changed

New Contributors

Full Changelog: helm/kind-action@v1.11.0...v1.12.0

v1.11.0

What's Changed

New Contributors

Full Changelog: helm/kind-action@v1.10.0...v1.11.0

Commits
  • a1b0e39 Bump actions/checkout from 4.1.4 to 4.2.2 in the actions group (#130)
  • 9315f6b feat: options to configure local registry (#113)
  • aed9fb9 update kind to use release v0.26.0 (#129)
  • ae94020 update kind to default to release v0.24.0 (#122)
  • 9fdad06 fix: Use new mirror for downloading kubectl (#127)
  • c93960c Bump actions/checkout from 4.2.1 to 4.2.2 in the actions group (#125)
  • fce224d Bump actions/checkout from 4.2.0 to 4.2.1 in the actions group (#123)
  • 0958ddc Bump actions/checkout from 4.1.7 to 4.2.0 in the actions group (#121)
  • 5d66646 feat: add custom kubeconfig option as action input (#119)
  • 6f17223 Bump actions/checkout from 4.1.7 to 4.2.0 in the actions group (#120)
  • Additional commits viewable in compare view

Updates docker/build-push-action from 5 to 6

Release notes

Sourced from docker/build-push-action's releases.

v6.0.0

[!NOTE] This major release adds support for generating Build summary and exporting build record for your build. You can disable this feature by setting DOCKER_BUILD_SUMMARY: false environment variable in your workflow.

Full Changelog: docker/build-push-action@v5.4.0...v6.0.0

v5.4.0

Full Changelog: docker/build-push-action@v5.3.0...v5.4.0

v5.3.0

Full Changelog: docker/build-push-action@v5.2.0...v5.3.0

v5.2.0

Full Changelog: docker/build-push-action@v5.1.0...v5.2.0

v5.1.0

Full Changelog: docker/build-push-action@v5.0.0...v5.1.0

Commits
  • 2634353 Merge pull request #1381 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • c0432d2 chore: update generated content
  • 0bb1f27 set builder driver and endpoint attributes for dbc summary support
  • 5f9dbf9 chore(deps): Bump @​docker/actions-toolkit from 0.61.0 to 0.62.1
  • 0788c44 Merge pull request #1375 from crazy-max/remove-gcr
  • aa179ca e2e: remove GCR
  • 1dc7386 Merge pull request #1364 from crazy-max/history-export-cmd
  • 9c9803f chore: update generated content
  • db1f6c4 DOCKER_BUILD_EXPORT_LEGACY env var to opt-in for legacy export
  • 721e8c7 Bump @​docker/actions-toolkit from 0.59.0 to 0.61.0
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 4 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/setup-go](https://github.com/actions/setup-go), [helm/kind-action](https://github.com/helm/kind-action) and [docker/build-push-action](https://github.com/docker/build-push-action).


Updates `actions/checkout` from 4 to 5
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v5)

Updates `actions/setup-go` from 4 to 6
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v4...v6)

Updates `helm/kind-action` from 1.10.0 to 1.12.0
- [Release notes](https://github.com/helm/kind-action/releases)
- [Commits](helm/kind-action@v1.10.0...v1.12.0)

Updates `docker/build-push-action` from 5 to 6
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-go
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: helm/kind-action
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 4, 2025
@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2025

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 4, 2025
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-85f0130962 branch September 4, 2025 11:48
sunib added a commit that referenced this pull request Jul 30, 2026
…pported, and one encoder for the mirror (#290)

* docs(queue): strike the shipped attribution work and rank what it left

The queue was built bottom-up: Tier 0 and Tier 1 are still unbuilt while the
largest Tier 2 item shipped anyway, together with a consumer ask (#23) that was
filed and fixed before it was ever ranked. Record that rather than smoothing it
into a re-ranking.

Struck: the fact stream, #23, the name tier, metrics Phase 1. Ranked in their
place: the removal-wait decision (F then C, Tier 1, because a watched type the
audit policy excludes is #15's failure mode one level down), the head-of-line
block on the shard goroutine, the aggregated create, and the stream's two
capacity questions.

#5 loses one of its two arguments and says so: "audit cannot attribute a
finalized delete at all" is false now that the sticky removal pointer does
exactly that. The first argument — a hosted control plane will not give you an
audit webhook — carries it alone.

Also answers what "Event" meant in the inference deletion's open question: a
real corev1.Event, which is not nearly free there because placement runs on the
branch worker rather than in a controller, must attach to the GitTarget rather
than to an object that may live in a remote cluster, and is a notification
rather than a record. The durable half belongs to B2.

* fix(analyzer)!: a refusal that can be fixed must not call itself unsupported

Consumer ask #22, all three parts. Each one was a sentence, and each one was
misleading a consumer that reads our source as the contract.

ReasonRefusedStructural documented itself as "the permanent support boundary".
It has not been permanent since Solvable shipped: the same code answers both
ways, correctly, because a root refused for a configMapGenerator is nobody's to
solve while one whose kustomization.yaml does not parse is one commit from
adoptable. A consumer wrote Permanent = true off that sentence and shipped "this
can never be synced" to the second author. The doc now points at Solvable.

The refusal detail had one stem for both branches, so a solvable refusal read
"kustomization uses unsupported feature(s): unparseable" — the opposite of what
Solvable said beside it. The stem now comes from the same classification that
sets Solvable, so the two cannot drift the way the doc comment did. The
not-solvable stem is byte-identical to what it was, which is why the corpus
baseline moves on exactly one refusal: the one that was lying.

The nested-kustomization message shares that stem, and stops listing every
construct it might have been in favour of the ones it found.

Actor now states which scans can report which values. The ask asked whether a
structure-only scan can name the platform operator; it cannot, and the reason is
not the one reported. InScope gates only IssueOutOfScope; IssueUnresolvedKRM
carries the same actor and is gated on a type registry that has seen a cluster.
Cluster-awareness is the real gate, which is what makes the guarantee safe to
state, and a corpus test pins it.

BREAKING CHANGE: the refusal detail for a solvable render-root refusal and the
message on an unsupported-kustomize issue are reworded. Both are documented as
unstable strings; no code switches on them.

* fix(git): one encoder for a create and an update, so the diff is one field

Consumer ask #11, filed as cosmetic and accepted as not. A create serialized
through sigs.k8s.io/yaml and an update through gopkg.in/yaml.v3, so sequences
landed at the parent key's column in one and two columns deeper in the other,
and the first update after a create rewrote every list line in the file to carry
one changed field. For a product whose entire output is a Git diff, that is not
ugliness, it is illegibility.

Built in the order the queue asked for: a test pinning create and update output
byte-for-byte first, then the fix wherever it failed.

The direction was forced rather than chosen. yaml.v3 always indents a sequence
under its mapping key, so the create style cannot be produced by the encoder
that edits documents in place; create moved to yaml.v3. It is also what every
file in a repository the operator has already updated once looks like.

The fix is a package and not a shared constant: two encoders agreeing on an
indent width are one refactor from diverging again, silently, because both emit
valid YAML and nothing fails. internal/yamlstyle is the only place the write
path constructs an encoder, and a source-scanning test refuses a second one.

It also contains one behaviour difference that had to be absorbed: yaml.v3
raises "cannot marshal type" by panicking with a bare string, which escapes its
own recover, where the JSON path returned an error. A write path that returns an
error retries and reports; one that panics takes the process down.

Adding a key still differs between the two paths, deliberately: a patch appends
it where the document's own order puts it while a canonical render sorts keys,
and preserving a human's key order is what the in-place editor is for.

* docs(queue): strike #22 and #11, and record what building them taught

Tier 0 and the one Tier 3 entry worth doing beside it are built, so they leave
the queue. Both entries keep their argument and gain what the work found:

#22's Actor answer was better than the doc line asked for — cluster-awareness is
the gate, not AcceptancePolicy.InScope, and the second raise site the consumer's
trace missed is the one that proves it.

#11 records three things that only came out of doing it: the direction was
forced by yaml.v3's sequence indentation rather than chosen, the fix had to be a
package rather than a shared constant, and one panic-versus-error difference had
to be absorbed at the seam.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants