Skip to content

Bump the github-actions-updates group with 2 updates - #38

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-1b562637e2
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-updates-1b562637e2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml.

Updates lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml from 2.1.1 to 2.2.2

Release notes

Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.

v2.2.2

Downloads for this release

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

v2.2.1

Downloads for this release

🐛 Bug Fixes 🐛

Links

v2.2.0

Downloads for this release

✨ New Features ✨

🐛 Bug Fixes 🐛

🔧 Maintenance 🔧

  • Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.1 to 0.2.2 @dependabot[bot] (#424)
  • Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.1 to 0.10.3 @dependabot[bot] (#425)
  • Chore: Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#426)
  • Chore: Bump responses from 0.26.2 to 0.26.3 @dependabot[bot] (#427)

... (truncated)

Commits
  • 5f84610 Merge pull request #453 from lfreleng-actions/pre-commit-ci-update-config
  • e6edf55 Chore: pre-commit autoupdate
  • 047f4cd Merge pull request #449 from modeseven-lfreleng-actions/fix/gerrit-port-prece...
  • c58fb38 Merge pull request #447 from modeseven-lfreleng-actions/fix/pin-sync
  • 25f8632 Merge pull request #452 from modeseven-lfreleng-actions/fix/codeql-host-subst...
  • 5f6521a Test: Assert the whole no-change message, not the host
  • e35278a Merge pull request #451 from lfreleng-actions/dependabot/uv/ruff-0.16.7
  • 41d359e Merge pull request #450 from lfreleng-actions/dependabot/github_actions/astra...
  • 2e2fe48 Chore: Bump ruff from 0.16.6 to 0.16.7
  • 6965273 Chore: Bump astral-sh/setup-uv from 10.0.1 to 10.1.0
  • Additional commits viewable in compare view

Updates lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml from 0.7.0 to 0.8.0

Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.8.0

Downloads for this release

✨ New Features ✨

🔧 Maintenance 🔧

🎓 Code Quality 🎓

Links

Commits
  • 7483557 Merge pull request #107 from lfreleng-actions/pre-commit-ci-update-config
  • 178e5fe Chore: pre-commit autoupdate
  • ca64c26 Merge pull request #99 from modeseven-lfreleng-actions/feat/migration-audit-i...
  • a6e1fd2 Merge pull request #106 from modeseven-lfreleng-actions/chore/bump-maven-defa...
  • 68cb394 Chore: Default Maven to 3.9.11 on the build lanes
  • 46e670d Merge pull request #80 from lfreleng-actions/pre-commit-ci-update-config
  • 8da137f Merge branch 'main' into pre-commit-ci-update-config
  • a37cdc5 Merge pull request #105 from modeseven-lfreleng-actions/ci/self-repository-sy...
  • 2dbacca CI: Adopt the self-repository reference syntax
  • c83f7d8 Chore: pre-commit autoupdate
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-updates group with 2 updates: [lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml](https://github.com/lfreleng-actions/github2gerrit-action) and [lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml](https://github.com/lfreleng-actions/security-workflows).


Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.1.1 to 2.2.2
- [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases)
- [Commits](lfreleng-actions/github2gerrit-action@bbf43f3...5f84610)

Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.7.0 to 0.8.0
- [Release notes](https://github.com/lfreleng-actions/security-workflows/releases)
- [Commits](lfreleng-actions/security-workflows@bdcf7d8...7483557)

---
updated-dependencies:
- dependency-name: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
- dependency-name: lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml
  dependency-version: 0.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 24, 2026
@github-actions

Copy link
Copy Markdown

PR: #38
Mode: squash
Topic: GH-policy-api-38
Change-Ids:
If85f6e4a499e25ddf7d2cf8d3e27a3d506e6f832
Digest: 5bb9a4c34d9f
GitHub-Hash: da84b555d04e34df

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/api/+/147733

onap-github pushed a commit that referenced this pull request Sep 24, 2026
Bumps the github-actions-updates group with 2 updates: lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml and lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml.

Updates `lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml` from 2.1.1 to 2.2.2
## Release notes

Sourced from lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml's releases.

v2.2.2

🐛 Bug Fixes 🐛

Fix: Settle one effective Gerrit host in derivation @​ModeSevenIndustrialSolutions (#446)
Fix: Give the Gerrit port its own precedence @​ModeSevenIndustrialSolutions (#449)

🔧 Maintenance 🔧

Chore: Bump astral-sh/setup-uv from 10.0.1 to 10.1.0 @dependabot[bot] (#450)
Chore: Bump ruff from 0.16.6 to 0.16.7 @dependabot[bot] (#451)
Build: Sync mypy hook pins from uv.lock instead of testing them @​ModeSevenIndustrialSolutions (#447)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#453)

🎓 Code Quality 🎓

Test: Assert the whole no-change message, not the host @​ModeSevenIndustrialSolutions (#452)

Links

Submit bugs/feature requests

v2.2.1

🐛 Bug Fixes 🐛

Fix: Resolve the Gerrit project from .gitreview early @​ModeSevenIndustrialSolutions (#442)

Links

Submit bugs/feature requests

v2.2.0

✨ New Features ✨

Feat: Lift the fork gate from a privileged trigger @​ModeSevenIndustrialSolutions (#418)

🐛 Bug Fixes 🐛

Fix: Harden the lint and test gates @​ModeSevenIndustrialSolutions (#412)
Fix: Make every documented setting reachable @​ModeSevenIndustrialSolutions (#423)

🔧 Maintenance 🔧

Chore: Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.1 to 0.2.2 @dependabot[bot] (#424)
Chore: Bump lfit/releng-reusable-workflows/.github/workflows/reuse-openssf-scorecard.yaml from 0.10.1 to 0.10.3 @dependabot[bot] (#425)
Chore: Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#426)
Chore: Bump responses from 0.26.2 to 0.26.3 @dependabot[bot] (#427)

... (truncated)

## Commits

5f84610 Merge pull request #453 from lfreleng-actions/pre-commit-ci-update-config
e6edf55 Chore: pre-commit autoupdate
047f4cd Merge pull request #449 from modeseven-lfreleng-actions/fix/gerrit-port-prece
c58fb38 Merge pull request #447 from modeseven-lfreleng-actions/fix/pin-sync
25f8632 Merge pull request #452 from modeseven-lfreleng-actions/fix/codeql-host-subst
5f6521a Test: Assert the whole no-change message, not the host
e35278a Merge pull request #451 from lfreleng-actions/dependabot/uv/ruff-0.16.7
41d359e Merge pull request #450 from lfreleng-actions/dependabot/github_actions/astra
2e2fe48 Chore: Bump ruff from 0.16.6 to 0.16.7
6965273 Chore: Bump astral-sh/setup-uv from 10.0.1 to 10.1.0
Additional commits viewable in compare view

Updates `lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml` from 0.7.0 to 0.8.0
## Release notes

Sourced from lfreleng-actions/security-workflows/.github/workflows/sonatype-lifecycle.yaml's releases.

v0.8.0

✨ New Features ✨

Feat: Settle the migration-audit input regressions @​ModeSevenIndustrialSolutions (#99)

🔧 Maintenance 🔧

CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/clear-action-cache.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#101)
CI(actions): Bump lfreleng-actions/generic-workflows/.github/workflows/release.yaml from 0.2.2 to 0.3.1 @dependabot[bot] (#102)
CI(actions): Bump step-security/harden-runner from 2.21.0 to 2.21.1 @dependabot[bot] (#103)
CI(actions): Bump lfreleng-actions/zizmor-scan-action from 0.5.0 to 0.5.1 @dependabot[bot] (#104)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#80)
Chore: Default Maven to 3.9.11 on the build lanes @​ModeSevenIndustrialSolutions (#106)
Chore: pre-commit autoupdate @pre-commit-ci[bot] (#107)

🎓 Code Quality 🎓

CI: Adopt the self-repository reference syntax @​ModeSevenIndustrialSolutions (#105)

Links

Submit bugs/feature requests

## Commits

7483557 Merge pull request #107 from lfreleng-actions/pre-commit-ci-update-config
178e5fe Chore: pre-commit autoupdate
ca64c26 Merge pull request #99 from modeseven-lfreleng-actions/feat/migration-audit-i
a6e1fd2 Merge pull request #106 from modeseven-lfreleng-actions/chore/bump-maven-defa
68cb394 Chore: Default Maven to 3.9.11 on the build lanes
46e670d Merge pull request #80 from lfreleng-actions/pre-commit-ci-update-config
8da137f Merge branch 'main' into pre-commit-ci-update-config
a37cdc5 Merge pull request #105 from modeseven-lfreleng-actions/ci/self-repository-sy
2dbacca CI: Adopt the self-repository reference syntax
c83f7d8 Chore: pre-commit autoupdate
Additional commits viewable in compare view

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <[email protected]>
Change-Id: If85f6e4a499e25ddf7d2cf8d3e27a3d506e6f832
GitHub-PR: #38
GitHub-Hash: da84b555d04e34df
Signed-off-by: onap.gh2gerrit <[email protected]>
@github-actions

Copy link
Copy Markdown

Automated PR Closure

This pull request has been automatically closed by GitHub2Gerrit.

The corresponding Gerrit change has been accepted and merged ✅

The changes from this PR are now part of the main codebase in Gerrit.


This is an automated action performed by the GitHub2Gerrit tool.

@github-actions github-actions Bot closed this Sep 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-updates-1b562637e2 branch September 24, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

0 participants