Skip to content

build: bump the github-actions group across 2 directories with 1 update#4520

Merged
fr4nc1sc0-r4m0n merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-4c406f0ea6
Jun 29, 2026
Merged

build: bump the github-actions group across 2 directories with 1 update#4520
fr4nc1sc0-r4m0n merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-4c406f0ea6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update in the / directory: actions/attest.
Bumps the github-actions group with 1 update in the /.github/workflows directory: actions/attest.

Updates actions/attest from 4.1.0 to 4.1.1

Release notes

Sourced from actions/attest's releases.

v4.1.1

What's Changed

Full Changelog: actions/attest@v4.1.0...v4.1.1

Commits
  • a1948c3 Bump @​sigstore/oci from 0.6.1 to 0.7.1 (#432)
  • b21da33 Bump csv-parse from 5.6.0 to 6.2.1 (#414)
  • d811ccf Bump actions/checkout from 6.0.3 to 7.0.0 (#431)
  • 2e48bd5 Bump the npm-development group across 1 directory with 4 updates (#433)
  • 4ad76f8 Bump markdown-it and markdownlint-cli (#425)
  • 701ae0b Bump tar from 7.5.11 to 7.5.17 (#429)
  • a8f22ca Bump form-data from 4.0.5 to 4.0.6 (#428)
  • 01540af Bump typescript from 5.9.3 to 6.0.3 (#407)
  • 5ec407f Bump github/codeql-action in the actions-minor group (#422)
  • 08210f8 Bump the npm-development group across 1 directory with 8 updates (#419)
  • Additional commits viewable in compare view

Updates actions/attest from 4.1.0 to 4.1.1

Release notes

Sourced from actions/attest's releases.

v4.1.1

What's Changed

Full Changelog: actions/attest@v4.1.0...v4.1.1

Commits
  • a1948c3 Bump @​sigstore/oci from 0.6.1 to 0.7.1 (#432)
  • b21da33 Bump csv-parse from 5.6.0 to 6.2.1 (#414)
  • d811ccf Bump actions/checkout from 6.0.3 to 7.0.0 (#431)
  • 2e48bd5 Bump the npm-development group across 1 directory with 4 updates (#433)
  • 4ad76f8 Bump markdown-it and markdownlint-cli (#425)
  • 701ae0b Bump tar from 7.5.11 to 7.5.17 (#429)
  • a8f22ca Bump form-data from 4.0.5 to 4.0.6 (#428)
  • 01540af Bump typescript from 5.9.3 to 6.0.3 (#407)
  • 5ec407f Bump github/codeql-action in the actions-minor group (#422)
  • 08210f8 Bump the npm-development group across 1 directory with 8 updates (#419)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 1 update in the / directory: [actions/attest](https://github.com/actions/attest).
Bumps the github-actions group with 1 update in the /.github/workflows directory: [actions/attest](https://github.com/actions/attest).


Updates `actions/attest` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@59d8942...a1948c3)

Updates `actions/attest` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@59d8942...a1948c3)

---
updated-dependencies:
- dependency-name: actions/attest
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/attest
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 28, 2026
@dependabot dependabot Bot requested review from a team as code owners June 28, 2026 22:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 28, 2026
@github-actions

Copy link
Copy Markdown

🤖 GitHub comments

Just comment with:

  • run docs-build : Re-trigger the docs validation. (use unformatted text in the comment!)

@mergify

mergify Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Queued — the merge queue status continues in this comment ↓.

@mergify

mergify Bot commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Merge Queue Status

This pull request spent 28 minutes 59 seconds in the queue, including 28 minutes 10 seconds running CI.

Required conditions to merge
  • github-require-last-push-approval [🛡 GitHub repository ruleset rule branch protection main]
  • github-review-approved [🛡 GitHub repository ruleset rule [org] Require a PR for Renovate]
  • github-review-approved [🛡 GitHub repository ruleset rule [org] Require a PR]
  • github-review-approved [🛡 GitHub repository ruleset rule branch protection main]
  • github-review-decision = APPROVED [🛡 GitHub repository ruleset rule branch protection main]
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-success = @github-actions/build / build
    • check-neutral = @github-actions/build / build
    • check-skipped = @github-actions/build / build
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-skipped = Application Server integration tests
    • check-neutral = Application Server integration tests
    • check-success = Application Server integration tests
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-success = build / build
    • check-neutral = build / build
    • check-skipped = build / build
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-success = CLA
    • check-neutral = CLA
    • check-skipped = CLA
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-skipped = Non-Application Server integration tests
    • check-neutral = Non-Application Server integration tests
    • check-success = Non-Application Server integration tests
  • any of [🛡 GitHub repository ruleset rule branch protection main]:
    • check-success = Unit Tests
    • check-neutral = Unit Tests
    • check-skipped = Unit Tests

Reason

Pull request #4520 has been dequeued

GitHub refused to merge the pull request. Repository rule violations found

3 of 6 required status checks are in progress. This is usually enforced by a branch protection or ruleset rule.

Hint

You should look at the reason for the failure and decide if the pull request needs to be fixed or if you want to requeue it.
If you do update this pull request, it will automatically be requeued once the queue conditions match again.
If you think this was a flaky issue instead, you can requeue the pull request, without updating it, by posting a @mergifyio queue comment.

Tick the box to put this pull request back in the merge queue (same as @mergifyio queue).

  • Requeue this pull request

@mergify mergify Bot added the queued label Jun 29, 2026
mergify Bot added a commit that referenced this pull request Jun 29, 2026
@mergify mergify Bot added dequeued and removed queued labels Jun 29, 2026

@fr4nc1sc0-r4m0n fr4nc1sc0-r4m0n left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@fr4nc1sc0-r4m0n fr4nc1sc0-r4m0n merged commit 7f6c358 into main Jun 29, 2026
38 of 47 checks passed
@fr4nc1sc0-r4m0n fr4nc1sc0-r4m0n deleted the dependabot/github_actions/github-actions-4c406f0ea6 branch June 29, 2026 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent-java dependencies Pull requests that update a dependency file dequeued github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants