Skip to content

🌱(deps): Bump the all-github-actions group with 2 updates - #871

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/main/all-github-actions-1718ccd4db
Open

🌱(deps): Bump the all-github-actions group with 2 updates#871
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/main/all-github-actions-1718ccd4db

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-github-actions group with 2 updates: kiegroup/git-backporting and zizmorcore/zizmor-action.

Updates kiegroup/git-backporting from 4.9.1 to 4.10.0

Release notes

Sourced from kiegroup/git-backporting's releases.

Release 4.10.0

4.10.0 (2026-07-25)

Features

  • add ability to open PRs from forked repo (#216) (da19e2a)
  • filter unused blobs when cloning repo (#217) (9a4855c)

Bug Fixes

  • deps: resolve all npm audit vulnerabilities (39 → 0) (#220) (84c49d5)
  • properly identify rebase and then ff (#215) (6ae3bf8)
  • removed legacy node 18 from matrix run (56c0deb)
  • use node 22 and override undici version to 6.24.1 (0c16eed)
  • wrong resolved registry in package-lock.json (54ea4cd)
Changelog

Sourced from kiegroup/git-backporting's changelog.

Changelog

4.10.0 (2026-07-25)

Features

  • add ability to open PRs from forked repo (#216) (da19e2a)
  • filter unused blobs when cloning repo (#217) (9a4855c)

Bug Fixes

  • deps: resolve all npm audit vulnerabilities (39 → 0) (#220) (84c49d5)
  • properly identify rebase and then ff (#215) (6ae3bf8)

4.9.1 (2026-03-25)

Bug Fixes

  • removed legacy node 18 from matrix run 56c0deb
  • use node 22 and override undici version to 6.24.1 0c16eed
  • wrong resolved registry in package-lock.json 54ea4cd

4.9.0 (2026-03-19)

Features

4.8.7 (2025-12-11)

Bug Fixes

  • override conventional-changelog-conventionalcommits (#178) (42d5ca8)
  • throw error when trying to backport single undefined commit (#177) (39b6b15)

4.8.6 (2025-09-04)

  • ci: bump node version to 20 for ci workflows (#161) (c5ce1d4), closes #161
  • build: audit fix (#159) (8f0df7b), closes #159
  • build(deps): bump form-data from 4.0.0 to 4.0.4 (#158) (83a65d8), closes #158
  • build(deps): bump tmp and @​inquirer/editor (#160) (8c412dc), closes #160
  • build(deps): bump undici, @​release-it/conventional-changelog and release-it (#157) (8625efa), closes #157

4.8.5 (2025-04-15)

4.8.4 (2024-11-02)

... (truncated)

Commits
  • 17bab14 chore: release v4.10.0 (#221)
  • 6ae3bf8 fix: properly identify rebase and then ff (#215)
  • 84c49d5 fix(deps): resolve all npm audit vulnerabilities (39 → 0) (#220)
  • 3c886f8 chore: update package-lock.json (#219)
  • aaf96bd ci: verify dist/ bundle is up to date on pull requests (#218)
  • da19e2a feat: add ability to open PRs from forked repo (#216)
  • 9a4855c feat: filter unused blobs when cloning repo (#217)
  • c8acd7d build(deps): bump axios from 1.16.0 to 1.18.0 (#214)
  • 5b74d5f build(deps): bump form-data from 4.0.5 to 4.0.6 (#212)
  • 0e567a8 build(deps): bump simple-git from 3.33.0 to 3.36.0 (#209)
  • Additional commits viewable in compare view

Updates zizmorcore/zizmor-action from 0.6.0 to 0.6.1

Release notes

Sourced from zizmorcore/zizmor-action's releases.

v0.6.1

zizmor 1.28.0 is now the default version used by the action.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-github-actions group with 2 updates: [kiegroup/git-backporting](https://github.com/kiegroup/git-backporting) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action).


Updates `kiegroup/git-backporting` from 4.9.1 to 4.10.0
- [Release notes](https://github.com/kiegroup/git-backporting/releases)
- [Changelog](https://github.com/kiegroup/git-backporting/blob/main/CHANGELOG.md)
- [Commits](kiegroup/git-backporting@08da0b0...17bab14)

Updates `zizmorcore/zizmor-action` from 0.6.0 to 0.6.1
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@6599ee8...6fc4b00)

---
updated-dependencies:
- dependency-name: kiegroup/git-backporting
  dependency-version: 4.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-github-actions
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 3, 2026
@github-actions github-actions Bot added the semver:patch No API change label Aug 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code semver:patch No API change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants