Skip to content

build(deps): bump the all group with 3 updates - #370

Merged
step-ci merged 1 commit into
mainfrom
dependabot/github_actions/all-269b70bb04
Oct 7, 2026
Merged

step-ci merged 1 commit into
mainfrom
dependabot/github_actions/all-269b70bb04

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 3 updates: jdx/mise-action, github/codeql-action/init and github/codeql-action/analyze.

Updates jdx/mise-action from 4.3.0 to 5.0.1

Release notes

Sourced from jdx/mise-action's releases.

v5.0.1: Verify cached mise binaries before running them

mise-action now checks the integrity of an already-installed mise binary before running it. This fixes a security issue that was reported privately.

Fixed

  • An existing mise binary is verified before it is run. When a mise binary is already on the runner (for example, restored from cache or in mise_dir), the action now checks it before calling it. If you set a sha256 input, the binary must match that checksum and report the requested version. Otherwise, it must match the signed release checksums for the version being installed. If the check fails, the action prints a warning, deletes the binary and installs the requested release again. Before this fix, the action could run a cached binary before checking it. (#637 by @​jdx)

Changed

Changes to how the action handles an existing binary, also from #637:

  • Switching versions uses a full install. If the cached binary doesn't match the requested version, the action downloads and installs that version. It no longer runs mise self-update.
  • Unpinned runs always pick a release. Without a version input, the action now selects a release every time, using minimum_release_age, even when mise is already installed. It then checks the existing binary against that release, and reinstalls if the binary doesn't match.
  • Older releases need a sha256 input to reuse a cached binary. Some older mise releases have no signed checksums. With the sha256 input set, a cached binary of one of these releases can still be reused without a download. Without it, the action can't verify the binary and installs it again.

Full Changelog: jdx/mise-action@v5.0.0...v5.0.1

v5.0.0: Default minimum release age of 24 hours for mise

If you don't pin a version, mise-action now installs the newest stable mise release that is at least 24 hours old. Upgrading mise on a runner that already has it is also less likely to hit GitHub API rate limits.

Breaking Changes

minimum_release_age now defaults to 24h (#632 by @​jdx)

Before this release, minimum_release_age was an opt-in setting. It now defaults to 24h. If you don't set version, the action picks the highest-numbered stable mise release published at least 24 hours ago. A mise release that just shipped won't be installed until it's a day old.

To get the latest stable release right away, as in v4, set the delay to 0s. You can also choose a longer delay:

- uses: jdx/mise-action@v5
  with:
    minimum_release_age: 0s   # or e.g. 7d
  • An explicit version input still takes precedence and skips the delay.
  • The setting applies only to the mise binary, not to tools installed by mise.
  • The action now gets the release list from a public CDN index (releases.tsv on mise.jdx.dev) instead of paging through the GitHub Releases API. Picking a release doesn't use GitHub API quota, even when an installed binary is reused. If the index is missing or malformed, the action fails instead of skipping the release-age check.
  • Replacing an older installed binary still runs mise self-update, which may call the GitHub API to fetch that exact release.

Fixed

  • mise self-update now runs with MISE_GITHUB_TOKEN. When a runner already had a different mise version installed, the action runs mise self-update to switch versions. That GitHub API call used to go out without authentication, so busy shared or self-hosted runners could hit the rate limit and fail with HTTP 403 RateLimitedError. If you already set a token in your environment, the action leaves it unchanged. (#619 by @​hegde5)

New Contributors

Full Changelog: jdx/mise-action@v4.3.0...v5.0.0

Changelog

Sourced from jdx/mise-action's changelog.

Changelog


5.1.1 - 2026-10-04

🐛 Bug Fixes


5.1.0 - 2026-10-04

🚀 Features

🐛 Bug Fixes

  • (cache) keep a cached mise instead of re-downloading when version is unset (#642) by @​jdx in #642
  • save cache after inexact cache restore (#646) by @​jdx in #646
  • extract mise zip with PowerShell instead of unzip on Windows (#650) by @​jdx in #650
  • cache mise binary for caches saved without a version record (#648) by @​jdx in #648

📚 Documentation

  • explain the Rust cache caveat and workarounds (#651) by @​jdx in #651
  • add matrix and external cache guides; warn on shadowed mise_toml (#654) by @​jdx in #654

⚙️ Miscellaneous Tasks


5.0.1 - 2026-09-30

🐛 Bug Fixes


5.0.0 - 2026-09-28

🚀 Features

... (truncated)

Commits
  • 7a4e45a chore: release v5.0.1 (#638)
  • c4102d4 fix: verify cached mise before execution (#637)
  • baf7eb4 chore(deps): update dependency aube to latest (#636)
  • c75796c chore(deps): update dependency communique to latest (#635)
  • ec2665b chore(deps): update github actions (#633)
  • 342b4c0 chore(deps): update dependency aube to latest (#634)
  • 9149ea8 chore: release v5.0.0 (#620)
  • 279d505 feat!: default minimum release age to 24 hours (#632)
  • aa79241 chore(entire): restore lower-cost trail findings
  • 6ac0f83 chore(entire): commit claude session hooks
  • Additional commits viewable in compare view

Updates github/codeql-action/init from 4.38.1 to 4.38.2

Release notes

Sourced from github/codeql-action/init's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action/init's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates github/codeql-action/analyze from 4.38.1 to 4.38.2

Release notes

Sourced from github/codeql-action/analyze's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action/analyze's changelog.

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

[UNRELEASED]

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #4188

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146

4.38.0 - 09 Sept 2026

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #4072
  • Update default CodeQL bundle version to 2.27.0. #4129

4.37.9 - 26 Aug 2026

  • Update default CodeQL bundle version to 2.26.4. #4106

4.37.8 - 21 Aug 2026

No user facing changes.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085

4.37.6 - 04 Aug 2026

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #4070

4.37.5 - 03 Aug 2026

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #4061

4.37.4 - 29 Jul 2026

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #4037
  • Update default CodeQL bundle version to 2.26.2. #4051

4.37.3 - 22 Jul 2026

No user facing changes.

... (truncated)

Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 3 updates: [jdx/mise-action](https://github.com/jdx/mise-action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `jdx/mise-action` from 4.3.0 to 5.0.1
- [Release notes](https://github.com/jdx/mise-action/releases)
- [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md)
- [Commits](jdx/mise-action@c2a8761...7a4e45a)

Updates `github/codeql-action/init` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

Updates `github/codeql-action/analyze` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@1c5b675...2892aa5)

---
updated-dependencies:
- dependency-name: jdx/mise-action
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 7, 2026 02:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 7, 2026
@step-ci
step-ci enabled auto-merge October 7, 2026 02:37
@step-ci
step-ci merged commit 9a513d3 into main Oct 7, 2026
10 checks passed
@step-ci
step-ci deleted the dependabot/github_actions/all-269b70bb04 branch October 7, 2026 10:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants