Skip to content

chore(deps): Bump the actions group with 3 updates - #124

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-fdf06d1316
Sep 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-fdf06d1316

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 3 updates: github/codeql-action, trufflesecurity/trufflehog and Bogdanp/setup-racket.

Updates github/codeql-action from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action's changelog.

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

Updates trufflesecurity/trufflehog from 3.97.4 to 3.97.5

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.5

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.4...v3.97.5

Commits
  • f714bf4 [SCAN-177] Purge secret parts from verification cache (#5318)
  • 4ecb5c6 Add elasticsearch source documentation (#5284)
  • 8d77a9d Add filesystem source documentation (#5285)
  • b8a71ee Add documentation for CircleCI source (#5268)
  • b1d7dae perf(engine): lowercase prefilter chunks as ASCII in a pooled buffer (#5291)
  • 07e3ac7 Introduce a new optional detector interface that will allow us to verify cred...
  • 5a6944e ci: avoid Node 20 BuildPulse action (#5266)
  • ce7b2b8 fix(detectors/ngrok): broaden valid bearer tokens matching (#5152)
  • 58bf481 Postgres: drop non-connection URI params before verifying (#5296)
  • 82fd19c Adding no-ignore flag to allow reporting of "ignored" secrets (#5297)
  • Additional commits viewable in compare view

Updates Bogdanp/setup-racket from 1.9.1 to 1.15

Release notes

Sourced from Bogdanp/setup-racket's releases.

v1.15

  • No user-visible changes. This change simply updates the action to run using Node 24, as Node 20 will be dropped by GitHub in June.

v1.14

Changed

  • The snapshot sites have been updated to consolidate the set of builds provided between the Utah and Northwestern sites. BC snapshots are now no longer available, so if you currently use version: current with variant: BC, you'll have to change variant to CS to fix your builds going forward. Additionally, the "test" distribution from Northwestern is no longer available. In the highly unlikely case you were setting distribution to test, change it to full. The test option is rejected by the action as of this version.

v1.13

Added

  • Support for more arm configurations. See the "ARM Builds" section of the README for details. (#81, #80, #9)

Changed

  • The architecture flag no longer defaults to x64. Instead it defaults to the process arch. This may have an impact on macOS builds if you were using ARM runners and weren't specifying the arch.

v1.12

Added

Changed

  • The version argument now defaults to stable

v1.11

Changed

  • Bumped the Node.js runtime version from 16 to 20. (#70)

v1.10

Changed

  • By default, snapshot versions are now installed from whichever snapshot site (between Utah and Northwestern) finished building more recently. You can pick a specific snapshot site using the new snapshot_site option. (#63, #64)
Commits
  • 2466913 doc: s/1.14/1.15 and s/8.18/9.1 [skip ci]
  • 2d6a750 build: update dependencies and run on node 24
  • 8823878 ci: drop macos-13
  • 510c17a build(deps): bump js-yaml from 3.14.1 to 3.14.2 (#84)
  • 0e4942f doc: s/8.17/8.18
  • dff14a0 build(deps): bump form-data from 3.0.1 to 3.0.4 (#83)
  • fda0f4d doc: update version [skip ci]
  • e321cc4 ci: drop deprecated windows-2019 environment
  • b45ffad core: drop "test" Distribution
  • 2c52f9b ci: drop BC variant and "test" distribution from Northwestern tests
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 3 updates: [github/codeql-action](https://github.com/github/codeql-action), [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) and [Bogdanp/setup-racket](https://github.com/bogdanp/setup-racket).


Updates `github/codeql-action` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.38.0...v4.38.1)

Updates `trufflesecurity/trufflehog` from 3.97.4 to 3.97.5
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@v3.97.4...v3.97.5)

Updates `Bogdanp/setup-racket` from 1.9.1 to 1.15
- [Release notes](https://github.com/bogdanp/setup-racket/releases)
- [Commits](Bogdanp/setup-racket@v1.9.1...v1.15)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: Bogdanp/setup-racket
  dependency-version: '1.15'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner September 21, 2026 08:40
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 719a99d1-c40a-4f99-aeea-c7cf929c18c6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit a85de54 into main Sep 21, 2026
16 of 21 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-fdf06d1316 branch September 21, 2026 08:42

- name: Initialize CodeQL
uses: github/codeql-action/init@v4.38.0
uses: github/codeql-action/init@v4.38.1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4.38.0
uses: github/codeql-action/analyze@v4.38.1
- uses: actions/checkout@v7.0.1
- name: Secret scanning
uses: trufflesecurity/trufflehog@v3.97.4
uses: trufflesecurity/trufflehog@v3.97.5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants