From 2cdeabef3f4228d481b8f8de865e5093816e6b86 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 1 Sep 2026 06:58:06 +0000 Subject: [PATCH 1/2] chore(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.2 to 3.0.3. - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](https://github.com/softprops/action-gh-release/compare/v3.0.2...v3.0.3) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- .github/workflows/release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 88bdd2b..adee68b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -38,7 +38,7 @@ jobs: LICENSE - name: Create Release - uses: softprops/action-gh-release@v3.0.2 + uses: softprops/action-gh-release@v3.0.3 with: files: dist/* generate_release_notes: true From e8e57f890980b91046e3a2c858f84feeeece4865 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 08:43:56 +0100 Subject: [PATCH 2/2] chore(ci): regenerate actions.lock for the bumped action refs Dependabot cannot sign-push, so the lockfile that pins the bumped `uses:` refs is regenerated here (gh actions-lock, verify clean). Only actions.lock changes. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/actions.lock | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 3aaac7d..bcdc17f 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -3,12 +3,12 @@ # Docs: https://gh.io/actions-lockfile version: 'v0.0.2' workflows: - '.github/workflows/governance.yml': [] '.github/workflows/ci.yml': - 'actions/checkout@v7.0.1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - 'github/codeql-action@v4.37.8' + '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': - 'actions/checkout@v7.0.1' - 'actions/github-script@v9.0.0' @@ -30,7 +30,7 @@ workflows: - 'docker/metadata-action@v6.2.0' '.github/workflows/release.yml': - 'actions/checkout@v7.0.1' - - 'softprops/action-gh-release@v3.0.2' + - 'softprops/action-gh-release@v3.0.3' '.github/workflows/scorecard.yml': - 'actions/checkout@v7.0.1' - 'github/codeql-action@v4.37.8' @@ -100,9 +100,9 @@ dependencies: commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' owner_id: 18365890 repo_id: 220359305 - 'softprops/action-gh-release@v3.0.2': - ref: 'v3.0.2' - commit: 'sha1-3d0d9888cb7fd7b750713d6e236d1fcb99157228' + 'softprops/action-gh-release@v3.0.3': + ref: 'v3.0.3' + commit: 'sha1-efb35369e0ad2afab669f228072c1b0d510eae64' owner_id: 2242 repo_id: 204253808 'trufflesecurity/trufflehog@v3.97.1':