Skip to content

build(deps): Bump the actions group across 1 directory with 2 updates - #144

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-9567b69d5e
Sep 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-9567b69d5e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates in the / directory: SonarSource/sonarqube-scan-action and github/codeql-action.

Updates SonarSource/sonarqube-scan-action from 8.2.1 to 8.2.2

Release notes

Sourced from SonarSource/sonarqube-scan-action's releases.

v8.2.2

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8.2.1...v8.2.2

Commits
  • ba9859e SQSCANGHA-159 Bump undici from 6.24.1 to 6.28.1 (#261)
  • 5bc5285 Rename code-quality teams to code-orchestration in CODEOWNERS
  • ad82103 SQSCANGHA-158 NO-JIRA Bump actions/checkout from 7.0.0 to 7.0.1 (#260)
  • 7451daf SQSCANGHA-157 NO-JIRA Bump actions/setup-node from 6.4.0 to 7.0.0 (#259)
  • See full diff in compare view

Updates github/codeql-action from 4.38.0 to 4.38.1

Release notes

Sourced from github/codeql-action's releases.

v4.38.1

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Changelog

Sourced from github/codeql-action's changelog.

4.38.1 - 18 Sept 2026

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #4146
Commits
  • 1c5b675 Merge pull request #4152 from github/update-v4.38.1-a65b83a73
  • a97cdca Add changelog entry for #4146
  • cc6c691 Update changelog for v4.38.1
  • a65b83a Merge pull request #4146 from github/henrymercer/per-language-bundles-pr
  • 07fa87d Clarify the latest-nightly eligibility exception
  • f18f353 Describe the bundle URL resolver
  • ecec9b5 Share per-language telemetry fields without renaming
  • 79fe3a1 Move download telemetry into the status-report directory
  • ead1f7d Rename the platform module
  • 549d498 Simplify per-language platform eligibility checks
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 21, 2026
@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: cdff550c-7e49-46c4-a046-8b5667d507f1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Bumps the actions group with 2 updates in the / directory: [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) and [github/codeql-action](https://github.com/github/codeql-action).


Updates `SonarSource/sonarqube-scan-action` from 8.2.1 to 8.2.2
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](SonarSource/sonarqube-scan-action@v8.2.1...v8.2.2)

Updates `github/codeql-action` from 4.38.0 to 4.38.1
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.38.0...v4.38.1)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 8.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): Bump the actions group with 2 updates build(deps): Bump the actions group across 1 directory with 2 updates Sep 22, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-9567b69d5e branch from ec741ad to aeb4205 Compare September 22, 2026 02:17
@hyperpolymath
hyperpolymath merged commit 8d83459 into main Sep 22, 2026
27 of 31 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-9567b69d5e branch September 22, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant