chore(ci): bump the actions group with 3 updates - #14
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions group with 3 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv), [actions/github-script](https://github.com/actions/github-script) and [alibaba/open-code-review](https://github.com/alibaba/open-code-review). Updates `astral-sh/setup-uv` from 10.0.1 to 10.2.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@v10.0.1...v10.2.0) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v7...v9) Updates `alibaba/open-code-review` from 1.9.9 to 1.12.10 - [Release notes](https://github.com/alibaba/open-code-review/releases) - [Commits](alibaba/open-code-review@v1.9.9...v1.12.10) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: alibaba/open-code-review dependency-version: 1.12.10 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
🔍 OpenCodeReview found 2 issue(s) in this PR.
|
| # setup-uv stopped publishing floating major tags in v8, so this is pinned | ||
| # to an exact release rather than a tracking `@v10`. | ||
| - uses: astral-sh/setup-uv@v10.0.1 | ||
| - uses: astral-sh/setup-uv@v10.2.0 |
There was a problem hiding this comment.
astral-sh/setup-uv is a third-party action referenced by a mutable tag. Pinning to an exact release (instead of a floating @v10) is an improvement, but a tag can still be repointed, so this step can run different code than what was reviewed here. Prefer pinning to the v10.2.0 release commit SHA with the version noted in the adjacent comment. Applies to all four occurrences changed in this PR (two here, two in release.yml).
Suggestion:
| - uses: astral-sh/setup-uv@v10.2.0 | |
| # setup-uv v10.2.0, pinned to the release commit SHA | |
| - uses: astral-sh/setup-uv@<commit-sha-of-v10.2.0> |
|
|
||
| - name: Run OpenCodeReview | ||
| uses: alibaba/open-code-review@v1.9.9 | ||
| uses: alibaba/open-code-review@v1.12.10 |
There was a problem hiding this comment.
This third-party action is pinned to a mutable tag rather than a full commit SHA. This workflow runs on pull_request_target (secrets available even for fork PRs) and hands llm_auth_token directly to the action, so if the v1.12.10 tag is ever repointed to malicious code, the LLM API key could be exfiltrated. Pin to the exact commit SHA of the v1.12.10 release and keep the version in a comment, so the executed code is immutable.
Suggestion:
| uses: alibaba/open-code-review@v1.12.10 | |
| # alibaba/open-code-review v1.12.10, pinned to the release commit SHA | |
| uses: alibaba/open-code-review@<commit-sha-of-v1.12.10> |
Bumps the actions group with 3 updates: astral-sh/setup-uv, actions/github-script and alibaba/open-code-review.
Updates
astral-sh/setup-uvfrom 10.0.1 to 10.2.0Release notes
Sourced from astral-sh/setup-uv's releases.
... (truncated)
Commits
c18668achore(deps): roll up Dependabot updates (#1059)ffe1476chore: update known checksums for 0.12.17 (#1058)f5548c5chore: update known checksums for 0.12.16 (#1057)a761a4eDisable automatic cache saves for merge queues (#1056)3377a30chore: update known checksums for 0.12.15 (#1054)dfb5f38chore: update known checksums for 0.12.14 (#1053)45c121fchore: update known checksums for 0.12.13 (#1045)8073452docs: update version references to v10.1.0 (#1044)bec219dchore(deps-dev): roll up Dependabot updates (#1043)b90ec40fix: respect no proxy directive (#1037)Updates
actions/github-scriptfrom 7 to 9Release notes
Sourced from actions/github-script's releases.
... (truncated)
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionUpdates
alibaba/open-code-reviewfrom 1.9.9 to 1.12.10Release notes
Sourced from alibaba/open-code-review's releases.
... (truncated)
Commits
579b931fix(llmloop): account for tool_calls and arguments in messageTokens (#1413)1af527ddocs(cli-reference): list the manifest status values in the status field (#1587)486022dfix(llm): trim environment-sourced endpoint values (#1414)7dcaab2feat(llm): exercise a tool-call round trip in ocr llm test (#1394)d19649bfix(tool): keep non-ASCII paths literal in file_find results (#1530)5eeebb8fix(opencode): handle long background context (#1010)a290633feat(llm): add OpenRouter to list of providers (#1522)0243a38docs(readme): replace Go weekly badge with all-language weekly badge (#1559)5e1ed49docs(review-rules): document merge_system_rule in all five locales (#1555)dc2beb5feat(session): add 'ocr session rm' to delete a saved session (#1490)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions