Skip to content

chore(ci): bump the actions group with 3 updates - #14

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-8a5776c7d0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-8a5776c7d0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown

Bumps the actions group with 3 updates: astral-sh/setup-uv, actions/github-script and alibaba/open-code-review.

Updates astral-sh/setup-uv from 10.0.1 to 10.2.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.2.0 🌈 Disable automatic cache saves for merge queues

Changes

This release contains the known-checksum of the most recent uv releases and also disabled the uploading(saving) of the cache when in a merge queue since theses caches would almost never be used.

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

... (truncated)

Commits

Updates actions/github-script from 7 to 9

Release notes

Sourced from actions/github-script's releases.

v9.0.0

New features:

  • getOctokit factory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients with getOctokit for details and examples.
  • Orchestration ID in user-agent — The ACTIONS_ORCHESTRATION_ID environment variable is automatically appended to the user-agent string for request tracing.

Breaking changes:

  • require('@actions/github') no longer works in scripts. The upgrade to @actions/github v9 (ESM-only) means require('@actions/github') will fail at runtime. If you previously used patterns like const { getOctokit } = require('@actions/github') to create secondary clients, use the new injected getOctokit function instead — it's available directly in the script context with no imports needed.
  • getOctokit is now an injected function parameter. Scripts that declare const getOctokit = ... or let getOctokit = ... will get a SyntaxError because JavaScript does not allow const/let redeclaration of function parameters. Use the injected getOctokit directly, or use var getOctokit = ... if you need to redeclare it.
  • If your script accesses other @actions/github internals beyond the standard github/octokit client, you may need to update those references for v9 compatibility.

What's Changed

New Contributors

Full Changelog: actions/github-script@v8.0.0...v9.0.0

v8.0.0

What's Changed

⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

New Contributors

Full Changelog: actions/github-script@v7.1.0...v8.0.0

v7.1.0

What's Changed

... (truncated)

Commits
  • 3a2844b Merge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...
  • ca10bbd fix: use @​octokit/core/types import for v7 compatibility
  • 86e48e2 merge: incorporate main branch changes
  • c108472 chore: rebuild dist for v9 upgrade and getOctokit factory
  • afff112 Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...
  • ff8117e ci: fix user-agent test to handle orchestration ID
  • 81c6b78 ci: use deployment: false to suppress deployment noise from integration tests
  • 3953caf docs: update README examples from @​v8 to @​v9, add getOctokit docs and v9 brea...
  • c17d55b ci: add getOctokit integration test job
  • a047196 test: add getOctokit integration tests via callAsyncFunction
  • Additional commits viewable in compare view

Updates alibaba/open-code-review from 1.9.9 to 1.12.10

Release notes

Sourced from alibaba/open-code-review's releases.

v1.12.10

🚀 Features

  • feat(llm): exercise a tool-call round trip in ocr llm test (#1394)
  • feat(llm): add OpenRouter to list of providers (#1522)
  • feat(session): add 'ocr session rm' to delete a saved session (#1490)

🐛 Bug Fixes

  • fix(llmloop): account for tool_calls and arguments in messageTokens (#1413)
  • fix(llm): trim environment-sourced endpoint values (#1414)
  • fix(tool): keep non-ASCII paths literal in file_find results (#1530)
  • fix(opencode): handle long background context (#1010)
  • fix(action): allow checkpoints after out-of-diff findings (#1524)
  • fix(config): remove OCR_CONFIG_PATH (#1537)
  • fix(llm): replay tool_call extra_content and surface provider error bodies (#1393)

📖 Documentation

  • docs(cli-reference): list the manifest status values in the status field (#1587)
  • docs(readme): replace Go weekly badge with all-language weekly badge (#1559)
  • docs(review-rules): document merge_system_rule in all five locales (#1555)

Full Changelog: alibaba/open-code-review@v1.12.9...v1.12.10

v1.12.9

🐛 Bug Fixes

  • fix(session): preserve findings across file renames (#1529)
  • fix(config): preserve unknown JSON fields during config updates (#1508)
  • fix(review): keep git stderr out of --commit background (#1467)
  • fix(ci): pin workflow action references to full commit SHAs (#856)
  • fix(viewer): wrap long session metadata on mobile (#1458)

📖 Documentation

  • docs(agents): add guideline to comment sparingly and explain why (#1534)

Other Changes

  • security: validate credential commands and expand .gitattributes binary markers (#1291)
  • Fix/gitlab multiline comments and suggestions (#1000)
  • test: stabilize token boundary fixtures (#1015)
  • test(diff): guard quoted-path parsing through a real git subprocess (#1516)

Full Changelog: alibaba/open-code-review@v1.12.8...v1.12.9

v1.12.8

... (truncated)

Commits
  • 579b931 fix(llmloop): account for tool_calls and arguments in messageTokens (#1413)
  • 1af527d docs(cli-reference): list the manifest status values in the status field (#1587)
  • 486022d fix(llm): trim environment-sourced endpoint values (#1414)
  • 7dcaab2 feat(llm): exercise a tool-call round trip in ocr llm test (#1394)
  • d19649b fix(tool): keep non-ASCII paths literal in file_find results (#1530)
  • 5eeebb8 fix(opencode): handle long background context (#1010)
  • a290633 feat(llm): add OpenRouter to list of providers (#1522)
  • 0243a38 docs(readme): replace Go weekly badge with all-language weekly badge (#1559)
  • 5e1ed49 docs(review-rules): document merge_system_rule in all five locales (#1555)
  • dc2beb5 feat(session): add 'ocr session rm' to delete a saved session (#1490)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 3 updates: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv), [actions/github-script](https://github.com/actions/github-script) and [alibaba/open-code-review](https://github.com/alibaba/open-code-review).


Updates `astral-sh/setup-uv` from 10.0.1 to 10.2.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v10.0.1...v10.2.0)

Updates `actions/github-script` from 7 to 9
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](actions/github-script@v7...v9)

Updates `alibaba/open-code-review` from 1.9.9 to 1.12.10
- [Release notes](https://github.com/alibaba/open-code-review/releases)
- [Commits](alibaba/open-code-review@v1.9.9...v1.12.10)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/github-script
  dependency-version: '9'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: alibaba/open-code-review
  dependency-version: 1.12.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🔍 OpenCodeReview found 2 issue(s) in this PR.

  • ✅ Successfully posted inline: 2 comment(s)

Comment thread .github/workflows/ci.yml
# setup-uv stopped publishing floating major tags in v8, so this is pinned
# to an exact release rather than a tracking `@v10`.
- uses: astral-sh/setup-uv@v10.0.1
- uses: astral-sh/setup-uv@v10.2.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security · low
astral-sh/setup-uv is a third-party action referenced by a mutable tag. Pinning to an exact release (instead of a floating @v10) is an improvement, but a tag can still be repointed, so this step can run different code than what was reviewed here. Prefer pinning to the v10.2.0 release commit SHA with the version noted in the adjacent comment. Applies to all four occurrences changed in this PR (two here, two in release.yml).

Suggestion:

Suggested change
- uses: astral-sh/setup-uv@v10.2.0
# setup-uv v10.2.0, pinned to the release commit SHA
- uses: astral-sh/setup-uv@<commit-sha-of-v10.2.0>


- name: Run OpenCodeReview
uses: alibaba/open-code-review@v1.9.9
uses: alibaba/open-code-review@v1.12.10

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security · medium
This third-party action is pinned to a mutable tag rather than a full commit SHA. This workflow runs on pull_request_target (secrets available even for fork PRs) and hands llm_auth_token directly to the action, so if the v1.12.10 tag is ever repointed to malicious code, the LLM API key could be exfiltrated. Pin to the exact commit SHA of the v1.12.10 release and keep the version in a comment, so the executed code is immutable.

Suggestion:

Suggested change
uses: alibaba/open-code-review@v1.12.10
# alibaba/open-code-review v1.12.10, pinned to the release commit SHA
uses: alibaba/open-code-review@<commit-sha-of-v1.12.10>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants