chore(deps): bump the actions group with 3 updates - #243
Conversation
Bumps the actions group with 3 updates: [ocaml/setup-ocaml](https://github.com/ocaml/setup-ocaml), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `ocaml/setup-ocaml` from 3.7.1 to 3.7.2 - [Release notes](https://github.com/ocaml/setup-ocaml/releases) - [Commits](ocaml/setup-ocaml@605a7e9...f92e060) Updates `github/codeql-action/init` from 4.37.7 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...cdf488f) Updates `github/codeql-action/analyze` from 4.37.7 to 4.37.9 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@ff2f1c6...cdf488f) --- updated-dependencies: - dependency-name: ocaml/setup-ocaml dependency-version: 3.7.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/init dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
Up to standards ✅🟢 Issues
|
There was a problem hiding this comment.
Pull Request Overview
The proposed updates to the GitHub Action workflows are consistent with the project's dependency management and passed all automated quality checks. The review confirmed that the actions are correctly pinned to the target commit SHAs, and no security vulnerabilities or functional regressions were identified that would prevent merging.
Test suggestions
- Verify that the CI workflow successfully executes the
ocaml/setup-ocamlstep using the new commit SHA. - Verify that the CodeQL analysis workflow successfully initializes and runs using the new commit SHAs for version 4.37.9.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the CI workflow successfully executes the `ocaml/setup-ocaml` step using the new commit SHA.
2. Verify that the CodeQL analysis workflow successfully initializes and runs using the new commit SHAs for version 4.37.9.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback



Bumps the actions group with 3 updates: ocaml/setup-ocaml, github/codeql-action/init and github/codeql-action/analyze.
Updates
ocaml/setup-ocamlfrom 3.7.1 to 3.7.2Release notes
Sourced from ocaml/setup-ocaml's releases.
Commits
f92e060Merge pull request #1124 from ocaml/prepare-3.7.299053faPrepare 3.7.2d7daaa4Merge pull request #1123 from ocaml/preserve-readable-action-errors96228efPreserve readable action error messages2dc53f4Merge pull request #1121 from ocaml/dependabot/github_actions/jdx/mise-action...c929c36Bump jdx/mise-action from 4.2.4 to 4.2.5444691aMerge pull request #1120 from ocaml/dependabot/github_actions/jdx/mise-action...d8711a6Bump jdx/mise-action from 4.2.3 to 4.2.4Updates
github/codeql-action/initfrom 4.37.7 to 4.37.9Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Updates
github/codeql-action/analyzefrom 4.37.7 to 4.37.9Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
cdf488fMerge pull request #4107 from github/update-v4.37.9-920ba7cd17243f38Update changelog for v4.37.9920ba7cMerge pull request #4106 from github/update-bundle/codeql-bundle-v2.26.4ecfa6e1Add changelog noteadcdf4aUpdate default bundle to codeql-bundle-v2.26.4486fec2Merge pull request #4099 from github/update-supported-enterprise-server-versions134624cMerge pull request #4101 from github/dependabot/npm_and_yarn/npm-minor-457d82...ff43db8Merge pull request #4103 from github/mergeback/v4.37.8-to-main-db488dde4605e03Rebuild099c869Update changelog and version after v4.37.8Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions