chore(deps): update github-actions - #1316
Merged
Merged
Conversation
There was a problem hiding this comment.
Aptu Review
✅ Approve — This PR performs routine dependency updates for GitHub Actions and the Rust toolchain, bumping the Rust version from 1.96.1 to 1.97.1 and updating several action digests and versions. These changes ensure the CI environment remains current with security patches and feature improvements.
Posted by aptu
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
48b55a0→24997074be7066→4cda84dv4.36.3→v4.37.11.96.1→1.97.1v2.82.7→v2.83.3v2.83.43d9770c→12b7ad4v0.5.7→v0.6.0Release Notes
github/codeql-action (github/codeql-action)
v4.37.1Compare Source
v4.37.0Compare Source
config-fileinput for thecodeql-action/initstep will soon support a new[owner/]repo[@​ref][:path]format. All components except the repository name are optional. If omitted,ownerdefaults to the same owner as the repository the analysis is running for,reftomain, andpathto.github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #3973rust-lang/rust (rust)
v1.97.1Compare Source
==========================
This backports an LLVM submodule bump to include the LLVM-side fix and a
revert of the rustc change that is one known trigger for the bug. The rustc
side revert should not be strictly necessary but is done out of abundance of caution.
v1.97.0Compare Source
==========================
Language
Result<T, Uninhabited>andControlFlow<Uninhabited, T>to be equivalent toTfor must use lintdead_code_pub_in_binarylint for unused pub items in binary cratesdiv32,lam-bh,lamcas,ld-seq-saandscqtarget featurescfg(target_has_atomic_primitive_alignment)selfin imports in more casesPlatform Support
Refer to Rust's platform support page
for more information on Rust's tiered platform support.
Stabilized APIs
Default for RepeatNCopy for ffi::FromBytesUntilNulErrorSend for std::fs::Fileon UEFI<{integer}>::isolate_highest_one<{integer}>::isolate_lowest_one<{integer}>::highest_one<{integer}>::lowest_one<{integer}>::bit_widthNonZero<{integer}>::isolate_highest_oneNonZero<{integer}>::isolate_lowest_oneNonZero<{integer}>::highest_oneNonZero<{integer}>::lowest_oneNonZero<{integer}>::bit_widthThese previously stable APIs are now stable in const contexts:
char::is_controlCargo
build.warningsconfig. This controls how lint warnings from local packages are treated. Useful for enforcing a warning-free build in CI, replacing-Dwarnings. docsresolver.lockfile-pathconfig. This allows specifying the path to the lockfile to use when resolving dependencies. Useful when working with read-only source directories. docs--target-dirdoesn't look like a Cargo target directory. This prevents accidental deletion of non-target directories.-mshorthand for--manifest-pathcurldependency fromcrates-iocrateRustdoc
--emitflag--remap-path-prefixCompatibility Notes
f32: From<{float}>to constrain{float}pin!, in order to prevent unsoundness. The most likely case where this might impact users is: writingpin!(x)wherexhas type&mut Twill now always correctly produce a value of typePin<&mut &mut T>, instead of sometimes allowing a coercion that produces a value of typePin<&mut T>. This coercion was previously incorrectly allowed since Rust 1.88.0.std::charconstants and functionsf64methods which have been deprecated since 1.0varargs_without_patternlint in depslink_sectionspecifierenums have changed. This is not a breaking change, as it only applies toenums without layout guarantees, but is noted here as we've seen people impacted from having made assumptions about the layout algorithm.#[export_name = "..."]where the name is empty#[link_name = "..."]&#[link(name = "...")]parametersshutdownon a socket to shut down the write side, attempting to write to the socket will now produce aBrokenPipeerror rather thanOther. MapWSAESHUTDOWNtoio::ErrorKind::BrokenPipetaiki-e/install-action (taiki-e/install-action)
v2.83.3: 2.83.3Compare Source
Update
release-plz@latestto 0.3.160.Update
prek@latestto 0.4.9.Update
mise@latestto 2026.7.6.Update
dprint@latestto 0.55.2.Update
cargo-dinghy@latestto 0.8.5.Update
cargo-binstall@latestto 1.21.0.Update
biome@latestto 2.5.4.v2.83.2: 2.83.2Compare Source
Update
parse-dockerfile@latestto 0.1.8.Update
mise@latestto 2026.7.5.Update
just@latestto 1.56.0.Update
gungraun-runner@latestto 0.19.4.Update
cargo-neat@latestto 0.4.1.v2.83.1: 2.83.1Compare Source
Update
rclone@latestto 1.74.4.Update
mise@latestto 2026.7.4.Update
cargo-deny@latestto 0.20.2.v2.83.0: 2.83.0Compare Source
Support
cargo-about. (#1924, thanks @ruffsl)Update
uv@latestto 0.11.28.Update
martin@latestto 1.12.0.Update
kingfisher@latestto 1.106.0.Update
biome@latestto 2.5.3.v2.82.11: 2.82.11Compare Source
Update
wasm-tools@latestto 1.253.0.Update
uv@latestto 0.11.27.Update
mise@latestto 2026.7.2.Update
mdbook@latestto 0.5.4.v2.82.10: 2.82.10Compare Source
Update
tombi@latestto 1.2.0.Update
cargo-nextest@latestto 0.9.140.v2.82.9: 2.82.9Compare Source
Update
vacuum@latestto 0.29.9.Update
prek@latestto 0.4.8.Update
cargo-tarpaulin@latestto 0.37.0.Update
cargo-leptos@latestto 0.3.7.v2.82.8: 2.82.8Compare Source
Update
vacuum@latestto 0.29.8.Update
uv@latestto 0.11.26.Update
typos@latestto 1.48.0.Update
trivy@latestto 0.72.0.Update
tombi@latestto 1.1.7.Update
prek@latestto 0.4.6.Update
mise@latestto 2026.7.0.Update
just@latestto 1.55.1.Update
biome@latestto 2.5.2.zizmorcore/zizmor-action (zizmorcore/zizmor-action)
v0.6.0Compare Source
zizmor 1.27.0 is now the default version used by the action.
What's Changed
collectinput by @woodruffw in #139New Contributors
Full Changelog: zizmorcore/zizmor-action@v0.5.7...v0.6.0
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.