Update github actions (main) (patch) - #3448
Conversation
|
🤖 Finished Review · ✅ Success · Started 2:25 AM UTC · Completed 2:34 AM UTC |
ReviewFindingsHigh
Next steps:
Previous runReviewFindingsHigh
Labels: PR updates GitHub Actions workflow files with version pin bumps Next steps:
|
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
99a50a9 to
b5e44c1
Compare
|
🤖 Finished Review · ✅ Success · Started 2:19 AM UTC · Completed 2:28 AM UTC |
|
🤖 Finished Retro · ✅ Success · Started 12:24 PM UTC · Completed 12:36 PM UTC |
Retro: PR #3448 — Update GitHub Actions (MintMaker patch bump)Timeline
AssessmentThe workflow functioned correctly. The review agent properly identified the protected-path governance requirement, The main concern is efficiency. Two full Opus-tier review runs (~18 minutes total wall-clock) for a 10-line bot-authored version pin update is disproportionate. The second run after rebase produced an identical finding. Existing issue coverageAll improvement areas identified are well-covered by existing open issues. No new proposals filed. Key evidence from this PR:
|
This PR contains the following updates:
v5.5.4→v5.5.5v4.37.3→v4.37.4v2.4.3→v2.4.4v8.1.0→v8.1.1Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
codecov/codecov-action (codecov/codecov-action)
v5.5.5Compare Source
This release only contains the keybase.io change as described here.
Full Changelog: codecov/codecov-action@v5.5.4...v5.5.5
github/codeql-action (github/codeql-action)
v4.37.4Compare Source
toolsinput for thecodeql-action/initstep to be specified using agithub-codeql-toolsrepository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value totoolcacheto always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided fortoolsin the workflow definition always takes precedence unless the value of the repository property starts with!. #4037ossf/scorecard-action (ossf/scorecard-action)
v2.4.4Compare Source
What's Changed
This update bumps the Scorecard version to the v5.5.0 release. For a complete list of changes, please refer to the Scorecard v5.4.0 release notes and the Scorecard v5.5.0 release notes.
Full Changelog: ossf/scorecard-action@v2.4.3...v2.4.4
peter-evans/create-pull-request (peter-evans/create-pull-request)
v8.1.1: Create Pull Request v8.1.1Compare Source
What's Changed
Full Changelog: peter-evans/create-pull-request@v8.1.0...v8.1.1
Configuration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.