Bump the actions group with 3 updates
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: Contributor
Comments: 0
(1 day ago)
(1 day ago)
dependencies github_actions
Bumps the actions group with 3 updates: actions/setup-python, github/codeql-action and pypa/gh-action-pypi-publish.
Updates actions/setup-python
from 5 to 6
Release notes
Sourced from actions/setup-python's releases.
v6.0.0
What's Changed
Breaking Changes
- Upgrade to node 24 by
@salmanmkc
in actions/setup-python#1164Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes
Enhancements:
- Add support for
pip-version
by@priyagupta108
in actions/setup-python#1129- Enhance reading from .python-version by
@krystof-k
in actions/setup-python#787- Add version parsing from Pipfile by
@aradkdj
in actions/setup-python#1067Bug fixes:
- Clarify pythonLocation behaviour for PyPy and GraalPy in environment variables by
@aparnajyothi-y
in actions/setup-python#1183- Change missing cache directory error to warning by
@aparnajyothi-y
in actions/setup-python#1182- Add Architecture-Specific PATH Management for Python with --user Flag on Windows by
@aparnajyothi-y
in actions/setup-python#1122- Include python version in PyPy python-version output by
@cdce8p
in actions/setup-python#1110- Update docs: clarification on pip authentication with setup-python by
@priya-kinthali
in actions/setup-python#1156Dependency updates:
- Upgrade idna from 2.9 to 3.7 in /tests/data by
@dependabot
[bot] in actions/setup-python#843- Upgrade form-data to fix critical vulnerabilities #182 & #183 by
@aparnajyothi-y
in actions/setup-python#1163- Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIndex.download by
@aparnajyothi-y
in actions/setup-python#1165- Upgrade actions/checkout from 4 to 5 by
@dependabot
[bot] in actions/setup-python#1181- Upgrade
@actions/tool-cache
from 2.0.1 to 2.0.2 by@dependabot
[bot] in actions/setup-python#1095New Contributors
@krystof-k
made their first contribution in actions/setup-python#787@cdce8p
made their first contribution in actions/setup-python#1110@aradkdj
made their first contribution in actions/setup-python#1067Full Changelog: https://github.com/actions/setup-python/compare/v5...v6.0.0
v5.6.0
What's Changed
- Workflow updates related to Ubuntu 20.04 by
@aparnajyothi-y
in actions/setup-python#1065- Fix for Candidate Not Iterable Error by
@aparnajyothi-y
in actions/setup-python#1082- Upgrade semver and
@types/semver
by@dependabot
in actions/setup-python#1091- Upgrade prettier from 2.8.8 to 3.5.3 by
@dependabot
in actions/setup-python#1046- Upgrade ts-jest from 29.1.2 to 29.3.2 by
@dependabot
in actions/setup-python#1081Full Changelog: https://github.com/actions/setup-python/compare/v5...v5.6.0
v5.5.0
What's Changed
Enhancements:
- Support free threaded Python versions like '3.13t' by
@colesbury
in actions/setup-python#973- Enhance Workflows: Include ubuntu-arm runners, Add e2e Testing for free threaded and Upgrade
@action/cache
from 4.0.0 to 4.0.3 by@priya-kinthali
in actions/setup-python#1056- Add support for .tool-versions file in setup-python by
@mahabaleshwars
in actions/setup-python#1043Bug fixes:
- Fix architecture for pypy on Linux ARM64 by
@mayeut
in actions/setup-python#1011 This update maps arm64 to aarch64 for Linux ARM64 PyPy installations.
... (truncated)
Commits
e797f83
Upgrade to node 24 (#1164)3d1e2d2
Revert "Enhance cache-dependency-path handling to support files outside the w...65b0712
Clarify pythonLocation behavior for PyPy and GraalPy in environment variables...5b668cf
Bump actions/checkout from 4 to 5 (#1181)f62a0e2
Change missing cache directory error to warning (#1182)9322b3c
Upgrade setuptools to 78.1.1 to fix path traversal vulnerability in PackageIn...fbeb884
Bump form-data to fix critical vulnerabilities #182 & #183 (#1163)03bb615
Bump idna from 2.9 to 3.7 in /tests/data (#843)36da51d
Add version parsing from Pipfile (#1067)3c6f142
update documentation (#1156)- Additional commits viewable in compare view
Updates github/codeql-action
from 3.29.11 to 3.30.1
Release notes
Sourced from github/codeql-action's releases.
v3.30.1
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.1 - 05 Sep 2025
- Update default CodeQL bundle version to 2.23.0. #3077
See the full CHANGELOG.md for more information.
v3.30.0
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
3.30.0 - 01 Sep 2025
- Reduce the size of the CodeQL Action, speeding up workflows by approximately 4 seconds. #3054
See the full CHANGELOG.md for more information.
Changelog
Sourced from github/codeql-action's changelog.
CodeQL Action Changelog
See the releases page for the relevant changes to the CodeQL CLI and language packs.
[UNRELEASED]
No user facing changes.
3.30.1 - 05 Sep 2025
- Update default CodeQL bundle version to 2.23.0. #3077
3.30.0 - 01 Sep 2025
- Reduce the size of the CodeQL Action, speeding up workflows by approximately 4 seconds. #3054
3.29.11 - 21 Aug 2025
- Update default CodeQL bundle version to 2.22.4. #3044
3.29.10 - 18 Aug 2025
No user facing changes.
3.29.9 - 12 Aug 2025
No user facing changes.
3.29.8 - 08 Aug 2025
- Fix an issue where the Action would autodetect unsupported languages such as HTML. #3015
3.29.7 - 07 Aug 2025
This release rolls back 3.29.6 to address issues with language autodetection. It is identical to 3.29.5.
3.29.6 - 07 Aug 2025
- The
cleanup-level
input to theanalyze
Action is now deprecated. The CodeQL Action has written a limited amount of intermediate results to the database since version 2.2.5, and now automatically manages cleanup. #2999- Update default CodeQL bundle version to 2.22.3. #3000
3.29.5 - 29 Jul 2025
- Update default CodeQL bundle version to 2.22.2. #2986
3.29.4 - 23 Jul 2025
No user facing changes.
3.29.3 - 21 Jul 2025
... (truncated)
Commits
f1f6e5f
Merge pull request #3081 from github/update-v3.30.1-2d2f57ed35dd2164
Update changelog for v3.30.12d2f57e
Merge pull request #3079 from github/mbg/proxy/accept-git-sourceb364f99
Merge pull request #3077 from github/update-bundle/codeql-bundle-v2.23.05b8860a
Merge branch 'main' into update-bundle/codeql-bundle-v2.23.08fe8b24
Addgit_source
as supported registry type for Go6242bcb
Allow multiple registry types inLANGUAGE_TO_REGISTRY_TYPE
dfb741d
Merge pull request #3075 from github/mbg/remove-augmentation-properties920bba1
Add unit tests forcreateInitWithConfigStatusReport
37ddb03
AddcreateInitWithConfigStatusReport
function- Additional commits viewable in compare view
Updates pypa/gh-action-pypi-publish
from 1.12.4 to 1.13.0
Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
v1.13.0
[!important] 🚨 This release includes fixes for GHSA-vxmw-7h4f-hqxh discovered by
@woodruffw
💰. We've also integrated Zizmor to catch similar issues in the future and you should too.✨ New Stuff
@woodruffw
💰 updated the README to no longer mention the attestations feature being experimental in #347: it's been rather stable for a year already 🎉 He also added more diagnostic output which includes printing out the GitHub Environment claim via #371 and warning about the unsupported reusable workflows configurations #306, when using Trusted Publishing.[!tip] The official support for reusable workflows is currently blocked on changes to PyPI. To get updates about progress on the action side, you may want to subscribe to #166. At PyCon US 2025 Sprints,
@facutuesca
💰,@miketheman
💰,@woodruffw
💰 and I💰 spent several hours IRL brainstorming how to fix this and migrate projects that happen to rely on an obscure corner case with reusable workflows that temporarily allows them to function by accident. The result of that discussion is posted @ pypi/warehouse#11096. Note that this is a volunteer-led effort and there is no ETA. If you need this soon, make your employer sponsor the PSF and maybe they'll be able to hire somebody for this work on Warehouse.In addition to that,
@konstin
💰 sent #378 to pinactions/setup-python
to a SHA hash. This makespypi-publish
compatible with new GitHub policies that allow organizations to mandate hash-pinning actions used in workflows.🛠️ Internal Dependencies
@webknjaz
💰 made a bunch of updates to the action runtime which includes bumping it to Python 3.13 in #331 and updating the dependency tree across the board.pip-with-requires-python
is no longer being installed (#332). Some related bumps were contributed by@woodruffw
💰 (#359) and@kurtmckee
💰 sent a contributor-facing PR, bumping the linting configuration via #335.💪 New Contributors
@kurtmckee
made their first contribution in #335@konstin
made their first contribution in #378🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.12.4...v1.13.0
🧔♂️ Release Manager:
@webknjaz
🇺🇦💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
Commits
ed0c539
📦📌 Bump the pinned dependency tree77db1b7
Merge branch PR #306, GHSA-vxmw-7h4f-hqxh fix and PR #378 into unstable/v1280b3a1
Aliastyping as t
in importse380240
Useobject
in place oftyping.Any
in annotationse50bff6
Deduplicate claim ref lookupdecbc9a
Hint people to subscribe to #166 for notifications8208ad3
Ask not to report bugs with reusable workflowff0fef5
🧪 Scope WPS202 suppression to specific files1293b8c
Use yamllint disable line length linted01280
Linter (different rule)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions
Pull Request Statistics
1
4
+8
-8
Package Dependencies
github/codeql-action
actions
3.29.11 → 3.30.1
Minor
pypa/gh-action-pypi-publish
actions
1.12.4 → 1.13.0
Minor
Technical Details
ID: | 7102941 |
UUID: | 2806519523 |
Node ID: | PR_kwDOLuh4Ks6nSBbj |
Host: | GitHub |
Repository: | mongodb/django-mongodb-backend |
Merge State: | Unknown |