Skip to content

ci: bump the github-actions group across 1 directory with 2 updates - #58

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-0ba97f940e
Sep 22, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-0ba97f940e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates in the / directory: astral-sh/setup-uv and google/osv-scanner-action/osv-scanner-action.

Updates astral-sh/setup-uv from 10.0.1 to 10.1.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

Commits

Updates google/osv-scanner-action/osv-scanner-action from 2.5.1 to 2.6.0

Release notes

Sourced from google/osv-scanner-action/osv-scanner-action's releases.

v2.6.0

What's Changed

New Contributors

Full Changelog: google/osv-scanner-action@v2.5.1...v2.6.0

Commits
  • a345acf Merge pull request #144 from google/update-to-v2.6.0
  • 6b289e0 Update unified workflow example to point to v2.6.0 reusable workflows
  • c7c7bcb Update reusable workflows to point to v2.6.0 actions
  • 7f58dd6 "Update actions to use v2.6.0 osv-scanner image"
  • 8e5cf47 Merge pull request #139 from alimony/fail-closed-on-incomplete-scan
  • bf5f924 Merge remote-tracking branch 'upstream/main' into fail-closed-on-incomplete-scan
  • ffa0a5f Merge pull request #142 from google/fix-json-export-code
  • 259ba4a Fix JSON results export
  • d291480 Check for file size as well
  • 2dff55c Fail the job when a scan does not complete
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Dependency updates github-actions GitHub Actions workflow pin updates labels Sep 21, 2026
@dependabot dependabot Bot added dependencies Dependency updates github-actions GitHub Actions workflow pin updates labels Sep 21, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved automatically for a trusted Dependabot revision.

@github-actions
github-actions Bot enabled auto-merge (squash) September 21, 2026 13:26
Bumps the github-actions group with 2 updates in the / directory: [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) and [google/osv-scanner-action/osv-scanner-action](https://github.com/google/osv-scanner-action).


Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@20cfd1b...bec219d)

Updates `google/osv-scanner-action/osv-scanner-action` from 2.5.1 to 2.6.0
- [Release notes](https://github.com/google/osv-scanner-action/releases)
- [Commits](google/osv-scanner-action@6e4298e...a345acf)

---
updated-dependencies:
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: google/osv-scanner-action/osv-scanner-action
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-0ba97f940e branch from 19b31a0 to 0bcec9e Compare September 22, 2026 13:24

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved automatically for a trusted Dependabot revision.

@github-actions
github-actions Bot merged commit 465c9a0 into main Sep 22, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-0ba97f940e branch September 22, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates github-actions GitHub Actions workflow pin updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants