Skip to content

chore(deps): bump the github-actions-dependencies group with 3 updates - #1084

Merged
mbevc1 merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-3865b16dd1
Aug 14, 2026
Merged

mbevc1 merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-dependencies-3865b16dd1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions-dependencies group with 3 updates: step-security/harden-runner, actions/attest and anthropics/claude-code-action.

Updates step-security/harden-runner from 2.20.0 to 2.20.1

Release notes

Sourced from step-security/harden-runner's releases.

v2.20.1

What's Changed

  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1

Commits
  • b09bb98 Merge pull request #680 from step-security/aws-code-build
  • 35cd77b docs: document the Global Block List in the features list
  • bb6dbef chore: rebuild dist with clean dependency install
  • 98f73c5 chore: update eBPF agent to v1.8.14
  • 54193c1 Reapply "feat(runners): detect AWS CodeBuild-hosted runners as third-party pr...
  • d22dd48 Revert "fix(self-hosted): flush agent events at job end when deploy-on-self-h...
  • 0ff0941 fix(self-hosted): flush agent events at job end when deploy-on-self-hosted-vm...
  • a3c333d Revert "feat(runners): detect AWS CodeBuild-hosted runners as third-party pro...
  • bf94c00 feat(runners): detect AWS CodeBuild-hosted runners as third-party provider
  • 514522c fix(self-hosted): resolve runner user when USER env var is unset
  • See full diff in compare view

Updates actions/attest from 4.2.1 to 4.2.2

Release notes

Sourced from actions/attest's releases.

v4.2.2

What's Changed

Full Changelog: actions/attest@v4.2.1...v4.2.2

Commits

Updates anthropics/claude-code-action from 1.0.183 to 1.0.189

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.189

Full Changelog: anthropics/claude-code-action@v1...v1.0.189

v1.0.188

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.188

v1.0.187

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.187

v1.0.186

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.186

v1.0.185

What's Changed

... (truncated)

Commits
  • 6b082c4 chore: bump Claude Code to 2.1.226 and Agent SDK to 0.3.226
  • 7ff6806 chore: bump Claude Code to 2.1.225 and Agent SDK to 0.3.225
  • 751e003 fix(branch): collapse empty path segments in branch_name_template (#1539)
  • b704dd3 fix(branch): validate generated branch name under commit signing (#1582)
  • ecf573b fix: expose conclusion output (#1549)
  • 7764306 fix: stop retrying deterministic ref updates (#1551)
  • 5dd098c ci: pass allowed tools through claude args (#1552)
  • 4c4309a fix(cache): disable setup-bun cache to avoid 5-retry HTML-error burn (#1580)
  • c4190db docs: update base action inputs (#1550)
  • 9a2db97 docs: fix broken Bedrock anchor in cloud-providers.md (#1579)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions-dependencies group with 3 updates: [step-security/harden-runner](https://github.com/step-security/harden-runner), [actions/attest](https://github.com/actions/attest) and [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action).


Updates `step-security/harden-runner` from 2.20.0 to 2.20.1
- [Release notes](https://github.com/step-security/harden-runner/releases)
- [Commits](step-security/harden-runner@bf7454d...b09bb98)

Updates `actions/attest` from 4.2.1 to 4.2.2
- [Release notes](https://github.com/actions/attest/releases)
- [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md)
- [Commits](actions/attest@v4.2.1...v4.2.2)

Updates `anthropics/claude-code-action` from 1.0.183 to 1.0.189
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@v1.0.183...v1.0.189)

---
updated-dependencies:
- dependency-name: step-security/harden-runner
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
- dependency-name: actions/attest
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.189
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github-actions labels Aug 11, 2026
@mbevc1
mbevc1 enabled auto-merge (squash) August 14, 2026 08:26
@mbevc1
mbevc1 merged commit b5c5c40 into main Aug 14, 2026
33 checks passed
@mbevc1
mbevc1 deleted the dependabot/github_actions/github-actions-dependencies-3865b16dd1 branch August 14, 2026 08:27
social4hyq pushed a commit to social4hyq/homebrew-core that referenced this pull request Sep 20, 2026
kosli-cli 2.36.6

Created-by: HarmonybrewBot
Commit-by: HarmonybrewBot
Merged-by: HarmonybrewBot
Description: Created by `brew bump`

---

Created with `brew bump-formula-pr`.<details>
  <summary>release notes</summary>
  <pre># Bug fixes
- Empty `--attachments` or `--template` elements (e.g. from unset shell variables) are now rejected with a clear error instead of being silently dropped.
- An empty `KOSLI_CONFIG_FILE` environment variable no longer suppresses config file loading; it is treated as unset and falls back to the default.
- An empty `KOSLI_API_TOKEN` environment variable no longer skips decryption of a config-file token.
- A boolean flag given an empty value (e.g. `--compliant ""` or `--new-compliance-status ""`) is now rejected with a clear error naming the flag, preventing the opposite compliance verdict from being recorded silently.
- Config file or environment values that cannot be applied to a flag now produce an error naming the flag and its source, instead of silently failing.

## What's Changed
* fix(attest): always serialise commits in pull request attestations by @dangrondahl in kosli-dev/cli#1083
* fix(docs): correct invalid regex in snapshot ecs help examples by @dangrondahl in kosli-dev/cli#1080
* fix(config): treat empty KOSLI_* env vars as unset, not as set by @JonJagger in kosli-dev/cli#1089
* fix(config): report config values that cannot be applied to their flag by @JonJagger in kosli-dev/cli#1090
* fix(flags): reject an empty element in a multi-value flag by @JonJagger in kosli-dev/cli#1092
* fix(flags): reject an empty value written after a boolean flag by @JonJagger in kosli-dev/cli#1091
* chore(deps): bump the github-actions-dependencies group with 3 updates by @dependabot[bot] in kosli-dev/cli#1084
* chore(deps): bump the go-dependencies group with 9 updates by @dependabot[bot] in kosli-dev/cli#1085
* chore(deps): bump anthropics/claude-code-action from 1.0.189 to 1.0.191 in the github-actions-dependencies group by @dependabot[bot] in kosli-dev/cli#1094
* chore(deps): bump the go-dependencies group with 7 updates by @dependabot[bot] in kosli-dev/cli#1095
* chore(deps): bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 by @dependabot[bot] in kosli-dev/cli#1096


**Full Changelog**: https://github.com/kosli-dev/cli/compare/v2.36.5...v2.36.6</pre>
  <p>View the full release notes at <a href="https://github.com/kosli-dev/cli/releases/tag/v2.36.6">https://github.com/kosli-dev/cli/releases/tag/v2.36.6</a>.</p>
</details>
<hr>

See merge request: Harmonybrew/homebrew-core!16566
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github-actions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant