Skip to content

ci(deps): bump the actions group with 7 updates - #16

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-99c34aa1f6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-99c34aa1f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown

Bumps the actions group with 7 updates:

Package From To
docker/login-action 4.1.0 4.6.0
actions/setup-go 5.5.0 7.0.0
praxis-proxy/conventions/.github/actions/setup-rust 0.1.0 0.3.0
docker/build-push-action 6.18.0 7.4.0
praxis-proxy/conventions/.github/actions/setup-rust-lint 0.1.0 0.3.0
praxis-proxy/conventions/.github/actions/coverage-check 0.1.0 0.3.0
praxis-proxy/conventions/.github/actions/supply-chain-audit 0.1.0 0.3.0

Updates docker/login-action from 4.1.0 to 4.6.0

Release notes

Sourced from docker/login-action's releases.

v4.6.0

Full Changelog: docker/login-action@v4.5.2...v4.6.0

v4.5.2

Full Changelog: docker/login-action@v4.5.1...v4.5.2

v4.5.1

Full Changelog: docker/login-action@v4.5.0...v4.5.1

v4.5.0

Full Changelog: docker/login-action@v4.4.0...v4.5.0

v4.4.0

Full Changelog: docker/login-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/login-action@v4.2.0...v4.3.0

v4.2.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates actions/setup-go from 5.5.0 to 7.0.0

Release notes

Sourced from actions/setup-go's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/setup-go@v6...v7.0.0

v6.5.0

What's Changed

Dependency update

New Contributors

Full Changelog: actions/setup-go@v6...v6.5.0

v6.4.0

What's Changed

Enhancement

Dependency update

Documentation update

New Contributors

Full Changelog: actions/setup-go@v6...v6.4.0

v6.3.0

What's Changed

Full Changelog: actions/setup-go@v6...v6.3.0

v6.2.0

What's Changed

... (truncated)

Commits

Updates praxis-proxy/conventions/.github/actions/setup-rust from 0.1.0 to 0.3.0

Commits
  • c5837c3 release: v0.3.0
  • bd62781 feat(ci): let other repos run these workflows instead of copying them
  • 747ec18 fix(ci): let the org's maintainer teams triage issues
  • 23a6013 fix(ci): explain PR Conventions failures on fork and Dependabot PRs
  • fee1681 fix(ci): stop PR Conventions failing on every Dependabot PR
  • f4422e2 chore(deps): Bump docker/build-push-action (#11)
  • 29ef9b4 chore(deps): Bump taiki-e/install-action (#12)
  • 47bb6d1 feat: add metadata-context input to ghcr-publish action (#8)
  • cfdba0f chore(deps): Bump docker/setup-buildx-action (#7)
  • 728a69f chore(deps): Bump docker/login-action in /.github/actions/ghcr-publish (#6)
  • Additional commits viewable in compare view

Updates docker/build-push-action from 6.18.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.

v7.4.0

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

v7.3.0

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

v7.2.0

Full Changelog: docker/build-push-action@v7.1.0...v7.2.0

v7.1.0

... (truncated)

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

Updates praxis-proxy/conventions/.github/actions/setup-rust-lint from 0.1.0 to 0.3.0

Commits
  • c5837c3 release: v0.3.0
  • bd62781 feat(ci): let other repos run these workflows instead of copying them
  • 747ec18 fix(ci): let the org's maintainer teams triage issues
  • 23a6013 fix(ci): explain PR Conventions failures on fork and Dependabot PRs
  • fee1681 fix(ci): stop PR Conventions failing on every Dependabot PR
  • f4422e2 chore(deps): Bump docker/build-push-action (#11)
  • 29ef9b4 chore(deps): Bump taiki-e/install-action (#12)
  • 47bb6d1 feat: add metadata-context input to ghcr-publish action (#8)
  • cfdba0f chore(deps): Bump docker/setup-buildx-action (#7)
  • 728a69f chore(deps): Bump docker/login-action in /.github/actions/ghcr-publish (#6)
  • Additional commits viewable in compare view

Updates praxis-proxy/conventions/.github/actions/coverage-check from 0.1.0 to 0.3.0

Commits
  • c5837c3 release: v0.3.0
  • bd62781 feat(ci): let other repos run these workflows instead of copying them
  • 747ec18 fix(ci): let the org's maintainer teams triage issues
  • 23a6013 fix(ci): explain PR Conventions failures on fork and Dependabot PRs
  • fee1681 fix(ci): stop PR Conventions failing on every Dependabot PR
  • f4422e2 chore(deps): Bump docker/build-push-action (#11)
  • 29ef9b4 chore(deps): Bump taiki-e/install-action (#12)
  • 47bb6d1 feat: add metadata-context input to ghcr-publish action (#8)
  • cfdba0f chore(deps): Bump docker/setup-buildx-action (#7)
  • 728a69f chore(deps): Bump docker/login-action in /.github/actions/ghcr-publish (#6)
  • Additional commits viewable in compare view

Updates praxis-proxy/conventions/.github/actions/supply-chain-audit from 0.1.0 to 0.3.0

Commits
  • c5837c3 release: v0.3.0
  • bd62781 feat(ci): let other repos run these workflows instead of copying them
  • 747ec18 fix(ci): let the org's maintainer teams triage issues
  • 23a6013 fix(ci): explain PR Conventions failures on fork and Dependabot PRs
  • fee1681 fix(ci): stop PR Conventions failing on every Dependabot PR
  • f4422e2 chore(deps): Bump docker/build-push-action (#11)
  • 29ef9b4 chore(deps): Bump taiki-e/install-action (#12)
  • 47bb6d1 feat: add metadata-context input to ghcr-publish action (#8)
  • cfdba0f chore(deps): Bump docker/setup-buildx-action (#7)
  • 728a69f chore(deps): Bump docker/login-action in /.github/actions/ghcr-publish (#6)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by CodeRabbit

  • Chores
    • Updated the versions of tools used in conformance checks, integration tests, releases, and CI checks.

Bumps the actions group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [docker/login-action](https://github.com/docker/login-action) | `4.1.0` | `4.6.0` |
| [actions/setup-go](https://github.com/actions/setup-go) | `5.5.0` | `7.0.0` |
| [praxis-proxy/conventions/.github/actions/setup-rust](https://github.com/praxis-proxy/conventions) | `0.1.0` | `0.3.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6.18.0` | `7.4.0` |
| [praxis-proxy/conventions/.github/actions/setup-rust-lint](https://github.com/praxis-proxy/conventions) | `0.1.0` | `0.3.0` |
| [praxis-proxy/conventions/.github/actions/coverage-check](https://github.com/praxis-proxy/conventions) | `0.1.0` | `0.3.0` |
| [praxis-proxy/conventions/.github/actions/supply-chain-audit](https://github.com/praxis-proxy/conventions) | `0.1.0` | `0.3.0` |


Updates `docker/login-action` from 4.1.0 to 4.6.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@4907a6d...dbcb813)

Updates `actions/setup-go` from 5.5.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@d35c59a...b7ad1da)

Updates `praxis-proxy/conventions/.github/actions/setup-rust` from 0.1.0 to 0.3.0
- [Changelog](https://github.com/praxis-proxy/conventions/blob/main/docs/release.md)
- [Commits](praxis-proxy/conventions@7e1e8d9...c5837c3)

Updates `docker/build-push-action` from 6.18.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@2634353...c3c9e26)

Updates `praxis-proxy/conventions/.github/actions/setup-rust-lint` from 0.1.0 to 0.3.0
- [Changelog](https://github.com/praxis-proxy/conventions/blob/main/docs/release.md)
- [Commits](praxis-proxy/conventions@7e1e8d9...c5837c3)

Updates `praxis-proxy/conventions/.github/actions/coverage-check` from 0.1.0 to 0.3.0
- [Changelog](https://github.com/praxis-proxy/conventions/blob/main/docs/release.md)
- [Commits](praxis-proxy/conventions@7e1e8d9...c5837c3)

Updates `praxis-proxy/conventions/.github/actions/supply-chain-audit` from 0.1.0 to 0.3.0
- [Changelog](https://github.com/praxis-proxy/conventions/blob/main/docs/release.md)
- [Commits](praxis-proxy/conventions@7e1e8d9...c5837c3)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: actions/setup-go
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: praxis-proxy/conventions/.github/actions/setup-rust
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: praxis-proxy/conventions/.github/actions/setup-rust-lint
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: praxis-proxy/conventions/.github/actions/coverage-check
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: praxis-proxy/conventions/.github/actions/supply-chain-audit
  dependency-version: 0.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: praxis-proxy/coderabbit/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 042f3f2b-f505-4152-821b-a7b0175852c8
📥 Commits

Reviewing files that changed from the base of the PR and between fb8beaa and 10e7c53.

📒 Files selected for processing (4)
  • .github/workflows/conformance.yaml
  • .github/workflows/integration.yaml
  • .github/workflows/release.yaml
  • .github/workflows/tests.yaml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The conformance, integration, release, and test workflows now use updated pinned versions of their GitHub Actions.

Changes

Workflow action updates

Layer / File(s) Summary
Update workflow action pins
.github/workflows/*
The workflows use updated pins for Docker login, Docker build-and-push, Go setup, Rust setup, lint, coverage, and supply-chain audit actions.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: shaneutt

Merge Risk: ⚪ Minimal · up to 10e7c

The workflow action updates match the configured inputs and Rust version requirements, with no actionable CI or release risk evident in the reviewed changes.

Architecture Summary

Architecture risk: 🔵 Low · up to 10e7c

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/conformance.yaml: Updated the pinned docker/login-action revision from v4.1.0 to v4.6.0.
  • observed — Modified behavior in .github/workflows/conformance.yaml: Updated the pinned actions/setup-go revision from v5.5.0 to v7.0.0.
  • observed — Modified behavior in .github/workflows/integration.yaml: The GHCR login action changes from v4.1.0 to v4.6.0, and the Rust setup action changes from v0.1.0 to v0.3.0.
  • observed — Modified behavior in .github/workflows/release.yaml: The Rust setup step now uses setup-rust v0.3.0 instead of v0.1.0.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: seven GitHub Actions dependencies are updated.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants