From faf55f22c829fb519078b6cf83c71e958d9905c6 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 21 Jul 2026 05:09:43 +0000 Subject: [PATCH] chore(deps)(deps): bump the github-actions group with 10 updates Bumps the github-actions group with 10 updates: | Package | From | To | | --- | --- | --- | | [jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [jebel-quant/rhiza/.github/workflows/rhiza_book.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [jebel-quant/rhiza/.github/workflows/rhiza_ci.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [jebel-quant/rhiza/.github/workflows/rhiza_mutation.yml](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [actions/checkout](https://github.com/actions/checkout) | `6.0.3` | `6.1.0` | | [jebel-quant/rhiza](https://github.com/jebel-quant/rhiza) | `1.2.1` | `1.2.2` | | [actions/attest](https://github.com/actions/attest) | `4.1.1` | `4.2.0` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.0` | `1.14.1` | Updates `jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `jebel-quant/rhiza/.github/workflows/rhiza_book.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `jebel-quant/rhiza/.github/workflows/rhiza_ci.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `jebel-quant/rhiza/.github/workflows/rhiza_mutation.yml` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `actions/checkout` from 6.0.3 to 6.1.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v6.0.3...v6.1.0) Updates `jebel-quant/rhiza` from 1.2.1 to 1.2.2 - [Release notes](https://github.com/jebel-quant/rhiza/releases) - [Changelog](https://github.com/Jebel-Quant/rhiza/blob/main/CHANGELOG.md) - [Commits](https://github.com/jebel-quant/rhiza/compare/v1.2.1...v1.2.2) Updates `actions/attest` from 4.1.1 to 4.2.0 - [Release notes](https://github.com/actions/attest/releases) - [Changelog](https://github.com/actions/attest/blob/main/RELEASE.md) - [Commits](https://github.com/actions/attest/compare/v4.1.1...v4.2.0) Updates `pypa/gh-action-pypi-publish` from 1.14.0 to 1.14.1 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.0...v1.14.1) --- updated-dependencies: - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_book.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_ci.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: jebel-quant/rhiza/.github/workflows/rhiza_mutation.yml dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: jebel-quant/rhiza dependency-version: 1.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: actions/attest dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/rhiza_benchmark.yml | 2 +- .github/workflows/rhiza_book.yml | 2 +- .github/workflows/rhiza_ci.yml | 2 +- .github/workflows/rhiza_codeql.yml | 2 +- .github/workflows/rhiza_marimo.yml | 2 +- .github/workflows/rhiza_mutation.yml | 2 +- .github/workflows/rhiza_release.yml | 20 ++++++++++---------- 7 files changed, 16 insertions(+), 16 deletions(-) diff --git a/.github/workflows/rhiza_benchmark.yml b/.github/workflows/rhiza_benchmark.yml index 390fcb0..a828854 100644 --- a/.github/workflows/rhiza_benchmark.yml +++ b/.github/workflows/rhiza_benchmark.yml @@ -20,5 +20,5 @@ on: jobs: benchmark: - uses: jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_benchmark.yml@v1.2.2 secrets: inherit diff --git a/.github/workflows/rhiza_book.yml b/.github/workflows/rhiza_book.yml index 6c1c11e..73c3f40 100644 --- a/.github/workflows/rhiza_book.yml +++ b/.github/workflows/rhiza_book.yml @@ -29,7 +29,7 @@ on: jobs: book: - uses: jebel-quant/rhiza/.github/workflows/rhiza_book.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_book.yml@v1.2.2 secrets: inherit permissions: contents: read diff --git a/.github/workflows/rhiza_ci.yml b/.github/workflows/rhiza_ci.yml index 7756855..b98e895 100644 --- a/.github/workflows/rhiza_ci.yml +++ b/.github/workflows/rhiza_ci.yml @@ -26,5 +26,5 @@ on: jobs: ci: - uses: jebel-quant/rhiza/.github/workflows/rhiza_ci.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_ci.yml@v1.2.2 secrets: inherit diff --git a/.github/workflows/rhiza_codeql.yml b/.github/workflows/rhiza_codeql.yml index 521d5e1..a444a1f 100644 --- a/.github/workflows/rhiza_codeql.yml +++ b/.github/workflows/rhiza_codeql.yml @@ -39,7 +39,7 @@ on: jobs: codeql: - uses: jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_codeql.yml@v1.2.2 secrets: inherit permissions: security-events: write # Upload CodeQL results to code scanning diff --git a/.github/workflows/rhiza_marimo.yml b/.github/workflows/rhiza_marimo.yml index b663088..34e8dc2 100644 --- a/.github/workflows/rhiza_marimo.yml +++ b/.github/workflows/rhiza_marimo.yml @@ -28,5 +28,5 @@ on: jobs: marimo: - uses: jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_marimo.yml@v1.2.2 secrets: inherit diff --git a/.github/workflows/rhiza_mutation.yml b/.github/workflows/rhiza_mutation.yml index 182cb72..66cbd16 100644 --- a/.github/workflows/rhiza_mutation.yml +++ b/.github/workflows/rhiza_mutation.yml @@ -42,7 +42,7 @@ jobs: # this repo sets the `MUTATION_ENABLED` variable to 'true'. Gating here in # the caller keeps it optional regardless of the pinned reusable workflow. if: ${{ vars.MUTATION_ENABLED == 'true' }} - uses: jebel-quant/rhiza/.github/workflows/rhiza_mutation.yml@v1.2.1 + uses: jebel-quant/rhiza/.github/workflows/rhiza_mutation.yml@v1.2.2 secrets: inherit permissions: contents: read diff --git a/.github/workflows/rhiza_release.yml b/.github/workflows/rhiza_release.yml index 4c1f3b0..d09d119 100644 --- a/.github/workflows/rhiza_release.yml +++ b/.github/workflows/rhiza_release.yml @@ -127,7 +127,7 @@ jobs: tag: ${{ steps.set_tag.outputs.tag }} steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -212,7 +212,7 @@ jobs: attestations: write # SLSA provenance + SBOM attestations (public repos only) steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -222,7 +222,7 @@ jobs: version: "0.11.16" - name: Configure git auth for private packages - uses: jebel-quant/rhiza/.github/actions/configure-git-auth@v1.2.1 + uses: jebel-quant/rhiza/.github/actions/configure-git-auth@v1.2.2 with: token: ${{ secrets.GH_PAT }} @@ -287,7 +287,7 @@ jobs: # The XML format is provided for compatibility but doesn't need separate attestation. id: attest-sbom if: hashFiles('pyproject.toml') != '' && github.event.repository.private == false - uses: actions/attest@v4.1.1 + uses: actions/attest@v4.2.0 with: subject-path: sbom.cdx.json sbom-path: sbom.cdx.json @@ -342,7 +342,7 @@ jobs: steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -393,7 +393,7 @@ jobs: steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -431,7 +431,7 @@ jobs: # repository-url and password only used for custom feeds, not for PyPI with OIDC - name: Publish to PyPI if: ${{ steps.check_dist.outputs.should_publish == 'true' }} - uses: pypa/gh-action-pypi-publish@v1.14.0 + uses: pypa/gh-action-pypi-publish@v1.14.1 with: packages-dir: dist/ skip-existing: true @@ -450,7 +450,7 @@ jobs: steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -529,7 +529,7 @@ jobs: image_name: ${{ steps.image_name.outputs.image_name }} steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0 @@ -616,7 +616,7 @@ jobs: contents: write # Needed to undraft/publish the GitHub release steps: - name: Checkout Code - uses: actions/checkout@v6.0.3 + uses: actions/checkout@v6.1.0 with: fetch-depth: 0