Skip to content

chore(deps): actions: bump the all-actions group with 3 updates#625

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/all-actions-771d7f107e
Open

chore(deps): actions: bump the all-actions group with 3 updates#625
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/all-actions-771d7f107e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-actions group with 3 updates: aws-actions/configure-aws-credentials, withastro/action and github/issue-metrics.

Updates aws-actions/configure-aws-credentials from 6.2.1 to 6.2.2

Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.2.2

6.2.2 (2026-07-07)

Miscellaneous Chores

Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.2.2 (2026-07-07)

Miscellaneous Chores

6.2.1 (2026-06-26)

Bug Fixes

  • enforce allowed-account-ids on all auth paths (#1847) (4d281fb)

6.2.0 (2026-06-01)

Features

Bug Fixes

  • skip credential check on output-env-credentials: false (#1778) (58e7c47)
  • assumeRole failing from session tag size too large (#1808) (d6f5dc3)

6.1.3 (2026-05-28)

Bug Fixes

  • fix: allow kubelet token symlink in #1805

6.1.2 (2026-05-26)

Bug Fixes

6.1.1 (2026-05-05)

Miscellaneous Chores

... (truncated)

Commits
  • 517a711 chore(main): release 6.2.2 (#1876)
  • d01d678 chore: release 6.2.2
  • 8efa52b chore(deps-dev): bump vitest dependencies (#1874)
  • 8e1eed5 chore(deps-dev): bump @​smithy/property-provider from 4.4.4 to 4.4.6 (#1869)
  • 112421a chore(deps-dev): bump @​biomejs/biome from 2.5.1 to 2.5.2 (#1868)
  • fbc01c6 chore(deps-dev): bump @​types/node from 26.0.1 to 26.1.0 (#1871)
  • b12ca87 chore(deps-dev): bump memfs from 4.57.8 to 4.58.0 (#1873)
  • d314f7f chore: Update dist
  • a53b65b chore(deps): bump @​aws-sdk/client-sts from 3.1076.0 to 3.1080.0 (#1867)
  • 338d2c1 chore(deps-dev): bump sigstore from 4.1.0 to 4.1.1 (#1864)
  • Additional commits viewable in compare view

Updates withastro/action from 6.1.1 to 6.1.2

Release notes

Sourced from withastro/action's releases.

v6.1.2

Changelog

See details of all code changes since previous release.

Commits

Updates github/issue-metrics from 4.2.8 to 5.0.0

Release notes

Sourced from github/issue-metrics's releases.

v5.0.0

Changelog

💥 Breaking Changes

🧰 Maintenance

See details of all code changes since previous release

Commits
  • df8c49d refactor: migrate from github3.py to PyGithub (#789)
  • 0241b11 chore(deps): bump the dependencies group with 4 updates (#788)
  • dba1789 chore(deps): bump python from 63a4c7f to b877e50 (#786)
  • 2c2cef3 chore(deps): bump pytest from 9.1.0 to 9.1.1 in the dependencies group (#787)
  • 92b54ef chore(deps): bump python from 44dd044 to 63a4c7f (#781)
  • 172961b chore(deps): bump the dependencies group with 2 updates (#782)
  • afbd9f7 chore(deps): bump github-community-projects/contributors (#783)
  • 74a065a chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#784)
  • c4559e3 chore(deps): bump python in the dependencies group (#780)
  • 12aa671 chore(deps): bump cryptography from 46.0.7 to 48.0.1 (#778)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-actions group with 3 updates: [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials), [withastro/action](https://github.com/withastro/action) and [github/issue-metrics](https://github.com/github/issue-metrics).


Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.2
- [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases)
- [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md)
- [Commits](aws-actions/configure-aws-credentials@254c19b...517a711)

Updates `withastro/action` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/withastro/action/releases)
- [Commits](withastro/action@b7d5362...e84f40b)

Updates `github/issue-metrics` from 4.2.8 to 5.0.0
- [Release notes](https://github.com/github/issue-metrics/releases)
- [Commits](github-community-projects/issue-metrics@44173f9...df8c49d)

---
updated-dependencies:
- dependency-name: aws-actions/configure-aws-credentials
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-actions
- dependency-name: withastro/action
  dependency-version: 6.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-actions
- dependency-name: github/issue-metrics
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 18, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 18, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 18, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

Approve. Clean, correctly SHA-pinned GitHub Actions bump. All three new pins verify against their upstream release tags, CI is green, and the one major bump (github/issue-metrics 4.2.8 -> 5.0.0) is an internal-only refactor that does not touch the action's input/output contract as we consume it.

Vision alignment

Supports the platform's operational-excellence and bounded/reviewable tenets: keeps the CI supply chain current while preserving immutable SHA pinning (the safe way to consume third-party actions). No control-plane or blast-radius impact. No ADR/RFC needed.

Blocking issues

None.

Version delta verification (done, not assumed)

Each uses: pin in the diff was checked against the upstream release tag via gh api .../git/ref/tags/<tag>:

Action Old -> New New SHA in diff Upstream tag SHA Match
aws-actions/configure-aws-credentials v6.2.1 -> v6.2.2 517a711 517a711dbcd0e402f90c77e7e2f81e849156e31d (v6.2.2) yes
withastro/action v6.1.1 -> v6.1.2 e84f40b e84f40bd8d2caa9e768ec82ad30dd81f0b280853 (v6.1.2) yes
github/issue-metrics v4.2.8 -> v5.0.0 df8c49d df8c49d20958f9345281fa2124858bd0ad227e1f (v5.0.0) yes

Comment tags on each line match the resolved version. configure-aws-credentials v6.2.2 is a chore/release patch (no functional change). withastro/action v6.1.2 only bumps its internal tool versions (PNPM/Node/Deno/cache).

The one major bump: github/issue-metrics 5.0.0

The breaking change in 5.0.0 is a purely internal migration (github3.py -> PyGithub) - it does not change the action's public interface. Verified against our usage in .github/workflows/monthly-repo-metrics.yml:

  • We drive the action only via env: GH_TOKEN and env: SEARCH_QUERY, and consume the default output file issue_metrics.md.
  • The v5.0.0 README still documents GH_TOKEN (required), SEARCH_QUERY (required), and default OUTPUT_FILE: issue_metrics.md - identical to how we call it; the v5 sample workflow is the same shape as ours.
  • SEARCH_QUERY uses standard GitHub search syntax (repo:, is:issue, -reason:, is:pr, -is:draft) which PyGithub honors the same way.
  • Blast radius is minimal regardless: this is a scheduled/workflow_dispatch-only monthly reporting job, not on the deploy/test critical path.

Note: .github/dependabot.yml groups these under all-actions with no ignore: version-update:semver-major restriction for that group, so this major bump is permitted by config (the semver-major ignores at lines 47/70 apply to other ecosystems).

Non-blocking suggestions / nits

  1. github/issue-metrics crossed a major version silently inside a grouped Dependabot PR. That is fine here given the internal-only nature, but for grouped major bumps in general it is worth a human eyeball on the changelog before merge (as done here). No action needed.

Documentation

No docs impact. CI action version bumps do not touch docs/guides/, docs/design/, ADRs, or the Starlight mirror. No mirror-sync required. No dependabot.yml drift.

Tests & CI

CI green: build (agentcore) pass, Secrets, deps, and workflow scan pass, Dead-code detection (advisory) pass, Validate PR title pass. auto-approve/CodeQL skipping (expected for this path). No CDK construct/stack changes -> bootstrap synth-coverage not applicable. No unit tests required or expected for a workflow-only SHA bump; the workflows themselves are the executable surface and are exercised by CI.

Review agents run

  • /security-review - RAN. GitHub Actions changes touch the CI supply-chain/secrets boundary. Result: 0 high-confidence findings. SHA pinning preserved on all three actions; no new trigger surface (monthly-repo-metrics.yml stays schedule/workflow_dispatch); no change to secret flow (AWS_ROLE_TO_ASSUME, GITHUB_TOKEN, github.token) or permissions blocks.
  • code-reviewer - OMITTED: no application source changed (YAML workflow pins only); style/guideline scope not touched.
  • silent-failure-hunter - OMITTED: no error-handling/fallback code in the diff.
  • type-design-analyzer - OMITTED: no new/changed types.
  • comment-analyzer - OMITTED: the only comments are the # vX.Y.Z pin tags, which were verified accurate against the resolved SHAs above.
  • pr-test-analyzer - OMITTED: no testable code units; N/A for a workflow dependency bump.

Human heuristics

  • Proportionality - Pass. Minimal 6-line diff; no new abstraction.
  • Coherence - Pass. Every uses: pin follows the repo's established @<40-char-sha> # vX.Y.Z convention; consistent across all four files.
  • Clarity - Pass. Version comment tags accurately name the resolved release for each SHA.
  • Appropriateness - Pass. Maintainable and standard Dependabot flow; the major bump was verified against the real upstream README/changelog (AI001), not assumed.

@scottschreckengaust
scottschreckengaust added this pull request to the merge queue Jul 21, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant