Skip to content

Commit 9c01790

Browse files
chore(deps): bump the github-actions group with 3 updates (#854)
Bumps the github-actions group with 3 updates: [coder/coder](https://github.com/coder/coder), [crate-ci/typos](https://github.com/crate-ci/typos) and [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action). Updates `coder/coder` from 2.31.9 to 2.32.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/coder/coder/releases">coder/coder's releases</a>.</em></p> <blockquote> <h2>v2.32.0</h2> <h2>Changelog</h2> <blockquote> <p>[!NOTE] This is a mainline Coder release. We advise enterprise customers without a staging environment to install our <a href="https://github.com/coder/coder/releases/latest">latest stable release</a> while we refine this version. Learn more about our <a href="https://coder.com/docs/install/releases">Release Schedule</a>.</p> </blockquote> <h3>BREAKING CHANGES</h3> <ul> <li> <p>chore!: remove members' ability to read their own AI Bridge interceptions (<a href="https://redirect.github.com/coder/coder/pull/23320">#23320</a>)</p> <blockquote> <p>Regular users (non-owners, non-auditors) can no longer read AI Bridge interception data, including their own. Only owners and auditors retain read access. This tightens the RBAC surface to prevent insiders from observing what data is tracked.</p> </blockquote> </li> <li> <p>fix(cli)!: <code>coder groups list -o json</code> output structure changed (<a href="https://redirect.github.com/coder/coder/pull/22923">#22923</a>)</p> <blockquote> <p>The JSON output is now a flat structure matching other <code>coder list -o json</code> commands. Previously this command returned empty zero-value structs due to a bug, so no working consumer of the old format could exist.</p> </blockquote> </li> </ul> <h3>DEPRECATIONS</h3> <ul> <li>AI Gateway (previously known as AI Bridge): injected MCP tools are now deprecated (<a href="https://redirect.github.com/coder/coder/pull/23031">#23031</a>); this feature will remain functional but will be replaced with an MCP Gateway in a future release.</li> </ul> <h3>Features</h3> <h4>Coder Agents</h4> <p><a href="https://coder.com/docs/ai-coder/agents">Coder Agents</a> is newly introduced in Early Access. See our <a href="https://coder.com/docs/ai-coder/agents/getting-started">getting started guide</a> to enable and start using it.</p> <ul> <li>Voice-to-text input in agent chat (<a href="https://redirect.github.com/coder/coder/pull/23022">#23022</a>)</li> <li>Pinned chats with drag-to-reorder in the sidebar (<a href="https://redirect.github.com/coder/coder/pull/23615">#23615</a>)</li> <li>Chat cost analytics dashboard for admins — tracks spend, model usage, and trends (<a href="https://redirect.github.com/coder/coder/pull/23037">#23037</a>, <a href="https://redirect.github.com/coder/coder/pull/23215">#23215</a>)</li> <li>PR Insights analytics dashboard — shows PRs created/merged by AI agents, merge rates, lines shipped, cost per merged PR (<a href="https://redirect.github.com/coder/coder/pull/23215">#23215</a>)</li> <li>Agent desktop recordings — record and replay agent desktop sessions (<a href="https://redirect.github.com/coder/coder/pull/23894">#23894</a>, <a href="https://redirect.github.com/coder/coder/pull/23895">#23895</a>)</li> <li>Per-chat system prompt override per conversation (<a href="https://redirect.github.com/coder/coder/pull/24053">#24053</a>)</li> <li>Chat spend limits with inline usage indicator (<a href="https://redirect.github.com/coder/coder/pull/23071">#23071</a>, <a href="https://redirect.github.com/coder/coder/pull/23072">#23072</a>) — configurable via <a href="https://coder.com/docs/ai-coder/agents/platform-controls">platform controls</a></li> <li>Per-user per-model compaction threshold overrides (<a href="https://redirect.github.com/coder/coder/pull/23412">#23412</a>)</li> <li>Skills — agents read context files and discover skills locally; skills persist as message parts (<a href="https://redirect.github.com/coder/coder/pull/23935">#23935</a>, <a href="https://redirect.github.com/coder/coder/pull/23748">#23748</a>) — see <a href="https://coder.com/docs/ai-coder/agents/extending-agents">extending agents</a></li> <li>Suffix-based agent selection — select an agent model by name suffix (<a href="https://redirect.github.com/coder/coder/pull/23741">#23741</a>)</li> <li>Provider key policies and per-user provider settings (<a href="https://redirect.github.com/coder/coder/pull/23751">#23751</a>) — see <a href="https://coder.com/docs/ai-coder/agents/models">models &amp; providers</a></li> <li>Manual chat title regeneration (<a href="https://redirect.github.com/coder/coder/pull/23633">#23633</a>)</li> <li>Chat read/unread indicator in sidebar (<a href="https://redirect.github.com/coder/coder/pull/23129">#23129</a>)</li> <li>Chat labels (<a href="https://redirect.github.com/coder/coder/pull/23594">#23594</a>)</li> <li>Workspace and agent badges in chat top bar and workspace list (<a href="https://redirect.github.com/coder/coder/pull/23964">#23964</a>, <a href="https://redirect.github.com/coder/coder/pull/23453">#23453</a>)</li> <li>File/image attachments in chat input; large pasted text auto-converts to file attachments (<a href="https://redirect.github.com/coder/coder/pull/22604">#22604</a>, <a href="https://redirect.github.com/coder/coder/pull/23379">#23379</a>)</li> <li>Inline file reference rendering in user messages (<a href="https://redirect.github.com/coder/coder/pull/23131">#23131</a>)</li> <li><code>propose_plan</code> tool for markdown plan proposals (<a href="https://redirect.github.com/coder/coder/pull/23452">#23452</a>)</li> <li>Provider-native web search tools in agent chats (<a href="https://redirect.github.com/coder/coder/pull/22909">#22909</a>)</li> <li>Workspace awareness system message automatically included on chat creation (<a href="https://redirect.github.com/coder/coder/pull/23213">#23213</a>)</li> <li>Workspace TTL automatically extended on chat heartbeat (<a href="https://redirect.github.com/coder/coder/pull/23314">#23314</a>)</li> <li>Global chat workspace TTL deployment-wide setting (<a href="https://redirect.github.com/coder/coder/pull/23265">#23265</a>)</li> <li>Template allowlist for chats — restrict which templates agents can create workspaces from (<a href="https://redirect.github.com/coder/coder/pull/23262">#23262</a>)</li> <li>Chat-access site-wide role to gate chat creation (<a href="https://redirect.github.com/coder/coder/pull/23724">#23724</a>)</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/coder/coder/commit/34584e909bbe6f501fb2cbdc994325b4d3f9e2ef"><code>34584e9</code></a> fix: update to our fork of charm.land/fantasy with appendCompact perf improve...</li> <li><a href="https://github.com/coder/coder/commit/2625056e7108bc66557b67188422b9b924db3b74"><code>2625056</code></a> fix: backport Go 1.25.9 and dependency fixes (<a href="https://redirect.github.com/coder/coder/issues/24330">#24330</a>)</li> <li><a href="https://github.com/coder/coder/commit/bd1568b0b7ab9164fbe46699403e69c5260c71e5"><code>bd1568b</code></a> fix: bump coder/tailscale to pick up RTM_MISS fix (cherry-pick <a href="https://redirect.github.com/coder/coder/issues/24187">#24187</a>) (<a href="https://redirect.github.com/coder/coder/issues/24214">#24214</a>)</li> <li><a href="https://github.com/coder/coder/commit/eb2b1d3a8ba38d9b531e4db405b4c3effe79d136"><code>eb2b1d3</code></a> fix: update directory for terraform-managed subagents (<a href="https://redirect.github.com/coder/coder/issues/24220">#24220</a>) (<a href="https://redirect.github.com/coder/coder/issues/24242">#24242</a>)</li> <li><a href="https://github.com/coder/coder/commit/9626fdacad9e12107d173bb19a1d71b666ca0de1"><code>9626fda</code></a> fix(cli): retry dial timeouts in SSH connection setup (<a href="https://redirect.github.com/coder/coder/issues/24199">#24199</a>) (<a href="https://redirect.github.com/coder/coder/issues/24229">#24229</a>)</li> <li><a href="https://github.com/coder/coder/commit/52190f032d6f002f5efa2a063c7d99399cabfec8"><code>52190f0</code></a> fix: revert auto-assign agents-access role enabled (<a href="https://redirect.github.com/coder/coder/issues/24170">#24170</a>) (<a href="https://redirect.github.com/coder/coder/issues/24186">#24186</a>)</li> <li><a href="https://github.com/coder/coder/commit/8d4148b1986008ed3b9b1cdbc13c35473a7c648b"><code>8d4148b</code></a> chore: remove kyleosophy easter egg (<a href="https://redirect.github.com/coder/coder/issues/24174">#24174</a>)</li> <li><a href="https://github.com/coder/coder/commit/d3bdd5d1535db5f713634cf781500cae0bddb2ae"><code>d3bdd5d</code></a> feat: add httproute (<a href="https://redirect.github.com/coder/coder/issues/23501">#23501</a>) (<a href="https://redirect.github.com/coder/coder/issues/24172">#24172</a>)</li> <li><a href="https://github.com/coder/coder/commit/727ec00f7f693a4edb513013f356340a8acf7564"><code>727ec00</code></a> chore: revert force deploying main (<a href="https://redirect.github.com/coder/coder/issues/23290">#23290</a>) (<a href="https://redirect.github.com/coder/coder/issues/24072">#24072</a>) (<a href="https://redirect.github.com/coder/coder/issues/24166">#24166</a>)</li> <li><a href="https://github.com/coder/coder/commit/89a0ee3d1d2f61970b2f0856622ca6693eeb62dc"><code>89a0ee3</code></a> feat: support disabling reverse/local port forwarding in agent SSH server (<a href="https://redirect.github.com/coder/coder/issues/2">#2</a>...</li> <li>Additional commits viewable in <a href="https://github.com/coder/coder/compare/2f5d21d1be7864b3e21d9c0b8e87d3ba229a1140...34584e909bbe6f501fb2cbdc994325b4d3f9e2ef">compare view</a></li> </ul> </details> <br /> Updates `crate-ci/typos` from 1.45.0 to 1.45.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/crate-ci/typos/releases">crate-ci/typos's releases</a>.</em></p> <blockquote> <h2>v1.45.1</h2> <h2>[1.45.1] - 2026-04-13</h2> <h3>Fixes</h3> <ul> <li><em>(action)</em> Use a temp dir for caching</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/crate-ci/typos/blob/master/CHANGELOG.md">crate-ci/typos's changelog</a>.</em></p> <blockquote> <h1>Change Log</h1> <p>All notable changes to this project will be documented in this file.</p> <p>The format is based on <a href="https://keepachangelog.com/">Keep a Changelog</a> and this project adheres to <a href="https://semver.org/">Semantic Versioning</a>.</p> <!-- raw HTML omitted --> <h2>[Unreleased] - ReleaseDate</h2> <h2>[1.45.1] - 2026-04-13</h2> <h3>Fixes</h3> <ul> <li><em>(action)</em> Use a temp dir for caching</li> </ul> <h2>[1.45.0] - 2026-04-01</h2> <h3>Features</h3> <ul> <li>Updated the dictionary with the <a href="https://redirect.github.com/crate-ci/typos/issues/1509">March 2026</a> changes</li> </ul> <h2>[1.44.0] - 2026-02-27</h2> <h3>Features</h3> <ul> <li>Updated the dictionary with the <a href="https://redirect.github.com/crate-ci/typos/issues/1488">February 2026</a> changes</li> </ul> <h2>[1.43.5] - 2026-02-16</h2> <h3>Fixes</h3> <ul> <li><em>(pypi)</em> Hopefully fix the sdist build</li> </ul> <h2>[1.43.4] - 2026-02-09</h2> <h3>Fixes</h3> <ul> <li>Don't correct <code>pincher</code></li> </ul> <h2>[1.43.3] - 2026-02-06</h2> <h3>Fixes</h3> <ul> <li><em>(action)</em> Adjust how typos are reported to github</li> </ul> <h2>[1.43.2] - 2026-02-05</h2> <h3>Fixes</h3> <ul> <li>Don't correct <code>certifi</code> in Python</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/crate-ci/typos/commit/cf5f1c29a8ac336af8568821ec41919923b05a83"><code>cf5f1c2</code></a> chore: Release</li> <li><a href="https://github.com/crate-ci/typos/commit/485d42553ebf5bd9c810c24c6521bf608d663e70"><code>485d425</code></a> docs: Update changelog</li> <li><a href="https://github.com/crate-ci/typos/commit/2fe77ce0ce53ef0ba47e9b371fef1a949baaff3a"><code>2fe77ce</code></a> Merge pull request <a href="https://redirect.github.com/crate-ci/typos/issues/1539">#1539</a> from epage/action</li> <li><a href="https://github.com/crate-ci/typos/commit/a9595eaf0cc3266bd7fa5c3b2ec7e2a5f3685d18"><code>a9595ea</code></a> fix(action): Leave binary in temp dir</li> <li>See full diff in <a href="https://github.com/crate-ci/typos/compare/02ea592e44b3a53c302f697cddca7641cd051c3d...cf5f1c29a8ac336af8568821ec41919923b05a83">compare view</a></li> </ul> </details> <br /> Updates `zizmorcore/zizmor-action` from 0.5.2 to 0.5.3 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/zizmorcore/zizmor-action/releases">zizmorcore/zizmor-action's releases</a>.</em></p> <blockquote> <h2>v0.5.3</h2> <h2>What's Changed</h2> <ul> <li><code>1.24.0</code> and <code>1.24.1</code> are now available via the action</li> <li><code>1.24.1</code> is now the default version of zizmor used by the action</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.2...v0.5.3">https://github.com/zizmorcore/zizmor-action/compare/v0.5.2...v0.5.3</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/zizmorcore/zizmor-action/commit/b1d7e1fb5de872772f31590499237e7cce841e8e"><code>b1d7e1f</code></a> Sync zizmor versions (<a href="https://redirect.github.com/zizmorcore/zizmor-action/issues/102">#102</a>)</li> <li><a href="https://github.com/zizmorcore/zizmor-action/commit/a195b57475917ddcb70845e5ffe1c3a15dbbdedc"><code>a195b57</code></a> Sync zizmor versions (<a href="https://redirect.github.com/zizmorcore/zizmor-action/issues/100">#100</a>)</li> <li><a href="https://github.com/zizmorcore/zizmor-action/commit/629d5d01fe5939a6aeae25c1bd1acd2cfa28e9b2"><code>629d5d0</code></a> chore(deps): bump github/codeql-action in the github-actions group (<a href="https://redirect.github.com/zizmorcore/zizmor-action/issues/99">#99</a>)</li> <li><a href="https://github.com/zizmorcore/zizmor-action/commit/453d591467e8199b1d5c6883b6ec5c22a12aac72"><code>453d591</code></a> chore(deps): bump the github-actions group with 2 updates (<a href="https://redirect.github.com/zizmorcore/zizmor-action/issues/98">#98</a>)</li> <li><a href="https://github.com/zizmorcore/zizmor-action/commit/ea2c18b942410df0b22bed3b94c361c407518d45"><code>ea2c18b</code></a> Bump pins (<a href="https://redirect.github.com/zizmorcore/zizmor-action/issues/97">#97</a>)</li> <li>See full diff in <a href="https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f31590499237e7cce841e8e">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent b9f9fac commit 9c01790

3 files changed

Lines changed: 6 additions & 6 deletions

File tree

.github/workflows/ci.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ jobs:
3737
all:
3838
- '**'
3939
- name: Set up Terraform
40-
uses: coder/coder/.github/actions/setup-tf@2f5d21d1be7864b3e21d9c0b8e87d3ba229a1140 # v2.31.9
40+
uses: coder/coder/.github/actions/setup-tf@34584e909bbe6f501fb2cbdc994325b4d3f9e2ef # v2.32.0
4141
- name: Set up Bun
4242
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
4343
with:
@@ -87,13 +87,13 @@ jobs:
8787
bun-version: latest
8888
# Need Terraform for its formatter
8989
- name: Install Terraform
90-
uses: coder/coder/.github/actions/setup-tf@2f5d21d1be7864b3e21d9c0b8e87d3ba229a1140 # v2.31.9
90+
uses: coder/coder/.github/actions/setup-tf@34584e909bbe6f501fb2cbdc994325b4d3f9e2ef # v2.32.0
9191
- name: Install dependencies
9292
run: bun install
9393
- name: Validate formatting
9494
run: bun fmt:ci
9595
- name: Check for typos
96-
uses: crate-ci/typos@02ea592e44b3a53c302f697cddca7641cd051c3d # v1.45.0
96+
uses: crate-ci/typos@cf5f1c29a8ac336af8568821ec41919923b05a83 # v1.45.1
9797
with:
9898
config: .github/typos.toml
9999
validate-readme-files:

.github/workflows/version-bump.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
bun-version: latest
3232

3333
- name: Set up Terraform
34-
uses: coder/coder/.github/actions/setup-tf@2f5d21d1be7864b3e21d9c0b8e87d3ba229a1140 # v2.31.9
34+
uses: coder/coder/.github/actions/setup-tf@34584e909bbe6f501fb2cbdc994325b4d3f9e2ef # v2.32.0
3535

3636
- name: Install dependencies
3737
run: bun install

.github/workflows/zizmor.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
persist-credentials: false
2828

2929
- name: Run zizmor (blocking, HIGH only)
30-
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
30+
uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3
3131
with:
3232
advanced-security: false
3333
annotations: true
@@ -49,7 +49,7 @@ jobs:
4949
persist-credentials: false
5050

5151
- name: Run zizmor (SARIF)
52-
uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
52+
uses: zizmorcore/zizmor-action@b1d7e1fb5de872772f31590499237e7cce841e8e # v0.5.3
5353
with:
5454
inputs: |
5555
.github/workflows

0 commit comments

Comments
 (0)