Skip to content

chore(deps): bump actions/setup-python from 5 to 6#4

Closed
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/github_actions/actions/setup-python-6
Closed

chore(deps): bump actions/setup-python from 5 to 6#4
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/github_actions/actions/setup-python-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown

Bumps actions/setup-python from 5 to 6.

Release notes

Sourced from actions/setup-python's releases.

v6.0.0

What's Changed

Breaking Changes

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Enhancements:

Bug fixes:

Dependency updates:

New Contributors

Full Changelog: actions/setup-python@v5...v6.0.0

v5.6.0

What's Changed

Full Changelog: actions/setup-python@v5...v5.6.0

v5.5.0

What's Changed

Enhancements:

Bug fixes:

... (truncated)

Commits
  • a309ff8 Bump urllib3 from 2.6.0 to 2.6.3 in /tests/data (#1264)
  • bfe8cc5 Upgrade @​actions dependencies to Node 24 compatible versions (#1259)
  • 4f41a90 Bump urllib3 from 2.5.0 to 2.6.0 in /tests/data (#1253)
  • 83679a8 Bump @​types/node from 24.1.0 to 24.9.1 and update macos-13 to macos-15-intel ...
  • bfc4944 Bump prettier from 3.5.3 to 3.6.2 (#1234)
  • 97aeb3e Bump requests from 2.32.2 to 2.32.4 in /tests/data (#1130)
  • 443da59 Bump actions/publish-action from 0.3.0 to 0.4.0 & Documentation update for pi...
  • cfd55ca graalpy: add graalpy early-access and windows builds (#880)
  • bba65e5 Bump typescript from 5.4.2 to 5.9.3 and update docs/advanced-usage.md (#1094)
  • 18566f8 Improve wording and "fix example" (remove 3.13) on testing against pre-releas...
  • Additional commits viewable in compare view

- Core: init, scan, version
- Dependency analysis: deps, drift, watch, tpn
- Security analysis: reach, audit, secrets
- Remediation: fix, update
- Compliance: baseline (OSPS), badge, license, policy
- Supply chain: slsa, supply-chain, pin, maturity (S2C2F)
- Generation: insights, sbom-gen, ci, report
- Container: container (Dockerfile linting)
- Utilities: compare, fuzz
- 147 unit tests
- OpenSSF repo standards: LICENSE, SECURITY.md, CODE_OF_CONDUCT.md,
  CONTRIBUTING.md, CHANGELOG.md, CI workflow, Scorecard, CodeQL,
  Dependabot, SBOM generation, Sigstore signing
@dependabot @github

dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

kkotari and others added 3 commits May 7, 2026 17:44
- Fix all 47 ruff lint errors (unused imports, ambiguous variables)
- Rewrite README.md documenting all 26 commands
- Add CI badges (CI status, license, Python version)
- Add PyPI release workflow with trusted publishing
- Remove stale roadmap (all items implemented)
- Fix GitHub URLs to kirankotari/ossguard
- Run ruff format on all 31 unformatted files
- Fix ossf/scorecard-action@v2 (tag doesn't exist) to @v2.4.0
- Fix scorecard generator template to use v2.4.0
- All ruff check + format + 147 tests pass
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 6.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): Bump actions/setup-python from 5 to 6 chore(deps): bump actions/setup-python from 5 to 6 May 7, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/setup-python-6 branch from 532397f to 3663e55 Compare May 7, 2026 22:00
@kirankotari kirankotari closed this May 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github May 7, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/github_actions/actions/setup-python-6 branch May 7, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants