Skip to content

ci: Update ci-actions#28

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ci-actions
Open

ci: Update ci-actions#28
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ci-actions

Conversation

@renovate

@renovate renovate Bot commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout (changelog) action digest de0fac2df4cb1c
github/codeql-action (changelog) action digest 7211b7c8aad20d
luckyPipewrench/pipelock action minor v2.6.0v2.8.0

Release Notes

luckyPipewrench/pipelock (luckyPipewrench/pipelock)

v2.8.0

Compare Source

Changelog
  • a728e24 Add Enterprise Fleet Receipt Report minting (#​749)
  • 0c023e7 Add Fleet Receipt Report verifier foundation (#​748)
  • 2f0f898 Receipt evidence: clean-A2A allow receipts + fleet-receipt conformance (#​801)
  • 0e5ebb2 ci: Update ci-actions to v7 (#​798)
  • 4d44bbf deps: Update docker-base-images (#​734)
  • 524e068 deps: Update docker-base-images (#​764)
  • 0a0c854 deps: Update docker-base-images (#​777)
  • fce5a64 deps: Update docker-base-images (#​789)
  • 03e6299 deps: Update docker-base-images (#​800)
  • 5ff537a deps: Update go-deps to v0.9.0 (#​781)
  • 9abd09a deps: Update go-deps to v1.52.0 (#​793)
  • 8b14341 deps: Update go-deps to v2.7.0 (#​754)
  • 6634a00 deps: Update k8s-images (#​747)
  • ca519a5 deps: Update ts-verifier to v24.13.0 (#​765)
  • c01c561 deps: Update ts-verifier to v24.13.1 (#​787)
  • 480d06e docs(metrics): complete Prometheus metric catalog (#​756)
  • 939f8d5 feat(cli): add 'explain' command for remediable block explanations (#​750)
  • c2ec807 feat(cli): add 'keys status' unified signing-key inventory (#​752)
  • d49fb60 feat(cli): add 'support bundle' diagnostics command (#​753)
  • 2c542a3 feat(cli): add 'update' self-update command (#​757)
  • c036238 feat(conductor): offline fleet-report export and verification (#​791)
  • 2e72b0f feat(conductor): operator credential and enrollment-token lifecycle (#​792)
  • a240b9e feat(conductor): operator recovery commands for the fleet control plane (#​763)
  • 1b54c20 feat(conductor): operator stream observability + publish-error clarity (#​758)
  • be8c25f feat(conductor): verify emergency-control signatures at all leader read paths (#​776)
  • 5a641c9 feat(conductor): wire follower audience labels into policy, rollback, and remote-kill apply paths (#​772)
  • 07621dc feat(contain): install/UX hardening for first-run and older hosts (#​761)
  • 2425c2e feat(contain): publishable offline containment conformance artifact with must-fail fixture (#​773)
  • a917feb feat(doctor): flag inert exemptions and semantic config mismatches (#​751)
  • 70faa8a feat(license): add 'license crl inspect' and 'license crl verify' (#​762)
  • 026b7f2 feat(license): gate CLI issuance on paid capability + signed service import table (#​779)
  • 7d2b4ba feat(license): monotonic CRL generation with consumer rollback rejection (#​770)
  • 19bd993 feat(license): require-intermediate enforcement, issuer-side intermediate revocation, CRL freshness (#​775)
  • 8f658d4 feat(mcp): defer authorization action with fail-closed resolution (#​799)
  • b9bdfdd feat(mcp): per-server response suppression + airlock reset for first-party tools (#​774)
  • 3482757 feat(playground): bundle generator + stable published orchestrator key (#​795)
  • 26ce17d feat(playground): gated live-chat backend (stream seam, gate, fail-closed limits, SSE server) (#​802)
  • 6ec8b4e feat(playground): honest live-chat demo backend (bundle, caps, trust-class) (#​812)
  • bbaaf4d feat(playground): honest live-chat demo for the agent firewall (#​809)
  • af5f0dd feat(playground): live demo engine with offline-verifiable evidence (#​784)
  • 9fdd1b1 feat(playground): live model-backed agent for the demo (#​804)
  • 1437a0f feat(playground): live-demo spend controls + polish (#​807)
  • 3a5423a feat(playground): split-proof contained mode with signed host-containment witness (#​785)
  • d7dfaab feat(receipts): freeze v1 fixtures and publish versioning policy (#​755)
  • 1de117a fix(chart): render valid Conductor image refs (digest vs tag) (#​790)
  • 3f5a7bb fix(conductor): tolerate abandoned fork siblings + offline recovery (#​786)
  • 49d660b fix(deps): bump Python verifier cryptography to 48.0.1 (GHSA-537c-gmf6-5ccf) (#​788)
  • 5236c74 fix(license): evaluate token expiry against the injected verification clock (#​780)
  • 4fa9952 fix(mcp): opt-in stdio response timeout + self-update downgrade warning (#​810)
  • 1a30205 fix(playground): harden live demo adversarial edges (#​808)
  • 90812be fix(proxy): make redaction config key invariant to per-agent config deep-copy (#​783)
  • 1413a09 fix(scanner): direction-anchor Credential Solicitation to stop documentation false positives (#​760)
  • b3807cd fix(scanner): fail closed on over-depth JSON and stacked URL DLP encodings (#​803)
  • bb33140 fix(wsutil): treat Windows Winsock close errnos as expected WS teardown (#​769)
  • 08538ae fix: close stacked-encoding DLP bypass, freeze receipt v1 canonical, correct dropped-action accounting (#​814)
  • d897e51 fix: operability, UX, and support-bundle secret-redaction fixes (#​805)
  • edad608 fix: verify raw action receipt chain jsonl (#​771)
  • f8bf755 refactor(license): extract splitToken helper and rename Decode to DecodeUnverified (#​782)
  • ac614ac test(certgen): make read-only-dir tests portable (#​767)
  • a73ce53 test(cli): make read-only-dir/config tests portable on Windows (#​766)
  • abce869 test(mcp): close recorder in receipt harness to fix Windows TempDir cleanup (#​768)

v2.7.0

Compare Source

Changelog
  • 5b7beb1 Add Conductor emergency control and stale-policy fail-closed enforcement (#​741)
  • 0ed5f57 Add Conductor fleet observability and audit query commands (#​740)
  • 05268b0 Add Conductor production operator runbook and provisioning docs (#​739)
  • 954c3df Add conductor publish for signed policy bundle distribution (#​738)
  • e606f17 Add contain egress explanations and response-size allowances (#​706)
  • 5b246c1 Add live baseline ratify operator surface (#​732)
  • 1953501 Bind EvidenceReceipt v2 decisions to policy_hash (#​719)
  • eb462a1 Bind action receipts to process runs with nonce (#​729)
  • f8690af Conductor follower enrollment, rollback application, head-reset (#​743)
  • 6adfb48 Contain control-plane adaptive escalation (#​709)
  • 3d07dcb Emit receipts on A2A block paths for transport parity (#​727)
  • 867bd6d Export recorder signing public keys (#​735)
  • dbcb080 Fail closed when signed receipts are required (#​730)
  • f8f849e Fix Conductor rollback reconcile upgrade crashloop, restore coverage (#​745)
  • 1d08461 Fix URL-DLP false-positive remediation hint (#​742)
  • 3e52a2f Fix receipt-chain rotation and operator evidence ACLs (#​725)
  • 2f3556c Gate per-profile address allowlists on verified entitlement (#​714)
  • bcb9741 Harden conductor audit ingest idempotency and lookup (#​678)
  • 094e9f2 Harden conductor audit queue lifecycle and error mapping (#​724)
  • b3dffd0 Harden contain credential defaults and git push guard (#​705)
  • 2bccfb8 Harden contain setup and MCP receipt parity (#​723)
  • d5c2dfc Make receipt verification safe by default (#​726)
  • 29ecdc7 chore(deps): update dependency cryptography to v48 (#​669)
  • 5588a58 chore(hooks): scope pre-commit stages so a Go-only push doesn't need verifier toolchains (#​682)
  • 511b209 chore(verifiers): make TS + Rust reference verifiers publishable (npm + crates.io) (#​713)
  • 15dd5c2 ci(govulncheck): float to latest 1.26.x so stdlib advisories self-heal (#​667)
  • fda3d19 ci: Update Azure/setup-helm action to v5 (#​651)
  • 7a5031a ci: Update ci-actions (#​717)
  • d3be8d3 ci: run python verifier from source to stop recurring Scorecard pin alert (#​665)
  • 7351c78 deps: Lock file maintenance rust-verifier (#​649)
  • 786052a deps: Pin dependencies (#​646)
  • 42c2978 deps: Update Rust crate serde_json to v1.0.150 (#​647)
  • 736a519 deps: Update docker-base-images (#​638)
  • 49c01ff deps: Update docker-base-images (#​675)
  • f3f9cd6 deps: Update docker-base-images (#​694)
  • ed5855d deps: Update docker-base-images (#​702)
  • 7585a71 deps: Update docker-base-images (#​716)
  • dadcde0 deps: Update go-deps to v0.46.0 (#​718)
  • 3638b23 deps: Update go-deps to v1.51.0 (#​703)
  • 2299f75 deps: Update rust-verifier to v0.1.25 (#​668)
  • a976cfa docs(aarp): publish claims dictionary (#​721)
  • 54e3bac feat(a2a): verify Agent Card signatures against trusted origin-scoped keys (#​689)
  • 8bd4fbd feat(aarp): AARP v0.1 assurance envelope core (#​660)
  • 1e2ae96 feat(aarp): SVID X.509 attestation appraisal + hostile corpus (Go reference) (#​670)
  • 7eeeb05 feat(aarp): four-language hostile corpus + verifier lock (#​663)
  • 381c4fc feat(aarp): make the appraiser brutally literal about what it proves (#​720)
  • 55e3eb0 feat(aarp): port X.509-SVID attestation to TS/Rust/Python; lock four-language SVID corpus (#​674)
  • 10fa815 feat(aarp): verified X.509-SVID attestation binding (#​661)
  • 6157e26 feat(assess): honor CRL in paid artifact gating (#​690)
  • e7dde68 feat(capture): add rpc id to CaptureRequest for request<->response join (#​708)
  • 720b67e feat(conductor): add bootstrap command for a self-verifying dev fleet (#​655)
  • ae2b537 feat(contain): runtime contract + contain doctor self-test (#​704)
  • ced2901 feat(dlp): detect DB connection strings, GitLab token families, and cloud service-account keys (#​657)
  • e828c3f feat(license): intermediate signing certificates with CRL revocation (#​684)
  • 22958a7 feat(license): wire intermediate license chain through runtime and service flows (#​687)
  • 343a4e9 feat(playground): synthetic replay capture rig for signed Audit Packet gallery (#​681)
  • d075eab feat(receipt): add source-span v2 receipt payload (#​697)
  • d8c4b0b feat(receipt): dual-emit v2 proxy_decision receipts on the live proxy path (#​691)
  • 7c65323 feat(receipts): enable flight recorder by default and seal transcript root on shutdown (#​728)
  • c2c3ba9 feat(runtime): close in-flight conductor apply window and add license-reload error precision (#​712)
  • a4119e1 feat(runtime): enforce fleet-license revocation at runtime (#​707)
  • 1e25fb1 feat(svid): offline X.509-SVID validation against pinned trust-bundle history (#​653)
  • e909785 feat(taint): cross-agent contamination tracking across A2A/MCP (#​677)
  • f653dce feat(verifier): verify EvidenceReceipt v2 chains offline (#​664)
  • 43f9dcb feat(verifiers): add spanned EvidenceReceipt v2 verification (#​700)
  • 521cdbb feat: add operation-aware playground replay capture (#​686)
  • 30b62ca feat: add skill scan command (#​672)
  • e98995c feat: self-service Enterprise Eval fulfillment (license service) (#​680)
  • 6907555 fix(ci): avoid unpinned AARP verifier install (#​679)
  • 9df41e3 fix(dlp): bound Twilio + Mailgun patterns to documented key shapes (#​656)
  • 92981b6 fix(dlp): require secret-plausible leading value char on credential patterns (#​715)
  • 03db814 fix(mcp): protect concurrent subprocess teardown (#​733)
  • 496e968 fix(mcp): treat connection teardown as a clean stream end in ForwardScanned (#​654)
  • bab2d93 fix(mcp/provenance): domain-separate tool signatures and block duplicate names (#​659)
  • 8da835c fix(proxy): harden cross-request exfil detection against key partitioning and flood-to-evict (#​666)
  • 4802074 fix(receipt): align cross-language verifier canonicalization, reject duplicate keys (#​652)
  • f5fd95e fix(receipt): sanitize secret-bearing fields before signing (#​676)
  • 6482bc5 fix(release): build with patched Go 1.25.11 (#​746)
  • 92d9c70 fix(runtime): join listener goroutines before cleanup nils shared fields (#​688)
  • f174d70 fix(scanner): direction-scope agent-secret exfil checks; skip path-shaped env values (#​693)
  • d8d278a fix(scanner): exempt operator-governed API paths from path entropy; harden flaky test families (#​701)
  • 00a5266 fix(scanner): label MatchSpan offsets by indexed view (#​685)
  • 40abeb4 fix(seedprotect): close Unicode evasion gaps in BIP-39 seed-phrase detection (#​658)
  • caa96d1 fix(testdata): force LF line endings for test goldens on Windows checkouts (#​710)
  • 8a790bf fix(windows): cross-platform file-permission gate (#​695) + key-free MCP capture (#​696) (#​698)
  • 6dda831 fix: clarify conductor key purposes and chart examples (#​736)
  • 4ce2833 fix: detect cross-tool sensitive file directives (#​650)
  • eb102fb fix: response-injection FPs on standards prose + seccomp CI test hang (#​737)
  • 069a2e7 helm: add enterprise deployment modes (#​648)
  • d2eff87 test(aarp): add Evidence Theater Kill Suite overclaim gate (#​722)
  • 1b5f812 test(cli): harden run listener port allocation (#​692)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from luckyPipewrench as a code owner June 2, 2026 11:13
@renovate renovate Bot added ci dependencies Pull requests that update a dependency file labels Jun 2, 2026
@renovate renovate Bot changed the title ci: Update github/codeql-action digest to 87557b9 ci: Update ci-actions to 87557b9 Jun 2, 2026
@renovate renovate Bot force-pushed the renovate/ci-actions branch from 2810f56 to 69b0472 Compare June 3, 2026 16:47
@renovate renovate Bot changed the title ci: Update ci-actions to 87557b9 ci: Update ci-actions Jun 3, 2026
@renovate renovate Bot force-pushed the renovate/ci-actions branch from 69b0472 to 1032361 Compare June 4, 2026 15:57
@renovate renovate Bot force-pushed the renovate/ci-actions branch from 1032361 to c420b95 Compare June 12, 2026 06:50
@renovate renovate Bot force-pushed the renovate/ci-actions branch from c420b95 to fc63a89 Compare June 19, 2026 00:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants