Skip to content

chore(deps): update github-actions - #163

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

chore(deps): update github-actions#163
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v6.0.2v6.1.0
actions/setup-go action minor v6.4.0v6.5.0
actions/setup-node action minor v6.4.0v6.5.0
anthropics/claude-code-action (changelog) action digest f4fb5c69d7150b
anthropics/claude-code-action action patch v1.0.121v1.0.193
aws-actions/configure-aws-credentials action minor v6.1.3v6.2.3
azure/setup-helm action patch v5.0.0v5.0.1
dev-hanz-ops/install-gh-cli-action action minor v0.2.1v0.3.0
docker/login-action action minor v4.4.0v4.6.0
dorny/paths-filter action patch v4.0.1v4.0.3
loft-sh/github-actions (changelog) action digest 53686d2c40c1db
loft-sh/github-actions (changelog) action digest 85d70235bee69a
openai/codex-action action minor v1.8v1.11
reviewdog/action-actionlint action minor v1.72.0v1.73.2
slackapi/slack-github-action action patch v3.0.3v3.0.5

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

v6.0.3

Compare Source

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

actions/setup-node (actions/setup-node)

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.193

Compare Source

v1.0.192

Compare Source

v1.0.191

Compare Source

v1.0.190

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.190

v1.0.189

Compare Source

v1.0.188

Compare Source

v1.0.187

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.187

v1.0.186

Compare Source

v1.0.185

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.185

v1.0.184

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.184

v1.0.183

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.182

v1.0.181

Compare Source

v1.0.180

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Compare Source

v1.0.178

Compare Source

v1.0.177

Compare Source

v1.0.176

Compare Source

v1.0.175

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.175

v1.0.174

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.174

v1.0.173

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.173

v1.0.172

Compare Source

What's Changed

  • fix(sdk): fail step when result has is_error:true despite success subtype by @​syf2211 in #​1496

Full Changelog: anthropics/claude-code-action@v1...v1.0.172

v1.0.171

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.171

v1.0.170

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.170

v1.0.169

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.169

v1.0.168

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.168

v1.0.167

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.167

v1.0.166

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.166

v1.0.165

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.165

v1.0.164

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.164

v1.0.163

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.163

v1.0.162

Compare Source

v1.0.161

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.161

v1.0.160

Compare Source

v1.0.159

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.159

v1.0.158

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.158

v1.0.157

Compare Source

v1.0.156

Compare Source

v1.0.155

Compare Source

v1.0.154

Compare Source

v1.0.153

Compare Source

v1.0.152

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.152

v1.0.151

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.151

v1.0.150

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.150

v1.0.149

Compare Source

What's Changed

  • fix(parse-sdk-options): prevent shell-quote from collapsing unquoted Bash(X:*) rules to bare Bash by @​alexglynn in #​1350
  • fix(mcp): align allowed-tools parser with SDK option parser by @​bymle in #​1373

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.149

v1.0.148

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.148

v1.0.147

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.147

v1.0.146

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.146

v1.0.145

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.145

v1.0.144

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.144

v1.0.143

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.143

v1.0.142

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.142

v1.0.141

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.141

v1.0.140

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.140

v1.0.139

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.139

v1.0.138

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.138

v1.0.137

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.137

v1.0.136

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.136

v1.0.135

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.135

v1.0.134

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.134

v1.0.133

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.133

v1.0.132

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.132

v1.0.131

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.131

v1.0.130

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.130

v1.0.129

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.129

v1.0.128

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.128

v1.0.127

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.127

v1.0.126

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.126

v1.0.125

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.125

v1.0.124

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.124

v1.0.123

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.123

v1.0.122

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.122

aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)

v6.2.3

Compare Source

v6.2.2

Compare Source

v6.2.2

Compare Source

Miscellaneous Chores

v6.2.1

Compare Source

Bug Fixes

v6.2.0

Compare Source

Features
Bug Fixes
azure/setup-helm (azure/setup-helm)

v5.0.1

Compare Source

dev-hanz-ops/install-gh-cli-action (dev-hanz-ops/install-gh-cli-action)

v0.3.0: - update to node24

Compare Source

docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

v4.5.1

Compare Source

v4.5.0

Compare Source

dorny/paths-filter (dorny/paths-filter)

v4.0.3

Compare Source

v4.0.2

Compare Source

openai/codex-action (openai/codex-action)

v1.11

Compare Source

  • #​116 keep the permission profile helper backward compatible

v1.10

Compare Source

  • #​113 add Codex permission profile support

v1.9

Compare Source

  • #​85 update the internal setup-node pin to v6.3.0
reviewdog/action-actionlint (reviewdog/action-actionlint)

v1.73.2

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.1...v1.73.2

v1.73.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.0...v1.73.1

v1.73.0

Compare Source

What's Changed

New Contributors

Full Changelog: reviewdog/action-actionlint@v1.72.1...v1.73.0

v1.73

Compare Source

v1.72.1

Compare Source

v1.72.1: PR #​211 - fix: include digest in Docker image reference for action.yml

slackapi/slack-github-action (slackapi/slack-github-action)

v3.0.5: Slack GitHub Action v3.0.5

Compare Source

Patch Changes
  • 96fddbe: fix: revert multiline yaml parsing indentation change

v3.0.4: Slack GitHub Action v3.0.4

Compare Source

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 17s —— View job


Review: Renovate dependency bump

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for stale/mismatched pins and risky jumps

Findings

No bugs, security issues, or performance problems in the workflow/action changes. This is a clean SHA-pin bump.

Verified locally:

  • Every executable .github/ reference resolves to exactly one SHA per action — no split-brain pins:
    • checkoutdf4cb1c (v6.0.3), setup-go924ae3a (v6.5.0), claude-code-actionba0aafd (v1.0.168), codex-action52fe01e (v1.11), setup-helm9bc31f4 (v5.0.1), configure-aws-credentials517a711 (v6.2.2), paths-filter7b450ff (v4.0.2).
  • No stale old SHAs remain in any workflow/action YAML.
  • All version comments (# v...) match the update table in the PR body.

Minor (non-blocking)

Doc drift only: the old checkout pin de0fac2 # v6.0.2 still appears in example snippets in several README.md files (publish-helm-chart, go-licenses, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact — Renovate just doesn't rewrite doc examples. Worth a periodic sweep to keep examples current, but nothing to block this PR on.

Note on verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (gh api / git ls-remote / WebFetch to github.com are blocked in this sandbox). The SHAs were produced by Renovate's digest resolution and the version comments are consistent, so risk is low, but a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge. The bumps are patch/minor across trusted, already-pinned actions.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by the shared auto-approve workflow because this PR matched the approval criteria.

For more information, see https://github.com/loft-sh/github-actions?tab=readme-ov-file#auto-approve-bot-prs.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4eafdd1 to b2f1f27 Compare July 9, 2026 03:10
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 57s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Verified across the whole .github/ tree — every executable reference resolves to exactly one SHA per action, no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes:

  • claude-code-action moved to v1.0.169 (37b464c) since the PR body was written (body says v1.0.168) — the sync picked up a newer patch. SHA is consistent everywhere it appears (both the # v1.0.169 pin in ai-pr-review/action.yml and the # v1 float-tag comment in the claude*.yaml workflows point at the same commit). No mismatch.
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (subtree-mirror, go-licenses, govulncheck, checkov, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network is blocked in this sandbox). The SHAs come from Renovate's digest resolution and the version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from b2f1f27 to 021a49f Compare July 9, 2026 08:09
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 44s —— View job


Review: Renovate dependency bump

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action is pinned to the same SHA (37b464c) whether commented # v1.0.169 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — no mismatch. (Note: PR body says v1.0.168; the sync picked up the newer v1.0.169 patch.)
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 021a49f to 21a726e Compare July 10, 2026 01:59
@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 536f2c3 v1.0.170 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action moved again to v1.0.170 (536f2c3) since the last sync (PR body says v1.0.168, prior reviews saw v1.0.169). SHA is consistent across all 4 references — the # v1.0.170 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 21a726e to 4ef0d1c Compare July 11, 2026 03:28
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action fc46ded v3.0.4
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.171 (e90deca) (body says v1.0.170; earlier reviews saw v1.0.168/169/170). SHA is consistent across all 4 references — the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • slackapi/slack-github-action bumped v3.0.3 → v3.0.4 (fc46ded) in this sync (not listed in the PR body table). Consistent across all 4 references.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4ef0d1c to 82dc414 Compare July 11, 2026 07:43
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since prior reviews / PR body were written:

  • slackapi/slack-github-action moved further to v3.0.5 (0d95c9a) — PR body says v3.0.4, last review saw v3.0.4 (fc46ded). The sync picked up the newer patch. SHA is consistent across all 4 references.
  • claude-code-action is at v1.0.171 (e90deca), consistent across both the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 82dc414 to 5a21f93 Compare July 14, 2026 03:14
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 49s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action a08f891 v1.0.172 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.172 (a08f891) (body says v1.0.171; earlier reviews saw v1.0.168–171). SHA is consistent across all 4 references — the # v1.0.172 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • actions/setup-node also bumped to v6.5.0 (2499707) alongside setup-go — consistent, not in the PR body table.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5a21f93 to 514d3b5 Compare July 14, 2026 09:49
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action f1bd27c v1.0.173 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.173 (f1bd27c) (body says v1.0.172; earlier reviews saw v1.0.168–172). SHA is consistent across all 4 references — the # v1.0.173 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 514d3b5 to 0f2c6c6 Compare July 15, 2026 01:32
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1253134 v1.0.174 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.174 (1253134) (body says v1.0.173; earlier reviews saw v1.0.168–173). SHA is consistent across all 4 references — the # v1.0.174 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0f2c6c6 to fc67a83 Compare July 16, 2026 01:11
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1298632 v1.0.175 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.175 (1298632) (body says v1.0.174; earlier syncs saw v1.0.168–174). SHA is consistent across all references — the # v1.0.175 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from fc67a83 to a6bc804 Compare July 17, 2026 09:34
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.176 (700e7f8) (body says v1.0.175; earlier syncs saw v1.0.168–175). SHA is consistent across all references — the # v1.0.176 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a6bc804 to d0fbf65 Compare July 17, 2026 11:28
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 35s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, and every old SHA is fully replaced (verified: no stale pins remain in any workflow/action YAML):

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.176 (700e7f8) is consistent whether commented # v1.0.176 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from d0fbf65 to 8cb6560 Compare July 18, 2026 01:55
@github-actions

github-actions Bot commented Jul 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 10s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76, all uses: pin lines — no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3553f84 v1.0.177 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.177 (3553f84) (body says v1.0.176; earlier syncs saw v1.0.168–176). SHA is consistent across all references — the # v1.0.177 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, subtree-mirror, checkov, publish-helm-chart, govulncheck, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8cb6560 to 3af22e7 Compare July 19, 2026 06:05
@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 52s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all are pinned uses: references, no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action af0559e v1.0.178 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since the PR body was written:

  • claude-code-action advanced to v1.0.178 (af0559e) (body says v1.0.177; earlier syncs saw v1.0.168–177). SHA is consistent across all references — the # v1.0.178 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, vcluster-release, subtree-mirror, checkov, govulncheck, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3af22e7 to 45df450 Compare July 21, 2026 01:47
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 2s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • actions/checkout advanced to v6.1.0 (d23441a) — body says v6.0.3 (patch); the sync picked up a newer minor release. Consistent across all 48 executable references. Note this is a version-line change beyond what the PR title implies, but it's still a trusted, SHA-pinned action.
  • claude-code-action advanced to v1.0.179 (b76a077) (body says v1.0.178; earlier syncs saw v1.0.168–178). SHA is consistent across all references — the # v1.0.179 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 25s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (52 files, 85 added / 85 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: all 85 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action c038e4d v1.0.186 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main (which picked up c612bb2/f913bae, the promote-release retag fix, #214). All 13 pins land on the same SHAs the previous review verified; the line count ticked 84 → 85 because the rebased promote-release code carries one more bumped uses: line.

Notes vs the PR body table (unchanged from prior reviews): the sync carries versions higher than listed — checkout v6.1.0 and action-actionlint v1.73.0 (minor, vs. the patch bumps in the table), plus configure-aws-credentials v6.2.3, docker/login-action v4.6.0, paths-filter v4.0.3. All trusted, SHA-pinned actions.

Stale-pin scan: every replaced SHA has zero remaining hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths, the internal loft-sh/github-actions@<coordination-tag> refs with their zizmor: ignore[unpinned-uses] justifications, and a setup-go@v5 string inside an ::error:: message in .github/actions/aws-test-infra/action.yml:240 (not a real ref). This PR adds none.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected. SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 9f313d7 to 12ffa32 Compare August 7, 2026 04:39
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 34s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (52 files, 85 added / 85 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: all 85 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1623c36 v1.0.187 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d63ba75 v1.73.1
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.187 (1623c36) — body table says v1.0.186 (c038e4d). Consistent across all 4 references: the # v1.0.187 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this review job is itself running claude-code-action at 1623c36, so that SHA is a real, working commit of the action.
  • reviewdog/action-actionlint advanced to v1.73.1 (d63ba75) at actionlint.yaml:38 — prior review saw v1.73.0 (5084226). Single reference; old SHA fully gone.
  • The other 11 pins land on the same SHAs the previous review verified.

Notes vs the PR body table (unchanged from prior reviews): the sync carries versions higher than listed — checkout v6.1.0 and action-actionlint v1.73.1 (minor, vs. the patch bumps in the table), plus configure-aws-credentials v6.2.3, docker/login-action v4.6.0, paths-filter v4.0.3. All trusted, SHA-pinned actions.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in 20 spots across non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected. SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 12ffa32 to 2c65c24 Compare August 8, 2026 05:11
@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 29s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (52 files, 85 added / 85 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 85/85 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 6b082c4 v1.0.189 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d63ba75 v1.73.1
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.189 (6b082c4) — body table says v1.0.187 (1623c36). Consistent across all 4 references: the # v1.0.189 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this review job is itself running claude-code-action at 6b082c4, so that SHA is a real, working commit.
  • The other 12 pins land on the same SHAs the previous review verified. This sync also rebases onto main, picking up e46fe95 (promote-release: install crane before the ghcr login, fix(promote-release): install crane before the ghcr login #215).

Notes vs the PR body table (unchanged from prior reviews): the sync carries versions higher than listed — checkout v6.1.0 and action-actionlint v1.73.1 (minor, vs. the patch bumps in the table), plus configure-aws-credentials v6.2.3, docker/login-action v4.6.0, paths-filter v4.0.3. All trusted, SHA-pinned actions.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths, internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, and a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:240 (not a real ref). This PR adds none.

One security-positive note: dorny/paths-filter v4.0.3 carries GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure here — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but the bump is worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected. SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 2c65c24 to 716c39b Compare August 10, 2026 17:17
@renovate
renovate Bot requested a review from a team as a code owner August 10, 2026 17:17
@github-actions

github-actions Bot commented Aug 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 19s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (53 files, 86 added / 86 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 86/86 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in .github/ resolves to exactly one SHA per action — no split-brain pins (counted repo-wide):

Action SHA Version Refs
actions/checkout d23441a v6.1.0 55
actions/setup-go 924ae3a v6.5.0 10
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 6b082c4 v1.0.189 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 2
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) b5a50da ci-test-notify/v1 1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up 1b06580 (pre-release base resolution, #204). All 13 pins land on the same SHAs the previous review verified; the count ticked 52→53 files / 85→86 lines because the rebased tree carries one more bumped uses: line.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths, internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, and a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:240 (not a real ref). This PR adds none.

Security-positive note (carried from prior review): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure here — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in 20 spots across non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub: the checkout is shallow with no tags, and both git ls-remote and gh api needed approvals I don't have — so the two internal coordination-tag digests (validate-renovate/v1c40c1db, ci-test-notify/v1b5a50da) are unverified against the actual tags. Given the CLAUDE.md pin-drift history (DEVOPS-1126/923), that's the one spot-check worth a maintainer glance. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 716c39b to 5f0f332 Compare August 11, 2026 01:28
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 48s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (53 files, 86 added / 86 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 86/86 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in .github/ resolves to exactly one SHA per action — no split-brain pins (counted repo-wide):

Action SHA Version Refs
actions/checkout d23441a v6.1.0 55
actions/setup-go 924ae3a v6.5.0 10
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 5ef2e55 v1.0.190 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 2
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) b5a50da ci-test-notify/v1 1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review:

  • claude-code-action advanced to v1.0.190 (5ef2e55) — the body table says v1.0.189 (6b082c4). Consistent across all 4 references: the # v1.0.190 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself running claude-code-action at 5ef2e55, so that SHA is a real, working commit.
  • The other 12 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 20 spots across non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub: the checkout is shallow with zero tags and the referenced objects aren't in the local object store, so the two internal coordination-tag digests (ci-test-notify/v1b5a50da, validate-renovate/v1c40c1db) are unverified against the actual tags. Given the CLAUDE.md pin-drift history (DEVOPS-1126/923), that's the one spot-check worth a maintainer glance. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5f0f332 to 6163592 Compare August 11, 2026 12:57
@github-actions

github-actions Bot commented Aug 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 31s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (53 files, 86 added / 86 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 86/86 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in .github/ resolves to exactly one SHA per action — no split-brain pins (counted repo-wide):

Action SHA Version Refs
actions/checkout d23441a v6.1.0 55
actions/setup-go 924ae3a v6.5.0 10
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 5ef2e55 v1.0.190 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 2
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) 5bee69a ci-test-notify/v1 1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review:

  • ci-test-notify/v1 digest advanced b5a50da5bee69a at .github/actions/govulncheck/action.yml:91. Worth noting because 5bee69a is main's current HEAD~1 — the docs-only commit "drop dev-vcluster webhook from ci-test-notify example (docs: drop dev-vcluster webhook from ci-test-notify example #218)". So the coordination tag was advanced onto a commit with no behavioural change to the composite; harmless, and it confirms the tag isn't stranded (per the CLAUDE.md pin-drift discipline, DEVOPS-1126/923).
  • All 12 external pins land on the same SHAs the previous review verified. claude-code-action at v1.0.190 (5ef2e55) is the same commit whether commented # v1.0.190 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself running 5ef2e55.

Stale-pin scan: every replaced SHA has zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in ~20 spots across non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub: the checkout is shallow with zero local tags, so validate-renovate/v1c40c1db is unverified against the actual tag (ci-test-notify/v15bee69a at least resolves to a real commit present in this clone). This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 6163592 to 79141fb Compare August 12, 2026 04:48
@github-actions

github-actions Bot commented Aug 12, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (53 files, 86 added / 86 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 86/86 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in .github/ resolves to exactly one SHA per action — no split-brain pins (counted repo-wide):

Action SHA Version Refs
actions/checkout d23441a v6.1.0 55
actions/setup-go 924ae3a v6.5.0 10
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 239e3a7 v1.0.191 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 2
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) 5bee69a ci-test-notify/v1 1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review:

  • claude-code-action advanced to v1.0.191 (239e3a7) — the body table says v1.0.190 (5ef2e55). Consistent across all 4 references: the # v1.0.191 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/239e3a730883eeb5c53db12b0fc9573b3024b126/, so that SHA is a real, working commit of the action.
  • The other 12 pins land on the same SHAs the previous review verified. ci-test-notify/v15bee69a is origin/main's current HEAD, so that coordination tag is not stranded (per the CLAUDE.md pin-drift discipline, DEVOPS-1126/923).

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in 23 spots across non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so validate-renovate/v1c40c1db is unverified against the actual tag. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 79141fb to 669fa3e Compare August 12, 2026 09:02
@github-actions

github-actions Bot commented Aug 12, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 51s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (53 files, 88 added / 88 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 88/88 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in .github/ resolves to exactly one SHA per action — no split-brain pins (counted repo-wide):

Action SHA Version Refs
actions/checkout d23441a v6.1.0 56
actions/setup-go 924ae3a v6.5.0 11
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 239e3a7 v1.0.191 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 2
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) 5bee69a ci-test-notify/v1 1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up 664b74d (run-ginkgo: rerun only the previous attempt's failed specs, #219). The line count ticked 86 → 88 because that PR's new "Run focus selection tests" job in test-run-ginkgo.yaml adds a checkout + setup-go pair that now carries the bumped pins (test-run-ginkgo.yaml:26,29). All 13 pins land on the same SHAs the previous review verified.

claude-code-action at v1.0.191 (239e3a7) is the same commit whether commented # v1.0.191 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml:30, claude.yml:36, claude-code-review.yaml:54). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/239e3a730883eeb5c53db12b0fc9573b3024b126/, so that SHA is a real, working commit of the action.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:240 (not a real ref). This PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 20 spots across non-executed docs: root README.md (7×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, govulncheck, publish-helm-chart, checkov, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 669fa3e to f2c8584 Compare August 13, 2026 16:10
@github-actions

github-actions Bot commented Aug 13, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 26s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (55 files, 92 added / 92 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 92/92 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in executable YAML resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version Refs
actions/checkout d23441a v6.1.0 58
actions/setup-go 924ae3a v6.5.0 11
actions/setup-node 2499707 v6.5.0 1
anthropics/claude-code-action 239e3a7 v1.0.191 / # v1 4
openai/codex-action 52fe01e v1.11 1
azure/setup-helm 9bc31f4 v5.0.1 2
aws-actions/configure-aws-credentials e6de054 v6.2.3 1
docker/login-action dbcb813 v4.6.0 3
dorny/paths-filter ceb8a2b v4.0.3 3
reviewdog/action-actionlint d63ba75 v1.73.1 1
slackapi/slack-github-action 0d95c9a v3.0.5 4
ci-test-notify (internal) 5bee69a ci-test-notify/v1 2
validate-renovate.yaml (internal) c40c1db validate-renovate/v1 1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up d584ff9 (cve-scan: reusable action to scan container images for CVEs, #213). The count ticked 53→55 files / 88→92 lines because the new cve-scan/action.yml + test-cve-scan.yaml carry checkout/docker-login/ci-test-notify pins that now get bumped too. All 13 pins land on the same SHAs the previous review verified.

claude-code-action at v1.0.191 (239e3a7) is the same commit whether commented # v1.0.191 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/239e3a730883eeb5c53db12b0fc9573b3024b126/, so that SHA is a real, working commit.

Stale-pin scan: every replaced SHA has zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — de0fac2 # v6.0.2 (checkout) still appears in non-executed README snippets. The rebase added a seventh file to that list: .github/actions/cve-scan/README.md (new in #213, authored against the old pin), alongside checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from f2c8584 to a57cb1c Compare August 13, 2026 20:06
@github-actions

github-actions Bot commented Aug 13, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 36s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 94 added / 94 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 94/94 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in executable YAML resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 239e3a7 v1.0.191 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d63ba75 v1.73.1
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up 849f9b6 (commitlint: reusable action for commit message linting, #221). The count ticked 55→56 files / 92→94 lines because the new test-commitlint.yaml carries two checkout pins that now get bumped too. The new commitlint/action.yml itself has no external uses:, so nothing else to bump there.

claude-code-action at v1.0.191 (239e3a7) is the same commit whether commented # v1.0.191 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/239e3a730883eeb5c53db12b0fc9573b3024b126/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 25 spots across non-executed docs. The rebase added an eighth README to that list: .github/actions/commitlint/README.md (new in #221, authored against the old pin), alongside cve-scan, checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release, plus root README.md and .claude/skills/github-actions-dev/SKILL.md. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a57cb1c to 7d32d9a Compare August 14, 2026 01:02
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 12s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 94 added / 94 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 94/94 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in executable YAML resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action e63208c v1.0.192 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d63ba75 v1.73.1
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.192 (e63208c) — the body table says v1.0.191 (239e3a7). Consistent across all 4 references: the # v1.0.192 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/e63208cb983318a44e3f945e959ef894b707dcfa/, so that SHA is a real, working commit.
  • The other 12 pins land on the same SHAs the previous review verified; file/line counts are unchanged (56 / 94).

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, govulncheck, publish-helm-chart, cve-scan, commitlint, checkov, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 7d32d9a to 2bdf28a Compare August 14, 2026 18:41
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 16s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 94 added / 94 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 94/94 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in executable YAML resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action e63208c v1.0.192 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • reviewdog/action-actionlint advanced to v1.73.2 (dbe5299) at .github/workflows/actionlint.yaml:38 — the body table says v1.73.1 (d63ba75), so this sync picked up a newer patch. Single reference; the old SHA is fully gone.
  • The other 12 pins land on the same SHAs the previous review verified. claude-code-action at v1.0.192 (e63208c) is the same commit whether commented # v1.0.192 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/e63208cb983318a44e3f945e959ef894b707dcfa/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml. The only non-SHA uses: refs in the tree are pre-existing internal loft-sh/github-actions@<coordination-tag> refs in notify-release.yaml / backport.yaml carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:240 (not a real ref). This PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, govulncheck, publish-helm-chart, cve-scan, commitlint, checkov, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 2bdf28a to 6d03dab Compare August 14, 2026 23:50
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 7s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 94 added / 94 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 94/94 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Every pinned reference in executable YAML resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 9d7150b v1.0.193 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.193 (9d7150b) — the body table says v1.0.192 (e63208c). Consistent across all 4 references: the # v1.0.193 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/9d7150bc8a3dae8149739a88019d192b579ad90c/, so that SHA is a real, working commit.
  • The other 12 pins land on the same SHAs the previous review verified; file/line counts unchanged (56 / 94).

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml — the 25 remaining occurrences are all in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications; this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, govulncheck, publish-helm-chart, cve-scan, commitlint, checkov, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 6d03dab to 2755917 Compare August 15, 2026 12:54
@github-actions

github-actions Bot commented Aug 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 34s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 96 added / 96 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 96/96 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 9d7150b v1.0.193 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • dev-hanz-ops/install-gh-cli-action bumped v0.2.1 (af38ce0) → v0.3.0 (6089bdd) at .github/workflows/backport.yaml:47,80not listed in the PR body table, and it's the only third-party (non-org, small-publisher) action in this sync. It's SHA-pinned so the blast radius is bounded to that pin, but it's the one entry here where "trusted upstream" doesn't apply as automatically as it does for actions/* and docker/*. Worth a glance at the v0.3.0 diff before merge if you care; the action only installs the gh CLI in the backport job.
  • The other 13 pins land on the same SHAs the previous review verified. claude-code-action at v1.0.193 (9d7150b) is the same commit whether commented # v1.0.193 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/9d7150bc8a3dae8149739a88019d192b579ad90c/, so that SHA is a real, working commit.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml — the 25 remaining occurrences are all in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications; this PR adds none.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml:29, detect-changes.yaml:31, validate-renovate.yaml:21) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, govulncheck, publish-helm-chart, cve-scan, commitlint, checkov, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions. The only item I'd eyeball first is the install-gh-cli-action v0.3.0 bump noted above.
• branch renovate/github-actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants