Skip to content

chore(deps): update github-actions - #291

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
anthropics/claude-code-action (changelog) action digest 8cf3482 → 6fed3ca
anthropics/claude-code-action action patch v1.0.233 → v1.0.245
azure/setup-kubectl action minor v5.1.0 → v5.2.0
loft-sh/github-actions (changelog) action digest c6a76f1 → d15a1df
openai/codex-action action minor v1.12 → v1.13
reviewdog/action-actionlint action minor v1.77.0 → v1.79.1

Release Notes

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.245

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.244...v1.0.245

v1.0.244

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.243...v1.0.244

v1.0.243

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.242...v1.0.243

v1.0.242

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.241...v1.0.242

v1.0.241

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.240...v1.0.241

v1.0.240

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.239...v1.0.240

v1.0.239

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.238...v1.0.239

v1.0.238

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.237...v1.0.238

v1.0.237

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.236...v1.0.237

v1.0.236

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.235...v1.0.236

v1.0.235

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.234...v1.0.235

v1.0.234

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.233...v1.0.234

azure/setup-kubectl (azure/setup-kubectl)

v5.2.0

Compare Source

Added
Fixed
Changed
Security
openai/codex-action (openai/codex-action)

v1.13

Compare Source

  • #​183 preserve system service access when restricting runner sockets under Linux drop-sudo.
  • Bound output draining to five seconds after Codex exits so descendants retaining log streams cannot keep the action open.
  • Linux drop-sudo now requires setfacl (the acl package) and ACL support on /run.
reviewdog/action-actionlint (reviewdog/action-actionlint)

v1.79.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.79.0...v1.79.1

v1.79.0

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.78.1...v1.79.0

v1.78.1

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.78.0...v1.78.1

v1.78.0

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.77.0...v1.78.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 24, 2026 21:22
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 16s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • The same full-length SHA pin (9171db3e…) is applied to all four places that use it. No copy of the old digest (8cf3482) is left anywhere in the repo, so none of the pins is out of step.
  • The pins stay on full commit SHAs, and the existing zizmor: ignore annotations are unchanged.
  • Upstream's v1.0.234 release has no notes. From what's in the PR, it looks like a plain patch bump with no new inputs or permissions.

Release note: .github/actions/ai-pr-review is a shared composite action. Callers get this bump only after its floating tag is moved to the merge commit (see the Release Process section in CLAUDE.md). The change asks nothing new of callers, so moving the existing tag is fine.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 754b98d to 9f43891 Compare September 25, 2026 11:16
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 18s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • All four uses of anthropics/claude-code-action now point at the same full commit SHA (9171db3e…). The old SHA (8cf3482) no longer appears anywhere in the repo's YAML.
  • actions/checkout goes to v6.1.0 (d23441a4…) in test-platform-release.yaml. That file was the last workflow still pinned to v6. Every other workflow and composite action is on v7.0.1, so this bump leaves nothing behind. Some README examples still say v6.0.2, but that is documentation and changes nothing at runtime.
  • The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged.

Release note: .github/actions/ai-pr-review is a shared composite action. Merging this PR does not reach its callers until the action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). The bump asks nothing new of callers, so it is fine to move the existing tag rather than cut a new major.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 9f43891 to f34ea1b Compare September 25, 2026 11:29
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 16s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • All four uses of anthropics/claude-code-action now point at the same full commit SHA (9171db3e…). The old SHA (8cf3482) no longer appears anywhere under .github/.
  • The actions/checkout change that the previous review covered is no longer in this PR. That is expected: test-platform-release.yaml is already on v7.0.1 on main (from chore(deps): update actions/checkout action to v7 #292), so the rebase dropped it.
  • The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged.

Release note: .github/actions/ai-pr-review is a shared composite action. Merging this PR does not reach its callers until the action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). The bump asks nothing new of callers, so it is fine to move the existing tag rather than cut a new major.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from f34ea1b to 575b401 Compare September 25, 2026 22:17
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 14s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • Renovate has pushed a new commit. All four uses of anthropics/claude-code-action now point at 756cc22e… (v1.0.235). The earlier reviews on this PR checked the previous pin, 9171db3e…. Neither the old digest (8cf3482) nor 9171db3e appears anywhere under .github/, so no pin is out of step with the others.
  • The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged.
  • Upstream's v1.0.234 and v1.0.235 releases have no notes. The changed lines only move the SHA; no inputs or permissions change.

Release note: .github/actions/ai-pr-review is a shared composite action. Merging this PR does not reach its callers until the action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). The bump asks nothing new of callers, so moving the existing tag is fine.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 575b401 to ab878b6 Compare September 28, 2026 19:18
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 13s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • Renovate pushed a new commit. All four uses of anthropics/claude-code-action now point at 8ce9314f… (v1.0.236). The earlier reviews on this PR checked older pins. No other claude-code-action pin is left under .github/, so none of the pins is out of step.
  • The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged.
  • Upstream's v1.0.234–v1.0.236 releases have no notes. The changed lines only move the SHA; no inputs or permissions change.

Release note: .github/actions/ai-pr-review is a shared composite action. Merging this PR does not reach its callers until the action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). The bump asks nothing new of callers, so moving the existing tag is fine.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from ab878b6 to a5f62aa Compare September 29, 2026 20:10
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 18s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • Renovate pushed a new commit. All four uses of anthropics/claude-code-action now point at fd1c1286… (v1.0.237). No other claude-code-action pin is left under .github/, so none of the pins is out of step.
  • The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged.
  • Upstream's v1.0.234–v1.0.237 releases have no notes. The changed lines only move the SHA; no inputs or permissions change.

Release note: .github/actions/ai-pr-review is a shared composite action. Merging this PR does not reach its callers until the action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). The bump asks nothing new of callers, so moving the existing tag is fine.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a5f62aa to b05e956 Compare September 29, 2026 21:16
@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 28s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

Release note: ai-pr-review and govulncheck are both shared composite actions. Merging this PR does not reach their callers until each action's floating tag is moved to the merge commit (see the Release Process section of CLAUDE.md). Neither bump asks anything new of callers, so moving the existing tags is fine and no new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from b05e956 to 1757163 Compare September 30, 2026 19:26
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 22s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • Renovate pushed a new commit. All four uses of anthropics/claude-code-action now point at 12dd8d74… (v1.0.238), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • The ci-test-notify bump in .github/actions/govulncheck/action.yml:91 (c6a76f1 → e9b507c, feat(ci-test-notify): add info status and none run link position #298) is the same as in the last review. feat(ci-test-notify): add info status and none run link position #298 only adds an info status and a run-link-position: none option. govulncheck sends status: failure with the default link position, so its Slack message is unchanged.
  • Upstream's v1.0.234–v1.0.238 releases have no notes. The changed lines only move the SHA, and no inputs or permissions change.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see the Release Process section in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 1757163 to 494017c Compare October 1, 2026 08:25
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 16s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • New in this push: .github/workflows/actionlint.yaml:38 moves reviewdog/action-actionlint from v1.77.0 to v1.78.0 (1129829f…). Upstream's release notes list only dependency bumps (actions-create-release, pyflakes). No inputs change, and the github_token and reporter inputs it passes stay the same.
  • All four uses of anthropics/claude-code-action still point at 12dd8d74… (v1.0.238), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • The ci-test-notify bump in govulncheck/action.yml:91 (c6a76f1 → e9b507c, feat(ci-test-notify): add info status and none run link position #298) hasn't changed since the last review. Its Slack message stays the same.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 494017c to de210f3 Compare October 1, 2026 18:03
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 49s —— View job


Review: PR #291

Bug: this push rolls cve-scan back to an older ci-test-notify, which undoes #300

.github/actions/cve-scan/action.yml:167 and :197 change the ci-test-notify pin from 2c8ba9b to e9b507c. That is a downgrade: e9b507c is an ancestor of 2c8ba9b, and the only change between the two commits is #299, which added the footer-text input.

cve-scan passes that input at :185 and :220 (footer-text: "View run #…"). At e9b507c the input doesn't exist, so:

Likely cause: the # ci-test-notify/v1 tag comment. Renovate pins each SHA to whatever the tag points at, so the floating tag probably still points at e9b507c, which means it wasn't moved after #299 merged (pin drift). I couldn't confirm this: git ls-remote needed an approval I don't have.

Fix (pick one):

  • Advance the tag to a commit that includes feat(ci-test-notify): let callers set the footer link text #299, e.g. git tag -f ci-test-notify/v1 origin/main && git push origin ci-test-notify/v1 --force. Then have Renovate rebase, and it will re-pin all ci-test-notify uses forward.
  • Or revert the two cve-scan lines in this PR to 2c8ba9b4c4be9e873fac4898cfb4ea2eddb5faed.

Advancing the tag is safe. #299 only adds an optional input, so it asks nothing new of callers.

Fix this →

Everything else is unchanged since the last review and has no problems: the claude-code-action pins on 12dd8d74… (v1.0.238), the govulncheck ci-test-notify bump (c6a76f1 → e9b507c is forward, and govulncheck doesn't use footer-text), and action-actionlint v1.78.0.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from de210f3 to dbe7115 Compare October 1, 2026 19:17
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 20s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • The cve-scan downgrade from the last review is fixed. cve-scan/action.yml is no longer in the diff, and both of its ci-test-notify pins stay on 2c8ba9b (feat(ci-test-notify): let callers set the footer link text #299, which has footer-text). The notification_pins.bats guard expects exactly that SHA.
  • govulncheck/action.yml:91 now moves ci-test-notify from c6a76f1 to 2c8ba9b. That is forward: c6a76f1 is an ancestor of 2c8ba9b. The only commits in between are feat(ci-test-notify): add info status and none run link position #298 and feat(ci-test-notify): let callers set the footer link text #299, and both just add optional inputs. govulncheck uses neither, so its Slack message is unchanged.
  • All four uses of anthropics/claude-code-action now point at 97c53473… (v1.0.239), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • reviewdog/action-actionlint v1.78.0 is the same as in the last review: upstream only bumped dependencies.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from dbe7115 to f23c484 Compare October 2, 2026 06:17
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 21s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • New in this push: .github/workflows/actionlint.yaml:38 moves reviewdog/action-actionlint from v1.78.0 to v1.78.1 (13465d02…). Upstream's only change is a bump of the Python docker tag to 3.14.8. The inputs stay the same, and this workflow still passes the same github_token and reporter.
  • All four uses of anthropics/claude-code-action still point at 97c53473… (v1.0.239), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • govulncheck/action.yml:91 still moves ci-test-notify forward from c6a76f1 to 2c8ba9b, the same as in the last review. Both cve-scan pins stay on 2c8ba9b, so the downgrade flagged two reviews ago has not come back.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from f23c484 to cd3f913 Compare October 2, 2026 20:37
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 52s —— View job


Review: PR #291

Bug: this push rolls cve-scan back to a ci-test-notify that breaks on jq 1.6, undoing #303

.github/actions/cve-scan/action.yml:167 and :197 change the pin from d15a1df (on main since #303) to 2c8ba9b. That is a downgrade, because 2c8ba9b is an ancestor of d15a1df. The only ci-test-notify change between the two is #302. It added the else . branch to SLACK_ESCAPE_CHARS in build-payload.sh:23–24.

  • jq 1.6 rejects an if … elif … end that has no else. jq 1.6 is the version on ubuntu-22.04, where the scheduled scans run.
  • cve-scan passes footer-text (:185, :220), and that input sends the footer through the broken filter (build-payload.sh:115, :119). On 22.04 the jq call fails, so no payload is built. The step is advisory, so the Slack alert for a found CVE or a scanner error is dropped and nothing goes red.
  • .github/actions/cve-scan/test/notification_pins.bats:8 expects exactly d15a1df, so make test fails on this branch.

Likely cause: pin drift again, like the earlier e9b507c rollback on this PR. Renovate re-pins to whatever ci-test-notify/v1 points at, and that tag apparently still points at 2c8ba9b. It wasn't moved after #302 merged. I couldn't check this myself because git fetch/ls-remote needs approval I don't have.

Fix (pick one):

  • Advance the tag: git tag -f ci-test-notify/v1 d15a1df8ea70c58cf70343f7c3687a6014ed63f8 && git push origin ci-test-notify/v1 --force, then tick Renovate's rebase box. This is safe because fix(ci-test-notify): add the else branch jq 1.6 needs in the footer escape #302 is a pure bug fix and asks nothing new of callers.
  • Or revert the two cve-scan lines in this PR to d15a1df8ea70c58cf70343f7c3687a6014ed63f8.

Fix this →

govulncheck is fine. govulncheck/action.yml:91 moves from c6a76f1 to 2c8ba9b, which is forward. govulncheck doesn't pass footer-text, so it never runs the broken filter. Once the tag is advanced, Renovate will move it to d15a1df as well.

Nothing else changed since the last review: claude-code-action is on 97c53473… (v1.0.239) in all four places, and action-actionlint is on v1.78.1.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from cd3f913 to 0a8dec2 Compare October 2, 2026 21:17
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 22s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0a8dec2 to 499e299 Compare October 4, 2026 00:16
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 14s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • New in this push: all four uses of anthropics/claude-code-action now point at cab360f6… (v1.0.241). No older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed. Upstream's v1.0.239–v1.0.241 releases have no notes. The changed lines only move the SHA, and no inputs or permissions change.
  • govulncheck/action.yml:91 still moves ci-test-notify forward from c6a76f1 to d15a1df. That matches both cve-scan pins (:167, :197), which are not in the diff, so the downgrade flagged in earlier reviews has not come back.
  • reviewdog/action-actionlint v1.78.1 is the same as in the last review.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 499e299 to d36ac1f Compare October 4, 2026 04:16
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 15s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • New in this push: .github/workflows/actionlint.yaml:38 moves reviewdog/action-actionlint from v1.78.1 to v1.79.0 (a1e3e7ff…). Upstream's only change is a bump of pyflakes to v4.0.2. The inputs are the same, and the workflow still passes the same github_token and reporter.
  • All four uses of anthropics/claude-code-action still point at cab360f6… (v1.0.241), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • govulncheck/action.yml:91 still moves ci-test-notify forward from c6a76f1 to d15a1df. That is the same commit both cve-scan pins use, and they are not in the diff, so the downgrade from earlier reviews has not come back.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from d36ac1f to 8e8d0cd Compare October 4, 2026 09:16
@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 18s —— View job


Review: PR #291

I found no bugs, security issues or performance problems.

  • New in this push: .github/workflows/actionlint.yaml:38 moves reviewdog/action-actionlint from v1.79.0 to v1.79.1 (1758727b…). Upstream published no notes for v1.79.1, and the two earlier releases in this range (v1.78.x, v1.79.0) only bumped dependencies. The workflow still passes only github_token and reporter.
  • All four uses of anthropics/claude-code-action still point at cab360f6… (v1.0.241), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed.
  • govulncheck/action.yml:91 still moves ci-test-notify forward from c6a76f1 to d15a1df. That is the same commit both cve-scan pins (:167, :197) use, and they aren't in the diff, so the downgrade flagged in earlier reviews hasn't come back.

Release note: ai-pr-review and govulncheck are shared composite actions. Their callers won't get this bump until each action's floating tag is moved to the merge commit (see Release Process in CLAUDE.md). Neither bump asks anything new of callers, so you can move the existing tags. No new major is needed.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8e8d0cd to 79e78ea Compare October 6, 2026 00:17
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 33s —— View job


Review: PR #291

I found no bugs or security issues in the diff. One part of this push asks more of the runner than before, so it changes how ai-pr-review should be released.

New in this push: openai/codex-action v1.12 → v1.13 (.github/actions/ai-pr-review/action.yml:147)

  • The openai path sets safety-strategy: drop-sudo (:153). Upstream's v1.13 notes say: "Linux drop-sudo now requires setfacl (the acl package) and ACL support on /run."
  • GitHub-hosted ubuntu-latest should meet that. The ai-pr-review.yaml wrapper runs there and has continue-on-error: true, so wrapper callers should be fine. I couldn't run it to confirm.
  • Callers that use the composite directly on a self-hosted runner, or in a container image without acl, will now fail at the Codex step. The step has no continue-on-error of its own, so for those callers the composite's never-hard-fail promise depends on how their job is set up.

Release note (this replaces what the earlier reviews said for ai-pr-review): earlier reviews on this PR said moving the existing ai-pr-review tag was fine. With codex-action v1.13 in the PR, that no longer holds. The CLAUDE.md Release Process section treats "a new runner requirement or tool" as needing a new major, and this adds one. You can either:

  • cut the next ai-pr-review major and leave the existing tag alone, or
  • first check who pins the composite with gh search code 'loft-sh/github-actions/.github/actions/ai-pr-review@ org:loft-sh' (I didn't have approval to run it). If every caller goes through the wrapper on GitHub-hosted runners, moving the tag is low risk.

Separately, the wrapper checks out the composite at ref: main (ai-pr-review.yaml:58), so wrapper callers get this bump as soon as it merges, whatever happens to the tag.

Nothing else needs action:

  • All four anthropics/claude-code-action pins now point at the same full SHA, 6c690188… (v1.0.242). Upstream published no notes for v1.0.239–v1.0.242, and no inputs change.
  • govulncheck/action.yml:91 moves ci-test-notify from c6a76f1 forward to d15a1df. That matches both cve-scan pins (:167, :197), and neither is in the diff, so the earlier downgrade hasn't come back.
  • reviewdog/action-actionlint v1.79.1 is unchanged since the last review.
  • govulncheck still asks nothing new of callers, so moving its existing tag is fine.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 79e78ea to 0ac5e2b Compare October 6, 2026 04:17
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 21s —— View job


Review: PR #291

I found no bugs or security issues in this push. The ai-pr-review release caveat from the last review still applies.

  • New in this push: all four uses of anthropics/claude-code-action now point at 86d88e61… (v1.0.243), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed. Upstream published no notes for v1.0.242–v1.0.243. The changed lines only move the SHA, and no inputs or permissions change.
  • Still open, unchanged since the last review: openai/codex-action v1.13 (.github/actions/ai-pr-review/action.yml:147). With safety-strategy: drop-sudo, v1.13 needs setfacl (the acl package) and ACL support on /run. GitHub-hosted Ubuntu runners should have both. Self-hosted runners or container jobs without acl would fail at the Codex step.
  • govulncheck/action.yml:91 still moves ci-test-notify forward from c6a76f1 to d15a1df. That is the same commit both cve-scan pins (:167, :197) use, and they aren't in the diff, so the earlier downgrade hasn't come back.
  • reviewdog/action-actionlint v1.79.1 hasn't changed since the last review.

Release note:

  • ai-pr-review: codex-action v1.13 adds a runner requirement. The Release Process section of CLAUDE.md says that needs a new major, unless gh search code 'loft-sh/github-actions/.github/actions/ai-pr-review@ org:loft-sh' shows every caller goes through the wrapper on GitHub-hosted runners. The wrapper checks out the composite at ref: main, so wrapper callers get this bump as soon as the PR merges.
  • govulncheck: the bump asks nothing new of callers, so you can move its existing tag.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0ac5e2b to 1bc8d82 Compare October 6, 2026 19:18
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 20s —— View job


Review: PR #291

I found no bugs or security issues in this push. The ai-pr-review release caveat from the last two reviews still applies.

  • New in this push: all four uses of anthropics/claude-code-action now point at 58985842… (v1.0.244), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations are unchanged. Upstream published no notes for v1.0.243–v1.0.244, and the changed lines only move the SHA.
  • Still open: openai/codex-action v1.13 (.github/actions/ai-pr-review/action.yml:147). This path runs with safety-strategy: drop-sudo, and in v1.13 that mode needs setfacl (the acl package) and ACL support on /run. GitHub-hosted Ubuntu runners should have both. On a self-hosted runner or in a container without acl, the Codex step would fail.
  • govulncheck/action.yml:91 still moves ci-test-notify forward, from c6a76f1 to d15a1df. Both cve-scan pins (:167, :197) are on the same commit and aren't in the diff.
  • reviewdog/action-actionlint v1.79.1 is unchanged since the last review.

Release note:

  • ai-pr-review: codex-action v1.13 adds a runner requirement. Under the Release Process section of CLAUDE.md, that calls for a new major. The exception is if gh search code 'loft-sh/github-actions/.github/actions/ai-pr-review@ org:loft-sh' shows that every caller uses the wrapper on GitHub-hosted runners. Separately, the wrapper checks out the composite at ref: main, so wrapper callers get this bump as soon as the PR merges.
  • govulncheck: this bump asks nothing new of callers, so you can move its existing tag.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 1bc8d82 to de17847 Compare October 6, 2026 20:25
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 35s —— View job


Review: PR #291

I found no bugs or security issues in this push. The ai-pr-review release caveat from earlier reviews still applies.

  • New in this push: azure/setup-kubectl v5.1.0 → v5.2.0 (.github/actions/prerelease-setup/action.yml:65, bda439f5…). Upstream published no release notes, and I couldn't open the compare view because gh api and WebFetch need approval I don't have. The step passes no inputs, so an input rename can't break it, and it stays pinned to a full SHA. prerelease-setup is a shared composite: if v5.2.0 turns out to need nothing new from the runner, move its existing tag after merge.
  • Still open: openai/codex-action v1.13 (.github/actions/ai-pr-review/action.yml:147). With safety-strategy: drop-sudo, v1.13 needs setfacl (the acl package) and ACL support on /run. GitHub-hosted Ubuntu runners should have both. On a self-hosted runner or in a container without acl, the Codex step would fail.
  • All four anthropics/claude-code-action pins are on 58985842… (v1.0.244), and no older pin is left under .github/. govulncheck/action.yml:91 moves ci-test-notify forward to d15a1df, the same commit both cve-scan pins use. reviewdog/action-actionlint v1.79.1 hasn't changed since the last review.

Release note:

  • ai-pr-review: codex-action v1.13 adds a runner requirement. Under the Release Process section of CLAUDE.md, that calls for a new major, unless gh search code 'loft-sh/github-actions/.github/actions/ai-pr-review@ org:loft-sh' shows every caller uses the wrapper on GitHub-hosted runners. The wrapper checks out the composite at ref: main, so wrapper callers get this bump as soon as the PR merges.
  • govulncheck, prerelease-setup: neither bump asks anything new of callers, as far as I can tell, so you can move their existing tags.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from de17847 to 950fa42 Compare October 7, 2026 19:18
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 17s —— View job


Review: PR #291

I found no bugs or security issues in this push. The ai-pr-review release caveat from earlier reviews still applies.

  • New in this push: all four uses of anthropics/claude-code-action now point at 6fed3ca1… (v1.0.245), and no older pin is left under .github/. The pins are still full commit SHAs, and the zizmor: ignore annotations haven't changed. Upstream published no notes for v1.0.244–v1.0.245, and the changed lines only move the SHA.
  • Still open: openai/codex-action v1.13 (.github/actions/ai-pr-review/action.yml:147). This path runs with safety-strategy: drop-sudo, and in v1.13 that mode needs setfacl (the acl package) and ACL support on /run. GitHub-hosted Ubuntu runners should have both. On a self-hosted runner or in a container without acl, the Codex step would fail.
  • These haven't changed since the last review:
    • azure/setup-kubectl v5.2.0 in prerelease-setup. The step passes no inputs.
    • ci-test-notify in govulncheck/action.yml:91 moves forward to d15a1df, which matches the cve-scan pins.
    • reviewdog/action-actionlint is on v1.79.1.

Release note:

  • ai-pr-review: codex-action v1.13 adds a runner requirement, so the Release Process section of CLAUDE.md calls for a new major. The exception is if gh search code 'loft-sh/github-actions/.github/actions/ai-pr-review@ org:loft-sh' shows that every caller uses the wrapper on GitHub-hosted runners. Separately, the wrapper checks out the composite at ref: main, so wrapper callers get this bump as soon as the PR merges.
  • govulncheck, prerelease-setup: as far as I can tell, neither bump asks anything new of callers, so you can move their existing tags.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants