chore(deps): bump the github-actions group across 1 directory with 6 updates#5450
chore(deps): bump the github-actions group across 1 directory with 6 updates#5450dependabot[bot] wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 9391867. Configure here.
| pull-requests: write | ||
| steps: | ||
| - uses: getsentry/github-workflows/validate-pr@71588ddf95134f804e82c5970a8098588e2eaecd | ||
| - uses: getsentry/github-workflows/validate-pr@26f565c05d0dd49f703d238706b775883037d76b |
There was a problem hiding this comment.
validate-pr action downgraded instead of upgraded to v3.4.0
High Severity
The validate-pr action is being changed to commit 26f565c05d0dd49f703d238706b775883037d76b, which is the old v3.3.0 hash — the same hash that danger.yml and update-deps.yml were on before this PR. Those other two workflows are correctly updated to 607fed74f812e69201531a5185b6c3c57caa4e89 (v3.4.0), but validate-pr is effectively being downgraded from an intermediate commit back to v3.3.0 instead of being upgraded to v3.4.0. This loses features like "skip checks for users with write access" and the security hardening fixes included in v3.4.0.
Reviewed by Cursor Bugbot for commit 9391867. Configure here.
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
📲 Install BuildsAndroid
|
Performance metrics 🚀
|
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 3d205d0 | 352.15 ms | 432.53 ms | 80.38 ms |
| 27d7cf8 | 369.82 ms | 422.62 ms | 52.80 ms |
| 33a08cc | 267.08 ms | 340.45 ms | 73.37 ms |
| b750b96 | 408.98 ms | 480.32 ms | 71.34 ms |
| 96eeafa | 361.43 ms | 455.07 ms | 93.63 ms |
| 22f4345 | 314.79 ms | 375.02 ms | 60.23 ms |
| 8c1fb22 | 316.62 ms | 352.78 ms | 36.16 ms |
| cf708bd | 434.73 ms | 502.96 ms | 68.22 ms |
| 48277cd | 320.38 ms | 379.90 ms | 59.52 ms |
| 22f4345 | 307.87 ms | 354.51 ms | 46.64 ms |
App size
| Revision | Plain | With Sentry | Diff |
|---|---|---|---|
| 3d205d0 | 1.58 MiB | 2.10 MiB | 532.97 KiB |
| 27d7cf8 | 1.58 MiB | 2.12 MiB | 549.42 KiB |
| 33a08cc | 1.58 MiB | 2.12 MiB | 555.28 KiB |
| b750b96 | 1.58 MiB | 2.10 MiB | 533.19 KiB |
| 96eeafa | 1.58 MiB | 2.19 MiB | 620.21 KiB |
| 22f4345 | 1.58 MiB | 2.29 MiB | 719.83 KiB |
| 8c1fb22 | 0 B | 0 B | 0 B |
| cf708bd | 1.58 MiB | 2.11 MiB | 539.71 KiB |
| 48277cd | 0 B | 0 B | 0 B |
| 22f4345 | 1.58 MiB | 2.29 MiB | 719.83 KiB |
10b4011 to
b4c3551
Compare
…updates Bumps the github-actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `6.0.0` | `6.0.1` | | [getsentry/craft/.github/workflows/changelog-preview.yml](https://github.com/getsentry/craft) | `2.26.3` | `2.26.6` | | [github/codeql-action](https://github.com/github/codeql-action) | `4.35.4` | `4.36.0` | | [getsentry/github-workflows](https://github.com/getsentry/github-workflows) | `3.3.0` | `3.4.0` | | [actions/create-github-app-token](https://github.com/actions/create-github-app-token) | `3.1.1` | `3.2.0` | | [getsentry/craft](https://github.com/getsentry/craft) | `2.26.3` | `2.26.6` | Updates `codecov/codecov-action` from 6.0.0 to 6.0.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@57e3a13...e79a696) Updates `getsentry/craft/.github/workflows/changelog-preview.yml` from 2.26.3 to 2.26.6 - [Release notes](https://github.com/getsentry/craft/releases) - [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md) - [Commits](getsentry/craft@bae212c...3e6a0f4) Updates `github/codeql-action` from 4.35.4 to 4.36.0 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...7211b7c) Updates `getsentry/github-workflows` from 3.3.0 to 3.4.0 - [Release notes](https://github.com/getsentry/github-workflows/releases) - [Commits](getsentry/github-workflows@3.3.0...3.4.0) Updates `actions/create-github-app-token` from 3.1.1 to 3.2.0 - [Release notes](https://github.com/actions/create-github-app-token/releases) - [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md) - [Commits](actions/create-github-app-token@1b10c78...bcd2ba4) Updates `getsentry/craft` from 2.26.3 to 2.26.6 - [Release notes](https://github.com/getsentry/craft/releases) - [Changelog](https://github.com/getsentry/craft/blob/master/CHANGELOG.md) - [Commits](getsentry/craft@bae212c...3e6a0f4) --- updated-dependencies: - dependency-name: actions/create-github-app-token dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/craft dependency-version: 2.26.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/craft/.github/workflows/changelog-preview.yml dependency-version: 2.26.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: getsentry/github-workflows dependency-version: 3.4.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 4.35.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
b4c3551 to
73161bc
Compare


Bumps the github-actions group with 6 updates in the / directory:
6.0.06.0.12.26.32.26.64.35.44.36.03.3.03.4.03.1.13.2.02.26.32.26.6Updates
codecov/codecov-actionfrom 6.0.0 to 6.0.1Release notes
Sourced from codecov/codecov-action's releases.
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
e79a696chore(release): 6.0.1 (#1949)51e6422fix: prevent template injection in run: steps (VULN-1652) (#1947)Updates
getsentry/craft/.github/workflows/changelog-preview.ymlfrom 2.26.3 to 2.26.6Release notes
Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's releases.
Changelog
Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's changelog.
... (truncated)
Commits
3e6a0f4release: 2.26.62662e81fix(security): override@tootallnate/onceto ^2.0.1 (CVE-2026-3449) (#822)e9a5238fix: improve partial publishing recovery for CocoaPods and GitHub targets (#821)da0e0c1fix(nuget): move global.json aside duringdotnet setversion(#820)d1fa7dbmeta: Bump new development versionca52417Merge branch 'release/2.26.5'bc2e6a9release: 2.26.560b80e5fix(security): bump devalue override to ^5.8.1 (CVE-2026-42570) (#818)7bd2931meta: Bump new development version1389909Merge branch 'release/2.26.4'Updates
github/codeql-actionfrom 4.35.4 to 4.36.0Release notes
Sourced from github/codeql-action's releases.
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
7211b7cMerge pull request #3927 from github/update-v4.36.0-ebc2d9e2b7740f2fUpdate changelog for v4.36.0ebc2d9eMerge pull request #3926 from github/update-bundle/codeql-bundle-v2.25.5d1f74b7Add changelog note2dc40ceUpdate default bundle to codeql-bundle-v2.25.58449852Merge pull request #3910 from github/henrymercer/repo-size-diff-check72ac23cUpdate excluded required check listc5297a2Merge pull request #3919 from github/henrymercer/workflow-concurrency8ffeae7CI: Automatically cancel non-generated workflowsf3f52bfRevertgetErrorMessageimportUpdates
getsentry/github-workflowsfrom 3.3.0 to 3.4.0Release notes
Sourced from getsentry/github-workflows's releases.
Commits
607fed7release: 3.4.082866c1chore: update getsentry/craft to 2.26.3 (#168)24be696fix: complete script injection hardening across all actions (#152)a940f77fix(updater): Trigger CI for new PRs without changelog updates (#166)98c1e36test(updater): Accept either main or master as sentry-cli main branch (#167)d81d746chore: update danger/danger.properties to 13.0.5 (#160)80476a9fix(updater): Select first matching main branch (#165)43bf14bfeat(validate-pr): Make advisory; drop close + labels (#163)71588ddfeat(validate-pr): Skip checks for users with write access (#162)02fd7a2feat(validate-pr): Skip all checks when a maintainer reopens a PR (#161)Updates
actions/create-github-app-tokenfrom 3.1.1 to 3.2.0Release notes
Sourced from actions/create-github-app-token's releases.
Changelog
Sourced from actions/create-github-app-token's changelog.
Commits
bcd2ba4chore(main): release 3.2.0 (#370)f24bbd8fix: validate private-key input (#376)363531bdocs: capitalize Git as a proper noun in README (#374)fd28011docs: update procedure to configure Git (#287)85eb8ddfeat: support full repository names inrepositoriesinput (#372)c9aabb8build(deps-dev): bump yaml from 2.8.3 to 2.8.4 in the development-dependencie...e02e816build(deps-dev): bump undici from 7.24.6 to 8.2.0 (#366)8d835bfbuild(deps-dev): bump esbuild from 0.27.4 to 0.28.0 in the development-depend...952a2a7feat: add support for enterprise-level GitHub Apps (#263)43e5c34fix(deps): bump@actions/corefrom 3.0.0 to 3.0.1 in the production-dependenc...Updates
getsentry/craftfrom 2.26.3 to 2.26.6Release notes
Sourced from getsentry/craft's releases.
Changelog
Sourced from getsentry/craft's changelog.
... (truncated)
Commits
3e6a0f4release: 2.26.62662e81fix(security): override@tootallnate/onceto ^2.0.1 (CVE-2026-3449) (#822)e9a5238fix: improve partial publishing recovery for CocoaPods and GitHub targets (#821)da0e0c1fix(nuget): move global.json aside duringdotnet setversion(#820)d1fa7dbmeta: Bump new development versionca52417Merge branch 'release/2.26.5'bc2e6a9release: 2.26.560b80e5fix(security): bump devalue override to ^5.8.1 (CVE-2026-42570) (#818)7bd2931meta: Bump new development version1389909Merge branch 'release/2.26.4'