Skip to content

chore(ci): pin dependencies - #5520

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ci
Open

chore(ci): pin dependencies#5520
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/ci

Conversation

@renovate

@renovate renovate Bot commented Aug 7, 2026

Copy link
Copy Markdown

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/add-to-project action pinDigest 244f685
actions/checkout action minor v4.2.2v4.4.0
actions/stale action minor v10.2.0v10.4.0
benchmark-action/github-action-benchmark action minor v1v1.22.1
fossas/fossa-action action minor v1.7.0v1.9.0
github/codeql-action action minor v3.28.12v3.37.6
github/codeql-action action minor v3v3.37.6
mysql (source) final minor 8.08.4
open-telemetry/opentelemetry-python-contrib action pinDigest 3a96d1c
ossf/scorecard-action action patch v2.4.2v2.4.4
otel/opentelemetry-collector-contrib minor 0.156.00.158.0
python (source) container minor 3.13-slim3.14-slim
rafaeljesus/opencensus-collector pinDigest 1bfcd22
re-actors/alls-green action pinDigest 05ac938

Release Notes

actions/checkout (actions/checkout)

v4.4.0

Compare Source

v4.3.1

Compare Source

v4.3.0

Compare Source

actions/stale (actions/stale)

v10.4.0

Compare Source

What's Changed

Bug Fix
Dependency Updates
  • Bump undici to 6.27.0 via override, clean up stale license files, and version to 10.4.0. by @​dependabot in #​1342

New Contributors

Full Changelog: actions/stale@v10.3.0...v10.4.0

v10.3.0

Compare Source

What's Changed

Bug Fix
Dependency Updates

New Contributors

Full Changelog: actions/stale@v10...v10.3.0

benchmark-action/github-action-benchmark (benchmark-action/github-action-benchmark)

v1.22.1

Compare Source

  • fix scope tsconfig.build.json to src/ for reproducibility (#​352)
  • chore bump minimatch from 3.1.2 to 3.1.5 (#​347)
  • chore bump uuid and @​actions/core (#​350)
  • chore bump flatted from 3.2.4 to 3.4.2 (#​346)
  • chore bump js-yaml (#​344)
  • chore bump picomatch from 2.3.0 to 2.3.2 (#​342)

v1.22.0

Compare Source

v1.21.0

Compare Source

  • fix include package name for duplicate bench names (#​330)
  • fix avoid duplicate package suffix in Go benchmarks (#​337)

v1.20.7

Compare Source

  • fix improve parsing for custom benchmarks (#​323)

v1.20.5

Compare Source

  • feat allow to parse generic cargo bench/criterion units (#​280)
  • fix add summary even when failure threshold is surpassed (#​285)
  • fix time units are not normalized (#​318)

v1.20.4

Compare Source

  • feat add typings and validation workflow (#​257)

v1.20.3

Compare Source

  • fix Catch2 v.3.5.0 changed output format (#​247)

v1.20.2

Compare Source

  • fix Support sub-nanosecond precision on Cargo benchmarks (#​246)

v1.20.1

Compare Source

  • fix release script

v1.20.0

Compare Source

  • fix Rust benchmarks not comparing to baseline (#​235)
  • feat Comment on PR and auto update comment (#​223)

v1.19.3

Compare Source

  • fix ratio is NaN when previous value is 0. Now, print 1 when both values are 0 and +-∞ when divisor is 0 (#​222)
  • fix action hangs in some cases for go fiber benchmarks (#​225)

v1.19.2

Compare Source

  • fix markdown rendering for summary is broken (#​218)

v1.19.1

Compare Source

  • fix improve flaky CI runs (#​215)
  • fix write with retry fails with the separate repository (#​216)

v1.19.0

Compare Source

  • docs Add description for skip-fetch-gh-pages (#​180)
  • fix Mismatch input in action.yml (#​191)
  • fix Update Manifest.toml to fix julia test failure (#​210)
  • chore update to node 20 (#​208)
  • chore update actions/* (#​212)
  • fix summary-always and gh-repository don't work together (#​214)

v1.18.0

Compare Source

  • feat getServerUrl refers to the GITHUB_SERVER_URL environment variable (#​169)
  • feat extract multiple metrics from Golang benchmarks (#​177)
  • fix getCommitFromGitHubAPIRequest to refer to GITHUB_API_URL (#​171)
  • chore Remove unreachable code from extract.ts (#​153)

v1.17.0

Compare Source

  • feat support for JMH parameters (as separate charts) (#​161)
  • feat enable user to specify the ref being tested (#​163)
  • feat allow more characters in Golang bench outputs (#​131)

v1.16.2

Compare Source

  • Fix use commit.id over commit object (#​155)

v1.16.1

Compare Source

  • Fix action.yml missing summary-always input

v1.16.0

Compare Source

  • Feat Support pr summary for benchmark output (#​138)

v1.15.0

Compare Source

v1.14.0

Compare Source

  • Feat Added benchmark luau support (#​123)
  • Chore Bump minimist from 1.2.5 to 1.2.6 (#​114)
  • Feat Implement deploy to another repository (#​112)

v1.13.0

Compare Source

  • Feat: Updated urls to support GHES (#​104)
  • Feat: Add support for BenchmarkDotNet (#​109)
  • Chore Bump node-fetch from 2.6.6 to 2.6.7 (#​107)

v1.12.0

Compare Source

  • Feat: Support private repositories (#​105)
  • Chore Bump action runner to node v16 (#​106)

v1.11.3

Compare Source

  • Fix: Fix trailing whitespace characters in cargo benchmarks (#​97)

v1.11.2

Compare Source

  • Fix: Added option to use Rust benchmark names with spaces (#​94)

v1.11.1

Compare Source

  • Fix: Fix/go tabled benchmarks (#​32)
  • New: Support BenchmarkTools.jl in Julia (#​89)
  • Improve: Update several dependencies including TypeScript v4.5.2
  • Improve: Use Jest for unit testing

v1.11.0

Compare Source

v1.10.0

Compare Source

  • New: Allow user defined custom benchmarks (#​81)

v1.9.0

Compare Source

  • Fix: manual and scheduled runs (#​74)

v1.8.1

Compare Source

  • Fix: Allow / in cargo bench benchmark name (#​26)
  • New: Add an example with Criterion.rs for Rust projects

[Changes][v1.8.1]

v1.8.0

Compare Source

  • New: Added comment-always option to leave a comment of benchmarking results at the commit always. Thanks @​pksunkara
  • New: Added save-data-file option to skip saving data file. Setting false to this value is useful when you don't want to update Git repository. Thanks @​pksunkara
  • Improve: +/- is now replaced with ±
  • Improve: Better formatting for floating point numbers

[Changes][v1.8.0]

v1.7.1

Compare Source

  • Fix: Benchmark output parser could not parse \r\n as newline correctly (#​16)
  • Improve: Prefer @actions/github.GitHub wrapper to @octokit/rest.Octokit

[Changes][v1.7.1]

v1.7.0

Compare Source

  • New: Add Catch2 support. Please read the example for more details. Thanks @​bernedom
  • Fix: Deploying to GitHub Pages did not work when checking out the repository with actions/checkout@v2
  • Improve: Update several dependencies including @actions/* packages

[Changes][v1.7.0]

v1.6.7

Compare Source

  • Fix: Extracting the benchmark result value from go test -bench did not assume float numbers (Fixed #​5)
  • Fix: Running this action on pull_request event caused an error since head_commit payload is not set at the event. In the case, now this action tries to extract the commit information from pull_request payload

[Changes][v1.6.7]

v1.6.6

Compare Source

  • Fix: Parse floating numbers in the benchmark results from Benchmark.js. (Thanks @​Bnaya)

[Changes][v1.6.6]

v1.6.5

Compare Source

  • Fix: Titles are set to empty in auto-generated default index.html. To apply this fix, please remove current index.html in your GitHub Pages branch and run this action again
  • Fix: Skip fetching GitHub Pages branch before switching to the branch when skip-fetch-gh-pages is set to true
  • Improve: Explicitly note no action output from this action in README.md

[Changes][v1.6.5]

v1.6.4

Compare Source

  • Fix: Supported actions/checkout@v2
  • Improve: Refactored index.html automatically generated when it does not exist
  • Improve: Update dependencies (actions/github v2)

[Changes][v1.6.4]

v1.6.3

Compare Source

  • Improve: Tweak number of retries for more robust automatic git push

[Changes][v1.6.3]

v1.6.2

Compare Source

  • Fix: Retry logic for git push did not work properly since stderr output was not included in error message

[Changes][v1.6.2]

v1.6.1

Compare Source

  • Fix: Time unit of mean time in pytest benchmark results were always sec. Now time units are converted to msec, usec and nsec if necessary
  • Fix: Detecting rejection by remote on git push was not sufficient
  • Improve: Add a small link at right bottom of dashboard page to show this action provided the page
  • Improve: Showed at least 1 significant digit for threshold float values like 2.0
  • Improve: Updated dependencies

[Changes][v1.6.1]

v1.6.0

Compare Source

  • New: fail-threshold input was added. Format is the same as alert-threshold, but you can give different thresholds to sending a commit comment and making the workflow fail by giving different value to fail-threshold from alert-threshold. This value is optional. If omitted, fail-threshold value is the same as alert-threshold
  • Improve: Retry logic was improved on git push failed due to remote branch updates after git pull. Now this action retries entire process to update gh-pages branch when the remote rejected automatic git push. Previously this action tried to rebase the local onto the remote but it sometimes failed due to conflicts

[Changes][v1.6.0]

v1.5.0

Compare Source

  • New: Added max-items-in-chart input was added to limit the number of data points in a graph chart.
  • New: Supported Google C++ Benchmark Framework for C++ projects. Please check the example project and the example workflow to know the setup
  • Fix: Fix the order of graphs in the default index.html. To apply this fix, please remove index.html in your GitHub Pages branch and run your benchmark workflow again
  • Improve: Use the actions marketplace URL for the link to this action in commit comment
  • Improve: Updated dependencies
  • Dev: Added Many tests for checking the updates on a new benchmark result
  • Dev: Changed directory structure. Sources are now put in src/ directory

[Changes][v1.5.0]

v1.4.0

Compare Source

  • New: external-data-json-path input was added to support to put benchmark data externally rather than Git branch
    • By using this input and actions/cache, you no longer need to use Git branch for this action if you only want performance alerts. Benchmark data is stored as workflow cache.
    • By this input, minimal setup for this action is much easier. Please read 'How to use' section in README.md.

[Changes][v1.4.0]

v1.3.2

Compare Source

  • Improve: Styles in alert commit comment were improved
  • Fix: When benchmark name (with name input) contained spaces, URL for the workflow which detected performance regression was broken

[Changes][v1.3.2]

v1.3.1

Compare Source

  • Fix: git push sometimes failed in the situation where prepush hook is set and runs unexpectedly. Now git push is run with --no-verify for pushing auto generated commit to remote.

[Changes][v1.3.1]

v1.3.0

Compare Source

  • New: Alert feature was added 🎉
    • With this feature enabled, you can get alert commit comment or make workflow fail when possible performance regression is detected like this
    • comment-on-alert input was added to enable commit comment on alert. github-token input is necessary as well to use GitHub API. Unlike deploying GitHub Pages, secrets.GITHUB_TOKEN is sufficient for this purpose (if you don't use GitHub Pages). The input is set to false by default.
    • fail-on-alert input was added to mark running workflow fail on alert. The input is set to false by default.
    • alert-threshold input was added to specify the threshold to check alerts. When current result gets worse than previous exceeding the threshold. Value is ratio such as "200%". For example, when benchmark gets result 230 ns/iter and previous one was 100ns/iter, it means 230% worse and an alert will happen.
    • Please read documentation for setup
  • New: alert-comment-cc-users input was added to specify users mentioned in an alert commit comment so that they can easily notice it via GitHub notification
  • New: skip-fetch-gh-pages input was added to skip git pull which is automatically executed on public repo or when you set github-token on private repo.
  • Improve: E2E checks on CI were added
  • Improve: Updated dependencies

[Changes][v1.3.0]

v1.2.0

Compare Source

  • New: Support pytest-benchmark for Python projects which use pytest
    • Benchmark value is how long one iteration takes (seconds/iter)
  • Improve: Show more extra data in tooltip which are specific to tools
    • Go
      • Iterations
      • Number of CPUs used
    • Benchmark.js
      • Number of samples
    • pytest-benchmark
      • Mean time
      • Number of rounds

For reflecting the extra data improvement, please refresh your index.html. Remove current index.html in GitHub Pages branch and push the change to remote, then re-run your benchmark workflow.

[Changes][v1.2.0]

v1.1.4

Compare Source

  • Improve: Title styles in default index.html which is generated when no index.html is in your GitHub Pages branch. If you want to update your index.html to the latest, please remove it and push to remote at first then re-run your workflow which will invoke github-action-benchmark
  • Improve: More metadata in action.yml. Now icon and its color are set.

[Changes][v1.1.4]

v1.1.3

Compare Source

  • Fix: Retry failed when no Git user config is provided. Ensure to give bot user info to each git command invocations

[Changes][v1.1.3]

v1.1.2

Compare Source

  • Improve: Added retry for git push. When remote GitHub Pages branch is updated after the current workflow had fetched the branch, git push will fail because the remote branch is not up-to-date. In the case this action will try to rebase onto the latest remote by git pull --rebase and git push again. This is useful when your multiple workflows may be trying to push GitHub Pages branch at the same timing. auto-push input must be set to true for this.
  • Fix: Description for auto-push was missing in action.yml

[Changes][v1.1.2]

v1.1.1

Compare Source

  • Improve: More strict check for auto-push input. Now the value must be one of true, false (default value is false)

[Changes][v1.1.1]

v1.1.0

Compare Source

  • New: Added auto-push input
    • If this value is set to true, this action pushes GitHub Pages branch to remote automatically. You no longer need to push the branch by yourself.
    • Below github-token input must be set for this
    • This input is optional. You can still push the branch by yourself if you want
    • Please read documentation for more details
  • New: Added github-token input
    • For doing some operations which requires GitHub API token, this input is necessary
      • pull from remote branch when your repository is private
      • push to remote branch
      • deploy and trigger GitHub Pages build
    • This input is optional. When you do none of above operations, this input is not necessary
  • README.md was updated to avoid the issue on public repository (#​1)

e.g.

- name: Store benchmark result
  uses: rhysd/github-action-benchmark@v1
  with:
    name: My Project Go Benchmark
    tool: 'go'
    output-file-path: output.txt
    github-token: ${{ secrets.PERSONAL_GITHUB_TOKEN }}
    auto-push: true

Note that you need to make a personal access token for deploying GitHub Pages from GitHub Action workflow. Please read RADME.md for more details.

[Changes][v1.1.0]

v1.0.2

Compare Source

First release 🎉

Please read documentation for getting started:

https://github.com/benchmark-action/github-action-benchmark#readme

Changes

v1.0.1

Compare Source

fossas/fossa-action (fossas/fossa-action)

v1.9.0

Compare Source

What's Changed

New Contributors

Full Changelog: fossas/fossa-action@v1.8.0...v1.9.0

v1.8.0

Compare Source

github/codeql-action (github/codeql-action)

v3.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v3.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v3.37.4

Compare Source

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #​4037
  • Update default CodeQL bundle version to 2.26.2. #​4051

v3.37.3

Compare Source

No user facing changes.

v3.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v3.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v3.37.0

Compare Source

v3.36.3

Compare Source

No user facing changes.

v3.36.2

Compare Source

  • Cache CodeQL CLI version information across Actions steps. #​3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #​3937
  • Update default CodeQL bundle version to 2.25.6. #​3948

v3.36.1

Compare Source

No user facing changes.

v3.36.0

Compare Source

  • Breaking change: Bump the minimum required CodeQL bundle version to 2.19.4. #​3894
  • Add support for SHA-256 Git object IDs. #​3893
  • Update default CodeQL bundle version to 2.25.5. #​3926

v3.35.5

Compare Source

  • We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. #​3899
  • For performance and accuracy reasons, improved incremental analysis will now only be enabled on a pull request when diff-informed analysis is also enabled for that run. If diff-informed analysis is unavailable (for example, because the PR diff ranges could not be computed), the action will fall back to a full analysis. #​3791
  • If multiple inputs are provided for the GitHub-internal analysis-kinds input, only code-scanning will be enabled. The analysis-kinds input is experimental, for GitHub-internal use only, and may change without notice at any time. #​3892
  • Added an experimental change which, when running a Code Scanning analysis for a PR with improved incremental analysis enabled, prefers CodeQL CLI versions that have a cached overlay-base database for the configured languages. This speeds up analysis for a repository when there is not yet a cached overlay-base database for the latest CLI version. We expect to roll this change out to everyone in May. #​3880

v3.35.4

Compare Source

v3.35.3

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.19.3 and earlier. These versions of CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise Server 3.15, and will be unsupported by the next minor release of the CodeQL Action. #​3837
  • Configurations for private registries that use Cloudsmith or GCP OIDC are now accepted. #​3850
  • Best-effort connection tests for private registries now use GET requests instead of HEAD for better compatibility with various registry implementations. For NuGet feeds, the test is now always performed against the service index. #​3853
  • Fixed a bug where two diagnostics produced within the same millisecond could overwrite each other on disk, causing one of them to be lost. #​3852
  • Update default CodeQL bundle version to 2.25.3. #​3865

v3.35.2

Compare Source

  • The undocumented TRAP cache cleanup feature that could be enabled using the CODEQL_ACTION_CLEANUP_TRAP_CACHES environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the trap-caching: false input to the init Action. #​3795
  • The Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. #​3789
  • Python analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. #​3794
  • Fixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. #​3807
  • Update default CodeQL bundle version to 2.25.2. #​3823

v3.35.1

Compare Source

v3.35.0

Compare Source

v3.34.1

Compare Source

  • Downgrade default CodeQL bundle version to 2.24.3 due to issues with a small percentage of Actions and JavaScript analyses. #​3762

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner August 7, 2026 15:38
@renovate renovate Bot added dependencies Pull requests that update a dependency file Skip Changelog PRs that do not require a CHANGELOG.md entry labels Aug 7, 2026
@github-project-automation github-project-automation Bot moved this to Approved PRs in Python PR digest Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file Skip Changelog PRs that do not require a CHANGELOG.md entry

Projects

Status: Approved PRs

Development

Successfully merging this pull request may close these issues.

1 participant