Skip to content

chore: bump the actions group across 1 directory with 7 updates - #47

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-832a919b83
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-832a919b83

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 7 updates in the / directory:

Package From To
burnt-labs/github-workflows/.github/workflows/required-quality.yml 3332fc8e0049b837e851778cb1fb2be1f24acb1a d3096758fcd3e5bbc5a9622b8f1f5182b80aab86
burnt-labs/github-workflows/.github/workflows/cloudflare-version.yml bdb6a6c76b0fc229fa2a54ed91c3ddf78c2ea4ec d3096758fcd3e5bbc5a9622b8f1f5182b80aab86
cloudflare/wrangler-action 4.0.0 4.1.3
changesets/action 1.9.0 2.1.2
burnt-labs/github-workflows/.github/workflows/npm-publish.yml 3332fc8e0049b837e851778cb1fb2be1f24acb1a d3096758fcd3e5bbc5a9622b8f1f5182b80aab86
docker/setup-buildx-action 4.2.0 4.4.1
docker/build-push-action 7.3.0 7.4.0

Updates burnt-labs/github-workflows/.github/workflows/required-quality.yml from 3332fc8 to d309675

Commits
  • d309675 Merge pull request #48 from burnt-labs/work/burntbot/secrets-file-deploy-2026...
  • 051ebc9 Keep the working-directory check on the step that now carries secrets
  • 5311f29 Point Cloudflare flow callers at the secrets-file deploy
  • bdb6a6c Publish Worker secrets with the deploy, not a separate secret edit
  • 77f180e Merge pull request #46 from burnt-labs/work/burntbot/phala-public-url-2026092...
  • 01ce81b Refuse to create the release CVM
  • 081e88f Point flow callers at the pin-advance revision
  • See full diff in compare view

Updates burnt-labs/github-workflows/.github/workflows/cloudflare-version.yml from bdb6a6c to d309675

Commits
  • d309675 Merge pull request #48 from burnt-labs/work/burntbot/secrets-file-deploy-2026...
  • 051ebc9 Keep the working-directory check on the step that now carries secrets
  • 5311f29 Point Cloudflare flow callers at the secrets-file deploy
  • See full diff in compare view

Updates cloudflare/wrangler-action from 4.0.0 to 4.1.3

Release notes

Sourced from cloudflare/wrangler-action's releases.

v4.1.3

Patch Changes

v4.1.2

Patch Changes

  • #453 876f5b5 Thanks @​ericclemmons! - Create GitHub releases only after their compiled action tags are ready so immutable releases do not block publishing.

v4.1.1

[!WARNING] This release is broken due to a publishing issue and will fail when used in a workflow. Please update to v4.1.2 or v4. See #454 for details.

Patch Changes

  • #451 429a99d Thanks @​podonnell-dev! - Pin Workers Preview examples and integration tests to Wrangler 4.136.3, which includes the Worker name in Preview artifacts.

v4.1.0

[!WARNING] This release is broken due to a publishing issue and will fail when used in a workflow. Please update to v4.1.2 or v4. See #454 for details.

Minor Changes

  • #450 9500699 Thanks @​podonnell-dev! - Add support for Workers Previews, including Preview artifact parsing, Preview outputs, GitHub Deployments, and job summaries for wrangler preview.

Patch Changes

  • #418 789ac84 Thanks @​vliggio! - Surface wrangler error messages in the action step output instead of showing only a generic failure message.
Changelog

Sourced from cloudflare/wrangler-action's changelog.

Changelog

4.1.3

Patch Changes

4.1.2

Patch Changes

  • #453 876f5b5 Thanks @​ericclemmons! - Create GitHub releases only after their compiled action tags are ready so immutable releases do not block publishing.

4.1.1

Patch Changes

  • #451 429a99d Thanks @​podonnell-dev! - Pin Workers Preview examples and integration tests to Wrangler 4.136.3, which includes the Worker name in Preview artifacts.

4.1.0

Minor Changes

  • #450 9500699 Thanks @​podonnell-dev! - Add support for Workers Previews, including Preview artifact parsing, Preview outputs, GitHub Deployments, and job summaries for wrangler preview.

Patch Changes

  • #418 789ac84 Thanks @​vliggio! - Surface wrangler error messages in the action step output instead of showing only a generic failure message.

4.0.0

Major Changes

  • #412 1029e90 Thanks @​ericclemmons! - Update default Wrangler version to v4 (latest). The action now installs Wrangler v4 by default when no wranglerVersion input is specified. Users can still pin to v3 by setting wranglerVersion: "3.90.0" explicitly.

3.15.0

Minor Changes

  • #426 febbda6 Thanks @​WillTaylorDev! - Support version ranges and tags in wranglerVersion input. You can now set wranglerVersion to values like 4, ^4.0.0, 4.x, or latest instead of only exact versions like 4.81.0.

3.14.1

Patch Changes

3.14.0

... (truncated)

Commits
  • 953926a Automatic compilation
  • a17640a Merge pull request #457 from cloudflare/changeset-release/main
  • 8d350f6 Version Packages
  • df82e37 Merge pull request #456 from cloudflare/podonnell/preview-comms
  • d3cfe74 WC-6082 [previews] adjust wrangler guidance to v4.136.3
  • d4d1b2d Merge pull request #455 from cloudflare/changeset-release/main
  • 1e45d72 Version Packages
  • 194026b Merge pull request #453 from cloudflare/codex/fix-immutable-releases
  • 5fa9855 docs: Explain immutable release sequencing
  • d7fd981 refactor: Keep release publishing retryable
  • Additional commits viewable in compare view

Updates changesets/action from 1.9.0 to 2.1.2

Release notes

Sourced from changesets/action's releases.

v2.1.2

Patch Changes

v2.1.1

Patch Changes

v2.1.0

Minor Changes

  • #718 3b7c71c Thanks @​bluwy! - Add a cwd input to the root action, /select-mode, /version, /pack, and /publish sub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.

Patch Changes

v2.0.0

Major Changes

  • #692 cb3f011 Thanks @​Andarist! - Release commits and tags are now pushed using the GitHub API by default.

    Replace the commit-mode input with the boolean push-with-git-cli input. Set push-with-git-cli: true to continue using the Git CLI.

    Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled, github-token takes precedence over those repository credentials.

  • #680 ca57073 Thanks @​bluwy! - Add a new push-git-tags option that complements create-github-releases to control specifically if git tags should be created but not GitHub releases.

    If create-github-releases was previously set to false, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, set push-git-tags to false explicitly.

  • #657 4f718b5 Thanks @​Andarist! - Removed compatibility support for old Changesets v1.

  • #681 7359107 Thanks @​bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.

    Inputs:

    • version -> version-script
    • publish -> publish-script
    • commit -> commit-message
    • title -> pr-title
    • branch -> pr-base-branch

... (truncated)

Changelog

Sourced from changesets/action's changelog.

@​changesets/action

2.1.2

Patch Changes

2.1.1

Patch Changes

2.1.0

Minor Changes

  • #718 3b7c71c Thanks @​bluwy! - Add a cwd input to the root action, /select-mode, /version, /pack, and /publish sub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.

Patch Changes

2.0.0

Major Changes

  • #692 cb3f011 Thanks @​Andarist! - Release commits and tags are now pushed using the GitHub API by default.

    Replace the commit-mode input with the boolean push-with-git-cli input. Set push-with-git-cli: true to continue using the Git CLI.

    Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled, github-token takes precedence over those repository credentials.

  • #680 ca57073 Thanks @​bluwy! - Add a new push-git-tags option that complements create-github-releases to control specifically if git tags should be created but not GitHub releases.

    If create-github-releases was previously set to false, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, set push-git-tags to false explicitly.

  • #657 4f718b5 Thanks @​Andarist! - Removed compatibility support for old Changesets v1.

  • #681 7359107 Thanks @​bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.

    Inputs:

... (truncated)

Commits

Updates burnt-labs/github-workflows/.github/workflows/npm-publish.yml from 3332fc8 to d309675

Commits
  • d309675 Merge pull request #48 from burnt-labs/work/burntbot/secrets-file-deploy-2026...
  • 051ebc9 Keep the working-directory check on the step that now carries secrets
  • 5311f29 Point Cloudflare flow callers at the secrets-file deploy
  • bdb6a6c Publish Worker secrets with the deploy, not a separate secret edit
  • 77f180e Merge pull request #46 from burnt-labs/work/burntbot/phala-public-url-2026092...
  • 01ce81b Refuse to create the release CVM
  • 081e88f Point flow callers at the pin-advance revision
  • See full diff in compare view

Updates docker/setup-buildx-action from 4.2.0 to 4.4.1

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.4.1

Full Changelog: docker/setup-buildx-action@v4.4.0...v4.4.1

v4.4.0

Full Changelog: docker/setup-buildx-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

Commits
  • f87e599 Merge pull request #624 from crazy-max/skip-pull-with-endpoint
  • e700274 chore: update generated content
  • 3061c91 skip BuildKit image pre-pulls for explicit endpoints
  • 594f3bf Merge pull request #609 from crazy-max/pull-buildkit-image-before-create
  • bd6e702 chore: update generated content
  • 6268c9d pull BuildKit image before builder creation
  • e823525 Merge pull request #621 from docker/dependabot/github_actions/codeql-actions-...
  • 533ed8e build(deps): bump the codeql-actions group with 2 updates
  • bedaf13 Merge pull request #620 from crazy-max/shared-error-helpers
  • d5079fb chore: update generated content
  • Additional commits viewable in compare view

Updates docker/build-push-action from 7.3.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.

v7.4.0

Full Changelog: docker/build-push-action@v7.3.0...v7.4.0

Commits
  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 459b674 [dependabot skip] chore: update generated content
  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0
  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message
  • 9877975 chore: update generated content
  • 7ed0556 use the shared Buildx error summary helper
  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 80dbc86 [dependabot skip] chore: update generated content
  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0
  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 26, 2026
@dependabot
dependabot Bot requested review from a team and a lite review from Copilot September 26, 2026 02:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Update the Changesets action invocation for the v2 input interface.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Updates pinned GitHub Actions and reusable workflow revisions across deployment, publishing, and quality workflows.

Changes:

  • Advances internal workflow references.
  • Updates Wrangler, Changesets, and Docker actions.
  • Requires migration of changesets/action inputs to the v2 interface.
File Description
.github/​workflows/​phala-deploy.yml Updates workflow and Docker action pins
.github/​workflows/​npm-release.yml Updates reusable workflow pins
.github/​workflows/​npm-pr.yml Updates quality workflow pin
.github/​workflows/​npm-main.yml Updates reusable workflow pins
.github/​workflows/​npm-changesets.yml Updates quality and Changesets action pins; v2 input migration required
.github/​workflows/​cloudflare-version.yml Updates Wrangler action pins
.github/​workflows/​cloudflare-release.yml Updates reusable workflow pins
.github/​workflows/​cloudflare-pr.yml Updates reusable workflow pins
.github/​workflows/​cloudflare-main.yml Updates reusable workflow pins

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +239 to 242
uses: changesets/action@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2
with:
title: ${{ inputs.pr-title }}
commit: ${{ inputs.pr-commit }}
Bumps the actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [burnt-labs/github-workflows/.github/workflows/required-quality.yml](https://github.com/burnt-labs/github-workflows) | `3332fc8e0049b837e851778cb1fb2be1f24acb1a` | `d3096758fcd3e5bbc5a9622b8f1f5182b80aab86` |
| [burnt-labs/github-workflows/.github/workflows/cloudflare-version.yml](https://github.com/burnt-labs/github-workflows) | `bdb6a6c76b0fc229fa2a54ed91c3ddf78c2ea4ec` | `d3096758fcd3e5bbc5a9622b8f1f5182b80aab86` |
| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `4.0.0` | `4.1.3` |
| [changesets/action](https://github.com/changesets/action) | `1.9.0` | `2.1.2` |
| [burnt-labs/github-workflows/.github/workflows/npm-publish.yml](https://github.com/burnt-labs/github-workflows) | `3332fc8e0049b837e851778cb1fb2be1f24acb1a` | `d3096758fcd3e5bbc5a9622b8f1f5182b80aab86` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.2.0` | `4.4.1` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |



Updates `burnt-labs/github-workflows/.github/workflows/required-quality.yml` from 3332fc8 to d309675
- [Release notes](https://github.com/burnt-labs/github-workflows/releases)
- [Commits](3332fc8...d309675)

Updates `burnt-labs/github-workflows/.github/workflows/cloudflare-version.yml` from bdb6a6c to d309675
- [Release notes](https://github.com/burnt-labs/github-workflows/releases)
- [Commits](bdb6a6c...d309675)

Updates `cloudflare/wrangler-action` from 4.0.0 to 4.1.3
- [Release notes](https://github.com/cloudflare/wrangler-action/releases)
- [Changelog](https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md)
- [Commits](cloudflare/wrangler-action@ebbaa15...953926a)

Updates `changesets/action` from 1.9.0 to 2.1.2
- [Release notes](https://github.com/changesets/action/releases)
- [Changelog](https://github.com/changesets/action/blob/main/CHANGELOG.md)
- [Commits](changesets/action@a45c4d5...ae32849)

Updates `burnt-labs/github-workflows/.github/workflows/npm-publish.yml` from 3332fc8 to d309675
- [Release notes](https://github.com/burnt-labs/github-workflows/releases)
- [Commits](3332fc8...d309675)

Updates `docker/setup-buildx-action` from 4.2.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@bb05f3f...f87e599)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@53b7df9...c3c9e26)

---
updated-dependencies:
- dependency-name: burnt-labs/github-workflows/.github/workflows/cloudflare-version.yml
  dependency-version: 77f180e
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: burnt-labs/github-workflows/.github/workflows/npm-publish.yml
  dependency-version: 77f180e
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: burnt-labs/github-workflows/.github/workflows/required-quality.yml
  dependency-version: 77f180e
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: changesets/action
  dependency-version: 2.1.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: cloudflare/wrangler-action
  dependency-version: 4.1.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Copilot AI lite review requested due to automatic review settings October 2, 2026 20:12
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-832a919b83 branch from c5ab86a to 8508bf3 Compare October 2, 2026 20:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Rename the obsolete Changesets v1 inputs in .github/workflows/npm-changesets.yml for the v2 action.

Review effort: Lite
Findings: 1 High severity

Open (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant