Skip to content

chore(deps): bump the github-actions group across 1 directory with 4 updates - #2325

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/github_actions/github-actions-a0271f4b22
Open

chore(deps): bump the github-actions group across 1 directory with 4 updates#2325
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/github_actions/github-actions-a0271f4b22

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 4 updates in the / directory: anthropics/claude-code-action, openai/codex-action, docker/setup-buildx-action and actions/ai-inference.

Updates anthropics/claude-code-action from 1.0.193 to 1.0.199

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.199

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.198...v1.0.199

v1.0.198

Full Changelog: anthropics/claude-code-action@v1.0.197...v1.0.198

v1.0.197

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.196...v1.0.197

v1.0.196

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.195...v1.0.196

v1.0.195

Full Changelog: anthropics/claude-code-action@v1.0.194...v1.0.195

v1.0.194

What's Changed

... (truncated)

Commits
  • dcb5774 chore: bump Claude Code to 2.1.239 and Agent SDK to 0.3.239
  • 492d2d7 fix: teach claude_args --allowedTools in the signed prompt (#1704)
  • 2ca5fb4 fix: surface resolved model limits (#1608)
  • f3f2789 fix(mcp): recognize mcp__github aggregate selector for GitHub MCP server init...
  • 6a5f1d8 fix(cleanup): keep the base-branch config revert out of the auto-commit (#1677)
  • 39ad3c8 fix(github): honor GITHUB_GRAPHQL_URL for the GraphQL client (#1575)
  • 3f854a8 chore: bump Claude Code to 2.1.238 and Agent SDK to 0.3.238
  • 5ee796a chore: bump Claude Code to 2.1.237 and Agent SDK to 0.3.237
  • cff8d3c fix(git-config): neutralize checkout credential in include-based config (#1526)
  • e2a4b76 chore: bump Claude Code to 2.1.236 and Agent SDK to 0.3.236
  • Additional commits viewable in compare view

Updates openai/codex-action from 1.11 to 1.12

Changelog

Sourced from openai/codex-action's changelog.

codex-action Changelog

v1.12 (2026-08-20)

  • Strengthen Linux runner privilege isolation and Responses API proxy credential handling.
  • Reject Codex arguments and configuration overrides that conflict with protected execution settings.
  • Require unprivileged user namespaces for Linux drop-sudo; run the action after steps that need sudo, Docker, or privileged service sockets.
  • Document runner requirements, permission-profile behavior, and trusted configuration boundaries.

v1.11 (2026-07-04)

  • #116 keep the permission profile helper backward compatible

v1.10 (2026-07-02)

  • #113 add Codex permission profile support

v1.9 (2026-06-22)

  • #85 update the internal setup-node pin to v6.3.0

v1.8 (2026-04-29)

  • #91 tighten what bots are allowed

v1.7 (2026-04-24)

  • #89 restrict bot permission bypass

v1.6 (2026-03-16)

  • #77 enable GitHub-hosted Linux bubblewrap support

v1.5 (2026-03-16)

  • #74 harden shell interpolation in action workflows

v1.4 (2025-11-19)

  • #58 revert #56 and use the latest stable version of Codex CLI again

v1.3 (2025-11-19)

  • #56 temporarily set the default version of Codex CLI to 0.58.0

v1.2 (2025-11-07)

  • #52 add baseUrl to Octokit constructor, if appropriate, for GHE

v1.1 (2025-11-05)

... (truncated)

Commits
  • 8636508 fix: improve runner setup and configuration handling
  • c385816 Retry network errors/transient HTTP errors in GitHub API requests (#128)
  • dd78cb6 docs: update CHANGELOG for v1.11 (#117)
  • See full diff in compare view

Updates docker/setup-buildx-action from 4.2.0 to 4.3.0

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.3.0

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

Commits
  • 37fe631 Merge pull request #595 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • b5c4f91 [dependabot skip] chore: update generated content
  • 3e93b63 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.95.0
  • e527031 Merge pull request #600 from docker/dependabot/npm_and_yarn/brace-expansion-1...
  • c68814b [dependabot skip] chore: update generated content
  • 3f891b0 build(deps): bump brace-expansion from 1.1.13 to 1.1.18
  • 787db26 Merge pull request #585 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
  • f779368 [dependabot skip] chore: update generated content
  • 7d5e604 build(deps): bump js-yaml from 5.2.0 to 5.3.0
  • 292c2fb Merge pull request #590 from docker/dependabot/github_actions/actions/setup-n...
  • Additional commits viewable in compare view

Updates actions/ai-inference from 2.1.1 to 3

Release notes

Sourced from actions/ai-inference's releases.

v3

What's Changed

New Contributors

Full Changelog: actions/ai-inference@v2...v3

Commits
  • 2c43c91 Merge pull request #236 from jalafel/jalafel/delete-github-models
  • 0ac1e35 refine test response
  • aacc9f2 Fix local actions test with mock Copilot CLI
  • 8359fe6 add step to ci to install copilot cli
  • 498d1c1 Refresh Licensed cache
  • 9bd16ce Merge remote-tracking branch 'upstream/main' into jalafel/delete-github-models
  • 5709758 run prettier on README.md
  • 726535a Merge pull request #237 from actions/dependabot/npm_and_yarn/npm-development-...
  • 396a40a chore(deps-dev): bump the npm-development group across 1 directory with 7 upd...
  • b246edc Merge pull request #232 from actions/dependabot/npm_and_yarn/tmp-0.2.6
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from BigSimmo as a code owner August 24, 2026 01:09
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 24, 2026
@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

CI triage

CI failed on this PR. Automated classification of the 3 failed job(s):

  • Static PR checksneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.
  • Unit coverageneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.
  • PR requiredneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.

Compared with main CI run #13594 (failure).

Classification is evidence routing, not permission to ignore a failure. Exact quarantined Playwright identities remain governed by the flake ledger.

…updates

Bumps the github-actions group with 4 updates in the / directory: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action), [openai/codex-action](https://github.com/openai/codex-action), [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) and [actions/ai-inference](https://github.com/actions/ai-inference).


Updates `anthropics/claude-code-action` from 1.0.193 to 1.0.199
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@9d7150b...dcb5774)

Updates `openai/codex-action` from 1.11 to 1.12
- [Changelog](https://github.com/openai/codex-action/blob/main/CHANGELOG.md)
- [Commits](openai/codex-action@52fe01e...8636508)

Updates `docker/setup-buildx-action` from 4.2.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@bb05f3f...37fe631)

Updates `actions/ai-inference` from 2.1.1 to 3
- [Release notes](https://github.com/actions/ai-inference/releases)
- [Commits](actions/ai-inference@a780588...2c43c91)

---
updated-dependencies:
- dependency-name: actions/ai-inference
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.199
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: openai/codex-action
  dependency-version: '1.12'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the github-actions group with 4 updates chore(deps): bump the github-actions group across 1 directory with 4 updates Aug 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-a0271f4b22 branch from 7200338 to f15d2e4 Compare August 24, 2026 11:41
claude added 2 commits August 24, 2026 14:38
PR #2325 bumped anthropics/claude-code-action, openai/codex-action,
docker/setup-buildx-action, and actions/ai-inference to new pinned
commit SHAs. Add the reviewed-pin allowlist entries (with release-note
summaries, matching the existing convention) so check:github-actions
passes, and update the hardcoded expected SHA in
tests/codex-run-pr-operator-workflow.test.ts to match the new
openai/codex-action pin.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot was not present on this head after the required first poll, so that signal was skipped; no applicable approval policy required human review, and there are no unresolved automated-review findings. No reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

BigSimmo pushed a commit that referenced this pull request Aug 24, 2026
…, #2326

Immutable review records for the four-PR dependency sweep: CI fix on
#2325, clean main-syncs on #2296/#2297, and diagnosis-only on #2326
(Node 26 Docker bump incompatible with the engine-strict Node 24 pin).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1
BigSimmo added a commit that referenced this pull request Aug 24, 2026
* Add branch review record for PR #2342 sweep

Records the Run-PR-style sweep check on PR #2342 (Improve Therapy
best-match visibility): review comments already fixed, branch synced
from main, CI green on completed checks.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* docs(ledger): record Run PR sweep of Dependabot PRs #2296, #2297, #2325, #2326

Immutable review records for the four-PR dependency sweep: CI fix on
#2325, clean main-syncs on #2296/#2297, and diagnosis-only on #2326
(Node 26 Docker bump incompatible with the engine-strict Node 24 pin).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* Add branch review record for PR #2339 sweep

Records the Run-PR-style sweep check on PR #2339 (therapy comparison
mobile design mockups): already fully green, only needed a main sync.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* Add branch review records for PR #2341, #2347 sweep

Records the Run-PR-style sweep checks on #2341 (dictionary filter
band, fixed via main sync, unrelated flake confirmed) and #2347
(browser test gate handoff, fixed stale generated file + doc-link
allowlist entries; owner closed the PR mid-sweep for unrelated reasons).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

---------

Co-authored-by: Claude <noreply@anthropic.com>
BigSimmo added a commit that referenced this pull request Aug 24, 2026
* Add branch review record for PR #2342 sweep

Records the Run-PR-style sweep check on PR #2342 (Improve Therapy
best-match visibility): review comments already fixed, branch synced
from main, CI green on completed checks.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* docs(ledger): record Run PR sweep of Dependabot PRs #2296, #2297, #2325, #2326

Immutable review records for the four-PR dependency sweep: CI fix on
#2325, clean main-syncs on #2296/#2297, and diagnosis-only on #2326
(Node 26 Docker bump incompatible with the engine-strict Node 24 pin).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* Add branch review record for PR #2339 sweep

Records the Run-PR-style sweep check on PR #2339 (therapy comparison
mobile design mockups): already fully green, only needed a main sync.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* Add branch review records for PR #2341, #2347 sweep

Records the Run-PR-style sweep checks on #2341 (dictionary filter
band, fixed via main sync, unrelated flake confirmed) and #2347
(browser test gate handoff, fixed stale generated file + doc-link
allowlist entries; owner closed the PR mid-sweep for unrelated reasons).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

* Add branch review records for PR #2338, #2337, #2333 sweep

Records the Run-PR-style sweep checks: #2337 fixed a design-token
ratchet failure, #2333 fixed a tap-target size regression and
resolved a concurrent-push merge, #2338 was only a main sync. #2333
and #2338 still have an open PR-policy failure (missing Clinical
Governance Preflight section) left for the PR author to fill in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01C4RHy24AtgPobEQQwrj7u1

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant