Skip to content

chore(deps): update github-actions - #163

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

chore(deps): update github-actions#163
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v6.0.2v6.1.0
actions/setup-go action minor v6.4.0v6.5.0
anthropics/claude-code-action (changelog) action digest f4fb5c6a874e9e
anthropics/claude-code-action action patch v1.0.121v1.0.210
aws-actions/configure-aws-credentials action minor v6.1.3v6.2.3
azure/setup-helm action patch v5.0.0v5.0.1
dev-hanz-ops/install-gh-cli-action action minor v0.2.1v0.3.0
docker/login-action action minor v4.4.0v4.6.0
dorny/paths-filter action patch v4.0.1v4.0.3
loft-sh/github-actions (changelog) workflow digest 53686d2c40c1db
loft-sh/github-actions (changelog) action digest 85d70235bee69a
openai/codex-action action minor v1.8v1.12
reviewdog/action-actionlint action minor v1.72.0v1.73.2
slackapi/slack-github-action action patch v3.0.3v3.0.5

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

v6.0.3

Compare Source

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.210

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.209...v1.0.210

v1.0.209

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.208...v1.0.209

v1.0.208

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.207...v1.0.208

v1.0.207

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.206...v1.0.207

v1.0.206

Compare Source

v1.0.205

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.203...v1.0.205

v1.0.204

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.202...v1.0.204

v1.0.203

Compare Source

v1.0.202

Compare Source

v1.0.201

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.200...v1.0.201

v1.0.200

Compare Source

v1.0.199

Compare Source

v1.0.198

Compare Source

v1.0.197

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.196...v1.0.197

v1.0.196

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.195...v1.0.196

v1.0.195

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.194...v1.0.195

v1.0.194

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.193...v1.0.194

v1.0.193

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.192...v1.0.193

v1.0.192

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.191...v1.0.192

v1.0.191

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.190...v1.0.191

v1.0.190

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.190

v1.0.189

Compare Source

v1.0.188

Compare Source

v1.0.187

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.187

v1.0.186

Compare Source

v1.0.185

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.185

v1.0.184

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.184

v1.0.183

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.182

v1.0.181

Compare Source

v1.0.180

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Compare Source

v1.0.178

Compare Source

v1.0.177

Compare Source

v1.0.176

Compare Source

v1.0.175

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.175

v1.0.174

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.174

v1.0.173

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.173

v1.0.172

Compare Source

What's Changed

  • fix(sdk): fail step when result has is_error:true despite success subtype by @​syf2211 in #​1496

Full Changelog: anthropics/claude-code-action@v1...v1.0.172

v1.0.171

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.171

v1.0.170

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.170

v1.0.169

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.169

v1.0.168

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.168

v1.0.167

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.167

v1.0.166

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.166

v1.0.165

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.165

v1.0.164

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.164

v1.0.163

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.163

v1.0.162

Compare Source

v1.0.161

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.161

v1.0.160

Compare Source

v1.0.159

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.159

v1.0.158

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.158

v1.0.157

Compare Source

v1.0.156

Compare Source

v1.0.155

Compare Source

v1.0.154

Compare Source

v1.0.153

Compare Source

v1.0.152

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.152

v1.0.151

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.151

v1.0.150

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.150

v1.0.149

Compare Source

What's Changed

  • fix(parse-sdk-options): prevent shell-quote from collapsing unquoted Bash(X:*) rules to bare Bash by @​alexglynn in #​1350
  • fix(mcp): align allowed-tools parser with SDK option parser by @​bymle in #​1373

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.149

v1.0.148

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.148

v1.0.147

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.147

v1.0.146

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.146

v1.0.145

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.145

v1.0.144

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.144

v1.0.143

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.143

v1.0.142

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.142

v1.0.141

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.141

v1.0.140

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.140

v1.0.139

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.139

v1.0.138

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.138

v1.0.137

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.137

v1.0.136

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.136

v1.0.135

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.135

v1.0.134

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.134

v1.0.133

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.133

v1.0.132

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.132

v1.0.131

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.131

v1.0.130

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.130

v1.0.129

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.129

v1.0.128

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.128

v1.0.127

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.127

v1.0.126

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.126

v1.0.125

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.125

v1.0.124

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.124

v1.0.123

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.123

v1.0.122

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.122

aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)

v6.2.3

Compare Source

v6.2.2

Compare Source

v6.2.1

Compare Source

Bug Fixes

v6.2.0

Compare Source

Features
Bug Fixes
azure/setup-helm (azure/setup-helm)

v5.0.1

Compare Source

dev-hanz-ops/install-gh-cli-action (dev-hanz-ops/install-gh-cli-action)

v0.3.0: - update to node24

Compare Source

docker/login-action (docker/login-action)

v4.6.0

Compare Source

v4.5.2

Compare Source

v4.5.1

Compare Source

v4.5.0

Compare Source

dorny/paths-filter (dorny/paths-filter)

v4.0.3

Compare Source

v4.0.2

Compare Source

openai/codex-action (openai/codex-action)

v1.12

Compare Source

  • Strengthen Linux runner privilege isolation and Responses API proxy credential handling.
  • Reject Codex arguments and configuration overrides that conflict with protected execution settings.
  • Require unprivileged user namespaces for Linux drop-sudo; run the action after steps that need sudo, Docker, or privileged service sockets.
  • Document runner requirements, permission-profile behavior, and trusted configuration boundaries.

v1.11

Compare Source

  • #​116 keep the permission profile helper backward compatible

v1.10

Compare Source

  • #​113 add Codex permission profile support

v1.9

Compare Source

  • #​85 update the internal setup-node pin to v6.3.0
reviewdog/action-actionlint (reviewdog/action-actionlint)

v1.73.2

Compare Source

What's Changed

Full Changelog: reviewdog/action-actionlint@v1.73.1...v1.73.2

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 17s —— View job


Review: Renovate dependency bump

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for stale/mismatched pins and risky jumps

Findings

No bugs, security issues, or performance problems in the workflow/action changes. This is a clean SHA-pin bump.

Verified locally:

  • Every executable .github/ reference resolves to exactly one SHA per action — no split-brain pins:
    • checkoutdf4cb1c (v6.0.3), setup-go924ae3a (v6.5.0), claude-code-actionba0aafd (v1.0.168), codex-action52fe01e (v1.11), setup-helm9bc31f4 (v5.0.1), configure-aws-credentials517a711 (v6.2.2), paths-filter7b450ff (v4.0.2).
  • No stale old SHAs remain in any workflow/action YAML.
  • All version comments (# v...) match the update table in the PR body.

Minor (non-blocking)

Doc drift only: the old checkout pin de0fac2 # v6.0.2 still appears in example snippets in several README.md files (publish-helm-chart, go-licenses, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact — Renovate just doesn't rewrite doc examples. Worth a periodic sweep to keep examples current, but nothing to block this PR on.

Note on verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (gh api / git ls-remote / WebFetch to github.com are blocked in this sandbox). The SHAs were produced by Renovate's digest resolution and the version comments are consistent, so risk is low, but a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge. The bumps are patch/minor across trusted, already-pinned actions.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by the shared auto-approve workflow because this PR matched the approval criteria.

For more information, see https://github.com/loft-sh/github-actions?tab=readme-ov-file#auto-approve-bot-prs.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4eafdd1 to b2f1f27 Compare July 9, 2026 03:10
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 57s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Verified across the whole .github/ tree — every executable reference resolves to exactly one SHA per action, no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes:

  • claude-code-action moved to v1.0.169 (37b464c) since the PR body was written (body says v1.0.168) — the sync picked up a newer patch. SHA is consistent everywhere it appears (both the # v1.0.169 pin in ai-pr-review/action.yml and the # v1 float-tag comment in the claude*.yaml workflows point at the same commit). No mismatch.
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (subtree-mirror, go-licenses, govulncheck, checkov, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network is blocked in this sandbox). The SHAs come from Renovate's digest resolution and the version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from b2f1f27 to 021a49f Compare July 9, 2026 08:09
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 44s —— View job


Review: Renovate dependency bump

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action is pinned to the same SHA (37b464c) whether commented # v1.0.169 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — no mismatch. (Note: PR body says v1.0.168; the sync picked up the newer v1.0.169 patch.)
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 021a49f to 21a726e Compare July 10, 2026 01:59
@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 536f2c3 v1.0.170 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action moved again to v1.0.170 (536f2c3) since the last sync (PR body says v1.0.168, prior reviews saw v1.0.169). SHA is consistent across all 4 references — the # v1.0.170 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 21a726e to 4ef0d1c Compare July 11, 2026 03:28
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action fc46ded v3.0.4
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.171 (e90deca) (body says v1.0.170; earlier reviews saw v1.0.168/169/170). SHA is consistent across all 4 references — the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • slackapi/slack-github-action bumped v3.0.3 → v3.0.4 (fc46ded) in this sync (not listed in the PR body table). Consistent across all 4 references.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4ef0d1c to 82dc414 Compare July 11, 2026 07:43
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since prior reviews / PR body were written:

  • slackapi/slack-github-action moved further to v3.0.5 (0d95c9a) — PR body says v3.0.4, last review saw v3.0.4 (fc46ded). The sync picked up the newer patch. SHA is consistent across all 4 references.
  • claude-code-action is at v1.0.171 (e90deca), consistent across both the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 82dc414 to 5a21f93 Compare July 14, 2026 03:14
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 49s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action a08f891 v1.0.172 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.172 (a08f891) (body says v1.0.171; earlier reviews saw v1.0.168–171). SHA is consistent across all 4 references — the # v1.0.172 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • actions/setup-node also bumped to v6.5.0 (2499707) alongside setup-go — consistent, not in the PR body table.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5a21f93 to 514d3b5 Compare July 14, 2026 09:49
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action f1bd27c v1.0.173 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.173 (f1bd27c) (body says v1.0.172; earlier reviews saw v1.0.168–172). SHA is consistent across all 4 references — the # v1.0.173 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 514d3b5 to 0f2c6c6 Compare July 15, 2026 01:32
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1253134 v1.0.174 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.174 (1253134) (body says v1.0.173; earlier reviews saw v1.0.168–173). SHA is consistent across all 4 references — the # v1.0.174 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0f2c6c6 to fc67a83 Compare July 16, 2026 01:11
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1298632 v1.0.175 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.175 (1298632) (body says v1.0.174; earlier syncs saw v1.0.168–174). SHA is consistent across all references — the # v1.0.175 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from fc67a83 to a6bc804 Compare July 17, 2026 09:34
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.176 (700e7f8) (body says v1.0.175; earlier syncs saw v1.0.168–175). SHA is consistent across all references — the # v1.0.176 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a6bc804 to d0fbf65 Compare July 17, 2026 11:28
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 35s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, and every old SHA is fully replaced (verified: no stale pins remain in any workflow/action YAML):

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.176 (700e7f8) is consistent whether commented # v1.0.176 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from d0fbf65 to 8cb6560 Compare July 18, 2026 01:55
@github-actions

github-actions Bot commented Jul 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 10s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76, all uses: pin lines — no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3553f84 v1.0.177 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.177 (3553f84) (body says v1.0.176; earlier syncs saw v1.0.168–176). SHA is consistent across all references — the # v1.0.177 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, subtree-mirror, checkov, publish-helm-chart, govulncheck, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8cb6560 to 3af22e7 Compare July 19, 2026 06:05
@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 52s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all are pinned uses: references, no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action af0559e v1.0.178 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since the PR body was written:

  • claude-code-action advanced to v1.0.178 (af0559e) (body says v1.0.177; earlier syncs saw v1.0.168–177). SHA is consistent across all references — the # v1.0.178 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, vcluster-release, subtree-mirror, checkov, govulncheck, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3af22e7 to 45df450 Compare July 21, 2026 01:47
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 2s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • actions/checkout advanced to v6.1.0 (d23441a) — body says v6.0.3 (patch); the sync picked up a newer minor release. Consistent across all 48 executable references. Note this is a version-line change beyond what the PR title implies, but it's still a trusted, SHA-pinned action.
  • claude-code-action advanced to v1.0.179 (b76a077) (body says v1.0.178; earlier syncs saw v1.0.168–178). SHA is consistent across all references — the # v1.0.179 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from f9a1066 to 7d24da9 Compare August 20, 2026 21:44
@github-actions

github-actions Bot commented Aug 20, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 30s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 99 added / 99 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 99/99 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3f854a8 v1.0.198 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.198 (3f854a8) — the body table says v1.0.197 (5ee796a). Consistent across all 4 references: the # v1.0.198 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/3f854a8fb5146b39d5cbf8b57f70d80810e1366f/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml under .github/. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 7d24da9 to 5bd0e0c Compare August 21, 2026 00:57
@github-actions

github-actions Bot commented Aug 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 26s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (56 files, 99 added / 99 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 99/99 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3f854a8 v1.0.198 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • openai/codex-action advanced to v1.12 (8636508) — the body table says v1.8 → v1.11 (52fe01e), so this sync picked up a newer minor. Single reference (.github/actions/ai-pr-review/action.yml:147, the OpenAI review path); the old SHA is fully gone.
  • This sync also rebases onto main, picking up fa0b8ad (auto-approve: guard merges with the tested head, fix(auto-approve): guard merges with the tested head #233). All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml:72,177) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5bd0e0c to 6ed3ef2 Compare August 21, 2026 14:28
@github-actions

github-actions Bot commented Aug 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 32s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3f854a8 v1.0.198 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up 993feaa (aws-test-infra private-ip outputs + resolve-github-release action, #216). The count ticked 56→57 files / 99→101 lines because that PR's new test-resolve-github-release.yaml and the extra test-aws-test-infra.yaml steps carry checkout/setup-go pins that now get bumped too. All 14 pins land on the same SHAs the previous review verified.

claude-code-action at v1.0.198 (3f854a8) is the same commit whether commented # v1.0.198 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/3f854a8fb5146b39d5cbf8b57f70d80810e1366f/, so that SHA is a real, working commit.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 25 remaining occurrences are all in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs in notify-release.yaml / backport.yaml carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, cve-scan, govulncheck, publish-helm-chart, checkov, commitlint, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 6ed3ef2 to 3d9439a Compare August 21, 2026 22:27
@github-actions

github-actions Bot commented Aug 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 33s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action dcb5774 v1.0.199 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.199 (dcb5774) — the body table says v1.0.198 (3f854a8). Consistent across all 4 references: the # v1.0.199 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/dcb57747bfceeaa1fa72638cae52295d1d853d4a/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the remaining occurrences are all in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs in notify-release.yaml / backport.yaml carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, publish-helm-chart, govulncheck, cve-scan, vcluster-release, subtree-mirror, commitlint, checkov READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3d9439a to 4622670 Compare August 22, 2026 16:37
@github-actions

github-actions Bot commented Aug 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 22s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 24dcd50 v1.0.200 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.200 (24dcd50) — the body table says v1.0.199 (dcb5774). Consistent across all 4 references: the # v1.0.200 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/24dcd50c0568f0fc9e9211213a4fd2d9eb15c4e0/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs in notify-release.yaml / backport.yaml carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 and other replaced SHAs still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, cve-scan, govulncheck, publish-helm-chart, commitlint, vcluster-release, subtree-mirror, checkov READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4622670 to 8bcf260 Compare August 23, 2026 05:04
@github-actions

github-actions Bot commented Aug 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 19s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, no unpinned or floating refs introduced.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action c81e3bc v1.0.201 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.201 (c81e3bc) — the body table says v1.0.200 (24dcd50). Consistent across all 4 references: the # v1.0.201 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/c81e3bc69d1b18badbb63ba39581218f02421678/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. The only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 and other replaced SHAs still appear in 25 spots across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the go-licenses, cve-scan, govulncheck, publish-helm-chart, commitlint, vcluster-release, subtree-mirror, checkov READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8bcf260 to 0a528ab Compare August 25, 2026 00:16
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 32s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action e5ad3c7 v1.0.202 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.202 (e5ad3c7) — the body table says v1.0.201 (c81e3bc). Consistent across all 4 references: the # v1.0.202 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/e5ad3c7725bc2459721893f88879fef9dbcf97b0/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: the only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml:72,162) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not listed in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0a528ab to e51055d Compare August 25, 2026 14:15
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 18s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines are uses: …@<40-hex> # <version> pins — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 16b3b31 v1.0.205 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.205 (16b3b31) — the body table says v1.0.202 (e5ad3c7), so this sync picked up three more patches. Consistent across all 4 references: the # v1.0.205 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/16b3b310c3d7b5279df73130324d5205aeea8eac/, so that SHA is a real, working commit.
  • All other 13 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. Unpinned-ref scan: the only non-SHA uses: refs in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:246 (not a real ref). This PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from e51055d to 15d9ce0 Compare August 25, 2026 14:24
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 4s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (57 files, 101 added / 101 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 101/101 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 16b3b31 v1.0.205 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up baa2368 (semver-validation: trim the whitespace getInput trimmed). All pins land on the same SHAs the previous review verified.

claude-code-action at v1.0.205 (16b3b31) is the same commit whether commented # v1.0.205 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/16b3b310c3d7b5279df73130324d5205aeea8eac/, so that SHA is a real, working commit.

One correction to my previous reviews' tables: actions/setup-node no longer has any executable reference in this repo — it survives only as a mention in .claude/skills/github-actions-dev/SKILL.md on both main and this branch. So the PR body's setup-node v6.4.0 → v6.5.0 row is a no-op leftover, not a pin this PR moves. Nothing to fix; earlier tables listed it as live, and it isn't.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:246 (not a real ref). This PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 15d9ce0 to fb82aaf Compare August 25, 2026 14:35
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 29s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (58 files, 105 added / 105 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 0 of 105 added lines are anything other than a uses: …@<40-hex> # <version> pin — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 16b3b31 v1.0.205 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up c8c7c44 (test(setup-semstat): pin the reuse check off the new verifying default). The count ticked 57→58 files / 101→105 lines because that commit's reworked test-setup-semstat.yaml jobs carry two more checkout/setup-go pins that now get bumped too. Every pin lands on the same SHA the previous review verified.

claude-code-action at v1.0.205 (16b3b31) is the same commit whether commented # v1.0.205 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/16b3b310c3d7b5279df73130324d5205aeea8eac/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged from the last review: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from fb82aaf to cb92718 Compare August 25, 2026 17:22
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 32s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 107 added / 107 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 0 of 107 added lines are anything other than a uses: …@<40-hex> # <version> pin — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 16b3b31 v1.0.205 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up b6929d6 (comment-triggered-check: a comment-triggered check-run action, #226). The count ticked 58→59 files / 105→107 lines because that PR's new test-comment-triggered-check.yaml carries two checkout pins that now get bumped too. Every pin lands on the same SHA the previous review verified.

claude-code-action at v1.0.205 (16b3b31) is the same commit whether commented # v1.0.205 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/16b3b310c3d7b5279df73130324d5205aeea8eac/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message (not a real ref). This PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from cb92718 to 24e49f6 Compare August 25, 2026 23:39
@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 12s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 107 added / 107 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 107/107 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 1f291e1 v1.0.206 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.206 (1f291e1) — the body table says v1.0.205 (16b3b31). Consistent across all 4 references: the # v1.0.206 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/1f291e1cfe0f5fc21db2aef19af844591600ade7/, so that SHA is a real, working commit.
  • All other 12 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message (not a real ref). This PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Aug 27, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 56s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 107 added / 107 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 107/107 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 70fec18 v1.0.207 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.207 (70fec18) — the body table says v1.0.206 (1f291e1). Consistent across all 4 references: the # v1.0.207 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/70fec183852c4f82f3f1969faed7dd60c5149ca7/, so that SHA is a real, working commit.
  • All other 12 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications — this PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml:72,162) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Aug 27, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 16s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 107 added / 107 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 107/107 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e8c2d7c v1.0.208 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.208 (e8c2d7c) — the body table says v1.0.207 (70fec18). Consistent across all 4 references: the # v1.0.208 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/e8c2d7c16c018cf1e694711c1c07a5f5db2b5eb1/, so that SHA is a real, working commit.
  • All other 12 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — all 25 remaining occurrences are in non-executed .md docs. Unpinned-ref scan: the only non-SHA uses: refs are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at .github/actions/aws-test-infra/action.yml:246 (not a real ref). This PR adds none.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher, not in the PR body table. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md (9×), .claude/skills/github-actions-dev/SKILL.md (3×), and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Aug 28, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 14s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 107 added / 107 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 107/107 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a60f3e1 v1.0.209 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • claude-code-action advanced to v1.0.209 (a60f3e1) — the body table says v1.0.208 (e8c2d7c). Consistent across all 4 references: the # v1.0.209 pin in .github/actions/ai-pr-review/action.yml and the three # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/a60f3e1db3edbceed2b1e6c6a9d34c36b8a15eba/, so that SHA is a real, working commit.
  • All other 12 pins land on the same SHAs the previous review verified.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no non-SHA uses: refs added — the only ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Aug 28, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 3s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 108 added / 108 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Verified mechanically: 108/108 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, and the diff touches nothing outside .github/.

Enumerated every pinned ref in executable YAML — each action resolves to exactly one SHA, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a60f3e1 v1.0.209 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no version changes. This sync is a rebase onto main, which picked up f6288e7 (cve-scan: preview findings in Slack, #240). The count ticked 107 → 108 because that PR adds a third ci-test-notify reference in cve-scan/action.yml, which now carries the bumped pin too. Every pin lands on the same SHA the previous review verified.

claude-code-action at v1.0.209 (a60f3e1) is the same commit whether commented # v1.0.209 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this review job is itself executing from _actions/anthropics/claude-code-action/a60f3e1db3edbceed2b1e6c6a9d34c36b8a15eba/, so that SHA is a real, working commit.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no non-SHA uses: refs added — the only ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications.

Carried forward — dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (.github/workflows/backport.yaml) remains the one entry where "trusted upstream" doesn't apply as automatically as it does for actions/* / docker/*: small third-party publisher. It's SHA-pinned so the blast radius is bounded, and the release is just a Node 20→24 runtime bump; worth an eyeball at the v0.3.0 diff if you care.

Security-positive note (carried forward): dorny/paths-filter v4.0.3 includes GHSA-7hc6-8hq5-9q2m (escape multi-line filenames in list-files output). Not a live exposure — none of the three call sites (actionlint.yaml, detect-changes.yaml, validate-renovate.yaml) use list-files — but worth having.

Also unchanged: the PR body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — there is no executable setup-node reference left in this repo, only a mention in .claude/skills/github-actions-dev/SKILL.md.

Minor (non-blocking)

Doc drift only — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs: root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples. Fix this →

Verification scope

Confirmed internal consistency across the repo. I could not confirm tag→SHA mappings against GitHub (shallow checkout, no local tags), so the internal coordination-tag digests (ci-test-notify/v15bee69a, validate-renovate/v1c40c1db) are unverified against the actual tags. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: Safe to merge — patch/minor bumps across SHA-pinned actions.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Aug 28, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 25s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (59 files, 108 added / 108 removed lines)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

🔴 Blocking: this sync reverts the cve-scan notifier pin and reds test-cve-scan

main (f6288e7, #240) deliberately pinned both Slack notification steps in .github/actions/cve-scan/action.yml to the character-safe notifier revision 0157c66, and added .github/actions/cve-scan/test/notification_pins.bats to lock it:

CHARACTER_SAFE_NOTIFIER="0157c66f3034718081fd02ad01009e1ebc760129"
count="$(grep -Fc "$expected" "$MANIFEST" || true)"
[ "$count" -eq 2 ]

This PR rewrites both pins (action.yml:162,187) back to 5bee69a — the digest of the ci-test-notify/v1 tag, which is an older revision that predates the character-safe fix. Two consequences:

  1. CI fails. .github/workflows/test-cve-scan.yaml:29 runs bats .github/actions/cve-scan/test/*.bats, which includes that suite. Verified locally: the assertion's grep -Fc now returns 0, test expects 2.
  2. Functional revert. The cve-scan Slack preview path goes back to the notifier revision that feat(cve-scan): preview findings in Slack #240 moved off, so the character-safety fix is silently undone in the composite.

Root cause is a pin-drift instance of the class CLAUDE.md documents (DEVOPS-1126/923): #240 pinned a SHA that is not what ci-test-notify/v1 points at, but labelled it # ci-test-notify/v1. Renovate reads that comment, resolves the tag, and "corrects" the SHA backwards. The pin will keep getting reverted on every Renovate run until the mismatch is resolved.

Fix — advance the tag, don't take this hunk. Per the CLAUDE.md release discipline, ship the fix by moving the coordination tag onto the merged commit, then let Renovate resolve to it:

git tag -f ci-test-notify/v1 0157c66f3034718081fd02ad01009e1ebc760129
git push origin ci-test-notify/v1 --force

Then rebase this PR — Renovate will resolve ci-test-notify/v10157c66 and both pins stay put. (If 0157c66 is intentionally ahead of what v1 should carry, the alternative is to stop labelling it with the tag comment so Renovate leaves it alone — but that diverges from how every other internal ref in this repo is pinned.)

Fix this →

Everything else is clean

All 108 added lines match uses: …@<40-hex> # <version> — zero shell/logic edits, nothing outside .github/. Enumerated every pinned ref: each action resolves to exactly one SHA, no split-brain pins.

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a874e9e v1.0.210 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint dbe5299 v1.73.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 5bee69a ⚠️ see above
validate-renovate.yaml (internal) c40c1db validate-renovate/v1
  • claude-code-action advanced to v1.0.210 (a874e9e) — body table says v1.0.209 (a60f3e1). Consistent across all 4 references (# v1.0.210 in ai-pr-review/action.yml, # v1 in claude.yaml/claude.yml/claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/a874e9ecd7bb36efdad65429c6b35815f5a08f10/.
  • Unpinned-ref scan: no non-SHA uses: refs added. The only ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying zizmor: ignore[unpinned-uses] justifications.
  • Stale-pin scan: of the 14 replaced SHAs, 13 have zero remaining hits in any .yaml/.yml. The 14th is 0157c66 — the regression above.

Carried forward: dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is still the one small-third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Minor (non-blocking)

Doc drift — the stale checkout pin de0fac2 # v6.0.2 still appears across 10 non-executed docs (root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs). Renovate doesn't rewrite doc examples.

Also unchanged: the body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency across the repo and reproduced the failing assertion locally with grep -Fc. I could not run bats itself (not installed in this sandbox) or confirm tag→SHA mappings against GitHub (shallow checkout, no local tags) — so the claim that 0157c66 is newer than the ci-test-notify/v1 tag rests on git log -S, which shows f6288e7 introduced it while 5bee69a was already the tag digest in earlier syncs.

Recommendation: do not merge as-is. Advance ci-test-notify/v1 to 0157c66 and rebase, or the cve-scan bats job stays red and the notifier fix stays reverted.
• branch renovate/github-actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants