Skip to content

Bump the github-actions group with 3 updates#214

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-b67e97d45f
Open

Bump the github-actions group with 3 updates#214
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-b67e97d45f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 3 updates: pnpm/action-setup, ruby/setup-ruby and actions/setup-java.

Updates pnpm/action-setup from 5.0.0 to 6.0.9

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.9

What's Changed

Full Changelog: pnpm/action-setup@v6...v6.0.9

v6.0.8

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6.0.7...v6.0.8

v6.0.7

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6.0.6...v6.0.7

v6.0.6

What's Changed

Full Changelog: pnpm/action-setup@v6.0.5...v6.0.6

v6.0.5

What's Changed

Full Changelog: pnpm/action-setup@v6.0.4...v6.0.5

v6.0.4

What's Changed

New Contributors

... (truncated)

Commits
  • 0ebf471 fix: update pnpm to v11.7.0 (#267)
  • 0e279bb fix: update pnpm to 11.1.1 (#248)
  • 3e83581 fix: drop patchPnpmEnv so standalone+self-update works on Windows (#258)
  • 551b42e docs(README): fix cache_dependency_path type (#257)
  • 739bfe4 fix: self-update bootstrap to packageManager-pinned version (#233) (#256)
  • f61705d chore: add CODEOWNERS
  • 7a5507b fix: restore inputs from state in post (#255)
  • 1155470 fix: honor devEngines.packageManager.onFail=error (#252) (#254)
  • 91ab88e fix: bin_dest output points to self-updated pnpm, not bootstrap (#249)
  • e578e19 fix: update pnpm to 11.0.4
  • Additional commits viewable in compare view

Updates ruby/setup-ruby from 1.312.0 to 1.313.0

Release notes

Sourced from ruby/setup-ruby's releases.

v1.313.0

What's Changed

Full Changelog: ruby/setup-ruby@v1.312.0...v1.313.0

Commits

Updates actions/setup-java from 5.2.0 to 5.3.0

Release notes

Sourced from actions/setup-java's releases.

v5.3.0

What's Changed

New Contributors

Full Changelog: actions/setup-java@v5...v5.3.0

Commits
  • ad2b381 Bump @​vercel/ncc from 0.38.1 to 0.44.0 (#1018)
  • b24df5b Make the Adoptopenjdk package type look at the Temurin repo first for latest ...
  • 43120bc Implement pagination with link headers for Adoptium based apis (#1014)
  • ad9d6a6 Bump @​types/node from 24.1.0 to 25.9.3 (#950)
  • 039af37 Bump picomatch, @​types/jest, jest, jest-circus and ts-jest (#1016)
  • 1756ab6 Bump eslint-config-prettier from 8.10.0 to 10.1.8 (#881)
  • 662bb59 Bump @​typescript-eslint/eslint-plugin from 8.35.1 to 8.46.2 (#952)
  • 1071fc1 fix: resolve npm audit vulnerabilities in fast-xml-builder and fast-xml-parse...
  • 576b821 Merge pull request #674 from gdams/alpine
  • 307d3a2 update readme for ubuntu sudo java_home behavior (#1013)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 3 updates: [pnpm/action-setup](https://github.com/pnpm/action-setup), [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [actions/setup-java](https://github.com/actions/setup-java).


Updates `pnpm/action-setup` from 5.0.0 to 6.0.9
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@fc06bc1...0ebf471)

Updates `ruby/setup-ruby` from 1.312.0 to 1.313.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@12fd324...89f9052)

Updates `actions/setup-java` from 5.2.0 to 5.3.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@be666c2...ad2b381)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.9
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: ruby/setup-ruby
  dependency-version: 1.313.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: actions/setup-java
  dependency-version: 5.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot requested a review from eviltester as a code owner June 17, 2026 03:54
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jun 17, 2026
@greptile-apps

greptile-apps Bot commented Jun 17, 2026

Copy link
Copy Markdown

Greptile Summary

Routine Dependabot bump of three GitHub Actions in the CI workflow. All version references use immutable full-length SHAs, and the pnpm version is pinned to 11.1.1 via the version: input, so the major-version jump in pnpm/action-setup (v4/v5 → v6) does not change which pnpm release is actually installed.

  • pnpm/action-setup updated to v6.0.9 across all 7 job occurrences; the action's changelog covers bug-fixes for Windows self-update, devEngines.packageManager, and bootstrap path handling — no breaking changes for explicit-version usage.
  • ruby/setup-ruby bumped to v1.313.0 (adds JRuby 10.0.6.0 support only).
  • actions/setup-java bumped to v5.3.0 (Alpine Linux support for Temurin, dependency security patches, pagination fixes for Adoptium APIs).

Confidence Score: 5/5

All three action bumps are SHA-pinned, well-scoped, and carry no breaking changes for this workflow's configuration.

The changes are purely version bumps to established GitHub-maintained actions. pnpm is explicitly pinned via version: 11.1.1 so the major-version increment in pnpm/action-setup has no effect on which pnpm binary is installed. ruby/setup-ruby adds only JRuby support. setup-java adds Alpine Linux and Adoptium pagination — neither affects the Temurin/Java 21 configuration used here. All seven occurrences of pnpm/action-setup were updated consistently.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/node.js.yml Bumps pnpm/action-setup (×7 occurrences) from v4.4.0 SHA to v6.0.9 SHA, ruby/setup-ruby to v1.313.0, and actions/setup-java to v5.3.0 — all changes are SHA-pinned and consistent across jobs.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[CI Workflow Trigger] --> B[7 Jobs use pnpm/action-setup]
    B --> C["pnpm/action-setup@0ebf471 #v6.0.9\nversion: 11.1.1 pinned"]
    A --> D[multi-language job]
    D --> E["ruby/setup-ruby@89f9052 #v1.313.0\nruby-version: 3.3"]
    D --> F["actions/setup-java@ad2b381 #v5.3.0\ndistribution: temurin, java-version: 21"]
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
flowchart TD
    A[CI Workflow Trigger] --> B[7 Jobs use pnpm/action-setup]
    B --> C["pnpm/action-setup@0ebf471 #v6.0.9\nversion: 11.1.1 pinned"]
    A --> D[multi-language job]
    D --> E["ruby/setup-ruby@89f9052 #v1.313.0\nruby-version: 3.3"]
    D --> F["actions/setup-java@ad2b381 #v5.3.0\ndistribution: temurin, java-version: 21"]
Loading

Reviews (1): Last reviewed commit: "Bump the github-actions group with 3 upd..." | Re-trigger Greptile

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants