From 0482f2cb176b8290f1a09a5eb9d11405253459f7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 9 Jun 2026 10:35:01 +0000 Subject: [PATCH 1/2] chore: github actions update(deps): bump the version-updates group Bumps the version-updates group in /.github/workflows with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [github/codeql-action](https://github.com/github/codeql-action). Updates `actions/checkout` from 6.0.2 to 6.0.3 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v6.0.2...v6.0.3) Updates `github/codeql-action` from 4.36.0 to 4.36.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v4.36.0...v4.36.1) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates - dependency-name: github/codeql-action dependency-version: 4.36.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: version-updates ... Signed-off-by: dependabot[bot] --- .github/workflows/action-validator.yaml | 2 +- .github/workflows/agents-validate.yaml | 2 +- .github/workflows/codeql.yaml | 6 +++--- .github/workflows/dependabot-autobump.yaml | 2 +- .github/workflows/docs-bump.yaml | 2 +- .github/workflows/go-coverage-report.yaml | 2 +- .github/workflows/release.yml | 4 ++-- .github/workflows/static-checks.yaml | 4 ++-- 8 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/action-validator.yaml b/.github/workflows/action-validator.yaml index 90f8d754..bff2395a 100644 --- a/.github/workflows/action-validator.yaml +++ b/.github/workflows/action-validator.yaml @@ -19,7 +19,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 with: submodules: true diff --git a/.github/workflows/agents-validate.yaml b/.github/workflows/agents-validate.yaml index a493c7b3..4df51b95 100644 --- a/.github/workflows/agents-validate.yaml +++ b/.github/workflows/agents-validate.yaml @@ -28,7 +28,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 with: submodules: true diff --git a/.github/workflows/codeql.yaml b/.github/workflows/codeql.yaml index 85f1d097..62f2e798 100644 --- a/.github/workflows/codeql.yaml +++ b/.github/workflows/codeql.yaml @@ -56,11 +56,11 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@v4.36.0 + uses: github/codeql-action/init@v4.36.1 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} @@ -88,6 +88,6 @@ jobs: exit 1 - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@v4.36.0 + uses: github/codeql-action/analyze@v4.36.1 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/dependabot-autobump.yaml b/.github/workflows/dependabot-autobump.yaml index 4b77a290..729198f4 100644 --- a/.github/workflows/dependabot-autobump.yaml +++ b/.github/workflows/dependabot-autobump.yaml @@ -28,7 +28,7 @@ jobs: pull-requests: write steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 with: # Checkout the PR branch (head ref) not the target branch ref: ${{ github.event.pull_request.head.ref }} diff --git a/.github/workflows/docs-bump.yaml b/.github/workflows/docs-bump.yaml index 46f69605..04971b84 100644 --- a/.github/workflows/docs-bump.yaml +++ b/.github/workflows/docs-bump.yaml @@ -16,7 +16,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 - name: Install yq uses: mikefarah/yq@v4.53.2 diff --git a/.github/workflows/go-coverage-report.yaml b/.github/workflows/go-coverage-report.yaml index a8060e8c..51119617 100644 --- a/.github/workflows/go-coverage-report.yaml +++ b/.github/workflows/go-coverage-report.yaml @@ -34,7 +34,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 - name: Setup Go uses: actions/setup-go@v6 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e0f4f9d1..c888dd0f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -42,7 +42,7 @@ jobs: generated_at: ${{ steps.meta.outputs.generated_at }} steps: - name: Checkout target - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 with: fetch-depth: 0 ref: ${{ github.event_name == 'workflow_dispatch' && (inputs.target_commitish != '' && inputs.target_commitish || github.sha) || github.sha }} @@ -113,7 +113,7 @@ jobs: actions: read steps: - name: Checkout candidate commit - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 with: fetch-depth: 0 ref: ${{ needs.preflight.outputs.target_sha }} diff --git a/.github/workflows/static-checks.yaml b/.github/workflows/static-checks.yaml index d5b2ab62..cdbfbbcd 100644 --- a/.github/workflows/static-checks.yaml +++ b/.github/workflows/static-checks.yaml @@ -30,7 +30,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 - name: Install shellcheck, shfmt, and zsh run: | @@ -149,7 +149,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v6.0.2 + uses: actions/checkout@v6.0.3 - name: Run actionlint uses: rhysd/actionlint@v1.7.12 From d9dd869d708193a7160cacfeb16c276f43ad8bf0 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 9 Jun 2026 10:35:14 +0000 Subject: [PATCH 2/2] chore: auto-bump version and update CHANGELOG for Dependabot PR --- CHANGELOG.md | 4 ++++ bsctl/static/resources/constants.yaml | 2 +- resources/version.yaml | 2 +- 3 files changed, 6 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9b3bd29e..81b30042 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,10 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), --- +## [0.1.37] - 2026-06-09 +### Changed +- github actions update(deps): bump the version-updates group + ## [0.1.36] - 2026-06-08 ### Changed - Bump github.com/go-playground/validator/v10 from 10.30.2 to 10.30.3 diff --git a/bsctl/static/resources/constants.yaml b/bsctl/static/resources/constants.yaml index b154b93e..303d1524 100644 --- a/bsctl/static/resources/constants.yaml +++ b/bsctl/static/resources/constants.yaml @@ -1,2 +1,2 @@ # BasicSetupCliVersion - constant for semantic versioning -BasicSetupCliVersion: "0.1.36" +BasicSetupCliVersion: "0.1.37" diff --git a/resources/version.yaml b/resources/version.yaml index acacb5dc..3d07cb1e 100644 --- a/resources/version.yaml +++ b/resources/version.yaml @@ -1,2 +1,2 @@ # BasicSetupCliVersion - primary version source for releases and docs bump automation -BasicSetupCliVersion: "0.1.36" +BasicSetupCliVersion: "0.1.37"