Skip to content

chore(deps): update github-actions - #163

Merged
sydorovdmytro merged 1 commit into
mainfrom
renovate/github-actions
Sep 24, 2026
Merged

sydorovdmytro merged 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
anthropics/claude-code-action (changelog) action digest f4fb5c68cf3482
anthropics/claude-code-action action patch v1.0.121v1.0.233
aws-actions/configure-aws-credentials action minor v6.1.3v6.3.0
azure/setup-helm action patch v5.0.0v5.0.1
docker/login-action action minor v4.4.0v4.6.0
dorny/paths-filter action patch v4.0.1v4.0.3
loft-sh/github-actions (changelog) workflow digest 53686d2de873f4
loft-sh/github-actions (changelog) action digest 85d7023d462e84
openai/codex-action action minor v1.8v1.12
reviewdog/action-actionlint action minor v1.72.0v1.77.0

Release Notes

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.233

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.232...v1.0.233

v1.0.232

Compare Source

v1.0.231

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.230...v1.0.231

v1.0.230

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.229...v1.0.230

v1.0.229

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.228...v1.0.229

v1.0.228

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.227...v1.0.228

v1.0.227

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.226...v1.0.227

v1.0.226

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.225...v1.0.226

v1.0.225

Compare Source

v1.0.224

Compare Source

v1.0.223

Compare Source

v1.0.222

Compare Source

v1.0.221

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.220...v1.0.221

v1.0.220

Compare Source

v1.0.219

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.218...v1.0.219

v1.0.218

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.217...v1.0.218

v1.0.217

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.216...v1.0.217

v1.0.216

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.215...v1.0.216

v1.0.215

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.214...v1.0.215

v1.0.214

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.213...v1.0.214

v1.0.213

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.212...v1.0.213

v1.0.212

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.211...v1.0.212

v1.0.211

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.210...v1.0.211

v1.0.210

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.209...v1.0.210

v1.0.209

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.208...v1.0.209

v1.0.208

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.207...v1.0.208

v1.0.207

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.206...v1.0.207

v1.0.206

Compare Source

v1.0.205

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.203...v1.0.205

v1.0.204

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.202...v1.0.204

v1.0.203

Compare Source

v1.0.202

Compare Source

v1.0.201

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.200...v1.0.201

v1.0.200

Compare Source

v1.0.199

Compare Source

v1.0.198

Compare Source

v1.0.197

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.196...v1.0.197

v1.0.196

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.195...v1.0.196

v1.0.195

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.194...v1.0.195

v1.0.194

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.193...v1.0.194

v1.0.193

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.192...v1.0.193

v1.0.192

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.191...v1.0.192

v1.0.191

Compare Source

Full Changelog: anthropics/claude-code-action@v1.0.190...v1.0.191

v1.0.190

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.190

v1.0.189

Compare Source

v1.0.188

Compare Source

v1.0.187

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.187

v1.0.186

Compare Source

v1.0.185

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.185

v1.0.184

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.184

v1.0.183

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.182

v1.0.181

Compare Source

v1.0.180

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Compare Source

v1.0.178

Compare Source

v1.0.177

Compare Source

v1.0.176

Compare Source

v1.0.175

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.175

v1.0.174

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.174

v1.0.173

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.173

v1.0.172

Compare Source

What's Changed

  • fix(sdk): fail step when result has is_error:true despite success subtype by @​syf2211 in #​1496

Full Changelog: anthropics/claude-code-action@v1...v1.0.172

v1.0.171

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.171

v1.0.170

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.170

v1.0.169

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.169

v1.0.168

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.168

v1.0.167

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.167

v1.0.166

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.166

v1.0.165

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.165

v1.0.164

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.164

v1.0.163

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.163

v1.0.162

Compare Source

v1.0.161

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.161

v1.0.160

Compare Source

v1.0.159

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.159

v1.0.158

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.158

v1.0.157

Compare Source

v1.0.156

Compare Source

v1.0.155

Compare Source

v1.0.154

Compare Source

v1.0.153

Compare Source

v1.0.152

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.152

v1.0.151

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.151

v1.0.150

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.150

v1.0.149

Compare Source

What's Changed

  • fix(parse-sdk-options): prevent shell-quote from collapsing unquoted Bash(X:*) rules to bare Bash by @​alexglynn in #​1350
  • fix(mcp): align allowed-tools parser with SDK option parser by @​bymle in #​1373

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.149

v1.0.148

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.148

v1.0.147

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.147

v1.0.146

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.146

v1.0.145

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.145

v1.0.144

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.144

v1.0.143

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.143

v1.0.142

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.142

v1.0.141

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.141

v1.0.140

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.140

v1.0.139

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.139

v1.0.138

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.138

v1.0.137

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.137

v1.0.136

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.136

v1.0.135

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.135

v1.0.134

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.134

v1.0.133

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.133

v1.0.132

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.132

v1.0.131

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.131

v1.0.130

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.130

v1.0.129

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.129

v1.0.128

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.128

v1.0.127

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.127

v1.0.126

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.126

v1.0.125

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.125

v1.0.124

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.124

v1.0.123

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.123

v1.0.122

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.122

aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)

v6.3.0

Compare Source

v6.2.4

Compare Source

v6.2.3

Compare Source

v6.2.2

Compare Source

v6.2.1

Compare Source

Bug Fixes

v6.2.0

Compare Source

Features
Bug Fixes
azure/setup-helm (azure/setup-helm)

v5.0.1

Compare Source

docker/login-

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 17s —— View job


Review: Renovate dependency bump

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for stale/mismatched pins and risky jumps

Findings

No bugs, security issues, or performance problems in the workflow/action changes. This is a clean SHA-pin bump.

Verified locally:

  • Every executable .github/ reference resolves to exactly one SHA per action — no split-brain pins:
    • checkoutdf4cb1c (v6.0.3), setup-go924ae3a (v6.5.0), claude-code-actionba0aafd (v1.0.168), codex-action52fe01e (v1.11), setup-helm9bc31f4 (v5.0.1), configure-aws-credentials517a711 (v6.2.2), paths-filter7b450ff (v4.0.2).
  • No stale old SHAs remain in any workflow/action YAML.
  • All version comments (# v...) match the update table in the PR body.

Minor (non-blocking)

Doc drift only: the old checkout pin de0fac2 # v6.0.2 still appears in example snippets in several README.md files (publish-helm-chart, go-licenses, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact — Renovate just doesn't rewrite doc examples. Worth a periodic sweep to keep examples current, but nothing to block this PR on.

Note on verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (gh api / git ls-remote / WebFetch to github.com are blocked in this sandbox). The SHAs were produced by Renovate's digest resolution and the version comments are consistent, so risk is low, but a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge. The bumps are patch/minor across trusted, already-pinned actions.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by the shared auto-approve workflow because this PR matched the approval criteria.

For more information, see https://github.com/loft-sh/github-actions?tab=readme-ov-file#auto-approve-bot-prs.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4eafdd1 to b2f1f27 Compare July 9, 2026 03:10
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 57s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Verified across the whole .github/ tree — every executable reference resolves to exactly one SHA per action, no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes:

  • claude-code-action moved to v1.0.169 (37b464c) since the PR body was written (body says v1.0.168) — the sync picked up a newer patch. SHA is consistent everywhere it appears (both the # v1.0.169 pin in ai-pr-review/action.yml and the # v1 float-tag comment in the claude*.yaml workflows point at the same commit). No mismatch.
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (subtree-mirror, go-licenses, govulncheck, checkov, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network is blocked in this sandbox). The SHAs come from Renovate's digest resolution and the version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from b2f1f27 to 021a49f Compare July 9, 2026 08:09
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 44s —— View job


Review: Renovate dependency bump

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action is pinned to the same SHA (37b464c) whether commented # v1.0.169 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — no mismatch. (Note: PR body says v1.0.168; the sync picked up the newer v1.0.169 patch.)
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 021a49f to 21a726e Compare July 10, 2026 01:59
@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 536f2c3 v1.0.170 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action moved again to v1.0.170 (536f2c3) since the last sync (PR body says v1.0.168, prior reviews saw v1.0.169). SHA is consistent across all 4 references — the # v1.0.170 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 21a726e to 4ef0d1c Compare July 11, 2026 03:28
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action fc46ded v3.0.4
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.171 (e90deca) (body says v1.0.170; earlier reviews saw v1.0.168/169/170). SHA is consistent across all 4 references — the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • slackapi/slack-github-action bumped v3.0.3 → v3.0.4 (fc46ded) in this sync (not listed in the PR body table). Consistent across all 4 references.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4ef0d1c to 82dc414 Compare July 11, 2026 07:43
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since prior reviews / PR body were written:

  • slackapi/slack-github-action moved further to v3.0.5 (0d95c9a) — PR body says v3.0.4, last review saw v3.0.4 (fc46ded). The sync picked up the newer patch. SHA is consistent across all 4 references.
  • claude-code-action is at v1.0.171 (e90deca), consistent across both the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 82dc414 to 5a21f93 Compare July 14, 2026 03:14
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 49s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action a08f891 v1.0.172 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.172 (a08f891) (body says v1.0.171; earlier reviews saw v1.0.168–171). SHA is consistent across all 4 references — the # v1.0.172 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • actions/setup-node also bumped to v6.5.0 (2499707) alongside setup-go — consistent, not in the PR body table.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5a21f93 to 514d3b5 Compare July 14, 2026 09:49
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action f1bd27c v1.0.173 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.173 (f1bd27c) (body says v1.0.172; earlier reviews saw v1.0.168–172). SHA is consistent across all 4 references — the # v1.0.173 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 514d3b5 to 0f2c6c6 Compare July 15, 2026 01:32
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1253134 v1.0.174 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.174 (1253134) (body says v1.0.173; earlier reviews saw v1.0.168–173). SHA is consistent across all 4 references — the # v1.0.174 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0f2c6c6 to fc67a83 Compare July 16, 2026 01:11
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1298632 v1.0.175 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.175 (1298632) (body says v1.0.174; earlier syncs saw v1.0.168–174). SHA is consistent across all references — the # v1.0.175 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from fc67a83 to a6bc804 Compare July 17, 2026 09:34
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.176 (700e7f8) (body says v1.0.175; earlier syncs saw v1.0.168–175). SHA is consistent across all references — the # v1.0.176 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a6bc804 to d0fbf65 Compare July 17, 2026 11:28
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 35s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, and every old SHA is fully replaced (verified: no stale pins remain in any workflow/action YAML):

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.176 (700e7f8) is consistent whether commented # v1.0.176 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from d0fbf65 to 8cb6560 Compare July 18, 2026 01:55
@github-actions

github-actions Bot commented Jul 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 10s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76, all uses: pin lines — no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3553f84 v1.0.177 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.177 (3553f84) (body says v1.0.176; earlier syncs saw v1.0.168–176). SHA is consistent across all references — the # v1.0.177 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, subtree-mirror, checkov, publish-helm-chart, govulncheck, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8cb6560 to 3af22e7 Compare July 19, 2026 06:05
@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 52s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all are pinned uses: references, no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action af0559e v1.0.178 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since the PR body was written:

  • claude-code-action advanced to v1.0.178 (af0559e) (body says v1.0.177; earlier syncs saw v1.0.168–177). SHA is consistent across all references — the # v1.0.178 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, vcluster-release, subtree-mirror, checkov, govulncheck, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3af22e7 to 45df450 Compare July 21, 2026 01:47
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 2s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • actions/checkout advanced to v6.1.0 (d23441a) — body says v6.0.3 (patch); the sync picked up a newer minor release. Consistent across all 48 executable references. Note this is a version-line change beyond what the PR title implies, but it's still a trusted, SHA-pinned action.
  • claude-code-action advanced to v1.0.179 (b76a077) (body says v1.0.178; earlier syncs saw v1.0.168–178). SHA is consistent across all references — the # v1.0.179 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 13s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps (cve-scan/action.yml:165,190) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to that file is the docker/login-action bump at line 120. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 5ccc3a3 v1.0.219 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d290e33 v1.73.4
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 6469e11 / 5bee69a deliberate split, see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.219 (5ccc3a3) — body table says v1.0.218. Consistent across all 4 references: the # v1.0.219 pin at ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/5ccc3a35a6367cdb8e6fbd0728287467540ecfe2/, so that SHA is a real, working commit. No other resolved pin moved.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the seven in the tree are all pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Worth a follow-up (not a blocker, not caused by this PR)

Unchanged: ci-test-notify/v1 still resolves to 5bee69a, which predates the warning-header fix at 6469e11 that cve-scan pins directly. govulncheck/action.yml:91 bumps 85d70235bee69a in this PR — correct Renovate behaviour, but it means govulncheck and every external caller on the tag still run the pre-fix notifier. Per the CLAUDE.md release discipline (a fix strands on main until the tag moves), advancing the tag fixes both and lets cve-scan return to the tag comment form:

git tag -f ci-test-notify/v1 6469e11494a5aa39a9b84c3a80729c1e0f0c752c
git push origin ci-test-notify/v1 --force

Fix this →

Minor (non-blocking)

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in README/skill snippets. Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency and reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v1 claim above rests on the in-tree comments and prior syncs.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 8s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 19dda84 v1.0.220 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d290e33 v1.73.4
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 6469e11 / 5bee69a deliberate split, see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.220 (19dda84) — body table says v1.0.219 (5ccc3a3). Consistent across all 4 references: the # v1.0.220 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/19dda84776b3518d98b8798e591daee763049ed3/, so that SHA is a real, working commit. No other resolved pin moved.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the seven in the tree are all pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Worth a follow-up (not a blocker, not caused by this PR)

Unchanged: ci-test-notify/v1 still resolves to 5bee69a, which predates the warning-header fix at 6469e11 that cve-scan pins directly. govulncheck/action.yml:91 bumps 85d70235bee69a in this PR — correct Renovate behaviour, but it means govulncheck and every external caller on the tag still run the pre-fix notifier. Per the CLAUDE.md release discipline (a fix strands on main until the tag moves), advancing the tag fixes both and lets cve-scan return to the tag comment form:

git tag -f ci-test-notify/v1 6469e11494a5aa39a9b84c3a80729c1e0f0c752c
git push origin ci-test-notify/v1 --force

Fix this →

Minor (non-blocking)

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in README/skill snippets. Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency and reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v1 claim above rests on the in-tree comments and prior syncs.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 3s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 0a8d3c9 v1.0.221 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d290e33 v1.73.4
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 6469e11 / 5bee69a deliberate split, see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.221 (0a8d3c9) — body table says v1.0.220 (19dda84). Consistent across all 4 references: the # v1.0.221 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/0a8d3c9443bbff909ab973b6a17a340b913f229f/, so that SHA is a real, working commit. No other resolved pin moved.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the ones in the tree are all pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Worth a follow-up (not a blocker, not caused by this PR)

Unchanged: ci-test-notify/v1 still resolves to 5bee69a, which predates the warning-header fix at 6469e11 that cve-scan pins directly. govulncheck/action.yml:91 carries 5bee69a, so govulncheck and every external caller on the tag still run the pre-fix notifier. Per the CLAUDE.md release discipline (a fix strands on main until the tag moves), advancing the tag fixes both and lets cve-scan return to the tag comment form:

git tag -f ci-test-notify/v1 6469e11494a5aa39a9b84c3a80729c1e0f0c752c
git push origin ci-test-notify/v1 --force

Fix this →

Minor (non-blocking)

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in README/skill snippets. Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency and reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v1 claim above rests on the in-tree comments and prior syncs.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 58s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps (cve-scan/action.yml:164,189) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to that file is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 56cf60f v1.0.222 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d290e33 v1.73.4
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.222 (56cf60f) — body table says v1.0.221 (0a8d3c9). Consistent across all 4 references: the # v1.0.222 pin at ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/56cf60fde42f7b19c3abfd5c9c48b69a1288461f/.
  • ✅ The long-standing ci-test-notify/v1 follow-up looks resolved. govulncheck/action.yml:91 bumps 85d70231bd0023, which is origin/main's current HEAD — the tag was advanced. The tree at that commit documents warning as a notifying status (ci-test-notify/action.yml:11), so callers on v1 (including govulncheck and external repos) now get the warning-header behaviour instead of the pre-fix notifier. That was the one item I'd carried across the previous dozen syncs.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the six in the tree are the pre-existing internal coordination-tag refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking)

Now that v1 carries the fix, cve-scan's two pins can go back to the # ci-test-notify/v1 tag comment form, converging both call sites onto one revision and letting Renovate manage them again — notification_pins.bats would need updating alongside. Purely a consolidation; nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in 10 README/skill snippets. Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here), nor confirm 6469e11 is an ancestor of 1bd0023 — the checkout is shallow (2 commits, no tags) and 6469e11 isn't a fetchable object, so the "tag now carries the fix" conclusion rests on the tag digest equalling main HEAD plus that tree's warning-status support, not on ancestry.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions, no regressions, and the notifier tag drift that dogged earlier syncs now looks closed.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 13s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 9cdae7f v1.0.223 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint d290e33 v1.73.4
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.223 (9cdae7f) — body table says v1.0.222 (56cf60f). Consistent across all 4 references: the # v1.0.223 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/9cdae7f0d995e3ba7c33f226087fdf82a59cd520/, so that SHA is a real, working commit. No other resolved pin moved — govulncheck/action.yml:91 still lands on 1bd0023 (the ci-test-notify/v1 tag digest, which is origin/main HEAD), carrying the warning-header behaviour that the last review confirmed.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the five in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in README/skill snippets. Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment plus that digest equalling origin/main HEAD.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 13, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 18s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 9cdae7f v1.0.223 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 8b682e1 v1.74.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • reviewdog/action-actionlint advanced to v1.74.0 (8b682e1) at .github/workflows/actionlint.yaml:38 — the body table says v1.72.0 → v1.73.4 (d290e33), so this sync picked up a newer minor. Single reference; the old SHA is fully gone. It's the linter for this repo's own CI, so the blast radius is a lint-noise change at worst.
  • claude-code-action stays at v1.0.223 (9cdae7f), the same commit whether commented # v1.0.223 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/9cdae7f0d995e3ba7c33f226087fdf82a59cd520/.
  • govulncheck/action.yml:91 lands on 1bd0023 — the ci-test-notify/v1 tag digest, carrying the warning-header behaviour confirmed in the prior sync. No other resolved pin moved.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the ones in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in README/skill snippets; zero hits in any executable YAML. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment plus that digest equalling origin/main HEAD.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 42s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action bf38e86 v1.0.225 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials cbe3b39 v6.2.4
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 8b682e1 v1.74.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.225 (bf38e86) — the body table says v1.0.223 (9cdae7f), so this sync picked up two more patches. Consistent across all 4 references: the # v1.0.225 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/bf38e86e58df9ebf3420326d019f955bb3be64dd/, so that SHA is a real, working commit. No other resolved pin moved — govulncheck/action.yml:91 still lands on 1bd0023, the ci-test-notify/v1 tag digest carrying the warning-header behaviour.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs — the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in 9 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 29s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/. No unpinned uses: ref was introduced.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action bf38e86 v1.0.225 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 8b682e1 v1.74.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review:

  • aws-actions/configure-aws-credentials advanced to v6.3.0 (e125382) at .github/actions/prerelease-setup/action.yml:71 — the body table says v6.1.3 → v6.2.4 and the prior review saw v6.2.4 (cbe3b39), so this sync picked up a newer minor. Single reference; the old SHA is fully gone. It's the step that assumes e2e-test-executor via OIDC, so it's the one bump here that touches credential handling — worth a glance at the v6.3.0 notes, though v6.2.x already carried the allowed-account-ids hardening and this call site passes role-to-assume / role-session-name / region only.
  • claude-code-action stays at v1.0.225 (bf38e86), the same commit whether commented # v1.0.225 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/bf38e86e58df9ebf3420326d019f955bb3be64dd/.
  • govulncheck/action.yml:91 still lands on 1bd0023, the ci-test-notify/v1 tag digest carrying the warning-header behaviour. No other resolved pin moved.

Stale-pin scan: all 17 replaced pins have zero hits in any .yaml/.yml repo-wide — remaining hits are README snippets only. Pre-existing non-SHA refs (local ./ paths, internal loft-sh/github-actions@<coordination-tag> refs with zizmor: ignore[unpinned-uses] justifications, and a setup-go@v5 string inside an ::error:: message) are untouched.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in 8 action READMEs (checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 34s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps (cve-scan/action.yml:164,189) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve; this sync's only edit to that file is the docker/login-action bump at line 119. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats expects.

Every action name resolves to exactly one SHA in executable YAML:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 7b0b255 v1.0.226 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 8b682e1 v1.74.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.226 (7b0b255) — the body table says v1.0.225 (bf38e86). Consistent across all 4 references: the # v1.0.226 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/7b0b255830a1fab6e602658672acad11c12d841d/, so that SHA is a real, working commit. No other resolved pin moved — govulncheck/action.yml:91 still lands on 1bd0023, the ci-test-notify/v1 tag digest carrying the warning-header behaviour.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 10 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 23s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (62 files, 109 added / 109 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 109 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays fixed. Both Slack steps (cve-scan/action.yml:164,189) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 7b0b255 v1.0.226 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.74.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no resolved pin moved. This sync is a rebase — the branch now sits directly on eb804c3 (fix(vcluster-release): cut an rc from the release branch once it exists). claude-code-action stays at v1.0.226 (7b0b255), the same commit whether commented # v1.0.226 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml:30, claude.yml:36, claude-code-review.yaml:54). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/7b0b255830a1fab6e602658672acad11c12d841d/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the remaining hits are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 10 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 23s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (63 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

Note: this sync is a rebuilt branch off the new base 3e27d7b (linear-cve-summary, #263), so the diff now shows the full original→current pin set rather than the incremental deltas prior syncs reported — hence claude-code-action v1.0.121 → v1.0.226 and action-actionlint v1.72.0 → v1.75.0 appearing as single hops. Net result is the same tree state.

The cve-scan notifier pin stays fixed. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 7b0b255 v1.0.226 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.75.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

claude-code-action at 7b0b255 is the same commit whether commented # v1.0.226 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/7b0b255830a1fab6e602658672acad11c12d841d/, so that SHA is a real, working commit.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) with their zizmor: ignore[unpinned-uses] justifications. The new linear-cve-summary action and its test workflow carry correctly-bumped pins (checkout v6.1.0, setup-uv v9.0.0) plus local ./ refs.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again (with notification_pins.bats updated to match). Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 10 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 25s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (63 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, no unpinned refs introduced, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 3b8197d v1.0.227 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.75.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.227 (3b8197d) — the body table says v1.0.226 (7b0b255). Consistent across all 4 references: the # v1.0.227 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/3b8197d3d486006dd4af54613517f21ac6ac625e/, so that SHA is a real, working commit. No other resolved pin moved.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are README/skill snippets only.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in non-executed docs (root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs). Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.2.1 → v0.3.0 (backport.yaml) is the one small third-party publisher here; SHA-pinned, and the release is just a Node 20→24 bump.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 35s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (63 files, 111 added / 111 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 111 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 121. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 3b8197d v1.0.227 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.75.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: jlumbroso/free-disk-space v1.3.1 (54081f1) → v1.3.2 (3f13fea) at .github/actions/prerelease-setup/action.yml:46. Not in the PR body table and not in prior review tables, so it surfaced with this sync. Single reference; old SHA fully gone. It's the second small third-party publisher in this set (alongside install-gh-cli-action) and it runs sudo rm -rf over runner paths, so it's the one bump here I'd eyeball before merge — bounded by the SHA pin, and the call site passes only tool-cache: false.

claude-code-action at 3b8197d is the same commit whether commented # v1.0.227 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/3b8197d3d486006dd4af54613517f21ac6ac625e/, so that SHA is a real, working commit.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in non-executed docs (root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release READMEs). Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 25s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 112 added / 112 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 112 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:11 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 3b8197d v1.0.227 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.75.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: no resolved pin moved. This sync is a rebase — the branch now sits directly on 7ef3dda (refactor(oss-mirror-staleness): read trailers through the exporter's own lib). The count ticked 63→64 files / 111→112 lines because test-oss-mirror-staleness.yaml in the rebased tree carries the bumped checkout pin.

claude-code-action at 3b8197d is the same commit whether commented # v1.0.227 (.github/actions/ai-pr-review/action.yml) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/3b8197d3d486006dd4af54613517f21ac6ac625e/, so that SHA is a real, working commit.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 27 remaining occurrences are all in non-executed .md docs. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: the replaced SHAs (mostly de0fac2 # v6.0.2 for checkout) still appear in 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. The rebase added oss-mirror-staleness/README.md to that list (authored against the old pin). Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.3.0 and jlumbroso/free-disk-space v1.3.2 are the two small third-party publishers here; both SHA-pinned, so blast radius is bounded to the pin.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 32s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 112 added / 112 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 112 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

Note: the branch was rebuilt off a new base (5997911, e2e comment-check target selection, #269), so the diff again shows the full original→current pin set rather than incremental deltas — hence checkout v6.0.2 → v6.1.0 and claude-code-action v1.0.121 → v1.0.228 appearing as single hops. Net tree state is the same.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 2261fcf v1.0.228 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint ab71380 v1.75.0
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Delta since the last review: claude-code-action advanced to v1.0.228 (2261fcf) — the body table says v1.0.227 (3b8197d). Consistent across all 4 references: the # v1.0.228 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/2261fcfc88e7de1b55f179edd588805e12de71f2/, so that SHA is a real, working commit. No other resolved pin moved.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 11 remaining files are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.3.0 and jlumbroso/free-disk-space v1.3.2 are the two small third-party publishers here; both SHA-pinned, and the free-disk-space one runs sudo rm -rf over runner paths, so it's the one worth an eyeball if you care.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 26s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 112 added / 112 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 112 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps (cve-scan/action.yml:167,192) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to that file is the docker/login-action bump at line 121. Reproduced the bats assertion: the exact string notification_pins.bats greps for occurs 2 times, which is what it expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a4f54ef v1.0.229 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 0f79693 v1.75.2
slackapi/slack-github-action 0d95c9a v3.0.5
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.229 (a4f54ef) — body table says v1.0.228. Consistent across all 4 references: the # v1.0.229 pin in .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/a4f54ef2c58884867281bd8e2f8d63352ad019a9/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.75.2 (0f79693) — body table and prior review say v1.75.0 (ab71380). Single reference (actionlint.yaml); old SHA fully gone. It's this repo's own lint step, so blast radius is lint noise at worst.
  • Rebase onto main picked up 5997911 (e2e: target selection for comment checks, feat(e2e): add target selection to comment checks #269); file count 63 → 64.

Stale-pin scan: all 14 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 27 remaining occurrences are all in non-executed .md docs. Unpinned-ref scan: no new non-SHA uses: refs; the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 27 spots across 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.3.0 and jlumbroso/free-disk-space v1.3.2 are the two small third-party publishers here; both SHA-pinned.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -c (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 44s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 121. Reproduced the bats assertion: grep -c returns 2, which is what notification_pins.bats expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a4f54ef v1.0.229 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 0f79693 v1.75.2
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
dev-hanz-ops/install-gh-cli-action 6089bdd v0.3.0
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.229 (a4f54ef) — the body table says v1.0.227 (3b8197d), so this sync picked up two more patches. Consistent across all 4 references: the # v1.0.229 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/a4f54ef2c58884867281bd8e2f8d63352ad019a9/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.75.2 (0f79693) at .github/workflows/actionlint.yaml — prior review saw v1.75.0 (ab71380). Single reference; old SHA fully gone. It lints this repo's own CI, so worst case is lint noise.
  • No other resolved pin moved. The branch also rebased onto the new base 7d4ab86 (backport-legacy-split open-pr filter fix).

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 11 remaining files are all non-executed .md docs. Unpinned-ref scan: no new non-SHA uses: refs; the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.
  • dev-hanz-ops/install-gh-cli-action v0.3.0 and jlumbroso/free-disk-space v1.3.2 are the two small third-party publishers in this set; both SHA-pinned, and neither moved in this sync.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -c (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

This sync is a rebuilt branch off the new base ea06a67, so the diff shows the full original→current pin set again rather than incremental deltas — hence claude-code-action v1.0.121 → v1.0.229, codex-action v1.8 → v1.12, action-actionlint v1.72.0 → v1.75.3, paths-filter v4.0.1 → v4.0.3 appearing as single hops. Net tree state is the same progression prior syncs verified.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 121. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action a4f54ef v1.0.229 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 669cae8 v1.75.3
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas worth naming:

  • claude-code-action at v1.0.229 (a4f54ef) is the same commit whether commented # v1.0.229 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml, claude.yml, claude-code-review.yaml). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/a4f54ef2c58884867281bd8e2f8d63352ad019a9/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.75.3 (669cae8) at actionlint.yaml:38 — the body table says v1.75.2. Single reference; it's the linter for this repo's own CI, so worst case is lint noise.
  • dev-hanz-ops/install-gh-cli-action is gone from the pin set — main's backport.yaml no longer references it, so the small-third-party-publisher caveat I carried across earlier syncs no longer applies. Not a change this PR makes.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are README/skill snippets only. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message at aws-test-infra/action.yml:246 (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 33s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The branch was rebuilt off the current base, so the diff again shows the full original→current pin set rather than incremental deltas. 13 actions move:

Action before after
actions/checkout de0fac2 v6.0.2 d23441a v6.1.0
actions/setup-go 4a36011 v6.4.0 924ae3a v6.5.0
anthropics/claude-code-action f4fb5c6 v1.0.121 4036a18 v1.0.230
openai/codex-action e0fdf01 v1.8 8636508 v1.12
azure/setup-helm dda3372 v5.0.0 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 99214aa v6.1.3 e125382 v6.3.0
docker/login-action af1e73f v4.4.0 dbcb813 v4.6.0
dorny/paths-filter fbd0ab8 v4.0.1 ceb8a2b v4.0.3
reviewdog/action-actionlint 6fb7acc v1.72.0 320fcdd v1.76.0
slackapi/slack-github-action 45a88b9 v3.0.3 0d95c9a v3.0.5
jlumbroso/free-disk-space 54081f1 v1.3.1 3f13fea v1.3.2
ci-test-notify (internal) 85d7023 1bd0023 ci-test-notify/v1
validate-renovate.yaml (internal) 53686d2 c40c1db validate-renovate/v1

Enumerated every pinned ref repo-wide: each action name resolves to exactly one SHA in executable YAML, no split-brain pins. claude-code-action at 4036a18 is the same commit whether commented # v1.0.230 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml:30, claude.yml:36, claude-code-review.yaml:54). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/4036a180cf690f49529f5d8c79c998855287f590/, so that SHA is a real, working commit.

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 121. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — the 27 remaining occurrences are all in non-executed .md docs. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Versions run a bit ahead of the PR body table — claude-code-action v1.0.230 (body: v1.0.229) and action-actionlint v1.76.0 (body: v1.75.3). Both trusted, SHA-pinned.

Two carried-forward notes now closed

  • dev-hanz-ops/install-gh-cli-action is gone. main removed it from backport.yaml entirely, so the small-third-party-publisher caveat I'd flagged across the last several syncs no longer applies. (jlumbroso/free-disk-space remains the one such publisher; unchanged since the sync that bumped it to v1.3.2.)
  • ci-test-notify/v1 carries the fix. govulncheck/action.yml:91 bumps 85d70231bd0023, the advanced tag digest — so govulncheck and external callers on the tag now get the warning-header behaviour rather than the pre-fix notifier.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify is still deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck is on the v1 tag at 1bd0023. Now that the tag carries the fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 27 spots across 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 19, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 43s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: 110/110 added lines match uses: …@<40-hex> # <comment> — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps (cve-scan/action.yml:167,192) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:11 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action cfc3eb2 v1.0.231 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 320fcdd v1.76.0
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.231 (cfc3eb2) — the body table says v1.0.230. Consistent across all 4 references: the # v1.0.231 pin at .github/actions/ai-pr-review/action.yml and the # v1 float-tag comments in claude.yaml, claude.yml, claude-code-review.yaml all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/cfc3eb22bfed5c26ef66e3223c982af27e4524de/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.76.0 (320fcdd) at actionlint.yaml — prior review saw v1.75.0 (ab71380). Single reference; old SHA fully gone. Lints this repo's own CI, so worst case is lint-noise.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide — remaining hits are .md docs only. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs with their zizmor: ignore[unpinned-uses] justifications, plus a setup-go@v5 string inside an ::error:: message (not a real ref).

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 is on the v1 tag at 1bd0023. Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in 11 non-executed docs — root README.md, .claude/skills/github-actions-dev/SKILL.md, and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 36s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, and the diff touches nothing outside .github/ (0 of 64 files).

The cve-scan notifier pin stays protected. Both Slack steps keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone — this sync's only edit to cve-scan/action.yml is the docker/login-action bump at line 121. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action cfc3eb2 v1.0.231 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 5be522b v1.76.1
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.231 (cfc3eb2) — matches the PR body table for once. Consistent across all 4 references: the # v1.0.231 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/cfc3eb22bfed5c26ef66e3223c982af27e4524de/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.76.1 (5be522b) at actionlint.yaml:38 — the body table says v1.76.0, so this sync picked up a newer patch. Single reference; old SHA fully gone. (Unrelated and untouched: rhysd/actionlint@914e7df # v1.7.12, the linter binary itself.)
  • dev-hanz-ops/install-gh-cli-action is gone from the tree. The small-third-party bump I'd flagged in every review since v0.2.1 → v0.3.0 no longer has a call site — backport.yaml dropped it on main. Nothing to eyeball there anymore.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs; the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 bumps 85d70231bd0023 (the v1 tag digest). Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in non-executed docs (root README.md, .claude/skills/github-actions-dev/SKILL.md, and several action READMEs). Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment. This PR changes no action.yml inputs/outputs, so make check-docs drift isn't expected.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

The cve-scan notifier pin stays protected. Both Slack steps (cve-scan/action.yml:167,192) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:9 expects.

Enumerated every pinned ref in executable YAML — each action name resolves to exactly one SHA, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action cfc3eb2 v1.0.231 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 23bcc6a v1.76.3
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Deltas since the last review:

  • claude-code-action advanced to v1.0.231 (cfc3eb2) — the body table's digest row matches. Consistent across all 4 references: the # v1.0.231 pin at .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments at claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/cfc3eb22bfed5c26ef66e3223c982af27e4524de/, so that SHA is a real, working commit.
  • reviewdog/action-actionlint advanced to v1.76.3 (23bcc6a) at actionlint.yaml:38 — the body table says v1.76.1, so this sync picked up two more patches. Single reference; old SHA gone. It's the linter for this repo's own CI, so lint noise is the worst case.
  • dev-hanz-ops/install-gh-cli-action is gone from the treemain dropped it, so the third-party-publisher caveat I carried across many prior syncs no longer applies. jlumbroso/free-disk-space v1.3.2 (prerelease-setup/action.yml) is now the only small third-party publisher in this set; it runs sudo rm -rf over runner paths, SHA-pinned, call site passes only tool-cache: false.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide. Unpinned-ref scan: no new non-SHA uses: refs; the ones in the tree are pre-existing local ./ paths and internal loft-sh/github-actions@<coordination-tag> refs carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 is on the v1 tag at 1bd0023. Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) still appears in 27 spots across 11 non-executed docs — root README.md (10×), .claude/skills/github-actions-dev/SKILL.md (3×), and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Zero hits in any executable YAML; Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 22s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Verify SHA-pin consistency across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues, or performance problems. Verified mechanically: of the 110 added lines, 0 are anything other than a uses: …@<40-hex> # <comment> pin — zero shell/logic edits, nothing outside .github/.

This sync is a rebuilt branch off the new base 6c61d99 (vcluster-release diagnosability, #270), so the diff again shows the full original→current pin set rather than incremental deltas (hence checkout v6.0.2 → v6.1.0, claude-code-action v1.0.121 → v1.0.231 as single hops).

The cve-scan notifier pin stays protected. Both Slack steps (cve-scan/action.yml:167,192) keep the non-tag comment form @6469e11… # ci-test-notify warning-header fix, so Renovate has no tag to resolve and left them alone. Reproduced the bats assertion: grep -Fc returns 2, which is what notification_pins.bats:12 expects.

Enumerated every pinned ref repo-wide — each action name resolves to exactly one SHA in executable YAML, no split-brain pins (the ci-test-notify pair being the one deliberate exception):

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action cfc3eb2 v1.0.231 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 2085657 v1.77.0
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal) 1bd0023 / 6469e11 see below
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Notes on this sync:

  • claude-code-action at cfc3eb2 is the same commit whether commented # v1.0.231 (.github/actions/ai-pr-review/action.yml:98) or # v1 (claude.yaml:30, claude.yml:36, claude-code-review.yaml:54). Incidental confirmation: this job is executing from _actions/anthropics/claude-code-action/cfc3eb22bfed5c26ef66e3223c982af27e4524de/, so that SHA is a real, working commit. The body table and the pins agree on v1.0.231 this time.
  • reviewdog/action-actionlint lands on v1.77.0, one minor above the v1.76.3 the body table lists. Single reference (actionlint.yaml); it's the linter for this repo's own CI, so worst case is lint-noise.
  • dev-hanz-ops/install-gh-cli-action is gone. The small third-party publisher I'd flagged in every prior sync no longer appears anywhere in the tree — backport.yaml on the new base uses sorenlouv/backport-github-action instead. That carried-forward caveat is closed.

Stale-pin scan: all 13 replaced SHAs have zero hits in any .yaml/.yml repo-wide; the 27 remaining occurrences are all in non-executed .md docs. Unpinned-ref scan: no new non-SHA uses: refs — the seven in the tree are the pre-existing internal loft-sh/github-actions@<coordination-tag> refs (backport.yaml, backport-link-sweep.yaml, notify-release.yaml) carrying their zizmor: ignore[unpinned-uses] justifications.

Tidy-up (non-blocking, not caused by this PR)

ci-test-notify remains deliberately split: cve-scan pins 6469e11 directly with a non-tag comment, govulncheck/action.yml:91 is on the v1 tag at 1bd0023. Now that the tag carries the warning-header fix, the two cve-scan pins could return to the # ci-test-notify/v1 comment form so Renovate manages them again, with notification_pins.bats updated to match. Purely consolidation — nothing breaks as-is.

Fix this →

Minor

  • Doc drift: de0fac2 # v6.0.2 (checkout) and other replaced SHAs still appear in 27 spots across 11 non-executed docs — root README.md (10×), .claude/skills/github-actions-dev/SKILL.md (3×), and the checkov, commitlint, cve-scan, go-licenses, govulncheck, oss-mirror-staleness, publish-helm-chart, subtree-mirror, vcluster-release READMEs. Renovate doesn't rewrite doc examples.
  • The body's actions/setup-node v6.4.0 → v6.5.0 row is a no-op — no executable setup-node reference remains in this repo.

Verification scope

Confirmed internal consistency; reproduced the bats pin assertion with grep -Fc (count=2, matches). Could not run bats itself (not installed here) or confirm tag→SHA mappings against GitHub — shallow checkout with no tags, so the ci-test-notify/v11bd0023 claim rests on the in-tree comment.

Recommendation: safe to merge. Patch/minor bumps across SHA-pinned actions; no regressions in this sync, and the one third-party-publisher caveat from earlier syncs is now gone from the tree.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 34s —— View job


Review: Renovate dependency bump (re-review after sync)

No bugs, security issues or performance problems. All 110 added lines are SHA-pinned uses: refs (@<40-hex> # <version>). There are no shell or logic edits, and nothing outside .github/ changed.

  • One SHA per action. Every action resolves to a single SHA across the tree. Current pins: checkout d23441a (v6.1.0), setup-go 924ae3a (v6.5.0), claude-code-action 46a42b4 (v1.0.232 / # v1), codex-action 8636508 (v1.12), setup-helm 9bc31f4 (v5.0.1), configure-aws-credentials e125382 (v6.3.0), docker/login-action dbcb813 (v4.6.0), paths-filter ceb8a2b (v4.0.3), free-disk-space 3f13fea (v1.3.2), action-actionlint 2085657 (v1.77.0), slack-github-action 0d95c9a (v3.0.5).
  • What changed since the last review: claude-code-action moved to v1.0.232 and action-actionlint moved to v1.77.0. Both match the PR body table.
  • Old SHAs are gone. None of the 13 replaced SHAs appears in any .yml or .yaml file.
  • The cve-scan notifier pin is still protected. It stays on 6469e11… # ci-test-notify warning-header fix, so Renovate leaves it alone, and notification_pins.bats still finds the expected 2 matches.
  • govulncheck's notifier moves to the current tag. It goes from 85d7023 to 1bd0023, which is what the ci-test-notify/v1 tag points to now.

Worth a quick look before merging (not blocking): jlumbroso/free-disk-space v1.3.2 (prerelease-setup/action.yml) comes from a small third-party publisher and runs sudo rm -rf on runner paths. The SHA pin limits the exposure, but it's the one upgrade here I'd skim first.

Not checked: I didn't run bats, and I couldn't confirm tag→SHA mappings against GitHub. The checkout is shallow and has no tags.

Recommendation: safe to merge.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 38s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read diff vs origin/main
  • Check SHA-pin consistency across .github/
  • Re-check the cve-scan notifier pin

Findings

I found no bugs, security issues or performance problems in this sync. Every changed line is a uses: …@<40-hex> # <version> pin. No shell or logic lines change, and no unpinned refs are added.

Each external action resolves to one SHA across the tree:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 8cf3482 v1.0.233 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
jlumbroso/free-disk-space 3f13fea v1.3.2
reviewdog/action-actionlint 2085657 v1.77.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal, govulncheck) 1bd0023 ci-test-notify/v1
validate-renovate.yaml (internal) c40c1db validate-renovate/v1
  • What changed since the last review:
    • claude-code-action moved to v1.0.233 (8cf3482). All four references point at that commit. This review job is itself running from claude-code-action/8cf3482….
    • action-actionlint moved to v1.77.0 (2085657). It only lints this repo's own CI.
  • cve-scan notifier pin: Renovate left the pin at .github/actions/cve-scan/action.yml:167,192 unchanged at 6469e11 with its non-tag comment, so the old pin-revert loop is still gone. notification_pins.bats should stay green.

Tidy-up (not blocking, not caused by this PR)

ci-test-notify is still on two SHAs:

  • cve-scan pins 6469e11 directly.
  • govulncheck uses the v1 tag, which points at 1bd0023.

If 6469e11 is an ancestor of 1bd0023, switch the two cve-scan pins back to # ci-test-notify/v1 so Renovate manages them, and update notification_pins.bats to match.

Verification scope

I checked that the pins are consistent inside the repo. I could not confirm tag→SHA mappings against GitHub because the checkout is shallow and has no tags. I did not run bats.

Recommendation: safe to merge.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 24, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 48s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff against origin/main (64 files, 110 added / 110 removed)
  • Check SHA-pin consistency across .github/
  • Re-check the cve-scan notifier pin

No bugs, security issues, or performance problems found. All 110 added lines are uses: …@<40-hex> # <version> pins. No shell or logic lines change.

Each action resolves to one SHA across the tree, with no split pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 8cf3482 v1.0.233 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
jlumbroso/free-disk-space 3f13fea v1.3.2
reviewdog/action-actionlint 2085657 v1.77.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify (internal) 1bd0023 ci-test-notify/v1 (govulncheck)
validate-renovate.yaml (internal) c40c1db validate-renovate/v1

Changes since the last review:

  • claude-code-action is now at v1.0.233 (8cf3482). All 4 references point at the same commit, and this review job is itself running from that SHA.
  • action-actionlint is now at v1.77.0. It only lints this repo's own CI, so the worst case is new lint findings.

cve-scan notifier pin: Both notification steps (cve-scan/action.yml:167,192) still pin 6469e11 with a comment that isn't a tag name, so Renovate leaves them alone. The pin test in notification_pins.bats should still pass. govulncheck uses the v1 tag at 1bd0023. This split is deliberate and doesn't break anything.

Not checked: I didn't run bats, and I couldn't check tag→SHA mappings against GitHub because the checkout is shallow.

Recommendation: safe to merge.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 24, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (64 files, 110 added / 110 removed)
  • Check the SHA pins are consistent across .github/
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues or performance problems found. Every added line is a uses: …@<40-hex> # <version> pin. There are no shell or logic edits, and no unpinned refs were added. Each action points at exactly one SHA everywhere it's used.

Action New SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 8cf3482 v1.0.233 / # v1
openai/codex-action 8636508 v1.12
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e125382 v6.3.0
docker/login-action dbcb813 v4.6.0
dorny/paths-filter ceb8a2b v4.0.3
reviewdog/action-actionlint 2085657 v1.77.0
slackapi/slack-github-action 0d95c9a v3.0.5
jlumbroso/free-disk-space 3f13fea v1.3.2
ci-test-notify (internal, govulncheck) d462e84 ci-test-notify/v1
validate-renovate.yaml (internal) de873f4 validate-renovate/v1

What changed since the last review:

  • claude-code-action moved up to v1.0.233 (8cf3482). All 4 references agree: the # v1.0.233 pin in ai-pr-review/action.yml and the three # v1 comments in the claude*.yaml workflows. This review job is itself running from claude-code-action/8cf3482…, so that commit exists and works.
  • action-actionlint moved up to v1.77.0. It only lints this repo's own CI.
  • The ci-test-notify/v1 digest moved to d462e84, and the validate-renovate/v1 digest moved to de873f4. That's normal Renovate tag resolution.
  • The earlier dev-hanz-ops/install-gh-cli-action bump is no longer in the diff.

cve-scan notifier pin: Renovate didn't touch it. Both Slack steps (cve-scan/action.yml:167,192) still pin 6469e11 # ci-test-notify warning-header fix, which is exactly what notification_pins.bats expects. The only change to that file in this PR is the docker/login-action bump.

Verification scope

I checked the pins against each other and against the bats pin assertion by reading the files. I did not run bats, and I could not check tag→SHA mappings against GitHub because this is a shallow checkout with no tags.

Recommendation: safe to merge.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 24, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read the full diff against origin/main (64 files, 110 added / 110 removed)
  • Check that SHA pins are consistent across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues or performance problems. Every added line (110 of 110) is a uses: …@<40-hex> # <comment> pin. There are no shell or logic edits and no unpinned refs.

Each action resolves to exactly one SHA in executable YAML, so no action is pinned to two different commits. This sync moved these pins since the last review:

Action SHA Version
anthropics/claude-code-action 8cf3482 v1.0.233 (4 refs, the # v1.0.233 pin and the three # v1 comments all point at the same commit)
reviewdog/action-actionlint 2085657 v1.77.0
ci-test-notify (internal, govulncheck/action.yml:91) d462e84 ci-test-notify/v1
validate-renovate.yaml (internal) de873f4 validate-renovate/v1

The other pins are unchanged from the last review: checkout v6.1.0, setup-go v6.5.0, codex v1.12, configure-aws-credentials v6.3.0, docker/login v4.6.0, paths-filter v4.0.3, slack v3.0.5, free-disk-space v1.3.2 and setup-helm v5.0.1.

The cve-scan notifier pin is still safe. Renovate did not touch cve-scan/action.yml:167,192: both lines still pin 6469e11 with the non-tag comment # ci-test-notify warning-header fix. That is exactly what notification_pins.bats asserts, so test-cve-scan should stay green.

Non-blocking

  • ci-test-notify is split across two commits. The v1 tag has moved to d462e84, so govulncheck and cve-scan (still on 6469e11) run different notifier commits. If d462e84 contains the warning-header fix, the two cve-scan pins could go back to the # ci-test-notify/v1 comment form (with the bats test updated to match), which lets Renovate manage all three call sites together.
  • The PR body is out of date. It lists setup-node, but there is no executable setup-node reference left in this repo.

What I could not check

I checked that the pins are consistent with each other inside the repo. I could not check that each tag really points at its SHA on GitHub: the checkout is shallow and has no tags. I did not run bats.

Recommendation: safe to merge.
• branch renovate/github-actions

@github-actions

github-actions Bot commented Sep 24, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 40s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff vs origin/main (13 files, 17 added / 17 removed)
  • Check that each action uses one SHA across the .github/ tree
  • Re-check the cve-scan notifier pin

Findings

No bugs, security issues or performance problems found. The PR is much smaller now: main (#170) already took the checkout, setup-go, slack-github-action and free-disk-space bumps. The 17 lines left are all uses: …@<40-hex> # <version> pin changes. There are no shell or logic edits.

  • Each action uses exactly one SHA in executable YAML: claude-code-action 8cf3482 (4 refs, commented # v1.0.233 / # v1), codex-action 8636508 v1.12, docker/login-action dbcb813 v4.6.0 (3), setup-helm 9bc31f4 v5.0.1 (2), configure-aws-credentials e125382 v6.3.0, paths-filter ceb8a2b v4.0.3 (3), action-actionlint 2085657 v1.77.0, validate-renovate.yaml de873f4. The one exception is ci-test-notify, which is split on purpose (see below).
  • No old pins remain: none of the 9 replaced SHAs appears in any .yml/.yaml file.
  • The cve-scan notifier pin is untouched. cve-scan/action.yml:167,192 still pin 6469e11 # ci-test-notify warning-header fix, which is what notification_pins.bats expects. The only edit to that file is the docker/login-action bump.
  • govulncheck/action.yml:91 moves 85d7023d462e84 (# ci-test-notify/v1). This is Renovate following the coordination tag, as expected.

Worth a glance (not blocking)

  • configure-aws-credentials goes from v6.1.3 to v6.3.0 (prerelease-setup, OIDC role assumption). It is the only bump here that touches credential handling. v6.2.1 added allowed-account-ids enforcement on all auth paths. Our call site doesn't set that input, so it shouldn't change behaviour.
  • ci-test-notify still runs two revisions: 6469e11 directly in cve-scan and the v1 tag in govulncheck. If v1 now contains the warning-header fix, cve-scan could switch back to the tag-comment form, with notification_pins.bats updated to match. This is only tidying and has nothing to do with this PR.

What I couldn't check

I checked that the repo is internally consistent. I did not check that each tag maps to the right SHA on GitHub (shallow checkout, no tags) and I did not run bats.

Recommendation: safe to merge.
• branch renovate/github-actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant