Skip to content

Update patch dependencies#886

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/all-patch
Jan 26, 2026
Merged

Update patch dependencies#886
renovate[bot] merged 1 commit intomainfrom
renovate/all-patch

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jan 16, 2026

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v6.0.1v6.0.2
astral-sh/ruff-pre-commit repository patch v0.14.11v0.14.14
github/codeql-action action patch v4.31.10v4.31.11
step-security/harden-runner action patch v2.14.0v2.14.1

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

actions/checkout (actions/checkout)

v6.0.2

Compare Source

astral-sh/ruff-pre-commit (astral-sh/ruff-pre-commit)

v0.14.14

Compare Source

See: https://github.com/astral-sh/ruff/releases/tag/0.14.14

v0.14.13

Compare Source

See: https://github.com/astral-sh/ruff/releases/tag/0.14.13

v0.14.12

Compare Source

See: https://github.com/astral-sh/ruff/releases/tag/0.14.12

github/codeql-action (github/codeql-action)

v4.31.11

Compare Source

  • When running a Default Setup workflow with Actions debugging enabled, the CodeQL Action will now use more unique names when uploading logs from the Dependabot authentication proxy as workflow artifacts. This ensures that the artifact names do not clash between multiple jobs in a build matrix. #​3409
  • Improved error handling throughout the CodeQL Action. #​3415
  • Added experimental support for automatically excluding generated files from the analysis. This feature is not currently enabled for any analysis. In the future, it may be enabled by default for some GitHub-managed analyses. #​3318
  • The changelog extracts that are included with releases of the CodeQL Action are now shorter to avoid duplicated information from appearing in Dependabot PRs. #​3403
step-security/harden-runner (step-security/harden-runner)

v2.14.1

Compare Source

What's Changed
  1. In some self-hosted environments, the agent could briefly fall back to public DNS resolvers during startup if the system DNS was not yet available. This behavior was unintended for GitHub-hosted runners and has now been fixed to prevent any use of public DNS resolvers.

  2. Fixed npm audit vulnerabilities

Full Changelog: step-security/harden-runner@v2.14.0...v2.14.1


Configuration

📅 Schedule: Branch creation - "after 5pm every weekday,before 8am every weekday,every weekend" in timezone America/Chicago, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate labels Jan 16, 2026
@renovate renovate Bot force-pushed the renovate/all-patch branch from 366e008 to f1b5e51 Compare January 22, 2026 20:39
@renovate renovate Bot changed the title Update pre-commit hook astral-sh/ruff-pre-commit to v0.14.13 Update patch dependencies Jan 22, 2026
@renovate renovate Bot force-pushed the renovate/all-patch branch 2 times, most recently from 498d366 to 841b0d4 Compare January 23, 2026 16:49
@renovate renovate Bot force-pushed the renovate/all-patch branch from 841b0d4 to dfcaaca Compare January 26, 2026 06:36
@renovate renovate Bot merged commit 2a1af75 into main Jan 26, 2026
13 checks passed
@renovate renovate Bot deleted the renovate/all-patch branch January 26, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant