Skip to content

ci: bump the dependencies group with 3 updates - #16

Merged
kazeburo merged 1 commit into
mainfrom
dependabot/github_actions/dependencies-3ef8563b11
Sep 7, 2026
Merged

kazeburo merged 1 commit into
mainfrom
dependabot/github_actions/dependencies-3ef8563b11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 3 updates: the-pr-agent/pr-agent, Songmu/tagpr and wadackel/files-sync-action.

Updates the-pr-agent/pr-agent from 0.43.0 to 0.44.0

Release notes

Sourced from the-pr-agent/pr-agent's releases.

v0.44.0

⚠️ Important Changes

  • GitHub App webhooks now require a configured secret (#2595): get_body() no longer accepts unsigned webhooks — a deployment without GITHUB.WEBHOOK_SECRET set is rejected with HTTP 403 instead of trusting every caller. Set the secret on your GitHub App and in your config before upgrading. The same PR escapes attacker-controlled webhook fields that were interpolated into CLI command strings.
  • Dependency management migrated to uv (#2509): requirements.txt, requirements-dev.txt, and the legacy setup.py are gone — dependencies now live in pyproject.toml with a committed uv.lock. Set up a dev environment with uv sync and run tools via uv run. Optional features are now extras (lambda, langchain — uv sync --extra <name>) or a dependency group (similar-issue — uv sync --group similar-issue), and Docker images install from the lockfile with uv sync --frozen. Installing from PyPI with pip install pr-agent still works.
  • Linting consolidated on Ruff (#2880): flake8 and the standalone isort pre-commit hook were removed. Contributors should run uv run ruff check --fix on touched files before committing.
  • Dependency pins relaxed to patched ranges (#2881): exact pins were loosened so downstream consumers can pick up security updates; LiteLLM was also upgraded to v1.98.0 (#2794).

🚀 Features

🐛 Bug Fixes

... (truncated)

Commits
  • ab6ec54 fix(pr_agent/servers/gerrit_server.py): requiring credentials on the webhook ...
  • f876eed ci: smoke-start github_app container so a broken launcher fails CI (#2825)
  • 3edc06f feat(models): add OpenRouter router model support (#2893)
  • 6b7fbf9 chore(deps): Upgrade vulnerable transitive dependencies (#2891)
  • a16c993 docs: avoid duplicating the pre-commit hook list (#2892)
  • 872dacf fix: harden webhook auth and CLI argument injection vectors (#2595)
  • f879d4f fix: preserve YAML keys and values during fallback parsing (#2877)
  • ceae34b fix: surface the triggering workflow's conclusion in workflow_run reviews (#2...
  • 240e0e1 fix(improve): avoid false failure after inline publish (#2886)
  • c03f7b4 chore: unify ruff version in pre-commit and deps (#2889)
  • Additional commits viewable in compare view

Updates Songmu/tagpr from 1.20.1 to 1.20.2

Release notes

Sourced from Songmu/tagpr's releases.

v1.20.2

What's Changed

New Contributors

Full Changelog: Songmu/tagpr@v1.20.1...v1.20.2

Changelog

Sourced from Songmu/tagpr's changelog.

Changelog

v1.20.3 - 2026-09-03

v1.20.2 - 2026-08-25

v1.20.1 - 2026-07-14

v1.20.0 - 2026-06-01

v1.19.0 - 2026-05-09

... (truncated)

Commits
  • 242e229 Merge pull request #371 from Songmu/tagpr-from-v1.20.1
  • 21bbe12 [tagpr] update CHANGELOG.md
  • e48fe45 [tagpr] prepare for the next release
  • f39c0e0 Merge pull request #399 from Songmu/renovate/migrate-config
  • 20bca8e Migrate config .github/renovate.json5
  • 3474f5a Merge pull request #398 from Songmu/dependabot/github_actions/reviewdog/actio...
  • 195e77e Merge pull request #254 from 12ya/patch6
  • dc16ce3 build(deps): bump reviewdog/action-staticcheck from 1.30.0 to 1.31.0
  • fd3e13b Merge pull request #394 from Songmu/copilot/go-major-update-automation
  • 1ccebf1 Fix Renovate Go update allowlist
  • Additional commits viewable in compare view

Updates wadackel/files-sync-action from 3.6.0 to 4.0.2

Release notes

Sourced from wadackel/files-sync-action's releases.

v4.0.2

4.0.2 (2026-08-29)

Bug Fixes

  • declare the ejs module shape that v6 actually ships (e710446)
  • upgrade deepmerge-ts to v8 to resolve CVE-2026-40345 (b2f63ec)
  • upgrade ejs to v6 to drop the vulnerable jake dependency chain (243d184)

v4.0.1

4.0.1 (2026-08-29)

Bug Fixes

  • refresh runtime dependencies to resolve known CVEs (1e2d7a6)

v4.0.0

4.0.0 (2026-08-29)

Features

  • run the action on the Node 24 runtime (df98e34)

BREAKING CHANGES

  • the action now requires runner v2.327.1 or newer. GitHub-hosted runners already meet this; self-hosted runners and GitHub Enterprise Server installations on an older runner must be updated before upgrading.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com Claude-Session: https://claude.ai/code/session_01ApLCPbDKhWDDDSyzbvfFzB

v3.6.2

3.6.2 (2026-08-29)

Bug Fixes

  • allow committing only generated dist files (8ccd5c2)

v3.6.1

3.6.1 (2026-08-29)

Bug Fixes

... (truncated)

Commits
  • 80fcb2d Merge pull request #286 from wadackel/chore/enable-lockfile-maintenance
  • a1a4c42 Merge pull request #285 from wadackel/fix/upgrade-ejs-and-deepmerge-ts
  • e710446 fix: declare the ejs module shape that v6 actually ships
  • e32fe02 chore: enable Renovate lock file maintenance
  • d5e90e8 chore: rebuild dist with refreshed dependencies
  • 243d184 fix: upgrade ejs to v6 to drop the vulnerable jake dependency chain
  • b2f63ec fix: upgrade deepmerge-ts to v8 to resolve CVE-2026-40345
  • bf84e6c Merge pull request #283 from wadackel/fix/refresh-runtime-dependencies
  • da4ccf3 chore: rebuild dist with refreshed dependencies
  • 1e2d7a6 fix: refresh runtime dependencies to resolve known CVEs
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 3 updates: [the-pr-agent/pr-agent](https://github.com/the-pr-agent/pr-agent), [Songmu/tagpr](https://github.com/songmu/tagpr) and [wadackel/files-sync-action](https://github.com/wadackel/files-sync-action).


Updates `the-pr-agent/pr-agent` from 0.43.0 to 0.44.0
- [Release notes](https://github.com/the-pr-agent/pr-agent/releases)
- [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md)
- [Commits](The-PR-Agent/pr-agent@4ebd5c5...ab6ec54)

Updates `Songmu/tagpr` from 1.20.1 to 1.20.2
- [Release notes](https://github.com/songmu/tagpr/releases)
- [Changelog](https://github.com/Songmu/tagpr/blob/main/CHANGELOG.md)
- [Commits](Songmu/tagpr@d1b8138...242e229)

Updates `wadackel/files-sync-action` from 3.6.0 to 4.0.2
- [Release notes](https://github.com/wadackel/files-sync-action/releases)
- [Commits](wadackel/files-sync-action@2c7a879...80fcb2d)

---
updated-dependencies:
- dependency-name: the-pr-agent/pr-agent
  dependency-version: 0.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: Songmu/tagpr
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: wadackel/files-sync-action
  dependency-version: 4.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026
@kazeburo
kazeburo merged commit fb35e41 into main Sep 7, 2026
1 check passed
@kazeburo
kazeburo deleted the dependabot/github_actions/dependencies-3ef8563b11 branch September 7, 2026 13:50
@github-actions github-actions Bot mentioned this pull request Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant