Repository navigation
ci: bump the dependencies group with 3 updates - #16
Merged
Merged
Conversation
Bumps the dependencies group with 3 updates: [the-pr-agent/pr-agent](https://github.com/the-pr-agent/pr-agent), [Songmu/tagpr](https://github.com/songmu/tagpr) and [wadackel/files-sync-action](https://github.com/wadackel/files-sync-action). Updates `the-pr-agent/pr-agent` from 0.43.0 to 0.44.0 - [Release notes](https://github.com/the-pr-agent/pr-agent/releases) - [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md) - [Commits](The-PR-Agent/pr-agent@4ebd5c5...ab6ec54) Updates `Songmu/tagpr` from 1.20.1 to 1.20.2 - [Release notes](https://github.com/songmu/tagpr/releases) - [Changelog](https://github.com/Songmu/tagpr/blob/main/CHANGELOG.md) - [Commits](Songmu/tagpr@d1b8138...242e229) Updates `wadackel/files-sync-action` from 3.6.0 to 4.0.2 - [Release notes](https://github.com/wadackel/files-sync-action/releases) - [Commits](wadackel/files-sync-action@2c7a879...80fcb2d) --- updated-dependencies: - dependency-name: the-pr-agent/pr-agent dependency-version: 0.44.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dependencies - dependency-name: Songmu/tagpr dependency-version: 1.20.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dependencies - dependency-name: wadackel/files-sync-action dependency-version: 4.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
kazeburo
deleted the
dependabot/github_actions/dependencies-3ef8563b11
branch
September 7, 2026 13:50
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the dependencies group with 3 updates: the-pr-agent/pr-agent, Songmu/tagpr and wadackel/files-sync-action.
Updates
the-pr-agent/pr-agentfrom 0.43.0 to 0.44.0Release notes
Sourced from the-pr-agent/pr-agent's releases.
... (truncated)
Commits
ab6ec54fix(pr_agent/servers/gerrit_server.py): requiring credentials on the webhook ...f876eedci: smoke-start github_app container so a broken launcher fails CI (#2825)3edc06ffeat(models): add OpenRouter router model support (#2893)6b7fbf9chore(deps): Upgrade vulnerable transitive dependencies (#2891)a16c993docs: avoid duplicating the pre-commit hook list (#2892)872dacffix: harden webhook auth and CLI argument injection vectors (#2595)f879d4ffix: preserve YAML keys and values during fallback parsing (#2877)ceae34bfix: surface the triggering workflow's conclusion in workflow_run reviews (#2...240e0e1fix(improve): avoid false failure after inline publish (#2886)c03f7b4chore: unify ruff version in pre-commit and deps (#2889)Updates
Songmu/tagprfrom 1.20.1 to 1.20.2Release notes
Sourced from Songmu/tagpr's releases.
Changelog
Sourced from Songmu/tagpr's changelog.
... (truncated)
Commits
242e229Merge pull request #371 from Songmu/tagpr-from-v1.20.121bbe12[tagpr] update CHANGELOG.mde48fe45[tagpr] prepare for the next releasef39c0e0Merge pull request #399 from Songmu/renovate/migrate-config20bca8eMigrate config .github/renovate.json53474f5aMerge pull request #398 from Songmu/dependabot/github_actions/reviewdog/actio...195e77eMerge pull request #254 from 12ya/patch6dc16ce3build(deps): bump reviewdog/action-staticcheck from 1.30.0 to 1.31.0fd3e13bMerge pull request #394 from Songmu/copilot/go-major-update-automation1ccebf1Fix Renovate Go update allowlistUpdates
wadackel/files-sync-actionfrom 3.6.0 to 4.0.2Release notes
Sourced from wadackel/files-sync-action's releases.
... (truncated)
Commits
80fcb2dMerge pull request #286 from wadackel/chore/enable-lockfile-maintenancea1a4c42Merge pull request #285 from wadackel/fix/upgrade-ejs-and-deepmerge-tse710446fix: declare the ejs module shape that v6 actually shipse32fe02chore: enable Renovate lock file maintenanced5e90e8chore: rebuild dist with refreshed dependencies243d184fix: upgrade ejs to v6 to drop the vulnerable jake dependency chainb2f63ecfix: upgrade deepmerge-ts to v8 to resolve CVE-2026-40345bf84e6cMerge pull request #283 from wadackel/fix/refresh-runtime-dependenciesda4ccf3chore: rebuild dist with refreshed dependencies1e2d7a6fix: refresh runtime dependencies to resolve known CVEsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions