Skip to content

Update GitHub Actions dependencies#306

Merged
marc-jasper-sonarsource merged 1 commit intomasterfrom
renovate/github-actions-dependencies
Mar 24, 2026
Merged

Update GitHub Actions dependencies#306
marc-jasper-sonarsource merged 1 commit intomasterfrom
renovate/github-actions-dependencies

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 24, 2026

This PR contains the following updates:

Package Type Update Change
SonarSource/gh-action_release action patch 6.4.06.4.1
SonarSource/vault-action-wrapper action minor 3.3.03.4.0

Release Notes

SonarSource/gh-action_release (SonarSource/gh-action_release)

v6.4.1

Compare Source

What's Changed

Full Changelog: SonarSource/gh-action_release@6.4.0...6.4.1

SonarSource/vault-action-wrapper (SonarSource/vault-action-wrapper)

v3.4.0

Compare Source

What's Changed

Full Changelog: SonarSource/vault-action-wrapper@3.3.0...3.4.0


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@sonar-review-alpha
Copy link
Copy Markdown

sonar-review-alpha bot commented Mar 24, 2026

Summary

Routine updates to two internal SonarSource GitHub Actions used in CI/CD workflows. gh-action_release receives a patch fix (6.4.0 → 6.4.1) addressing hierarchical binary layout scoping for sonarqube-cli, while vault-action-wrapper gets a minor feature release (3.3.0 → 3.4.0) with improved Vault error diagnostics. Changes are confined to commit hash and version comment updates in workflow files—no functional code changes.

What reviewers should know

All changes are straightforward version/hash updates in GitHub workflow files (.github/workflows/release.yml and .github/actions/config-poetry/action.yml). The release.yml changes appear twice (test and production PyPI release jobs), so verify both are consistent. Since these are used in release workflows, ensure the updated actions' release notes (already provided above) don't introduce any breaking changes or new requirements. This is a low-risk update from Renovate.


  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

@sonarqube-next
Copy link
Copy Markdown

Quality Gate passed Quality Gate passed for 'Python Scanner'

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

Copy link
Copy Markdown

@sonar-review-alpha sonar-review-alpha bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

🗣️ Give feedback

Copy link
Copy Markdown
Contributor

@marc-jasper-sonarsource marc-jasper-sonarsource left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@marc-jasper-sonarsource marc-jasper-sonarsource merged commit 4c40749 into master Mar 24, 2026
21 checks passed
@marc-jasper-sonarsource marc-jasper-sonarsource deleted the renovate/github-actions-dependencies branch March 24, 2026 10:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant