Bumps the github-actions group with 3 updates in the / directory: msys2/setup-msys2, actions/cache and github/codeql-action.
Updates msys2/setup-msys2 from 2.31.0 to 2.31.1
Sourced from msys2/setup-msys2's releases.
Changelogv2.31.1
- input: allow empty input for "install" and "pacboy", meaning not packages will be installed [#589]
- input: deprecate the special "RUNNER_TEMP" value for "location" in favor of an empty string
- Update dependencies
Sourced from msys2/setup-msys2's changelog.
Commits2.31.1
- input: allow empty input for "install" and "pacboy", meaning not packages will be installed [#589]
- input: deprecate the special "RUNNER_TEMP" value for "location" in favor of an empty string
- Update dependencies
e989830 v2.31.1 9b1b97754d6b29a1930613de078be3eb976807fcUpdates actions/cache from 5.0.4 to 5.0.5
Sourced from actions/cache's releases.
Changelogv5.0.5
What's Changed
- Update ts-http-runtime dependency by
@yacaovsncin actions/cache#1747Full Changelog: actions/cache@v5...v5.0.5
Sourced from actions/cache's changelog.
CommitsReleases
How to prepare a release
[!NOTE]
Relevant for maintainers with write access only.
- Switch to a new branch from
main.- Run
npm testto ensure all tests are passing.- Update the version in
https://github.com/actions/cache/blob/main/package.json.- Run
npm run buildto update the compiled files.- Update this
https://github.com/actions/cache/blob/main/RELEASES.mdwith the new version and changes in the## Changelogsection.- Run
licensed cacheto update the license report.- Run
licensed statusand resolve any warnings by updating thehttps://github.com/actions/cache/blob/main/.licensed.ymlfile with the exceptions.- Commit your changes and push your branch upstream.
- Open a pull request against
mainand get it reviewed and merged.- Draft a new release https://github.com/actions/cache/releases use the same version number used in
package.json
- Create a new tag with the version number.
- Auto generate release notes and update them to match the changes you made in
RELEASES.md.- Toggle the set as the latest release option.
- Publish the release.
- Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
- There should be a workflow run queued with the same version number.
- Approve the run to publish the new version and update the major tags for this action.
Changelog
27d5ce7 Merge pull request #1747 from actions/yacaovsnc/update-dependencyf280785 licensed changes619aeb1 npm run build generated dist filesbcf16c2 Update ts-http-runtime to 0.3.5Updates github/codeql-action from 4.35.1 to 4.35.2
Sourced from github/codeql-action's releases.
Changelogv4.35.2
- The undocumented TRAP cache cleanup feature that could be enabled using the
CODEQL_ACTION_CLEANUP_TRAP_CACHESenvironment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing thetrap-caching: falseinput to theinitAction. #3795- The Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. #3789
- Python analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. #3794
- Fixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. #3807
- Update default CodeQL bundle version to 2.25.2. #3823
Sourced from github/codeql-action's changelog.
Commits4.35.2 - 15 Apr 2026
- The undocumented TRAP cache cleanup feature that could be enabled using the
CODEQL_ACTION_CLEANUP_TRAP_CACHESenvironment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing thetrap-caching: falseinput to theinitAction. #3795- The Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. #3789
- Python analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. #3794
- Fixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. #3807
- Update default CodeQL bundle version to 2.25.2. #3823
95e58e9 Merge pull request #3824 from github/update-v4.35.2-d2e135a736f31bfe Update changelog for v4.35.2d2e135a Merge pull request #3823 from github/update-bundle/codeql-bundle-v2.25.260abb65 Add changelog note5a0a562 Update default bundle to codeql-bundle-v2.25.26521697 Merge pull request #3820 from github/dependabot/github_actions/dot-github/wor...3c45af2 Merge pull request #3821 from github/dependabot/npm_and_yarn/npm-minor-345b93...f1c3393 Rebuild1024fc4 Rebuild9dd4cfe Bump the npm-minor group across 1 directory with 6 updatesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR@dependabot recreate will recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditionshttps://github.com/vim/vim/pull/20063
(2 files)
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.
To ignore these dependencies, configure ignore rules in dependabot.yml
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you are subscribed to this thread.![]()