Skip to content

chore(deps): update actions/checkout digest to 3d3c42e - autoclosed - #221

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-digest
Closed

chore(deps): update actions/checkout digest to 3d3c42e - autoclosed#221
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-checkout-digest

Conversation

@renovate

@renovate renovate Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout (changelog) action digest 9c091bb3d3c42e

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

gerfru added a commit that referenced this pull request Aug 18, 2026
…s, fix ruff format (#226)

Consolidates 10 stalled Renovate PRs (#215#225) that were each individually
BLOCKED by three systematic problems on main. No single PR could go green because
the Security (pip-audit) job requires all vulnerable deps fixed together, and the
Lint job failed for every PR.

Root causes fixed:
- Lint & Format: ruff 0.16.3 reformats Python code blocks inside markdown; 3 docs
  (Development.md, Niles-Core-Spec.md, Quality-Assessment.md) were unformatted.
- Security / Trivy: mcp 1.27.0, cryptography 49.0.0, json-repair 0.59.5 had HIGH
  advisories (PYSEC-2026-3481/82/83, CVE-2026-69247, GHSA-xf7x-x43h-rpqh). Bumped to
  the security-fix versions (mcp 1.28.1, cryptography 50.0.0, json-repair 0.60.1).
  Verified: fresh image Trivy scan is now clean (0 CRITICAL/HIGH); OS-package HIGHs
  are already handled by the existing apt-get upgrade in the runtime stage.

Bundled version updates (supersedes the individual Renovate PRs):
- langfuse docker tag v3 -> v4 (#224)
- prom/prometheus v3.13.0 -> v3.13.2 (#216)
- ghcr.io/astral-sh/uv 0.11.28 -> 0.12.5 (#218)
- actions/checkout v7.0.0 -> v7.0.1 across all workflows (#221, #222)
- actions/setup-python v6 -> v7 (#220)
- anthropics/claude-code-action digest bump (#215)
- mcp/cryptography/json-repair security bumps (#217, #219, #225)

Also fixes a marker bug in scripts/test.sh: it excluded llm_judge but not llm_eval,
so live-Ollama eval tests ran (and hung) on dev machines. Now aligned with CI.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gerfru

gerfru commented Aug 18, 2026

Copy link
Copy Markdown
Owner

Superseded by #226, das alle diese Updates gebündelt hat (gemergt in main). Die enthaltene Version/Change dieses PRs ist dort bereits drin.

@gerfru gerfru closed this Aug 18, 2026
@gerfru
gerfru deleted the renovate/actions-checkout-digest branch August 18, 2026 10:55
@renovate renovate Bot changed the title chore(deps): update actions/checkout digest to 3d3c42e chore(deps): update actions/checkout digest to 3d3c42e - autoclosed Aug 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant