Repository navigation
build: bump anthropics/claude-code-action from 1.0.235 to 1.0.240 - #655
Merged
kyle-sexton merged 1 commit intoOct 3, 2026
Merged
kyle-sexton merged 1 commit into
kyle-sexton merged 1 commit into
Conversation
Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.235 to 1.0.240. - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@756cc22...ed670b4) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.240 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/anthropics/claude-code-action-1.0.240
branch
from
October 3, 2026 04:53
4e43b26 to
e42a573
Compare
kyle-sexton
deleted the
dependabot/github_actions/anthropics/claude-code-action-1.0.240
branch
October 3, 2026 16:49
kyle-sexton
added a commit
that referenced
this pull request
Oct 4, 2026
No related issue: Phase 5 plan step (shared Dependabot auto-merge reusable R); tracked in the actions-conventions plan, not an issue. ## Summary Adds `.github/workflows/pr-automerge-dependabot.yml`, a `workflow_call` reusable that arms GitHub squash auto-merge on low-risk Dependabot PRs. GitHub then merges once `ci-status` and every other required check pass. It implements standards `components/dependabot-policy/policy.json` `autoMerge` (`github-actions`; `actions/*`, `github/*`, `anthropics/*`; no semver-major; `ci-status`). ## Fix - Gates, all required: event is `pull_request`; PR author id `49699333` (dependabot[bot]); event sender (`github.event.sender.id`, the pusher) is `49699333`; fetch-metadata succeeded, and failed, empty or invalid metadata is a skip; every update's ecosystem is `github_actions`; every dependency name matches the case-sensitive allowlist glob; every update is semver patch or minor (grouped PRs included; an uncomputable type skips); every PR commit, head included, has author `49699333`, committer `19864447` (web-flow) and a signature verified with reason `valid`. That commit shape matches live Dependabot commits on medley#2094 and ci-workflows #651, #655 and #674. - fetch-metadata is `continue-on-error`, and the gate step runs on `!cancelled()`. A force-push that makes fetch-metadata fail therefore still reaches the disarm. - Arms with `enablePullRequestAutoMerge(mergeMethod: SQUASH, expectedHeadOid: <verified head>)`. No direct-merge fallback, so nothing merges around `ci-status`. - A skipped PR that was armed on an earlier head is disarmed (GitHub keeps auto-merge on after a push by a write-access user). - No checkout; PR-derived values reach the script via `env:` only. Job permissions: `contents: write`, `pull-requests: write`. Input: `runner` (default `ubuntu-24.04`). - The gate runs inline in `actions/github-script` because a reusable has no ci-workflows checkout. `.github/scripts/pr-automerge-dependabot.test.cjs` extracts the script and runs it against fixtures, picked up by `test-contracts` (`node --test .github/scripts/*.test.cjs`). - README entry with the canonical caller. ## Verification - `node --test .github/scripts/*.test.cjs`: 219 pass, 0 fail (27 in the new file: vendor patch armed, vendor major, community patch, mixed group, vendor group with one major, non-Dependabot author, non-Dependabot sender, foreign head commit, forged author with a non-web-flow committer, unsigned commit, non-`valid` reason, moved head, non-actions ecosystem, lookalike owner, `Actions/checkout` case variant, empty and invalid metadata, failed metadata fetch disarmed, disarm). - Mutation spot-checks (unanchored glob, head-moved check, disarm, signature, committer, reason, sender, metadata outcome, continue-on-error) each turn a test red. - actionlint 1.7.12 and zizmor 1.30.0 clean on the new workflow; markdownlint and typos clean. - naming-lint `--mode enforcing` exits 0 after merging origin/main (#675). ## Related - Phase 5 plan Phase 3 (R). Next: Fable review, a minor release, then the standards `approvedReusableWorkflowContracts` entry and the allowlist lockstep test (separate PRs). - Ports medley `.github/workflows/dependabot-automerge.yml`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps anthropics/claude-code-action from 1.0.235 to 1.0.240.
Release notes
Sourced from anthropics/claude-code-action's releases.
Commits
ed670b4chore: bump Claude Code to 2.1.288 and Agent SDK to 0.3.28897c5347chore: bump Claude Code to 2.1.287 and Agent SDK to 0.3.28712dd8d7chore: bump Claude Code to 2.1.286 and Agent SDK to 0.3.286a8cb0dbci: security hardening for GitHub Actions workflows that call Claude (#1867)fd1c128chore: bump Claude Code to 2.1.285 and Agent SDK to 0.3.2858ce9314chore: bump Claude Code to 2.1.284 and Agent SDK to 0.3.284