Repository navigation
chore(deps): update all dependencies - #530
renovate[bot] wants to merge 1 commit into
Conversation
a434b52 to
04df0c7
Compare
04df0c7 to
e596ca1
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e596ca1637
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.0 |
There was a problem hiding this comment.
Pin TruffleHog to the released action tag
The reviewed dependency update is for v3.96.0, but this workflow references the unavailable v3.97.0 action tag. GitHub therefore cannot resolve the action, so every review_secrets job fails before scanning; because build explicitly needs review_secrets, this also blocks the reusable build and release workflow. Use the released v3.96.0 tag.
Useful? React with 👍 / 👎.
82bbc41 to
0f19e28
Compare
0f19e28 to
d6d8f91
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d6d8f91093
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| steps: | ||
| - uses: actions/checkout@v7 | ||
| - uses: apache/skywalking-eyes@v0.6.0 | ||
| - uses: apache/skywalking-eyes@v0.9.0 |
There was a problem hiding this comment.
Pin SkyWalking Eyes to the released v0.8.0 tag
When build-test-release.yaml runs, GitHub must resolve this action before the compliance-copyrights job can execute, but the dependency update and included release notes identify v0.8.0 as the available update while this line references v0.9.0. That unresolved tag causes the compliance job to fail during action setup on every workflow run; use the released v0.8.0 tag.
Useful? React with 👍 / 👎.
f743e68 to
f68cd11
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f68cd113b0
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.2 |
There was a problem hiding this comment.
Pin TruffleHog to the version listed by the update
The fresh code now references v3.97.2, whereas this revision's Renovate metadata identifies v3.97.1 as the available target and contains no v3.97.2 release. GitHub cannot resolve the nonexistent action tag, so every review_secrets run fails during action setup and consequently blocks the downstream build job; pin this to v3.97.1.
Useful? React with 👍 / 👎.
f68cd11 to
463c992
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 463c992ea5
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.4 |
There was a problem hiding this comment.
Pin TruffleHog to the released v3.97.2 tag
The fresh evidence in this revision is that the workflow now references v3.97.4, while the reviewed commit's Renovate dependency table and release inventory identify v3.97.2 as the available target and contain no v3.97.4 release. GitHub therefore cannot resolve this action ref, so every review_secrets job fails during action setup and blocks the downstream build job; use v3.97.2.
Useful? React with 👍 / 👎.
463c992 to
b04bf0a
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b04bf0ab80
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| with: | ||
| distribution: 'temurin' | ||
| java-version: '17' | ||
| java-version: '25.0.4+101.0.LTS' |
There was a problem hiding this comment.
Select an available Temurin Java version
When any caller runs this reusable workflow, actions/setup-java interprets this fully qualified value as an exact version, but 25.0.4+101.0.LTS is not a Temurin release identifier. The setup step therefore fails before pre-commit runs, and because build requires pre-commit, the entire build and release flow is blocked. Per setup-java's supported version syntax, retain Java 17 or specify an available Temurin version/range such as 25.
Useful? React with 👍 / 👎.
b04bf0a to
cacf709
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cacf70936d
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.5 |
There was a problem hiding this comment.
Pin TruffleHog to the released v3.97.4 tag
The fresh evidence in this revision is that the workflow now references v3.97.5, while the reviewed commit's Renovate dependency table identifies v3.97.4 as the target and its release inventory ends at v3.97.4. GitHub cannot resolve the nonexistent action ref, so every review_secrets job fails during action setup and blocks the downstream build job that explicitly requires it; use v3.97.4.
Useful? React with 👍 / 👎.
cacf709 to
b2fb6a8
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b2fb6a854f
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
|
||
| pre-commit: | ||
| runs-on: ubuntu-22.04 | ||
| runs-on: ubuntu-26.04 |
There was a problem hiding this comment.
Use a supported Ubuntu runner label
The official runner-images Available Images table lists ubuntu-24.04 and ubuntu-22.04, but not ubuntu-26.04; this job therefore remains queued with no matching GitHub-hosted runner. The same unsupported label is assigned to the unit-test, build, and setup jobs below, so callers cannot complete this reusable workflow; use the ubuntu-24.04 target identified in the dependency update.
Useful? React with 👍 / 👎.
b2fb6a8 to
808938d
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 808938d12d
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.6 |
There was a problem hiding this comment.
Pin TruffleHog to the released v3.97.5 tag
The fresh evidence in this revision is that the workflow now references v3.97.6, while the reviewed commit's Renovate dependency table and release inventory identify v3.97.5 as the target and contain no v3.97.6 release. GitHub cannot resolve this action ref, so every review_secrets job fails during action setup and blocks the downstream build job; use v3.97.5.
Useful? React with 👍 / 👎.
808938d to
256fb9e
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 256fb9e024
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.8 |
There was a problem hiding this comment.
Pin TruffleHog to the released v3.97.6 tag
The fresh evidence in this revision is that its Renovate table and included release inventory target and end at v3.97.6, but this workflow requests v3.97.8. GitHub cannot resolve that action ref, so review_secrets fails during setup; build explicitly requires that job, blocking the reusable build and release flow. Use the released v3.97.6 tag.
Useful? React with 👍 / 👎.
256fb9e to
32c5e07
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 32c5e07d63
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.97.9 |
There was a problem hiding this comment.
Reference the released TruffleHog version
The fresh evidence in this revision is that its Renovate dependency table and included release inventory end at v3.97.8, while this action reference requests v3.97.9. GitHub cannot resolve that ref, so review_secrets fails during setup; the build job explicitly requires review_secrets, blocking the reusable build and release workflow. Pin this to v3.97.8.
Useful? React with 👍 / 👎.
32c5e07 to
fc888e8
Compare
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fc888e8aed
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
|
||
| [tool.poetry.group.dev.dependencies] | ||
| pytest = "8.4.2" | ||
| pytest = "9.1.1" |
There was a problem hiding this comment.
Regenerate the Poetry lock for the pytest update
Because poetry.lock is unchanged and still locks pytest 8.4.2, the pre-commit job's poetry install --no-root aborts with “pyproject.toml changed significantly since poetry.lock was last generated” before running tests. This makes every PR and push fail its required validation gate; regenerate and commit the lock file with this dependency update.
AGENTS.md reference: AGENTS.md:L80-L80
Useful? React with 👍 / 👎.
|
|
||
| [tool.poetry.group.dev.dependencies] | ||
| pytest = "8.4.2" | ||
| pytest = "9.1.1" |
There was a problem hiding this comment.
Keep pytest 9 within the declared Python support range
Pytest 9 requires Python 3.10 or later, while this project still declares support starting at Python 3.9. After the lock is refreshed, Poetry cannot produce a dependency set valid across the declared range, and developers using Python 3.9 cannot install the dev dependencies; either retain pytest 8 for Python 3.9 or raise the project minimum Python version and regenerate the lock together.
Useful? React with 👍 / 👎.
| - uses: actions/setup-python@v7.0.0 | ||
| with: | ||
| python-version: "3.13" | ||
| python-version: "3.14" |
There was a problem hiding this comment.
Include the selected Python 3.14 in the project range
The selected interpreter is excluded by requires-python = ">=3.9,<3.14". Poetry therefore rejects the activated Python 3.14 and searches for an ambient compatible interpreter (falling back to 3.13 in the tested environment), so this job no longer validates the version it explicitly selects; on runners without another compatible Python it fails outright. Expand the project range and lock to include 3.14, or keep this job on a supported version.
Useful? React with 👍 / 👎.
fc888e8 to
a16e1d8
Compare
414b96b to
e2b51fa
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e2b51fa4f1
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| - uses: actions/setup-python@v7.0.0 | ||
| with: | ||
| python-version: "3.12" | ||
| python-version: "3.14" |
There was a problem hiding this comment.
Use a Python version supported by UCC 5.69.1
splunk_add_on_ucc_framework==5.69.1 declares Requires-Python: >=3.7,<3.14, so every invocation of this reusable publish workflow will have pip reject the next step's wheel under the newly selected Python 3.14, before ucc-gen publish runs. Keep this job at Python 3.13 or lower, or upgrade its UCC framework dependency to a version that supports 3.14. Package metadata
Useful? React with 👍 / 👎.
e2b51fa to
6271d95
Compare
6271d95 to
293e161
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 293e161d12
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| ref: ${{ github.head_ref }} | ||
| - name: Secret Scanning Trufflehog | ||
| uses: trufflesecurity/trufflehog@v3.95.9 | ||
| uses: trufflesecurity/trufflehog@v3.99.0 |
There was a problem hiding this comment.
Pin TruffleHog to the released v3.98.1 tag
The fresh evidence in this revision is that its Renovate dependency table and included release inventory target and end at v3.98.1, while this workflow requests v3.99.0. GitHub cannot resolve that unavailable action ref, so review_secrets fails during setup and blocks the downstream build job that explicitly requires it; use the released v3.98.1 tag.
AGENTS.md reference: AGENTS.md:L16-L17
Useful? React with 👍 / 👎.
This PR contains the following updates:
v5.7.0→v6.0.1v6.3.0→v7.0.0v0.6.0→v0.9.0v3.0.0→v3.2.04.1.0→5.0.017→253.12→3.143.13→3.14v1.7.3→v1.7.4v2.11→v2.15v3.95.9→v3.99.022.04→26.04Release Notes
actions/setup-java (actions/setup-java)
v6.0.1Compare Source
What's Changed
New Contributors
Full Changelog: actions/setup-java@v6.0.0...v6.0.1
v6.0.0Compare Source
What's Changed
18.0.1.1by @brunoborges in #1092New Contributors
Full Changelog: actions/setup-java@v5.7.0...v6.0.0
actions/setup-python (actions/setup-python)
v7.0.0Compare Source
What's Changed
Enhancements
Bug Fix
Dependency Upgrade
New Contributors
Full Changelog: actions/setup-python@v6...v7.0.0
apache/skywalking-eyes (apache/skywalking-eyes)
v0.9.0Compare Source
What's Changed
header diffcommand to show header differences by @wu-sheng in #276New Contributors
Full Changelog: apache/skywalking-eyes@v0.8.0...v0.9.0
v0.8.0: 0.8.0Compare Source
What's Changed
New Contributors
Full Changelog: apache/skywalking-eyes@v0.7.0...v0.8.0
v0.7.0Compare Source
What's Changed
New Contributors
Full Changelog: apache/skywalking-eyes@v0.6.0...v0.7.0
dorny/test-reporter (dorny/test-reporter)
v3.2.0Compare Source
v3.1.0Compare Source
actions/python-versions (python)
v3.14.8: 3.14.8Compare Source
Python 3.14.8
v3.14.7: 3.14.7Compare Source
Python 3.14.7
v3.14.6: 3.14.6Compare Source
Python 3.14.6
v3.14.5: 3.14.5Compare Source
Python 3.14.5
v3.14.4: 3.14.4Compare Source
Python 3.14.4
v3.14.3: 3.14.3Compare Source
Python 3.14.3
v3.14.2: 3.14.2Compare Source
Python 3.14.2
v3.14.1: 3.14.1Compare Source
Python 3.14.1
v3.14.0: 3.14.0Compare Source
Python 3.14.0
v3.13.16: 3.13.16Compare Source
Python 3.13.16
v3.13.15: 3.13.15Compare Source
Python 3.13.15
v3.13.14: 3.13.14Compare Source
Python 3.13.14
v3.13.13: 3.13.13Compare Source
Python 3.13.13
v3.13.12: 3.13.12Compare Source
Python 3.13.12
v3.13.11: 3.13.11Compare Source
Python 3.13.11
v3.13.10: 3.13.10Compare Source
Python 3.13.10
v3.13.9: 3.13.9Compare Source
Python 3.13.9
v3.13.8: 3.13.8Compare Source
Python 3.13.8
v3.13.7: 3.13.7Compare Source
Python 3.13.7
v3.13.6: 3.13.6Compare Source
Python 3.13.6
v3.13.5: 3.13.5Compare Source
Python 3.13.5
v3.13.4: 3.13.4Compare Source
Python 3.13.4
v3.13.3: 3.13.3Compare Source
Python 3.13.3
v3.13.2: 3.13.2Compare Source
Python 3.13.2
v3.13.1: 3.13.1Compare Source
Python 3.13.1
v3.13.0: 3.13.0Compare Source
Python 3.13.0
splunk/addonfactory-github-workflows (splunk/addonfactory-github-workflows)
v1.7.4Compare Source
Bug Fixes
splunk/appinspect-cli-action (splunk/appinspect-cli-action)
v2.15.0Compare Source
Features
v2.14.0Compare Source
Features
v2.13.0Compare Source
Features
v2.12.0Compare Source
Features
trufflesecurity/trufflehog (trufflesecurity/trufflehog)
v3.99.0Compare Source
What's Changed
Full Changelog: trufflesecurity/trufflehog@v3.98.1...v3.99.0
v3.98.1Compare Source
What's Changed
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.