Skip to content

chore(deps): update all dependencies - #530

Open
renovate[bot] wants to merge 1 commit into
developfrom
renovate/all
Open

renovate[bot] wants to merge 1 commit into
developfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/setup-java action major v5.7.0 → v6.0.1
actions/setup-python action major v6.3.0 → v7.0.0
apache/skywalking-eyes action minor v0.6.0 → v0.9.0
dorny/test-reporter action minor v3.0.0 → v3.2.0
ghcr.io/splunk/workflow-engine-base container major 4.1.0 → 5.0.0
java-jdk uses-with major 17 → 25
python uses-with minor 3.12 → 3.14
python uses-with minor 3.13 → 3.14
splunk/addonfactory-github-workflows workflow patch v1.7.3 → v1.7.4
splunk/appinspect-cli-action action minor v2.11 → v2.15
trufflesecurity/trufflehog action minor v3.95.9 → v3.99.0
ubuntu github-runner major 22.04 → 26.04

Release Notes

actions/setup-java (actions/setup-java)

v6.0.1

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v6.0.0...v6.0.1

v6.0.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v5.7.0...v6.0.0

actions/setup-python (actions/setup-python)

v7.0.0

Compare Source

What's Changed
Enhancements
Bug Fix
Dependency Upgrade
New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

apache/skywalking-eyes (apache/skywalking-eyes)

v0.9.0

Compare Source

What's Changed

New Contributors

Full Changelog: apache/skywalking-eyes@v0.8.0...v0.9.0

v0.8.0: 0.8.0

Compare Source

What's Changed

New Contributors

Full Changelog: apache/skywalking-eyes@v0.7.0...v0.8.0

v0.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: apache/skywalking-eyes@v0.6.0...v0.7.0

dorny/test-reporter (dorny/test-reporter)

v3.2.0

Compare Source

v3.1.0

Compare Source

actions/python-versions (python)

v3.14.8: 3.14.8

Compare Source

Python 3.14.8

v3.14.7: 3.14.7

Compare Source

Python 3.14.7

v3.14.6: 3.14.6

Compare Source

Python 3.14.6

v3.14.5: 3.14.5

Compare Source

Python 3.14.5

v3.14.4: 3.14.4

Compare Source

Python 3.14.4

v3.14.3: 3.14.3

Compare Source

Python 3.14.3

v3.14.2: 3.14.2

Compare Source

Python 3.14.2

v3.14.1: 3.14.1

Compare Source

Python 3.14.1

v3.14.0: 3.14.0

Compare Source

Python 3.14.0

v3.13.16: 3.13.16

Compare Source

Python 3.13.16

v3.13.15: 3.13.15

Compare Source

Python 3.13.15

v3.13.14: 3.13.14

Compare Source

Python 3.13.14

v3.13.13: 3.13.13

Compare Source

Python 3.13.13

v3.13.12: 3.13.12

Compare Source

Python 3.13.12

v3.13.11: 3.13.11

Compare Source

Python 3.13.11

v3.13.10: 3.13.10

Compare Source

Python 3.13.10

v3.13.9: 3.13.9

Compare Source

Python 3.13.9

v3.13.8: 3.13.8

Compare Source

Python 3.13.8

v3.13.7: 3.13.7

Compare Source

Python 3.13.7

v3.13.6: 3.13.6

Compare Source

Python 3.13.6

v3.13.5: 3.13.5

Compare Source

Python 3.13.5

v3.13.4: 3.13.4

Compare Source

Python 3.13.4

v3.13.3: 3.13.3

Compare Source

Python 3.13.3

v3.13.2: 3.13.2

Compare Source

Python 3.13.2

v3.13.1: 3.13.1

Compare Source

Python 3.13.1

v3.13.0: 3.13.0

Compare Source

Python 3.13.0

splunk/addonfactory-github-workflows (splunk/addonfactory-github-workflows)

v1.7.4

Compare Source

Bug Fixes
  • agreements: allowlist splunk-ta-helper bot (df5f395)
  • agreements: allowlist splunk-ta-helper bot (#​75) (9fdbd73)
splunk/appinspect-cli-action (splunk/appinspect-cli-action)

v2.15.0

Compare Source

Features
  • bump docker/build-push-action from 6 to 7 (35dc34a)
  • bump docker/build-push-action from 6 to 7 (#​165) (ecd09ed)

v2.14.0

Compare Source

Features
  • bump actions/checkout from 4 to 7 (ba0fefb)
  • bump actions/checkout from 4 to 7 (#​148) (4ba0389)
  • bump actions/setup-python from 6 to 7 (2b35b33)
  • bump splunk-appinspect from 4.2.1 to 4.3.0 (1386aed)
  • bump splunk-appinspect from 4.2.1 to 4.3.0 (#​168) (32bb801)
  • bumpp actions/setup-python from 6 to 7 (#​167) (6009e84)

v2.13.0

Compare Source

Features

v2.12.0

Compare Source

Features
trufflesecurity/trufflehog (trufflesecurity/trufflehog)

v3.99.0

Compare Source

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.98.1...v3.99.0

v3.98.1

Compare Source

What's Changed

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner July 27, 2026 03:02
@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from a434b52 to 04df0c7 Compare August 3, 2026 10:45

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e596ca1637

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released action tag

The reviewed dependency update is for v3.96.0, but this workflow references the unavailable v3.97.0 action tag. GitHub therefore cannot resolve the action, so every review_secrets job fails before scanning; because build explicitly needs review_secrets, this also blocks the reusable build and release workflow. Use the released v3.96.0 tag.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from 82bbc41 to 0f19e28 Compare August 25, 2026 18:41

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d6d8f91093

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

steps:
- uses: actions/checkout@v7
- uses: apache/skywalking-eyes@v0.6.0
- uses: apache/skywalking-eyes@v0.9.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin SkyWalking Eyes to the released v0.8.0 tag

When build-test-release.yaml runs, GitHub must resolve this action before the compliance-copyrights job can execute, but the dependency update and included release notes identify v0.8.0 as the available update while this line references v0.9.0. That unresolved tag causes the compliance job to fail during action setup on every workflow run; use the released v0.8.0 tag.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/all branch 2 times, most recently from f743e68 to f68cd11 Compare September 2, 2026 18:07

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f68cd113b0

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.2

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the version listed by the update

The fresh code now references v3.97.2, whereas this revision's Renovate metadata identifies v3.97.1 as the available target and contains no v3.97.2 release. GitHub cannot resolve the nonexistent action tag, so every review_secrets run fails during action setup and consequently blocks the downstream build job; pin this to v3.97.1.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 463c992ea5

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released v3.97.2 tag

The fresh evidence in this revision is that the workflow now references v3.97.4, while the reviewed commit's Renovate dependency table and release inventory identify v3.97.2 as the available target and contain no v3.97.4 release. GitHub therefore cannot resolve this action ref, so every review_secrets job fails during action setup and blocks the downstream build job; use v3.97.2.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b04bf0ab80

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

with:
distribution: 'temurin'
java-version: '17'
java-version: '25.0.4+101.0.LTS'

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Select an available Temurin Java version

When any caller runs this reusable workflow, actions/setup-java interprets this fully qualified value as an exact version, but 25.0.4+101.0.LTS is not a Temurin release identifier. The setup step therefore fails before pre-commit runs, and because build requires pre-commit, the entire build and release flow is blocked. Per setup-java's supported version syntax, retain Java 17 or specify an available Temurin version/range such as 25.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cacf70936d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released v3.97.4 tag

The fresh evidence in this revision is that the workflow now references v3.97.5, while the reviewed commit's Renovate dependency table identifies v3.97.4 as the target and its release inventory ends at v3.97.4. GitHub cannot resolve the nonexistent action ref, so every review_secrets job fails during action setup and blocks the downstream build job that explicitly requires it; use v3.97.4.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b2fb6a854f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".


pre-commit:
runs-on: ubuntu-22.04
runs-on: ubuntu-26.04

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a supported Ubuntu runner label

The official runner-images Available Images table lists ubuntu-24.04 and ubuntu-22.04, but not ubuntu-26.04; this job therefore remains queued with no matching GitHub-hosted runner. The same unsupported label is assigned to the unit-test, build, and setup jobs below, so callers cannot complete this reusable workflow; use the ubuntu-24.04 target identified in the dependency update.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 808938d12d

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released v3.97.5 tag

The fresh evidence in this revision is that the workflow now references v3.97.6, while the reviewed commit's Renovate dependency table and release inventory identify v3.97.5 as the target and contain no v3.97.6 release. GitHub cannot resolve this action ref, so every review_secrets job fails during action setup and blocks the downstream build job; use v3.97.5.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 256fb9e024

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.8

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released v3.97.6 tag

The fresh evidence in this revision is that its Renovate table and included release inventory target and end at v3.97.6, but this workflow requests v3.97.8. GitHub cannot resolve that action ref, so review_secrets fails during setup; build explicitly requires that job, blocking the reusable build and release flow. Use the released v3.97.6 tag.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 32c5e07d63

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.97.9

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reference the released TruffleHog version

The fresh evidence in this revision is that its Renovate dependency table and included release inventory end at v3.97.8, while this action reference requests v3.97.9. GitHub cannot resolve that ref, so review_secrets fails during setup; the build job explicitly requires review_secrets, blocking the reusable build and release workflow. Pin this to v3.97.8.

Useful? React with 👍 / 👎.

@renovate

renovate Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: poetry.lock
Creating virtualenv addonfactory-workflow-addon-release-eaaHW2NU-py3.13 in /home/ubuntu/.cache/pypoetry/virtualenvs

The current project's supported Python range (>=3.9,<3.14) is not compatible with some of the required packages Python requirement:
  - pytest requires Python >=3.10, so it will not be installable for Python >=3.9,<3.10

Because addonfactory-workflow-addon-release depends on pytest (9.1.1) which requires Python >=3.10, version solving failed.

  * Check your dependencies Python requirement: The Python requirement can be specified via the `python` or `markers` properties

    For pytest, a possible solution would be to set the `python` property to ">=3.10,<3.14"

    https://python-poetry.org/docs/dependency-specification/#python-restricted-dependencies,
    https://python-poetry.org/docs/dependency-specification/#using-environment-markers


@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fc888e8aed

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pyproject.toml Outdated

[tool.poetry.group.dev.dependencies]
pytest = "8.4.2"
pytest = "9.1.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Regenerate the Poetry lock for the pytest update

Because poetry.lock is unchanged and still locks pytest 8.4.2, the pre-commit job's poetry install --no-root aborts with “pyproject.toml changed significantly since poetry.lock was last generated” before running tests. This makes every PR and push fail its required validation gate; regenerate and commit the lock file with this dependency update.

AGENTS.md reference: AGENTS.md:L80-L80

Useful? React with 👍 / 👎.

Comment thread pyproject.toml Outdated

[tool.poetry.group.dev.dependencies]
pytest = "8.4.2"
pytest = "9.1.1"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep pytest 9 within the declared Python support range

Pytest 9 requires Python 3.10 or later, while this project still declares support starting at Python 3.9. After the lock is refreshed, Poetry cannot produce a dependency set valid across the declared range, and developers using Python 3.9 cannot install the dev dependencies; either retain pytest 8 for Python 3.9 or raise the project minimum Python version and regenerate the lock together.

Useful? React with 👍 / 👎.

- uses: actions/setup-python@v7.0.0
with:
python-version: "3.13"
python-version: "3.14"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include the selected Python 3.14 in the project range

The selected interpreter is excluded by requires-python = ">=3.9,<3.14". Poetry therefore rejects the activated Python 3.14 and searches for an ambient compatible interpreter (falling back to 3.13 in the tested environment), so this job no longer validates the version it explicitly selects; on runners without another compatible Python it fails outright. Expand the project range and lock to include 3.14, or keep this job on a supported version.

Useful? React with 👍 / 👎.

@renovate
renovate Bot force-pushed the renovate/all branch 3 times, most recently from 414b96b to e2b51fa Compare October 5, 2026 21:49
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T03:50:47.474115Z 293e161 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e2b51fa4f1

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

- uses: actions/setup-python@v7.0.0
with:
python-version: "3.12"
python-version: "3.14"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Use a Python version supported by UCC 5.69.1

splunk_add_on_ucc_framework==5.69.1 declares Requires-Python: >=3.7,<3.14, so every invocation of this reusable publish workflow will have pip reject the next step's wheel under the newly selected Python 3.14, before ucc-gen publish runs. Keep this job at Python 3.13 or lower, or upgrade its UCC framework dependency to a version that supports 3.14. Package metadata

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 293e161d12

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

ref: ${{ github.head_ref }}
- name: Secret Scanning Trufflehog
uses: trufflesecurity/trufflehog@v3.95.9
uses: trufflesecurity/trufflehog@v3.99.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pin TruffleHog to the released v3.98.1 tag

The fresh evidence in this revision is that its Renovate dependency table and included release inventory target and end at v3.98.1, while this workflow requests v3.99.0. GitHub cannot resolve that unavailable action ref, so review_secrets fails during setup and blocks the downstream build job that explicitly requires it; use the released v3.98.1 tag.

AGENTS.md reference: AGENTS.md:L16-L17

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants