Skip to content

chore(deps): update github-actions#163

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

chore(deps): update github-actions#163
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout action minor v6.0.2v6.1.0
actions/setup-go action minor v6.4.0v6.5.0
actions/setup-node action minor v6.4.0v6.5.0
anthropics/claude-code-action (changelog) action digest f4fb5c6be7b93b
anthropics/claude-code-action action patch v1.0.121v1.0.183
aws-actions/configure-aws-credentials action minor v6.1.3v6.2.3
azure/setup-helm action patch v5.0.0v5.0.1
docker/login-action action minor v4.4.0v4.5.1
dorny/paths-filter action patch v4.0.1v4.0.2
loft-sh/github-actions (changelog) action digest 53686d2c40c1db
loft-sh/github-actions (changelog) action digest 85d7023b5a50da
openai/codex-action action minor v1.8v1.11
reviewdog/action-actionlint action minor v1.72.0v1.73.0
slackapi/slack-github-action action patch v3.0.3v3.0.5

Release Notes

actions/checkout (actions/checkout)

v6.1.0

Compare Source

v6.0.3

Compare Source

actions/setup-go (actions/setup-go)

v6.5.0

Compare Source

actions/setup-node (actions/setup-node)

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

anthropics/claude-code-action (anthropics/claude-code-action)

v1.0.183

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Compare Source

v1.0.181

Compare Source

v1.0.180

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Compare Source

v1.0.178

Compare Source

v1.0.177

Compare Source

v1.0.176

Compare Source

v1.0.175

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.175

v1.0.174

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.174

v1.0.173

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.173

v1.0.172

Compare Source

What's Changed

  • fix(sdk): fail step when result has is_error:true despite success subtype by @​syf2211 in #​1496

Full Changelog: anthropics/claude-code-action@v1...v1.0.172

v1.0.171

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.171

v1.0.170

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.170

v1.0.169

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.169

v1.0.168

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.168

v1.0.167

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.167

v1.0.166

Compare Source

What's Changed
New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.166

v1.0.165

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.165

v1.0.164

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.164

v1.0.163

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.163

v1.0.162

Compare Source

v1.0.161

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.161

v1.0.160

Compare Source

v1.0.159

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.159

v1.0.158

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.158

v1.0.157

Compare Source

v1.0.156

Compare Source

v1.0.155

Compare Source

v1.0.154

Compare Source

v1.0.153

Compare Source

v1.0.152

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.152

v1.0.151

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.151

v1.0.150

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.150

v1.0.149

Compare Source

What's Changed

  • fix(parse-sdk-options): prevent shell-quote from collapsing unquoted Bash(X:*) rules to bare Bash by @​alexglynn in #​1350
  • fix(mcp): align allowed-tools parser with SDK option parser by @​bymle in #​1373

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.149

v1.0.148

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.148

v1.0.147

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.147

v1.0.146

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.146

v1.0.145

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.145

v1.0.144

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.144

v1.0.143

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.143

v1.0.142

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.142

v1.0.141

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.141

v1.0.140

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.140

v1.0.139

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.139

v1.0.138

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.138

v1.0.137

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.137

v1.0.136

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.136

v1.0.135

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.135

v1.0.134

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.134

v1.0.133

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.133

v1.0.132

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.132

v1.0.131

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.131

v1.0.130

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.130

v1.0.129

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.129

v1.0.128

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.128

v1.0.127

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.127

v1.0.126

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.126

v1.0.125

Compare Source

What's Changed

Full Changelog: anthropics/claude-code-action@v1...v1.0.125

v1.0.124

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.124

v1.0.123

Compare Source

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.123

v1.0.122

Compare Source

Full Changelog: anthropics/claude-code-action@v1...v1.0.122

aws-actions/configure-aws-credentials (aws-actions/configure-aws-credentials)

v6.2.3

Compare Source

v6.2.2

Compare Source

v6.2.2

Compare Source

Miscellaneous Chores

v6.2.1

Compare Source

Bug Fixes

v6.2.0

Compare Source

Features
Bug Fixes
azure/setup-helm (azure/setup-helm)

v5.0.1

Compare Source

docker/login-action (docker/login-action)

v4.5.1

Compare Source

v4.5.0

Compare Source

dorny/paths-filter (dorny/paths-filter)

v4.0.2

Compare Source

openai/codex-action (openai/codex-action)

v1.11

Compare Source

  • #​116 keep the permission profile helper backward compatible

v1.10

Compare Source

  • #​113 add Codex permission profile support

v1.9

Compare Source

  • #​85 update the internal setup-node pin to v6.3.0
reviewdog/action-actionlint (reviewdog/action-actionlint)

v1.73.0

Compare Source

What's Changed

New Contributors

Full Changelog: reviewdog/action-actionlint@v1.72.1...v1.73.0

v1.73

Compare Source

v1.72.1

Compare Source

v1.72.1: PR #​211 - fix: include digest in Docker image reference for action.yml

slackapi/slack-github-action (slackapi/slack-github-action)

v3.0.5: Slack GitHub Action v3.0.5

Compare Source

Patch Changes
  • 96fddbe: fix: revert multiline yaml parsing indentation change

v3.0.4: Slack GitHub Action v3.0.4

Compare Source

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 2m 17s —— View job


Review: Renovate dependency bump

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for stale/mismatched pins and risky jumps

Findings

No bugs, security issues, or performance problems in the workflow/action changes. This is a clean SHA-pin bump.

Verified locally:

  • Every executable .github/ reference resolves to exactly one SHA per action — no split-brain pins:
    • checkoutdf4cb1c (v6.0.3), setup-go924ae3a (v6.5.0), claude-code-actionba0aafd (v1.0.168), codex-action52fe01e (v1.11), setup-helm9bc31f4 (v5.0.1), configure-aws-credentials517a711 (v6.2.2), paths-filter7b450ff (v4.0.2).
  • No stale old SHAs remain in any workflow/action YAML.
  • All version comments (# v...) match the update table in the PR body.

Minor (non-blocking)

Doc drift only: the old checkout pin de0fac2 # v6.0.2 still appears in example snippets in several README.md files (publish-helm-chart, go-licenses, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact — Renovate just doesn't rewrite doc examples. Worth a periodic sweep to keep examples current, but nothing to block this PR on.

Note on verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (gh api / git ls-remote / WebFetch to github.com are blocked in this sandbox). The SHAs were produced by Renovate's digest resolution and the version comments are consistent, so risk is low, but a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge. The bumps are patch/minor across trusted, already-pinned actions.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved by the shared auto-approve workflow because this PR matched the approval criteria.

For more information, see https://github.com/loft-sh/github-actions?tab=readme-ov-file#auto-approve-bot-prs.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4eafdd1 to b2f1f27 Compare July 9, 2026 03:10
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 57s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (42 files)
  • Verify SHA-pin consistency across the tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Verified across the whole .github/ tree — every executable reference resolves to exactly one SHA per action, no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes:

  • claude-code-action moved to v1.0.169 (37b464c) since the PR body was written (body says v1.0.168) — the sync picked up a newer patch. SHA is consistent everywhere it appears (both the # v1.0.169 pin in ai-pr-review/action.yml and the # v1 float-tag comment in the claude*.yaml workflows point at the same commit). No mismatch.
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (subtree-mirror, go-licenses, govulncheck, checkov, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

I confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network is blocked in this sandbox). The SHAs come from Renovate's digest resolution and the version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from b2f1f27 to 021a49f Compare July 9, 2026 08:09
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 44s —— View job


Review: Renovate dependency bump

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 37b464c v1.0.169 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action is pinned to the same SHA (37b464c) whether commented # v1.0.169 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — no mismatch. (Note: PR body says v1.0.168; the sync picked up the newer v1.0.169 patch.)
  • No stale old SHAs remain in any workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old de0fac2 # v6.0.2 checkout pin still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 021a49f to 21a726e Compare July 10, 2026 01:59
@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 46s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (43 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 536f2c3 v1.0.170 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action moved again to v1.0.170 (536f2c3) since the last sync (PR body says v1.0.168, prior reviews saw v1.0.169). SHA is consistent across all 4 references — the # v1.0.170 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 21a726e to 4ef0d1c Compare July 11, 2026 03:28
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action fc46ded v3.0.4
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.171 (e90deca) (body says v1.0.170; earlier reviews saw v1.0.168/169/170). SHA is consistent across all 4 references — the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • slackapi/slack-github-action bumped v3.0.3 → v3.0.4 (fc46ded) in this sync (not listed in the PR body table). Consistent across all 4 references.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 4ef0d1c to 82dc414 Compare July 11, 2026 07:43
@github-actions

github-actions Bot commented Jul 11, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action e90deca v1.0.171 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since prior reviews / PR body were written:

  • slackapi/slack-github-action moved further to v3.0.5 (0d95c9a) — PR body says v3.0.4, last review saw v3.0.4 (fc46ded). The sync picked up the newer patch. SHA is consistent across all 4 references.
  • claude-code-action is at v1.0.171 (e90deca), consistent across both the # v1.0.171 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 82dc414 to 5a21f93 Compare July 14, 2026 03:14
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 49s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action a08f891 v1.0.172 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body / prior reviews were written:

  • claude-code-action moved again to v1.0.172 (a08f891) (body says v1.0.171; earlier reviews saw v1.0.168–171). SHA is consistent across all 4 references — the # v1.0.172 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • actions/setup-node also bumped to v6.5.0 (2499707) alongside setup-go — consistent, not in the PR body table.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5a21f93 to 514d3b5 Compare July 14, 2026 09:49
@github-actions

github-actions Bot commented Jul 14, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 50s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action f1bd27c v1.0.173 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.173 (f1bd27c) (body says v1.0.172; earlier reviews saw v1.0.168–172). SHA is consistent across all 4 references — the # v1.0.173 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 514d3b5 to 0f2c6c6 Compare July 15, 2026 01:32
@github-actions

github-actions Bot commented Jul 15, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 45s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1253134 v1.0.174 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.174 (1253134) (body says v1.0.173; earlier reviews saw v1.0.168–173). SHA is consistent across all 4 references — the # v1.0.174 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0f2c6c6 to fc67a83 Compare July 16, 2026 01:11
@github-actions

github-actions Bot commented Jul 16, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 1298632 v1.0.175 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.175 (1298632) (body says v1.0.174; earlier syncs saw v1.0.168–174). SHA is consistent across all references — the # v1.0.175 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (publish-helm-chart, go-licenses, vcluster-release, checkov, subtree-mirror, govulncheck — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from fc67a83 to a6bc804 Compare July 17, 2026 09:34
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (46 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.176 (700e7f8) (body says v1.0.175; earlier syncs saw v1.0.168–175). SHA is consistent across all references — the # v1.0.176 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml workflows all point at the same commit. No mismatch.
  • No stale old SHAs remain in any executable workflow/action YAML.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a6bc804 to d0fbf65 Compare July 17, 2026 11:28
@github-actions

github-actions Bot commented Jul 17, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 35s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, and every old SHA is fully replaced (verified: no stale pins remain in any workflow/action YAML):

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 700e7f8 v1.0.176 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.176 (700e7f8) is consistent whether commented # v1.0.176 (in ai-pr-review/action.yml) or # v1 (in the claude*.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from d0fbf65 to 8cb6560 Compare July 18, 2026 01:55
@github-actions

github-actions Bot commented Jul 18, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 10s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76, all uses: pin lines — no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 3553f84 v1.0.177 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.177 (3553f84) (body says v1.0.176; earlier syncs saw v1.0.168–176). SHA is consistent across all references — the # v1.0.177 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, subtree-mirror, checkov, publish-helm-chart, govulncheck, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 8cb6560 to 3af22e7 Compare July 19, 2026 06:05
@github-actions

github-actions Bot commented Jul 19, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 52s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all are pinned uses: references, no logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified every changed line is a pinned uses: reference (@<40-hex> # <version>) — zero non-pin edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout df4cb1c v6.0.3
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action af0559e v1.0.178 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Note since the PR body was written:

  • claude-code-action advanced to v1.0.178 (af0559e) (body says v1.0.177; earlier syncs saw v1.0.168–177). SHA is consistent across all references — the # v1.0.178 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (go-licenses, vcluster-release, subtree-mirror, checkov, govulncheck, publish-helm-chart). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3af22e7 to 45df450 Compare July 21, 2026 01:47
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 2s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 76/76 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since the PR body was written:

  • actions/checkout advanced to v6.1.0 (d23441a) — body says v6.0.3 (patch); the sync picked up a newer minor release. Consistent across all 48 executable references. Note this is a version-line change beyond what the PR title implies, but it's still a trusted, SHA-pinned action.
  • claude-code-action advanced to v1.0.179 (b76a077) (body says v1.0.178; earlier syncs saw v1.0.168–178). SHA is consistent across all references — the # v1.0.179 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 45df450 to 0b5f020 Compare July 21, 2026 14:44
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 48s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files, 77/77 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.179 (b76a077) is consistent whether commented # v1.0.179 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses — 10 occurrences). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0b5f020 to a2965d8 Compare July 21, 2026 19:23
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 54s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (48 files — every changed line is a pinned uses: reference, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action b76a077 v1.0.179 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 01d2dd6 v1.72.1
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.179 (b76a077) is consistent whether commented # v1.0.179 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (vcluster-release, subtree-mirror, publish-helm-chart, govulncheck, go-licenses, checkov). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from a2965d8 to 0670dde Compare July 22, 2026 02:51
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 10s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (49 files, 78/78 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action fa7e2f0 v1.0.180 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5

Notes since the PR body was written:

  • claude-code-action advanced to v1.0.180 (fa7e2f0) (body says v1.0.179). SHA is consistent across all references — the # v1.0.180 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.
  • reviewdog/action-actionlint advanced to v1.73.0 (5084226) — body/prior review saw v1.72.1 (patch); the sync picked up a newer minor release. Single SHA, consistent. Still a trusted, SHA-pinned action.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 0670dde to 201f001 Compare July 22, 2026 18:16
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 37s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (49 files, 78/78 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action fa7e2f0 v1.0.180 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials 517a711 v6.2.2
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.180 (fa7e2f0) is consistent whether commented # v1.0.180 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.
  • Note vs PR body: the sync picked up newer releases than the table implies — checkout v6.1.0 (minor, body said v6.0.3) and action-actionlint v1.73.0 (minor, body said v1.72.1). Both still trusted, SHA-pinned actions.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 201f001 to 5ad6e4e Compare July 22, 2026 19:53
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 39s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (49 files, 79/79 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action fa7e2f0 v1.0.180 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1

Notes since prior reviews / the PR body were written — the sync picked up newer releases than the table implies, all still trusted and SHA-pinned:

  • aws-actions/configure-aws-credentials advanced to v6.2.3 (e6de054) (body/prior reviews saw v6.2.2 517a711). Single executable reference (prerelease-setup/action.yml); the old 517a711 SHA is fully gone.
  • checkout at v6.1.0 (minor; body said v6.0.3) and action-actionlint at v1.73.0 (minor; body said v1.72.1).
  • claude-code-action at v1.0.180 (fa7e2f0) is consistent whether commented # v1.0.180 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit.

Minor (non-blocking)

Doc drift only — README example snippets still show older, non-executed pins (e.g. de0fac2 # v6.0.2 for checkout in checkov/go-licenses/govulncheck/publish-helm-chart/subtree-mirror/vcluster-release; configure-aws-credentials@v5.1.1/@v6 in aws-test-infra/prerelease-setup READMEs). Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5ad6e4e to deee67f Compare July 22, 2026 22:53
@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 37s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (49 files, 79/79 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
anthropics/claude-code-action 44423bd v1.0.181 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5

Note since prior reviews / the PR body were written:

  • claude-code-action advanced to v1.0.181 (44423bd) (body says v1.0.180). SHA is consistent across all references — the # v1.0.181 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit. No mismatch.
  • The sync also carries versions newer than the PR body table implies — checkout v6.1.0 (minor), action-actionlint v1.73.0 (minor), configure-aws-credentials v6.2.3. All still trusted, SHA-pinned actions.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release) and the root README.md. Not executed, so no functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from deee67f to cb03319 Compare July 23, 2026 11:28
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 43s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (50 files, 80/80 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 44423bd v1.0.181 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml b52efbd validate-renovate/v1
  • claude-code-action at v1.0.181 (44423bd) is consistent whether commented # v1.0.181 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.
  • Note vs PR body table: the sync carries some releases newer/higher than the table implies — checkout v6.1.0 (minor), action-actionlint v1.73.0 (minor), configure-aws-credentials v6.2.3. All still trusted, SHA-pinned actions.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release) and the root README.md. Confirmed these are not in any executable YAML (grep over .github/**/*.y{,a}ml returns none). No functional impact; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from cb03319 to 5d680d4 Compare July 23, 2026 12:06
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 41s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (50 files, 80/80 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 44423bd v1.0.181 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1
  • claude-code-action at v1.0.181 (44423bd) is consistent whether commented # v1.0.181 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.
  • The reusable-workflow pin validate-renovate.yaml advanced to c40c1db in this sync (prior reviews saw b52efbd). Single reference, consistent.
  • Note vs PR body table: the sync carries releases newer than the table implies — checkout v6.1.0 (minor, body said v6.0.3), action-actionlint v1.73.0 (minor, body said v1.72.1), configure-aws-credentials v6.2.3 (body said v6.2.2). All still trusted, SHA-pinned actions.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (govulncheck, publish-helm-chart, vcluster-release, checkov, subtree-mirror, go-licenses). Confirmed via grep that these are not in any executable YAML — zero hits under .github/**/*.y{,a}ml. No functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 5d680d4 to f5315c2 Compare July 23, 2026 17:48
@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 44s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (51 files, 81/81 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Confirmed every changed line is a uses: …@<40-hex> # <version> pin — no shell/logic edits.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins, no stale SHAs remaining:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action 44423bd v1.0.181 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1
  • claude-code-action at v1.0.181 (44423bd) is consistent whether commented # v1.0.181 (ai-pr-review/action.yml) or # v1 (the claude*.yaml / claude-code-review.yaml workflows) — same commit, no mismatch.
  • Note vs PR body table: the sync carries releases newer than the table implies — checkout v6.1.0 (minor, body said v6.0.3), action-actionlint v1.73.0 (minor, body said v1.72.1), configure-aws-credentials v6.2.3 (body said v6.2.2). All still trusted, SHA-pinned actions.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release). Confirmed via grep these are not in any executable YAML — zero hits under .github/**/*.y{,a}ml. No functional impact; Renovate doesn't rewrite doc examples.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from f5315c2 to 3009243 Compare July 24, 2026 19:34
@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 9s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (51 files, 81/81 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified mechanically: of the 81 added lines, all 81 match uses: …@<40-hex> # <version> — no shell/logic edits anywhere.

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action e0cf66d v1.0.182 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action abd2ef4 v4.5.1
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1

Deltas since the last sync / PR body:

  • claude-code-action advanced to v1.0.182 (e0cf66d) (body says v1.0.181). Consistent across all references — the # v1.0.182 pin in ai-pr-review/action.yml and the # v1 float-tag comments in the claude*.yaml / claude-code-review.yaml workflows all point at the same commit.
  • docker/login-action advanced to v4.5.1 (abd2ef4) (body table says v4.5.0). Single reference, consistent.
  • The sync also carries checkout v6.1.0 and action-actionlint v1.73.0 (minor, vs the patch bumps the body implies) and configure-aws-credentials v6.2.3. All trusted, SHA-pinned actions.

Confirmed no stale pin from this bump survives in any executable workflow/action YAML (grepped all 13 replaced SHAs across .github/**/*.y{,a}ml — zero hits).

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release, root README.md) and in .claude/skills/github-actions-dev/SKILL.md. None are executed; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

@renovate
renovate Bot force-pushed the renovate/github-actions branch from 3009243 to c40ffd6 Compare July 25, 2026 02:15
@github-actions

github-actions Bot commented Jul 25, 2026

Copy link
Copy Markdown

Claude finished @renovate[bot]'s task in 1m 2s —— View job


Review: Renovate dependency bump (re-review after sync)

  • Read full diff (51 files, 81/81 changed lines — all pinned uses: references, zero logic changes)
  • Verify SHA-pin consistency across the .github/ tree
  • Check for bugs / security / risky jumps

Findings

No bugs, security issues, or performance problems. Clean SHA-pin bump across trusted, already-pinned actions. Verified mechanically: every added line is a uses: …@<40-hex> # <version> pin — no shell/logic edits anywhere. (Pre-existing double-space-before-comment formatting on a few dorny/paths-filter, setup-go, setup-node, slack-github-action lines is untouched by this PR.)

Every executable reference in .github/ resolves to exactly one SHA per action — no split-brain pins:

Action SHA Version
actions/checkout d23441a v6.1.0
actions/setup-go 924ae3a v6.5.0
actions/setup-node 2499707 v6.5.0
anthropics/claude-code-action be7b93b v1.0.183 / # v1
openai/codex-action 52fe01e v1.11
azure/setup-helm 9bc31f4 v5.0.1
aws-actions/configure-aws-credentials e6de054 v6.2.3
docker/login-action abd2ef4 v4.5.1
dorny/paths-filter 7b450ff v4.0.2
reviewdog/action-actionlint 5084226 v1.73.0
slackapi/slack-github-action 0d95c9a v3.0.5
ci-test-notify b5a50da ci-test-notify/v1
validate-renovate.yaml c40c1db validate-renovate/v1

Deltas since the last sync / PR body:

  • claude-code-action advanced to v1.0.183 (be7b93b) (body says v1.0.182 / e0cf66d). Consistent across all 4 references — the # v1.0.183 pin in .github/actions/ai-pr-review/action.yml:98 and the # v1 float-tag comments in claude.yaml:30, claude.yml:36, claude-code-review.yaml:54 all point at the same commit. No mismatch.
  • The sync also carries checkout v6.1.0 and action-actionlint v1.73.0 (minor, vs the patch bumps the body table implies), plus configure-aws-credentials v6.2.3 and docker/login-action v4.5.1. All trusted, SHA-pinned actions.

Confirmed no stale pin survives: all 13 replaced SHAs were grepped across .github/**/*.y{,a}ml — zero hits.

Minor (non-blocking)

Doc drift only — the old checkout pin de0fac2 # v6.0.2 still appears in README example snippets (checkov, go-licenses, govulncheck, publish-helm-chart, subtree-mirror, vcluster-release, root README.md) and in .claude/skills/github-actions-dev/SKILL.md. None are executed; Renovate doesn't rewrite doc examples. Worth a periodic sweep but nothing to block on.

Verification scope

Confirmed internal consistency across the repo. I could not cryptographically confirm each tag→SHA mapping against GitHub (network blocked in this sandbox). SHAs come from Renovate's digest resolution and version comments are consistent, so risk is low; a tag→SHA spot-check is left to the maintainer if desired.

Recommendation: Safe to merge — patch/minor bumps across trusted, already-pinned actions.
• branch renovate/github-actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants