Skip to content

chore(deps): bump all rate-limited and major dependencies - #380

Merged
yacosta738 merged 3 commits into
mainfrom
copilot/update-cargo-dependencies
Apr 30, 2026
Merged

yacosta738 merged 3 commits into
mainfrom
copilot/update-cargo-dependencies

Conversation

Copilot AI commented Apr 30, 2026 •

Copy link
Copy Markdown
Contributor

Implements all pending Renovate Dependency Dashboard updates — rate-limited, digest, and major upgrades — in a single batch.

Cargo

  • reqwest: 0.13.2 → 0.13.3
  • zip: 8.5.1 → 8.6.0 (lock only; range "8" unchanged)

npm

  • @astrojs/starlight: ^0.38.2 → ^0.38.4
  • @iconify/json: ^2.2.456 → ^2.2.468
  • @biomejs/biome: 2.4.12 → 2.4.13
  • lefthook: ^2.1.4 → ^2.1.6
  • typescript: ^6.0.0 → ^6.0.3
  • pnpm-workspace.yaml catalog: @dallay/agentsync 1.42.3 → 1.42.10

Dockerfile

  • Build base: rust:1.94-alpine → rust:1.95-alpine

GitHub Actions — digest/patch

Action Before After
pnpm/action-setup v6.0.0 v6.0.3 (903f9c1a) — 3 workflows
actions/setup-node v6.3.0 v6.4.0 (48b55a01) — deploy-docs.yml

GitHub Actions — major upgrades

  • googleapis/release-please-action: v4.4.1 → v5.0.0 (breaking: Node 24 runtime only)
  • SonarSource/sonarqube-scan-action: v7.1 → v8.0.0 (breaking: skipSignatureVerification now defaults to false)
  • dallay/common-actions: v1 → v2 across 8 workflow files (breaking: callers must rename repo secret APP_ID → APP_CLIENT_ID)

⚠️ dallay/common-actions@v2 requires renaming the GitHub App secret from APP_ID to APP_CLIENT_ID in org/repo settings — workflows use secrets: inherit so no YAML change is needed beyond the version bump.

Copilot AI linked an issue Apr 30, 2026 that may be closed by this pull request
10 tasks
- reqwest: 0.13.2 → 0.13.3
- zip: 8.5.1 → 8.6.0 (Cargo.lock)
- @astrojs/starlight: ^0.38.2 → ^0.38.4
- @iconify/json: ^2.2.456 → ^2.2.468
- @biomejs/biome: 2.4.12 → 2.4.13
- lefthook: ^2.1.4 → ^2.1.6
- typescript: ^6.0.0 → ^6.0.3
- pnpm-workspace.yaml @dallay/agentsync catalog: 1.42.3 → 1.42.10
- Dockerfile: rust:1.94-alpine → rust:1.95-alpine
- pnpm/action-setup: v6.0.0 → v6.0.3 (3 workflows)
- actions/setup-node: v6.3.0 → v6.4.0 (deploy-docs.yml)
- googleapis/release-please-action: v4.4.1 → v5.0.0 (major)
- SonarSource/sonarqube-scan-action: v7.1 → v8.0.0 (major)
- dallay/common-actions: v1 → v2 (7 workflows, major)

Agent-Logs-Url: https://github.com/dallay/agentsync/sessions/8aa7ee44-5438-4012-b492-756b08349296

Co-authored-by: yacosta738 <33158051+yacosta738@users.noreply.github.com>
Copilot AI changed the title [WIP] Update cargo dependencies for better compatibility chore(deps): bump all rate-limited and major dependencies Apr 30, 2026
Copilot AI requested a review from yacosta738 April 30, 2026 11:46
@yacosta738
yacosta738 marked this pull request as ready for review April 30, 2026 12:45
@sentry

sentry Bot commented Apr 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud

Copy link
Copy Markdown

@yacosta738
yacosta738 merged commit ccd3d9a into main Apr 30, 2026
26 checks passed
@yacosta738
yacosta738 deleted the copilot/update-cargo-dependencies branch April 30, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔗 Dependency Dashboard

2 participants