Skip to content

chore(deps): bump the github-actions group across 1 directory with 2 updates - #61

Merged
mattinannt merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-b9cec4249f
Oct 6, 2026
Merged

mattinannt merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-b9cec4249f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates in the / directory: ruby/setup-ruby and SonarSource/sonarqube-scan-action.

Updates ruby/setup-ruby from 1.321.0 to 1.324.0

Release notes

Sourced from ruby/setup-ruby's releases.

v1.324.0

What's Changed

Full Changelog: ruby/setup-ruby@v1.323.0...v1.324.0

v1.323.0

What's Changed

Full Changelog: ruby/setup-ruby@v1.322.0...v1.323.0

v1.322.0

What's Changed

Full Changelog: ruby/setup-ruby@v1.321.0...v1.322.0

Commits

Updates SonarSource/sonarqube-scan-action from 6.0.0 to 8.2.2

Release notes

Sourced from SonarSource/sonarqube-scan-action's releases.

v8.2.2

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8.2.1...v8.2.2

v8.2.1

What's Changed

Bug fix

  • SQSCANGHA-156 GPG signature verification fails when temporary directory path is too long

Full Changelog: SonarSource/sonarqube-scan-action@v8.2.0...v8.2.1

v8.2.0

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8...v8.2.0

v8.1.0

What's Changed

Full Changelog: SonarSource/sonarqube-scan-action@v8...v8.1.0

v8.0.0

What's Changed

Breaking change

Full Changelog: SonarSource/sonarqube-scan-action@v7...v8.0.0

v7.2.1

What's Changed

... (truncated)

Commits
  • ba9859e SQSCANGHA-159 Bump undici from 6.24.1 to 6.28.1 (#261)
  • 5bc5285 Rename code-quality teams to code-orchestration in CODEOWNERS
  • ad82103 SQSCANGHA-158 NO-JIRA Bump actions/checkout from 7.0.0 to 7.0.1 (#260)
  • 7451daf SQSCANGHA-157 NO-JIRA Bump actions/setup-node from 6.4.0 to 7.0.0 (#259)
  • 2291811 SQSCANGHA-156 GPG signature verification fails when temporary directory path ...
  • 7cdc154 SQSCANGHA-153 NO-JIRA Bump actions/checkout from 6.0.2 to 7.0.0 (#255)
  • 45f2736 SQSCANGHA-151 Change Code Owners (#254)
  • 7138816 SQSCANGHA-127 Rename downloaded file to .zip before extraction on Windows (#251)
  • 3581139 SQSCANGHA-135 Fix scanner binaries always re-downloaded due to incompatible 4...
  • c9d327c SQSCANGHA-84 Remove outdated wget/curl references
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 2 updates in the / directory: [ruby/setup-ruby](https://github.com/ruby/setup-ruby) and [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action).


Updates `ruby/setup-ruby` from 1.321.0 to 1.324.0
- [Release notes](https://github.com/ruby/setup-ruby/releases)
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb)
- [Commits](ruby/setup-ruby@95ef2b0...a0102e0)

Updates `SonarSource/sonarqube-scan-action` from 6.0.0 to 8.2.2
- [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases)
- [Commits](SonarSource/sonarqube-scan-action@fd88b7d...ba9859e)

---
updated-dependencies:
- dependency-name: ruby/setup-ruby
  dependency-version: 1.324.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: SonarSource/sonarqube-scan-action
  dependency-version: 8.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 22, 2026
@mattinannt
mattinannt added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit b782cb0 Oct 6, 2026
2 of 3 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-b9cec4249f branch October 6, 2026 08:18
itsjavi added a commit that referenced this pull request Oct 6, 2026
Dependabot's group bump (#61) moved it to v8.2.2, which verifies the
scanner's GPG signature against keyservers this harden-runner macOS
runner cannot reach, so the SonarCloud step fails on every run. The
comment above the pin already explains why it is held at v6.0.0. This
restores that pin; it is a no-op once main carries the same revert.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Dhruwang added a commit that referenced this pull request Oct 8, 2026
#61 moved it to v8.2.2, which verifies the scanner's GPG signature against keyservers this
macOS runner cannot reach, so the SonarCloud step fails on every run. Restores the pin the
comment above it describes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant