Skip to content

Bump the github-actions group across 1 directory with 3 updates - #543

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-7bda3a0bb7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-7bda3a0bb7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 3 updates in the / directory: super-linter/super-linter/slim, super-linter/super-linter and PSModule/Invoke-ScriptAnalyzer.

Updates super-linter/super-linter/slim from 8.7.0 to 9.0.0

Release notes

Sourced from super-linter/super-linter/slim's releases.

v9.0.0

9.0.0 (2026-10-01)

⚠ BREAKING CHANGES

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • all: add dependency cooldowns (#7990) (123c30b)
  • bundler: bump rubocop (#8051) (8439a0b)
  • bundler: bump rubocop (#8124) (c55d5ad)
  • bundler: bump rubocop-minitest (#8005) (29e2320)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#7977) (fe04526)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#8085) (5d61d4a)
  • docker: bump python (#8048) (6c757dc)
  • docker: bump scalameta/scalafmt in the docker group (#8001) (07267f1)
  • docker: bump terraform-linters/tflint in the docker group (#8006) (260eccc)
  • docker: bump the docker group across 1 directory with 10 updates (#7997) (f89bfb7)
  • docker: bump the docker group across 1 directory with 13 updates (#8091) (2066911)
  • docker: bump the docker group across 1 directory with 5 updates (#8141) (0c4e34c)
  • docker: bump the docker group across 1 directory with 6 updates (#8050) (7d5c0e4)
  • docker: bump the docker group across 1 directory with 9 updates (#8118) (8a24b4b)
  • java: bump com.puppycrawl.tools:checkstyle (#7969) (a363fc9)
  • java: bump com.puppycrawl.tools:checkstyle (#7996) (b27705a)
  • java: bump com.puppycrawl.tools:checkstyle (#8026) (541db66)
  • java: bump com.puppycrawl.tools:checkstyle (#8075) (921de44)
  • java: bump the java-gradle group across 2 directories with 2 updates (#8060) (7ff6f35)
  • npm: bump @​stoplight/spectral-cli in /dependencies (#7973) (1779ac9)

... (truncated)

Changelog

Sourced from super-linter/super-linter/slim's changelog.

Changelog

9.0.0 (2026-10-01)

⚠ BREAKING CHANGES

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • all: add dependency cooldowns (#7990) (123c30b)
  • bundler: bump rubocop (#8051) (8439a0b)
  • bundler: bump rubocop (#8124) (c55d5ad)
  • bundler: bump rubocop-minitest (#8005) (29e2320)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#7977) (fe04526)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#8085) (5d61d4a)
  • docker: bump python (#8048) (6c757dc)
  • docker: bump scalameta/scalafmt in the docker group (#8001) (07267f1)
  • docker: bump terraform-linters/tflint in the docker group (#8006) (260eccc)
  • docker: bump the docker group across 1 directory with 10 updates (#7997) (f89bfb7)
  • docker: bump the docker group across 1 directory with 13 updates (#8091) (2066911)
  • docker: bump the docker group across 1 directory with 5 updates (#8141) (0c4e34c)
  • docker: bump the docker group across 1 directory with 6 updates (#8050) (7d5c0e4)
  • docker: bump the docker group across 1 directory with 9 updates (#8118) (8a24b4b)
  • java: bump com.puppycrawl.tools:checkstyle (#7969) (a363fc9)
  • java: bump com.puppycrawl.tools:checkstyle (#7996) (b27705a)
  • java: bump com.puppycrawl.tools:checkstyle (#8026) (541db66)
  • java: bump com.puppycrawl.tools:checkstyle (#8075) (921de44)
  • java: bump the java-gradle group across 2 directories with 2 updates (#8060) (7ff6f35)

... (truncated)

Commits

Updates super-linter/super-linter from 8.7.0 to 9.0.0

Release notes

Sourced from super-linter/super-linter's releases.

v9.0.0

9.0.0 (2026-10-01)

⚠ BREAKING CHANGES

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • all: add dependency cooldowns (#7990) (123c30b)
  • bundler: bump rubocop (#8051) (8439a0b)
  • bundler: bump rubocop (#8124) (c55d5ad)
  • bundler: bump rubocop-minitest (#8005) (29e2320)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#7977) (fe04526)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#8085) (5d61d4a)
  • docker: bump python (#8048) (6c757dc)
  • docker: bump scalameta/scalafmt in the docker group (#8001) (07267f1)
  • docker: bump terraform-linters/tflint in the docker group (#8006) (260eccc)
  • docker: bump the docker group across 1 directory with 10 updates (#7997) (f89bfb7)
  • docker: bump the docker group across 1 directory with 13 updates (#8091) (2066911)
  • docker: bump the docker group across 1 directory with 5 updates (#8141) (0c4e34c)
  • docker: bump the docker group across 1 directory with 6 updates (#8050) (7d5c0e4)
  • docker: bump the docker group across 1 directory with 9 updates (#8118) (8a24b4b)
  • java: bump com.puppycrawl.tools:checkstyle (#7969) (a363fc9)
  • java: bump com.puppycrawl.tools:checkstyle (#7996) (b27705a)
  • java: bump com.puppycrawl.tools:checkstyle (#8026) (541db66)
  • java: bump com.puppycrawl.tools:checkstyle (#8075) (921de44)
  • java: bump the java-gradle group across 2 directories with 2 updates (#8060) (7ff6f35)
  • npm: bump @​stoplight/spectral-cli in /dependencies (#7973) (1779ac9)

... (truncated)

Changelog

Sourced from super-linter/super-linter's changelog.

Changelog

9.0.0 (2026-10-01)

⚠ BREAKING CHANGES

🚀 Features

🐛 Bugfixes

⬆️ Dependency updates

  • all: add dependency cooldowns (#7990) (123c30b)
  • bundler: bump rubocop (#8051) (8439a0b)
  • bundler: bump rubocop (#8124) (c55d5ad)
  • bundler: bump rubocop-minitest (#8005) (29e2320)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#7977) (fe04526)
  • bundler: bump the rubocop group across 1 directory with 3 updates (#8085) (5d61d4a)
  • docker: bump python (#8048) (6c757dc)
  • docker: bump scalameta/scalafmt in the docker group (#8001) (07267f1)
  • docker: bump terraform-linters/tflint in the docker group (#8006) (260eccc)
  • docker: bump the docker group across 1 directory with 10 updates (#7997) (f89bfb7)
  • docker: bump the docker group across 1 directory with 13 updates (#8091) (2066911)
  • docker: bump the docker group across 1 directory with 5 updates (#8141) (0c4e34c)
  • docker: bump the docker group across 1 directory with 6 updates (#8050) (7d5c0e4)
  • docker: bump the docker group across 1 directory with 9 updates (#8118) (8a24b4b)
  • java: bump com.puppycrawl.tools:checkstyle (#7969) (a363fc9)
  • java: bump com.puppycrawl.tools:checkstyle (#7996) (b27705a)
  • java: bump com.puppycrawl.tools:checkstyle (#8026) (541db66)
  • java: bump com.puppycrawl.tools:checkstyle (#8075) (921de44)
  • java: bump the java-gradle group across 2 directories with 2 updates (#8060) (7ff6f35)

... (truncated)

Commits

Updates PSModule/Invoke-ScriptAnalyzer from 5.0.0 to 5.0.1

Release notes

Sourced from PSModule/Invoke-ScriptAnalyzer's releases.

v5.0.1

🪲 [Fix]: Configured report paths are honored (#42)

Configured TestResult_OutputPath and CodeCoverage_OutputPath values now reach Invoke-Pester unchanged, so enabled reports are written to the locations selected by the caller. Callers that leave either input empty retain the existing Invoke-Pester fallback path relative to WorkingDirectory.

Fixed: Configured report paths

The action now uses Invoke-Pester v5.1.1, which honors configured report output paths and keeps its action-private temporary state outside the caller worktree. Set either input independently when that report needs a custom destination; the other report continues to use its configured or default behavior.

with:
  TestResult_OutputPath: artifacts/TestResult/results.xml
  CodeCoverage_OutputPath: artifacts/CodeCoverage/coverage.xml

Adopting this release

  1. Select the release containing this fix in the PSModule/Invoke-ScriptAnalyzer workflow reference.
  2. Existing callers that leave both output-path inputs empty need no configuration, code, or invocation changes; reports continue to use the established Invoke-Pester defaults below WorkingDirectory.
  3. Existing callers that already set TestResult_OutputPath or CodeCoverage_OutputPath need no configuration change; the configured location is now honored. Set either input when a report should use a new custom destination.

Release impact

Field Value
Effective decision release:patch, selected for a backward-compatible report-path correction.
Semantic effect Patch, stable; configured output paths now work as documented and omitted inputs retain their prior behavior.
Release/base coordinates Final coordinates are resolved by the release process at publication. The published record supplies the target version, tag, immutable source, version-computation base, and release/source baseline.

Consumer change record

Identifier / surface Before After Applicability / prerequisites Consumer action Verification
REPORT-PATH-OVERRIDE / TestResult_OutputPath, CodeCoverage_OutputPath Invoke-Pester v5.1.0 overwrote values forwarded by this action, so configured destinations were not used. Invoke-Pester v5.1.1 retains each configured path. Empty inputs retain TestResult/PSScriptAnalyzer-TestResult-Report.xml and CodeCoverage/PSScriptAnalyzer-CodeCoverage-Report.xml below WorkingDirectory. Callers that enable test-result or code-coverage reports. Select this release. No change is needed for existing configured paths or omitted inputs; optionally set either input to choose a destination. The action-test suite verifies explicit generic artifacts/... paths, XML and JSON report creation, absence of legacy root report and .temp directories for the explicit case, and preserved fallback paths when inputs are omitted.

Template baseline

Not applicable. This composite action does not consume an integration template. Downstream framework adoption is tracked separately in PSModule/Process-PSModule#541.

Maintainer evidence

  • action.yml pins the published Invoke-Pester v5.1.1 fix to immutable commit c5494aba3c07d7bfd81bdbbc9f301e8fa4a729fb.
  • The focused action-test jobs cover both explicit overrides and omitted-input fallback behavior; tests/Assert-ReportPaths.ps1 verifies generated XML and JSON reports and expected directory isolation.
  • README.md documents the preserved fallback behavior and generic explicit override example.
  • Implementation plan progress: complete. The report-path regression was made red against v5.1.0 before the dependency was updated, then passed with v5.1.1.
  • Standards and framework alignment: reviewed GitHub Actions dependency pinning, action input contracts, PowerShell test conventions, and Markdown documentation; aligned.

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 3 updates in the / directory: [super-linter/super-linter/slim](https://github.com/super-linter/super-linter), [super-linter/super-linter](https://github.com/super-linter/super-linter) and [PSModule/Invoke-ScriptAnalyzer](https://github.com/psmodule/invoke-scriptanalyzer).


Updates `super-linter/super-linter/slim` from 8.7.0 to 9.0.0
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@4ce2083...2da1369)

Updates `super-linter/super-linter` from 8.7.0 to 9.0.0
- [Release notes](https://github.com/super-linter/super-linter/releases)
- [Changelog](https://github.com/super-linter/super-linter/blob/main/CHANGELOG.md)
- [Commits](super-linter/super-linter@4ce2083...2da1369)

Updates `PSModule/Invoke-ScriptAnalyzer` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/psmodule/invoke-scriptanalyzer/releases)
- [Commits](PSModule/Invoke-ScriptAnalyzer@4d633e4...9acddbd)

---
updated-dependencies:
- dependency-name: super-linter/super-linter/slim
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: super-linter/super-linter
  dependency-version: 9.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: PSModule/Invoke-ScriptAnalyzer
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code Major labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Super-linter summary

Language Validation result
CHECKOV Pass ✅
CSS Pass ✅
CSS_PRETTIER Pass ✅
GITHUB_ACTIONS Pass ✅
GITHUB_ACTIONS_ZIZMOR Fail ❌
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
HTML Pass ✅
JAVASCRIPT_ES Pass ✅
JAVASCRIPT_PRETTIER Pass ✅
MARKDOWN Pass ✅
NATURAL_LANGUAGE Pass ✅
POWERSHELL Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
TRIVY Pass ✅
YAML Pass ✅

Super-linter detected linting errors

For more information, see the GitHub Actions workflow run

Powered by Super-linter
Super-linter revision: 2da136927bd4a73596db63044b504547c62cb854
Super-linter version: 9.0.0

GITHUB_ACTIONS_ZIZMOR
�[1m�[96mhelp[self-repository]�[0m�[1m: use GitHub's dedicated self-repository syntax�[0m
  �[1m�[94m--> �[0m/github/workspace/.github/workflows/Docs.yml:76:15
   �[1m�[94m|�[0m
�[1m�[94m74�[0m �[1m�[94m|�[0m       - name: Update index
   �[1m�[94m|�[0m         �[1m�[94m------------------�[0m �[1m�[94mthis step�[0m
�[1m�[94m75�[0m �[1m�[94m|�[0m         if: github.event_name != 'pull_request' && github.ref == 'refs/heads/main'
�[1m�[94m76�[0m �[1m�[94m|�[0m         uses: ./.github/actions/update-index
   �[1m�[94m|�[0m               �[1m�[96m^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^�[0m �[1m�[96muse '$/...' instead of './...'�[0m
   �[1m�[94m|�[0m
   �[1m�[94m= �[0m�[1mnote�[0m: audit confidence → High
   �[1m�[94m= �[0m�[1mnote�[0m: this finding has an auto-fix
   �[1m�[94m= �[0m�[1mhelp�[0m: audit documentation → �[32mhttps://docs.zizmor.sh/audits/#self-repository�[39m

�[32m3�[39m findings (�[1m�[93m2�[39m suppressed, �[91m1�[39m unsafe fixes�[0m): �[35m0�[39m informational, �[36m1�[39m low, �[33m0�[39m medium, �[31m0�[39m high�[32m INFO�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 zizmor v1.30.1
�[32m INFO�[0m �[1maudit�[0m�[2m:�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 completed /github/workspace/.github/actions/update-index/action.yml
�[32m INFO�[0m �[1maudit�[0m�[2m:�[0m �[2mzizmor�[0m�[2m:�[0m 🌈 completed /github/workspace/.github/workflows/Docs.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code Major

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants