Skip to content

chore(deps): Update GitHub Actions to latest versions#69

Merged
nerdalytics merged 4 commits intomainfrom
automation/update-github-actions
Jan 28, 2026
Merged

chore(deps): Update GitHub Actions to latest versions#69
nerdalytics merged 4 commits intomainfrom
automation/update-github-actions

Conversation

@github-actions
Copy link
Contributor

Summary

Automatically updates GitHub Actions to their latest SHA-pinned versions.

Outdated GitHub Actions Detected

The following actions have newer versions available:

Action Current Latest Recommended Update
actions/cache v4 v5.0.2 actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2
actions/checkout v4 v6.0.1 actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6.0.1

How to Update

Replace each action reference in your workflow files with the SHA-pinned version shown in the "Recommended Update" column.

Why SHA Pinning?

Pinning to a commit SHA prevents supply chain attacks where a malicious actor could move a tag to point to compromised code. This is the most secure way to reference GitHub Actions.


This issue was automatically generated by the Check Action Versions workflow.


Fixes #68

This PR was automatically generated by the Check Action Versions workflow.

Configure git to sign commits with SSH_SIGNING_KEY secret so automated
commits pass the signed-commits branch protection rule.

Requires: Add SSH private signing key as SSH_SIGNING_KEY repo secret.
Use ssh-keygen to strip passphrase from the key on the ephemeral
runner before signing. Requires SSH_SIGNING_KEY_PASSPHRASE secret.
Updates actions to SHA-pinned versions for security.
See workflow file changes for details.
@github-actions github-actions bot added security Security-related issues dependencies Dependency updates labels Jan 28, 2026
@nerdalytics nerdalytics merged commit f41f7c4 into main Jan 28, 2026
6 checks passed
@nerdalytics nerdalytics deleted the automation/update-github-actions branch January 28, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates security Security-related issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: Outdated GitHub Actions detected

1 participant