Skip to content

chore(deps): update weekly update#19216

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/weekly-update
Open

chore(deps): update weekly update#19216
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/weekly-update

Conversation

@renovate

@renovate renovate Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/checkout action patch v7.0.0v7.0.1
actions/setup-java action minor v5.5.0v5.6.0
eclipse-temurin digest 68868d0201fbb8
eclipse-temurin digest 1eeacc8da9d3a4
eclipse-temurin digest 89dc1a6068a8f9
eclipse-temurin digest 29d6dba51cad80
eclipse-temurin digest 5dc0f37d044c29
eclipse-temurin digest 7302d5966c7f7a
eclipse-temurin digest 2e3bf0b9e32024
eclipse-temurin digest e17748c8d11d0f
eclipse-temurin final digest 7302d5966c7f7a
eclipse-temurin stage digest 29d6dba51cad80
github/codeql-action action patch v4.37.0v4.37.2
graalvm/setup-graalvm action patch v1.6.2v1.6.3
jdx/mise-action action patch v4.2.0v4.2.1
mcr.microsoft.com/windows/servercore stage digest a23b350b841bb0
ubuntu final digest b7f48193131b4c

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

actions/setup-java (actions/setup-java)

v5.6.0

Compare Source

What's Changed

Full Changelog: actions/setup-java@v5...v5.6.0

github/codeql-action (github/codeql-action)

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019
graalvm/setup-graalvm (graalvm/setup-graalvm)

v1.6.3

Compare Source

jdx/mise-action (jdx/mise-action)

v4.2.1: : Signed checksums and PATH export fix

Compare Source

A small patch release with two user-facing fixes: mise downloads are now verified against minisign-signed release checksums by default, and the env input no longer leaks the runner's PATH into subsequent steps.

Fixed
Verify mise downloads with signed checksums (#​548) by @​jdx

The action now embeds mise's minisign public key and verifies SHASUMS256.txt.minisig before trusting any release checksums, then checks the downloaded mise binary's SHA256 against the verified list. This applies to both GitHub release archives (verified before extraction) and the default mise.jdx.dev CDN path (verified against the signed checksum for the matching release asset). If a CDN download fails verification, the action warns and falls back to the signed GitHub release asset instead of installing an unverified binary.

  • The existing sha256 input still works as an explicit override.
  • Pinned mise versions older than 2024.12.24 (which predate minisign checksums) get a warning and skip signed verification rather than failing.
  • Because tar installs now extract from a verified file on disk, the previous streaming download | tar fast path is replaced with a download-then-verify-then-extract flow.

Thanks to @​potiuk for the detailed threat-model writeup in #​547.

Exclude PATH from environment export (#​556) by @​jdx

The env input has always documented that "PATH modifications are not part of this", but since the switch to mise env --json in #​252 (needed for redaction support), the action was exporting every string value returned by mise — including the computed PATH — into GITHUB_ENV. That effectively snapshotted the runner's entire PATH into subsequent steps and let [env] _.path entries in mise.toml leak past the action's own PATH management.

exportMiseEnv now skips PATH (case-insensitive) when exporting JSON env vars, restoring the documented behavior. Normal mise env vars are still exported, and PATH continues to be managed by the action's own setup (e.g. add_shims_to_path). Fixes #​555.

Full Changelog: jdx/mise-action@v4.2.0...v4.2.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 07:59 AM, only on Tuesday (* 0-7 * * 2)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner July 14, 2026 04:45
Copilot AI review requested due to automatic review settings July 14, 2026 04:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot can't review bot-authored pull requests automatically. A user with Copilot access can request a review manually.

@renovate renovate Bot changed the title chore(deps): update actions/setup-node action to v6.5.0 chore(deps): update actions/setup-node action to v6.5.0 - autoclosed Jul 14, 2026
@renovate renovate Bot closed this Jul 14, 2026
@renovate
renovate Bot deleted the renovate/weekly-update branch July 14, 2026 05:17
@renovate renovate Bot changed the title chore(deps): update actions/setup-node action to v6.5.0 - autoclosed chore(deps): update weekly update Jul 21, 2026
@renovate renovate Bot reopened this Jul 21, 2026
@renovate
renovate Bot force-pushed the renovate/weekly-update branch 2 times, most recently from c84169a to dcfb0af Compare July 21, 2026 04:52

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

zizmor found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@opentelemetry-pr-dashboard

opentelemetry-pr-dashboard Bot commented Jul 21, 2026

Copy link
Copy Markdown

Pull request dashboard status

Status last refreshed: 2026-07-22 01:50:00 UTC.

  • Waiting on: Reviewers
  • Next step: Review the latest changes.

This automated status or its linked feedback items may be incorrect. If something looks wrong, report it with the result you expected.

@renovate
renovate Bot force-pushed the renovate/weekly-update branch from dcfb0af to 4f97edf Compare July 21, 2026 15:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants