Skip to content

build(deps): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml from 0.1.13 to 0.1.16 - #419

Merged
rldyourmnd merged 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-codeql.yml-0.1.16
Sep 8, 2026
Merged

build(deps): bump NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml from 0.1.13 to 0.1.16#419
rldyourmnd merged 1 commit into
mainfrom
dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-codeql.yml-0.1.16

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml from 0.1.13 to 0.1.16.

Release notes

Sourced from NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml's releases.

0.1.16

  • security-bundle authenticates its exact called-workflow source fetch with the job token, so a shared fleet egress address cannot exhaust GitHub's anonymous allowance and stop the gate before any scanner runs.

0.1.14

  • Enable Corepack's pnpm and Yarn shims before activating the caller-pinned package-manager version, so hosted Node jobs resolve the requested binary instead of finding no pnpm or the image's unrelated Yarn Classic install.
Changelog

Sourced from NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml's changelog.

Changelog

This file is a release ledger: every heading below is a real release, and scripts/check_release_ledger.py enforces that in both directions.

The project follows Semantic Versioning.

[Unreleased]

  • Publish unsuccessful completed self-workflow attempts as unassigned, repository-local CI evidence; preserve actual conclusions and exact attempts.

  • Accept exact matching development-commit comments and correct nested action pin validation and container whitespace rejection. Keep registrations scoped to their actual action paths.

  • Declare both git-submodule and reusable-workflow consumption in the GDS module contract. Refresh its projection using the existing stable bundle.

  • Place the Docker publisher permission explanation inline so the pinned pedantic audit recognizes it; workflow permissions and behavior are unchanged.

[0.1.16] - 2026-09-02

  • security-bundle authenticates its exact called-workflow source fetch with the job token, so a shared fleet egress address cannot exhaust GitHub's anonymous allowance and stop the gate before any scanner runs.

[0.1.15] - 2026-08-31

  • docker-build.yml: reusable BuildKit image build whose layer cache outlives the runner (registry cache on ghcr by default, gha and none backends), registered across the catalog with an infra example.
  • security-bundle (free): the called-workflow source fetch retries and falls back to protocol v0, and evidence uploads only when the scan ran.
  • Dependabot pin-registry synchronization for the bumped action set.

[0.1.14] - 2026-08-30

  • Enable Corepack's pnpm and Yarn shims before activating the caller-pinned package-manager version, so hosted Node jobs resolve the requested binary instead of finding no pnpm or the image's unrelated Yarn Classic install.

[0.1.13] - 2026-08-27

  • Added an optional dedicated runner for Docker-based cargo-deny so cargo-audit and cargo-machete can use a lighter runner without weakening supply-chain coverage.

[0.1.12] - 2026-08-27

  • The signed 0.1.12 tag is retained as immutable rejected evidence because its candidate changelog used the next local-calendar date rather than the

... (truncated)

Commits
  • a285efa Merge pull request #85 from NDDev-OpenNetwork/chore/release-0.1.16
  • d3c4575 chore(release): prepare ci-workflows 0.1.16
  • e90a2c7 Merge pull request #84 from NDDev-OpenNetwork/fix/called-workflow-fetch-carri...
  • d58b89f fix(security-bundle): the called-workflow fetch carries the job token
  • 1ab6708 Merge pull request #83 from NDDev-OpenNetwork/fix/authenticated-self-fetch
  • 86170c0 fix(security): the self-fetch authenticates, and the ledger names 0.1.15
  • d67c0d0 Merge pull request #82 from NDDev-OpenNetwork/chore/bundle-0.8.0
  • 6f4449f chore(gds): promote stable bundle 0.8.0
  • 007f5a6 Merge pull request #81 from NDDev-OpenNetwork/feat/tool-source-baked
  • f155284 feat(actionlint): tool_source picks the baked surface over a download
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-codeql.yml-0.1.16 branch from dec9291 to 9d221ff Compare September 7, 2026 02:48
…blic-codeql.yml

Bumps [NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml](https://github.com/nddev-opennetwork/ci-workflows) from 0.1.13 to 0.1.16.
- [Release notes](https://github.com/nddev-opennetwork/ci-workflows/releases)
- [Changelog](https://github.com/NDDev-OpenNetwork/ci-workflows/blob/main/CHANGELOG.md)
- [Commits](NDDev-OpenNetwork/ci-workflows@dfdad5c...a285efa)

---
updated-dependencies:
- dependency-name: NDDev-OpenNetwork/ci-workflows/.github/workflows/public-codeql.yml
  dependency-version: 0.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-codeql.yml-0.1.16 branch from 9d221ff to c1b351f Compare September 7, 2026 06:29
@rldyourmnd
rldyourmnd merged commit a57584e into main Sep 8, 2026
10 checks passed
@rldyourmnd
rldyourmnd deleted the dependabot/github_actions/NDDev-OpenNetwork/ci-workflows/dot-github/workflows/public-codeql.yml-0.1.16 branch September 8, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant