Skip to content

chore(deps): bump github/codeql-action from 3.25.1 to 3.26.0 #40

chore(deps): bump github/codeql-action from 3.25.1 to 3.26.0

chore(deps): bump github/codeql-action from 3.25.1 to 3.26.0 #40

name: Approve and Merge Dependabot's PR
on:
pull_request_target:
types: [opened]
permissions:
pull-requests: write
contents: write
actions: write
jobs:
dependabot:
runs-on: ubuntu-latest
timeout-minutes: 5
if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }}
steps:
- name: Harden Runner
uses: step-security/harden-runner@0d381219ddf674d61a7572ddd19d7941e271515c # v2.9.0
with:
disable-sudo: true
egress-policy: "audit"
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
- name: Dependency Review
uses: actions/dependency-review-action@0c155c5e8556a497adf53f2c18edabf945ed8e70 # v4.3.2
with:
license-check: true
vulnerability-check: true
fail-on-severity: "low"
- name: Fetch Dependabot metadata
uses: dependabot/fetch-metadata@dbb049abf0d677abbd7f7eee0375145b417fdd34 # v2.2.0
with:
alert-lookup: true
compat-lookup: true
github-token: ${{ github.token }}
- name: Approve and Merge PR
uses: fastify/github-action-merge-dependabot@9e7bfb249c69139d7bdcd8d984f9665edd49020b # v3.10.1
with:
approve-only: false
merge-comment: "I'm **approving** this PR because **it includes dependency update**"
use-github-auto-merge: false
release:
name: Publish Release
runs-on: ubuntu-latest
if: ${{ github.event.pull_request.user.login == 'dependabot[bot]' }}
needs: [dependabot]
permissions:
packages: write
contents: write
issues: write
pull-requests: write
steps:
- name: Harden Runner
uses: step-security/harden-runner@0d381219ddf674d61a7572ddd19d7941e271515c # v2.9.0
with:
disable-sudo: true
egress-policy: audit
- name: Checkout
uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
with:
fetch-depth: 0
persist-credentials: false
- name: Semantic Release
uses: cycjimmy/semantic-release-action@cb425203a562475bca039ba4dbf90c7f9ac790f4 #v4.1.0
env:
GITHUB_TOKEN: ${{ github.token }}
with:
extra_plugins: |
conventional-changelog-conventionalcommits@6.1.0
@semantic-release/github@10.1.1