Skip to content

Bump the actions group with 9 updates - #2792

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions-4ea7a2c34c
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions-4ea7a2c34c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown

Bumps the actions group with 9 updates:

Package From To
huggingface/doc-builder/.github/workflows/build_main_documentation.yml bcff59fca682130d2e7271ca8589911b7ac0b8bf 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
huggingface/doc-builder/.github/workflows/build_pr_documentation.yml bcff59fca682130d2e7271ca8589911b7ac0b8bf 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml bcff59fca682130d2e7271ca8589911b7ac0b8bf 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
actions/checkout 6.0.2 7.0.1
actions/setup-node 3.9.1 7.0.0
pnpm/action-setup 2.4.1 6.1.0
peter-evans/create-pull-request 7.0.11 8.1.1
actions-cool/maintain-one-comment 4b2dbf086015f892dcb5e8c1106f5fccd6c1476b 0bff3c7c0b1ab0fe95273f6b65194f748a798adb
trufflesecurity/trufflehog 3.94.2 3.97.4

Updates huggingface/doc-builder/.github/workflows/build_main_documentation.yml from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/build_main_documentation.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates huggingface/doc-builder/.github/workflows/build_pr_documentation.yml from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/build_pr_documentation.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates actions/checkout from 6.0.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-node from 3.9.1 to 7.0.0

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Updates pnpm/action-setup from 2.4.1 to 6.1.0

Release notes

Sourced from pnpm/action-setup's releases.

v6.1.0

What's Changed

Full Changelog: pnpm/action-setup@v6.0.10...v6.1.0

v6.0.10

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6...v6.0.10

v6.0.9

What's Changed

Full Changelog: pnpm/action-setup@v6...v6.0.9

v6.0.8

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6.0.7...v6.0.8

v6.0.7

What's Changed

New Contributors

Full Changelog: pnpm/action-setup@v6.0.6...v6.0.7

... (truncated)

Commits

Updates peter-evans/create-pull-request from 7.0.11 to 8.1.1

Release notes

Sourced from peter-evans/create-pull-request's releases.

Create Pull Request v8.1.1

What's Changed

Full Changelog: peter-evans/create-pull-request@v8.1.0...v8.1.1

Create Pull Request v8.1.0

What's Changed

New Contributors

Full Changelog: peter-evans/create-pull-request@v8.0.0...v8.1.0

Create Pull Request v8.0.0

What's new in v8

What's Changed

New Contributors

Full Changelog: peter-evans/create-pull-request@v7.0.11...v8.0.0

Commits
  • 5f6978f fix: retry post-creation API calls on 422 eventual consistency errors (#4356)
  • d32e88d build(deps-dev): bump the npm group with 3 updates (#4349)
  • 8170bcc build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#4344)
  • 0041819 build(deps): bump picomatch (#4339)
  • b993918 build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (#4334)
  • 36d7c84 build(deps-dev): bump undici from 6.23.0 to 6.24.0 (#4328)
  • a45d1fb build(deps): bump @​tootallnate/once and jest-environment-jsdom (#4323)
  • 3499eb6 build(deps): bump the github-actions group with 2 updates (#4316)
  • 3f3b473 build(deps): bump minimatch (#4311)
  • 6699836 build(deps-dev): bump the npm group with 2 updates (#4305)
  • Additional commits viewable in compare view

Updates actions-cool/maintain-one-comment from 4b2dbf086015f892dcb5e8c1106f5fccd6c1476b to 0bff3c7c0b1ab0fe95273f6b65194f748a798adb

Changelog

Sourced from actions-cool/maintain-one-comment's changelog.

Changelog

v3.3.0

2026.04.11

  • 🚀 chore: bump node to 24.

v3.2.0

2024.05.22

  • 🚀 feat: get pr number for workflow_run & up Node 20. #9 @​sxzz

v3.1.1

2023.09.01

v3.1.0

2023.06.30

v3.0.0

2022.08.01

  • refactor: add default body-include.
  • feat: add delete.

v2.0.2

2021.10.19

  • ⚡️ chore: add pub.

... (truncated)

Commits

Updates trufflesecurity/trufflehog from 3.94.2 to 3.97.4

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.4

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.3...v3.97.4

v3.97.3

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.2...v3.97.3

v3.97.2

What's Changed

Bumps the actions group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) | `bcff59fca682130d2e7271ca8589911b7ac0b8bf` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `bcff59fca682130d2e7271ca8589911b7ac0b8bf` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `bcff59fca682130d2e7271ca8589911b7ac0b8bf` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.1` |
| [actions/setup-node](https://github.com/actions/setup-node) | `3.9.1` | `7.0.0` |
| [pnpm/action-setup](https://github.com/pnpm/action-setup) | `2.4.1` | `6.1.0` |
| [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) | `7.0.11` | `8.1.1` |
| [actions-cool/maintain-one-comment](https://github.com/actions-cool/maintain-one-comment) | `4b2dbf086015f892dcb5e8c1106f5fccd6c1476b` | `0bff3c7c0b1ab0fe95273f6b65194f748a798adb` |
| [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.94.2` | `3.97.4` |


Updates `huggingface/doc-builder/.github/workflows/build_main_documentation.yml` from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@bcff59f...17ccdf1)

Updates `huggingface/doc-builder/.github/workflows/build_pr_documentation.yml` from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@bcff59f...17ccdf1)

Updates `huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml` from bcff59fca682130d2e7271ca8589911b7ac0b8bf to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@bcff59f...17ccdf1)

Updates `actions/checkout` from 6.0.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...3d3c42e)

Updates `actions/setup-node` from 3.9.1 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@3235b87...8207627)

Updates `pnpm/action-setup` from 2.4.1 to 6.1.0
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@eae0cfe...ea17c68)

Updates `peter-evans/create-pull-request` from 7.0.11 to 8.1.1
- [Release notes](https://github.com/peter-evans/create-pull-request/releases)
- [Commits](peter-evans/create-pull-request@22a9089...5f6978f)

Updates `actions-cool/maintain-one-comment` from 4b2dbf086015f892dcb5e8c1106f5fccd6c1476b to 0bff3c7c0b1ab0fe95273f6b65194f748a798adb
- [Changelog](https://github.com/actions-cool/maintain-one-comment/blob/main/CHANGELOG.md)
- [Commits](actions-cool/maintain-one-comment@4b2dbf0...0bff3c7)

Updates `trufflesecurity/trufflehog` from 3.94.2 to 3.97.4
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@6bd2d14...363923b)

---
updated-dependencies:
- dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: pnpm/action-setup
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: peter-evans/create-pull-request
  dependency-version: 8.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions-cool/maintain-one-comment
  dependency-version: 0bff3c7c0b1ab0fe95273f6b65194f748a798adb
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 17, 2026
Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants