From ada16f1bf4287038d0400235a59abdf5b10f2098 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 24 Aug 2026 01:32:18 +0000 Subject: [PATCH 1/2] Bump gopkg.in/yaml.v3 from 3.0.0 to 3.0.1 Bumps gopkg.in/yaml.v3 from 3.0.0 to 3.0.1. --- updated-dependencies: - dependency-name: gopkg.in/yaml.v3 dependency-version: 3.0.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 6024d1dd..0758dce4 100644 --- a/go.mod +++ b/go.mod @@ -29,5 +29,5 @@ require ( gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15 // indirect gopkg.in/ini.v1 v1.66.2 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect - gopkg.in/yaml.v3 v3.0.0 // indirect + gopkg.in/yaml.v3 v3.0.1 // indirect ) diff --git a/go.sum b/go.sum index 4c150275..1113cf48 100644 --- a/go.sum +++ b/go.sum @@ -772,8 +772,8 @@ gopkg.in/yaml.v2 v2.4.0 h1:D8xgwECY7CYvx+Y2n4sBz93Jn9JRvxdiyyo8CTfuKaY= gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -gopkg.in/yaml.v3 v3.0.0 h1:hjy8E9ON/egN1tAYqKb61G10WtihqetD4sz2H+8nIeA= -gopkg.in/yaml.v3 v3.0.0/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= +gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= +gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gotest.tools v2.2.0+incompatible h1:VsBPFP1AI068pPrMxtb/S8Zkgf9xEmTLJjfM+P5UIEo= gotest.tools v2.2.0+incompatible/go.mod h1:DsYFclhRJ6vuDpmuTbkuFWG+y2sxOXAzmJt81HFBacw= honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= From 259967403179662b819ede3e4896d9f007723768 Mon Sep 17 00:00:00 2001 From: Jeffrey Aven Date: Tue, 25 Aug 2026 07:52:51 +1000 Subject: [PATCH 2/2] ci: drop CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN from upstream checkouts stackql/stackql and stackql/any-sdk are public, so actions/checkout can clone them with the default GITHUB_TOKEN. The explicit PAT input broke Dependabot-triggered runs, which only see the Dependabot secret store ("Input required and not supplied: token"). Co-Authored-By: Claude Fable 5 --- .github/workflows/aot.yml | 2 -- .github/workflows/regression.yml | 3 --- 2 files changed, 5 deletions(-) diff --git a/.github/workflows/aot.yml b/.github/workflows/aot.yml index 32e7dfe4..a0c961ba 100644 --- a/.github/workflows/aot.yml +++ b/.github/workflows/aot.yml @@ -56,7 +56,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core - name: Download any-sdk @@ -64,7 +63,6 @@ jobs: with: repository: ${{ env.STACKQL_ANY_SDK_REPOSITORY }} ref: ${{ env.STACKQL_ANY_SDK_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-any-sdk - name: Setup Python diff --git a/.github/workflows/regression.yml b/.github/workflows/regression.yml index 09b3e7ab..c7a043e3 100644 --- a/.github/workflows/regression.yml +++ b/.github/workflows/regression.yml @@ -35,7 +35,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core-pkg - name: Setup Python @@ -100,7 +99,6 @@ jobs: with: repository: ${{ env.STACKQL_CORE_REPOSITORY }} ref: ${{ env.STACKQL_CORE_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-core - name: Download any-sdk @@ -108,7 +106,6 @@ jobs: with: repository: ${{ env.STACKQL_ANY_SDK_REPOSITORY }} ref: ${{ env.STACKQL_ANY_SDK_REF }} - token: ${{ secrets.CI_STACKQL_PACKAGE_DOWNLOAD_TOKEN }} path: stackql-any-sdk - name: Setup Python