Skip to content

Build: Bump the github-actions group across 1 directory with 6 updates - #44

Merged
scoder merged 1 commit into
masterfrom
dependabot/github_actions/github-actions-7097a79963
Oct 8, 2026
Merged

scoder merged 1 commit into
masterfrom
dependabot/github_actions/github-actions-7097a79963

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 6 updates in the / directory:

Package From To
actions/checkout 6.0.2 7.0.1
actions/setup-python 6.2.0 7.0.0
docker/setup-qemu-action 4.0.0 4.4.0
pypa/cibuildwheel 3.4.1 4.3.0
TheMrMilchmann/setup-msvc-dev 4.0.0 4.1.0
softprops/action-gh-release 3.0.0 3.0.3

Updates actions/checkout from 6.0.2 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-python from 6.2.0 to 7.0.0

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

Commits

Updates docker/setup-qemu-action from 4.0.0 to 4.4.0

Release notes

Sourced from docker/setup-qemu-action's releases.

v4.4.0

Full Changelog: docker/setup-qemu-action@v4.3.0...v4.4.0

v4.3.0

Full Changelog: docker/setup-qemu-action@v4.2.0...v4.3.0

v4.2.0

Full Changelog: docker/setup-qemu-action@v4.1.0...v4.2.0

v4.1.0

Full Changelog: docker/setup-qemu-action@v4.0.0...v4.1.0

Commits
  • 9901266 Merge pull request #342 from docker/dependabot/npm_and_yarn/js-yaml-4.3.2
  • 9364d8b Merge pull request #340 from docker/dependabot/npm_and_yarn/humanfs/node-0.16.8
  • 95c3240 Merge pull request #337 from docker/dependabot/npm_and_yarn/postcss-selector-...
  • c24671a Merge pull request #338 from docker/dependabot/github_actions/codeql-actions-...
  • fa83965 Merge pull request #345 from crazy-max/shared-error-helpers
  • f396a65 build(deps): bump the codeql-actions group across 1 directory with 2 updates
  • a63df2f chore: update generated content
  • 3e4165f use the shared error helper for Docker commands
  • 18c52d9 Merge pull request #344 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • 896cbed [dependabot skip] chore: update generated content
  • Additional commits viewable in compare view

Updates pypa/cibuildwheel from 3.4.1 to 4.3.0

Release notes

Sourced from pypa/cibuildwheel's releases.

v4.3.0

  • ✨ Extends option inheritance to every configuration layer, so global and platform-specific settings can append or prepend to existing values, including cibuildwheel's defaults. Environment variables can also extend earlier settings using CIBW_INHERIT. (#2928)
  • ✨ Adds PyPy 3.12 support and updates PyPy 3.11 to v8.0.0, available with the pypy enable flag (#2998)
  • ✨ Adds GraalPy 3.13 (v25.3) support on Linux, Windows, and macOS arm64, available with the graalpy enable flag (#2982)
  • ✨ Adds log-fold-mode to override CI log folding, including CIBW_LOG_FOLD_MODE=disabled to keep build steps expanded (#2972)
  • ✨ Adds a python-path input to the GitHub Action to choose the Python interpreter used to run cibuildwheel, and falls back to system python3 on runner architectures unsupported by setup-python, such as native riscv64 (#2990)
  • 🐛 Fixes Windows command execution when paths or arguments contain shell metacharacters, including dependency specifiers containing < or > (#2978)
  • 🛠 Improves readability of logged commands whose arguments contain quotes (#2993)
  • 🛠 Updates Pyodide to 0.27.8, 0.29.5, and 314.0.7, and updates its build tooling, including auditwheel-emscripten 0.3.0 (#2996)
  • 🛠 Updates dependencies and container pins, including CPython 3.15.0rc3 (#2986, #3003)
  • 📚 Corrects references to --archs in CLI help, error messages, and documentation (#2992)

v4.2.1

  • 🐛 Respects the NuGet package sources configured on the machine when installing CPython on Windows, instead of always falling back to nuget.org (#2966)
  • 🐛 Fixes a NameError on Pyodide when an already-compatible wheel was reused, which made the test step fail (#2968)
  • 🛠 Updates the Android Python versions, and the Android testbed's Gradle version, making it compatible with Java 25 (#2962)
  • 🛠 Updates dependencies including CPython 3.15.0rc2 (#2965, #2970, #2976, #2981, #2985)

v4.2.0

  • 🌟 CPython 3.15 wheels are now built by default - without the "cpython-prerelease" enable set. It's time to build and upload these wheels to PyPI! This release includes CPython 3.15.0rc1, which is guaranteed to be ABI compatible with the final release. (#2944)
  • ✨ Adds Pyodide 3.15 support with the cp315-pyodide_wasm32 build identifier, using Pyodide 315.0.0a2. These are also stable wrt. the final release. (#2958)
  • 🐛 Retries a failed download six times with exponential backoff, so short network outages no longer stop a build. A 4xx response is still reported at once. (#2953)
  • 🐛 Accepts default as a build-frontend value on Pyodide, and accepts pyodide-build in the top-level table and in overrides (#2951)
  • 🛠 Holds pip back on GraalPy, where newer pip breaks the build (#2955)
  • 🛠 Updates Pyodide to 314.0.4 (#2949, #2952)
  • 🛠 Updates dependencies and container pins (#2952, #2960)
  • 💼 Updates CI action pins (#2948, #2954)
  • 🧪 Uses pp311 for the abi3 test, and deletes test_overridden_pip_constraint, which is not necessary since #2583 (#2956, #2957)

v4.1.1

  • ✨ Adds pyodide-build as a separate build-frontend, now the default frontend for Pyodide, with verbosity flags handling. Any other frontend is ignored with a warning on Pyodide. (#2609, #2945)
  • 🔐 Uses digests instead of tags for pinned container images, strengthening supply-chain security. The human-readable tags remain as comments in pinned_docker_images.cfg. (#2915)
  • 🐛 Fixes platform-specific test-runtime environment variables (e.g. CIBW_TEST_RUNTIME_ANDROID) not being honored (#2941)
  • 🐛 Fixes quoting of test-requires and audit-requires so PEP 508 specifiers containing spaces work (#2913)
  • 🐛 Makes archs parsing case-insensitive and platform-aware, so e.g. arm64 works on Windows (#2920)
  • 🐛 Uses an absolute path for the {project} placeholder in config-settings (#2934)
  • 🐛 Validates the pyodide-version option against the build identifier with a clear error (#2925)
  • 🐛 Fixes PyPy installs on macOS after PyPy switched its downloads from .tar.bz2 to .tar.gz (#2939)
  • 🐛 Makes a matching python3-config available in the build and test venvs on macOS (#2922)
  • 🛠 Updates dependencies and container pins (#2917, #2935, #2939)
  • 🛠 Updates Android tests to current Python versions and the new test repository URL (#2933)
  • 🛠 Drops the orjson dependency, no longer used by mypy 2+ (#2923)
  • 📚 Builds the docs with properdocs, a MkDocs fork (#2946)
  • 📚 Adds the missing cp314-pyodide_wasm32 entry to the build identifier table (#2947)
  • 📚 Removes outdated notes about the pip wheel build frontend and ClearLinux (#2926)
  • 💼 Adds a "CI: PyPy EoL" PR label to run PyPy EoL tests on PRs (#2930)
  • 💼 Updates CI action pins and pre-commit hooks (#2914, #2932, #2938, #2940, #2942, #2943)

v4.1.0

  • ✨ Updates Pyodide to the final 314.0.0 release, so Pyodide 3.14 wheels now build by default without the pyodide-prerelease enable flag. (#2906)

... (truncated)

Changelog

Sourced from pypa/cibuildwheel's changelog.


title: Changelog ref: changelog

Changelog

v4.3.0

5 October 2026

  • ✨ Extends option inheritance to every configuration layer, so global and platform-specific settings can append or prepend to existing values, including cibuildwheel's defaults. Environment variables can also extend earlier settings using CIBW_INHERIT. (#2928)
  • ✨ Adds PyPy 3.12 support and updates PyPy 3.11 to v8.0.0, available with the pypy enable flag (#2998)
  • ✨ Adds GraalPy 3.13 (v25.3) support on Linux, Windows, and macOS arm64, available with the graalpy enable flag (#2982)
  • ✨ Adds log-fold-mode to override CI log folding, including CIBW_LOG_FOLD_MODE=disabled to keep build steps expanded (#2972)
  • ✨ Adds a python-path input to the GitHub Action to choose the Python interpreter used to run cibuildwheel, and falls back to system python3 on runner architectures unsupported by setup-python, such as native riscv64 (#2990)
  • 🐛 Fixes Windows command execution when paths or arguments contain shell metacharacters, including dependency specifiers containing < or > (#2978)
  • 🛠 Improves readability of logged commands whose arguments contain quotes (#2993)
  • 🛠 Updates Pyodide to 0.27.8, 0.29.5, and 314.0.7, and updates its build tooling, including auditwheel-emscripten 0.3.0 (#2996)
  • 🛠 Updates dependencies and container pins, including CPython 3.15.0rc3 (#2986, #3003)
  • 📚 Corrects references to --archs in CLI help, error messages, and documentation (#2992)

v4.2.1

5 September 2026

  • 🐛 Respects the NuGet package sources configured on the machine when installing CPython on Windows, instead of always falling back to nuget.org (#2966)
  • 🐛 Fixes a NameError on Pyodide when an already-compatible wheel was reused, which made the test step fail (#2968)
  • 🛠 Updates the Android Python versions, and the Android testbed's Gradle version, making it compatible with Java 25 (#2962)
  • 🛠 Updates dependencies including CPython 3.15.0rc2 (#2965, #2970, #2976, #2981, #2985)

v4.2.0

4 August 2026

  • 🌟 CPython 3.15 wheels are now built by default - without the "cpython-prerelease" enable set. It's time to build and upload these wheels to PyPI! This release includes CPython 3.15.0rc1, which is guaranteed to be ABI compatible with the final release. (#2944)
  • ✨ Adds Pyodide 3.15 support with the cp315-pyodide_wasm32 build identifier, using Pyodide 315.0.0a2. These are also stable wrt. the final release. (#2958)
  • 🐛 Retries a failed download six times with exponential backoff, so short network outages no longer stop a build. A 4xx response is still reported at once. (#2953)
  • 🐛 Accepts default as a build-frontend value on Pyodide, and accepts pyodide-build in the top-level table and in overrides (#2951)
  • 🛠 Holds pip back on GraalPy, where newer pip breaks the build (#2955)
  • 🛠 Updates Pyodide to 314.0.4 (#2949, #2952)
  • 🛠 Updates dependencies and container pins (#2952, #2960)
  • 💼 Updates CI action pins (#2948, #2954)
  • 🧪 Uses pp311 for the abi3 test, and deletes test_overridden_pip_constraint, which is not necessary since #2583 (#2956, #2957)

v4.1.1

24 July 2026

  • ✨ Adds pyodide-build as a separate build-frontend, now the default frontend for Pyodide, with verbosity flags handling. Any other frontend is ignored with a warning on Pyodide. (#2609, #2945)

... (truncated)

Commits
  • adba99c Bump version: v4.3.0
  • 8a0d481 Add the ability to set 'inherit' at all levels of the options cascade (#2928)
  • 8bc038b chore(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the actions gro...
  • 5cad3d9 [Bot] Update dependencies (#3003)
  • 82bef7c Make logged commands readable when they contain quotes (#2993)
  • 84f6233 feat: add GraalPy 3.13 (25.3) (#2982)
  • 85ca3f6 fix(ci): use GitHub's dedicated self-repository syntax (#3002)
  • ae4799a [Bot] Update dependencies (#2986)
  • 69adf52 fix: don't run call() through cmd.exe on Windows (#2978)
  • ad9dc7a feat: add log fold mode override (#2972)
  • Additional commits viewable in compare view

Updates TheMrMilchmann/setup-msvc-dev from 4.0.0 to 4.1.0

Release notes

Sourced from TheMrMilchmann/setup-msvc-dev's releases.

4.1.0

Improvements

  • Improved vswhere discovery to take into account well-known installation paths before falling back to invocation via %PATH%.
Commits

Updates softprops/action-gh-release from 3.0.0 to 3.0.3

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

v3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

v3.0.1

3.0.1

  • maintenance release with updated dependencies
Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

... (truncated)

Commits
  • efb3536 release 3.0.3 (#840)
  • 6441963 chore(deps): bump the npm group with 2 updates (#839)
  • e5ee6bc chore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)
  • d1e6617 chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)
  • 6403751 chore(deps): bump the npm group with 2 updates (#835)
  • 7c7184b chore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)
  • 0f3f0d2 chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)
  • 77fb938 chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 27, 2026
@scoder

scoder commented Oct 8, 2026

Copy link
Copy Markdown
Owner

@dependabot recreate

Bumps the github-actions group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.1` |
| [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `7.0.0` |
| [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `4.0.0` | `4.4.0` |
| [pypa/cibuildwheel](https://github.com/pypa/cibuildwheel) | `3.4.1` | `4.3.0` |
| [TheMrMilchmann/setup-msvc-dev](https://github.com/themrmilchmann/setup-msvc-dev) | `4.0.0` | `4.1.0` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `3.0.0` | `3.0.3` |



Updates `actions/checkout` from 6.0.2 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@de0fac2...3d3c42e)

Updates `actions/setup-python` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@a309ff8...5fda3b9)

Updates `docker/setup-qemu-action` from 4.0.0 to 4.4.0
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@ce36039...9901266)

Updates `pypa/cibuildwheel` from 3.4.1 to 4.3.0
- [Release notes](https://github.com/pypa/cibuildwheel/releases)
- [Changelog](https://github.com/pypa/cibuildwheel/blob/main/docs/changelog.md)
- [Commits](pypa/cibuildwheel@8d2b08b...adba99c)

Updates `TheMrMilchmann/setup-msvc-dev` from 4.0.0 to 4.1.0
- [Release notes](https://github.com/themrmilchmann/setup-msvc-dev/releases)
- [Commits](TheMrMilchmann/setup-msvc-dev@79dac24...368ef7d)

Updates `softprops/action-gh-release` from 3.0.0 to 3.0.3
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@b430933...efb3536)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/setup-qemu-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: pypa/cibuildwheel
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: TheMrMilchmann/setup-msvc-dev
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-7097a79963 branch from 8b1778d to 1a48146 Compare October 8, 2026 16:13
@scoder
scoder merged commit 1613bbd into master Oct 8, 2026
90 of 94 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-7097a79963 branch October 8, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant