Skip to content

chore(deps): bump the ci-dependencies group across 1 directory with 8 updates - #900

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dot-github/workflows/ci-dependencies-ec7b3b9539
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dot-github/workflows/ci-dependencies-ec7b3b9539

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the ci-dependencies group with 8 updates in the /.github/workflows directory:

Package From To
Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml c6b3effa6d2e9fff97500d9688b54106f556c433 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
actions/checkout 4 7
astral-sh/setup-uv 5.4.2 10.2.0
Comfy-Org/github-workflows/.github/workflows/cursor-review.yml f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
Comfy-Org/github-workflows/.github/workflows/groom.yml 23c7b69392d08e57f545d393faa391e43cf4dd55 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
actions/setup-python 5 7
Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
codecov/codecov-action 7.0.0 7.1.1

Updates Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml from c6b3effa6d2e9fff97500d9688b54106f556c433 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b

Commits
  • 4d05e52 ci(bump-callers): make an empty area-label roster fail loudly (#333)
  • 9cbbaa9 chore(groom): delete the superseded key-broker.mjs loopback proxy and its tes...
  • 90da1d5 ci(bump-callers): exclude tests/ and README.md from the agents-md, coderabbit...
  • 9bda5ab fix(cursor-review): record each round's merge base and pin the incremental bl...
  • 84db66a fix(cursor-review): build the incremental hunks block as a subset of the revi...
  • c7a53c6 test(bump-callers): assert the suite's own trigger covers every fleet `paths:...
  • df7422f fix(cursor-review): keep the -i status line and headers when a review POST fa...
  • 6de6765 fix(lint): NUL-delimit the fallback org-repo-literal scan so a newline in a p...
  • 65ff890 feat(cursor-review): fail the review when workflows_ref differs from the uses...
  • ba2e67b fix(pr-risk): publish the Check Run on a manual dispatch regardless of `enabl...
  • Additional commits viewable in compare view

Updates actions/checkout from 4 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates astral-sh/setup-uv from 5.4.2 to 10.2.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.2.0 🌈 Disable automatic cache saves for merge queues

Changes

This release contains the known-checksum of the most recent uv releases and also disabled the uploading(saving) of the cache when in a merge queue since theses caches would almost never be used.

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

... (truncated)

Commits

Updates Comfy-Org/github-workflows/.github/workflows/cursor-review.yml from f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b

Commits
  • 4d05e52 ci(bump-callers): make an empty area-label roster fail loudly (#333)
  • 9cbbaa9 chore(groom): delete the superseded key-broker.mjs loopback proxy and its tes...
  • 90da1d5 ci(bump-callers): exclude tests/ and README.md from the agents-md, coderabbit...
  • 9bda5ab fix(cursor-review): record each round's merge base and pin the incremental bl...
  • 84db66a fix(cursor-review): build the incremental hunks block as a subset of the revi...
  • c7a53c6 test(bump-callers): assert the suite's own trigger covers every fleet `paths:...
  • df7422f fix(cursor-review): keep the -i status line and headers when a review POST fa...
  • 6de6765 fix(lint): NUL-delimit the fallback org-repo-literal scan so a newline in a p...
  • 65ff890 feat(cursor-review): fail the review when workflows_ref differs from the uses...
  • ba2e67b fix(pr-risk): publish the Check Run on a manual dispatch regardless of `enabl...
  • Additional commits viewable in compare view

Updates Comfy-Org/github-workflows/.github/workflows/groom.yml from 23c7b69392d08e57f545d393faa391e43cf4dd55 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b

Commits
  • 4d05e52 ci(bump-callers): make an empty area-label roster fail loudly (#333)
  • 9cbbaa9 chore(groom): delete the superseded key-broker.mjs loopback proxy and its tes...
  • 90da1d5 ci(bump-callers): exclude tests/ and README.md from the agents-md, coderabbit...
  • 9bda5ab fix(cursor-review): record each round's merge base and pin the incremental bl...
  • 84db66a fix(cursor-review): build the incremental hunks block as a subset of the revi...
  • c7a53c6 test(bump-callers): assert the suite's own trigger covers every fleet `paths:...
  • df7422f fix(cursor-review): keep the -i status line and headers when a review POST fa...
  • 6de6765 fix(lint): NUL-delimit the fallback org-repo-literal scan so a newline in a p...
  • 65ff890 feat(cursor-review): fail the review when workflows_ref differs from the uses...
  • ba2e67b fix(pr-risk): publish the Check Run on a manual dispatch regardless of `enabl...
  • Additional commits viewable in compare view

Updates actions/setup-python from 5 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml from 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b

Commits
  • 4d05e52 ci(bump-callers): make an empty area-label roster fail loudly (#333)
  • 9cbbaa9 chore(groom): delete the superseded key-broker.mjs loopback proxy and its tes...
  • 90da1d5 ci(bump-callers): exclude tests/ and README.md from the agents-md, coderabbit...
  • 9bda5ab fix(cursor-review): record each round's merge base and pin the incremental bl...
  • 84db66a fix(cursor-review): build the incremental hunks block as a subset of the revi...
  • c7a53c6 test(bump-callers): assert the suite's own trigger covers every fleet `paths:...
  • df7422f fix(cursor-review): keep the -i status line and headers when a review POST fa...
  • 6de6765 fix(lint): NUL-delimit the fallback org-repo-literal scan so a newline in a p...
  • 65ff890 feat(cursor-review): fail the review when workflows_ref differs from the uses...
  • ba2e67b fix(pr-risk): publish the Check Run on a manual dispatch regardless of `enabl...
  • Additional commits viewable in compare view

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 19, 2026
@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c0a25986-e396-4060-8b55-0bce5f4b4298

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

… updates

Bumps the ci-dependencies group with 8 updates in the /.github/workflows directory:

| Package | From | To |
| --- | --- | --- |
| [Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml](https://github.com/comfy-org/github-workflows) | `c6b3effa6d2e9fff97500d9688b54106f556c433` | `4d05e52f3ac9a5ded77ad60f6288be5782ee788b` |
| [actions/checkout](https://github.com/actions/checkout) | `4` | `7` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `5.4.2` | `10.2.0` |
| [Comfy-Org/github-workflows/.github/workflows/cursor-review.yml](https://github.com/comfy-org/github-workflows) | `f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0` | `4d05e52f3ac9a5ded77ad60f6288be5782ee788b` |
| [Comfy-Org/github-workflows/.github/workflows/groom.yml](https://github.com/comfy-org/github-workflows) | `23c7b69392d08e57f545d393faa391e43cf4dd55` | `4d05e52f3ac9a5ded77ad60f6288be5782ee788b` |
| [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` |
| [Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml](https://github.com/comfy-org/github-workflows) | `3b2c8ca1f52056b54453a659fdb4473cfc88aa0e` | `4d05e52f3ac9a5ded77ad60f6288be5782ee788b` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.0.0` | `7.1.1` |



Updates `Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml` from c6b3effa6d2e9fff97500d9688b54106f556c433 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
- [Commits](Comfy-Org/github-workflows@c6b3eff...4d05e52)

Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

Updates `astral-sh/setup-uv` from 5.4.2 to 10.2.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@v5.4.2...c18668a)

Updates `Comfy-Org/github-workflows/.github/workflows/cursor-review.yml` from f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
- [Commits](Comfy-Org/github-workflows@f22ad8f...4d05e52)

Updates `Comfy-Org/github-workflows/.github/workflows/groom.yml` from 23c7b69392d08e57f545d393faa391e43cf4dd55 to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
- [Commits](Comfy-Org/github-workflows@23c7b69...4d05e52)

Updates `actions/setup-python` from 5 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

Updates `Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml` from 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e to 4d05e52f3ac9a5ded77ad60f6288be5782ee788b
- [Commits](Comfy-Org/github-workflows@3b2c8ca...4d05e52)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@fb8b358...303a32d)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/cursor-review.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/groom.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/dot-github/workflows/ci-dependencies-ec7b3b9539 branch from 0a9ae75 to b754cf5 Compare September 24, 2026 21:25

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants