Skip to content

chore(ci): bump taiki-e/install-action from 2 to 2.85.5 - #337

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/taiki-e/install-action-2.85.5
Closed

chore(ci): bump taiki-e/install-action from 2 to 2.85.5#337
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/taiki-e/install-action-2.85.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps taiki-e/install-action from 2 to 2.85.5.

Release notes

Sourced from taiki-e/install-action's releases.

2.85.5

  • Update uv@latest to 0.12.0.

  • Update syft@latest to 1.50.0.

  • Update sccache@latest to 0.17.0.

  • Update mise@latest to 2026.7.16.

2.85.4

  • Update uv@latest to 0.11.33.

  • Update mise@latest to 2026.7.15.

  • Update biome@latest to 2.5.6.

2.85.3

  • Update xh@latest to 0.26.2.

  • Update ubi@latest to 0.10.0.

  • Update mise@latest to 2026.7.14.

  • Update martin@latest to 1.13.0.

  • Update cargo-shear@latest to 1.13.3.

  • Update cargo-binstall@latest to 1.21.1.

2.85.2

  • Update prek@latest to 0.4.11.

  • Update mise@latest to 2026.7.13.

  • Update kingfisher@latest to 1.109.0.

2.85.1

  • Update vacuum@latest to 0.30.0.

  • Update uv@latest to 0.11.32.

  • Update mise@latest to 2026.7.12.

  • Update cyclonedx@latest to 0.33.1.

  • Update cargo-neat@latest to 0.5.2.

2.85.0

  • Support wild (alias: wild-linker). (#1949)

... (truncated)

Changelog

Sourced from taiki-e/install-action's changelog.

[2.85.7] - 2026-08-02

  • Update wasmtime@latest to 47.0.3.

  • Update uv@latest to 0.12.1.

  • Update rclone@latest to 1.75.0.

  • Update kingfisher@latest to 1.110.0.

[2.85.6] - 2026-08-01

  • Update wasm-tools@latest to 1.255.0.

  • Update tombi@latest to 1.2.5.

  • Update mise@latest to 2026.7.18.

  • Update cargo-neat@latest to 0.5.3.

  • Update cargo-crap@latest to 0.4.0.

[2.85.5] - 2026-07-30

  • Update uv@latest to 0.12.0.

  • Update syft@latest to 1.50.0.

  • Update sccache@latest to 0.17.0.

  • Update mise@latest to 2026.7.16.

[2.85.4] - 2026-07-29

  • Update uv@latest to 0.11.33.

  • Update mise@latest to 2026.7.15.

  • Update biome@latest to 2.5.6.

[2.85.3] - 2026-07-28

  • Update xh@latest to 0.26.2.

  • Update ubi@latest to 0.10.0.

  • Update mise@latest to 2026.7.14.

  • Update martin@latest to 1.13.0.

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by CodeRabbit

  • Chores
    • Updated security checks to use a fixed version of the installation tooling, improving build consistency and reliability.

Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2 to 2.85.5.
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2...v2.85.5)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from doublegate as a code owner August 3, 2026 10:07
@dependabot dependabot Bot added dependencies Dependency updates github-actions GitHub Actions dependencies labels Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 0602403d-9ae4-42f5-8b02-91c80f32612d

📥 Commits

Reviewing files that changed from the base of the PR and between 71d48ef and 84b3ea0.

📒 Files selected for processing (1)
  • .github/workflows/security.yml

📝 Walkthrough

Walkthrough

The security workflow pins both taiki-e/install-action references to v2.85.5 for the cargo-audit and cargo-deny jobs.

Changes

Security workflow

Layer / File(s) Summary
Pin security actions
.github/workflows/security.yml
The cargo-audit and cargo-deny jobs now use taiki-e/install-action@v2.85.5 instead of @v2.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: doublegate

🚥 Pre-merge checks | ✅ 9
✅ Passed checks (9 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the CI dependency and version update described in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Docs-As-Spec Sync ✅ Passed The PR changes only two CI action pins in .github/workflows/security.yml; no rustynes CPU, PPU, APU, mapper, or matching docs files changed.
Changelog Entry For User-Visible Changes ✅ Passed The commit only changes two taiki-e/install-action pins in .github/workflows/security.yml; no product files or changelog entries changed, so this is CI/tooling-only.
No Unwrap/Expect/Panic On Untrusted Input ✅ Passed The PR changes only two GitHub Actions version strings; no new .unwrap(), .expect(), or panic!() calls are present.
Safety Comment On New Unsafe Blocks ✅ Passed The commit changes only .github/workflows/security.yml, and its patch contains no Rust unsafe blocks or unsafe fn declarations.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/taiki-e/install-action-2.85.5

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown

Antigravity review (Gemini via Ultra)

This PR updates taiki-e/install-action references in .github/workflows/security.yml from the major version tag v2 to patch version tag v2.85.5.

Blocking issues

None found.

Suggestions

  • .github/workflows/security.yml:63 & .github/workflows/security.yml:78: Pin third-party GitHub Actions to a full 40-character commit SHA instead of a mutable release tag (e.g. uses: taiki-e/install-action@<commit-sha> # v2.85.5) to prevent supply chain tampering via tag mutation.

Nitpicks

None.

Automated first-pass review by agy on a self-hosted runner -- not a human review.

@doublegate

Copy link
Copy Markdown
Owner

Superseded by #340, which consolidates this bump together with the other two open Dependabot PRs (#336 gradle/actions, #337 taiki-e/install-action, #338 wide + clap_complete) into a single reviewed-and-verified change. Closing in favour of that consolidated PR.

@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/taiki-e/install-action-2.85.5 branch August 3, 2026 19:10
doublegate added a commit that referenced this pull request Aug 3, 2026
Roll the three currently-open Dependabot PRs into a single change so they
land and close together instead of as three separate merges, matching this
repo's standing "master Dependabot consolidation" practice.

Cargo (production-dependencies group, #338):
  - wide          1.5.0 -> 1.6.0  (SIMD; used by the frontend software blitter)
  - clap_complete 4.6.7 -> 4.6.8  (CLI shell-completion generation)
  Cargo.lock is taken verbatim from Dependabot's #338 so the diff is exactly
  the four version+checksum lines and nothing else. A local
  `cargo update -p clap_complete --precise 4.6.8` additionally re-resolved
  four transitive `windows-sys` references off 0.61.2 (down to 0.52.0/0.48.0)
  -- a valid but non-minimal churn cargo does opportunistically against a
  newer registry index; Dependabot's own lockfile does NOT do this (clap
  4.6.8 does not require it), and agy's review flagged the drift, so the
  minimal lockfile is used instead. `cargo metadata --locked` accepts it, so
  it is consistent with the manifest with zero re-resolution.

GitHub Actions:
  - taiki-e/install-action  v2 -> v2.85.5  (#337) -- both call sites in
    .github/workflows/security.yml (the cargo-audit and cargo-deny jobs,
    which install the prebuilt binaries rather than compiling them under
    the 1.96 pin).
  - gradle/actions/setup-gradle  v6 -> v6.2.0  (#336) -- the Android
    foss+play bundle job in .github/workflows/android.yml.
  Both move from a floating `@vN` major tag to the exact patch Dependabot
  pins; Dependabot's github-actions ecosystem then tracks them forward.
  (agy suggested SHA-pinning; declined -- the repo deliberately keeps `@vN`
  tags for every action except the compiler-installing
  dtolnay/rust-toolchain, a documented maintenance-policy choice.)

Verification:
  - Cargo.lock diff == Dependabot #338 (wide + clap_complete only, no
    windows-sys or other transitive churn); `cargo metadata --locked` clean.
  - `cargo check --workspace` compiles the full graph on the new lockfile.
  - `cargo build -p rustynes-core --target thumbv7em-none-eabihf
    --no-default-features` -- the standalone no_std build a full workspace
    build masks (the lz4_flex-0.14 lesson) -- stays green.
  - Both edited workflows parse as valid YAML.

Supersedes #336, #337, #338 (closed in favour of this consolidated PR).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
doublegate added a commit that referenced this pull request Aug 3, 2026
…340)

Roll the three currently-open Dependabot PRs into a single change so they
land and close together instead of as three separate merges, matching this
repo's standing "master Dependabot consolidation" practice.

Cargo (production-dependencies group, #338):
  - wide          1.5.0 -> 1.6.0  (SIMD; used by the frontend software blitter)
  - clap_complete 4.6.7 -> 4.6.8  (CLI shell-completion generation)
  Cargo.lock is taken verbatim from Dependabot's #338 so the diff is exactly
  the four version+checksum lines and nothing else. A local
  `cargo update -p clap_complete --precise 4.6.8` additionally re-resolved
  four transitive `windows-sys` references off 0.61.2 (down to 0.52.0/0.48.0)
  -- a valid but non-minimal churn cargo does opportunistically against a
  newer registry index; Dependabot's own lockfile does NOT do this (clap
  4.6.8 does not require it), and agy's review flagged the drift, so the
  minimal lockfile is used instead. `cargo metadata --locked` accepts it, so
  it is consistent with the manifest with zero re-resolution.

GitHub Actions:
  - taiki-e/install-action  v2 -> v2.85.5  (#337) -- both call sites in
    .github/workflows/security.yml (the cargo-audit and cargo-deny jobs,
    which install the prebuilt binaries rather than compiling them under
    the 1.96 pin).
  - gradle/actions/setup-gradle  v6 -> v6.2.0  (#336) -- the Android
    foss+play bundle job in .github/workflows/android.yml.
  Both move from a floating `@vN` major tag to the exact patch Dependabot
  pins; Dependabot's github-actions ecosystem then tracks them forward.
  (agy suggested SHA-pinning; declined -- the repo deliberately keeps `@vN`
  tags for every action except the compiler-installing
  dtolnay/rust-toolchain, a documented maintenance-policy choice.)

Verification:
  - Cargo.lock diff == Dependabot #338 (wide + clap_complete only, no
    windows-sys or other transitive churn); `cargo metadata --locked` clean.
  - `cargo check --workspace` compiles the full graph on the new lockfile.
  - `cargo build -p rustynes-core --target thumbv7em-none-eabihf
    --no-default-features` -- the standalone no_std build a full workspace
    build masks (the lz4_flex-0.14 lesson) -- stays green.
  - Both edited workflows parse as valid YAML.

Supersedes #336, #337, #338 (closed in favour of this consolidated PR).

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates github-actions GitHub Actions dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant