FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Update github-actions by renovate[bot] · Pull Request #157 · phpstan/php-8-stubs · GitHub

Repository navigation

Update github-actions - #157

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

renovate Bot commented Jun 8, 2026 •
edited
Loading

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
WyriHaximus/github-action-get-previous-tag action minor v2.0.0 → v2.1.0
actions/checkout action patch v7.0.0 → v7.0.1
astral-sh/setup-uv action minor v8.1.0 → v8.3.2
github/codeql-action action minor v4.36.0 → v4.38.3
shivammathur/setup-php action minor v2.37.1 → 2.40.0
softprops/action-gh-release action patch v3.0.0 → v3.0.3
stefanzweifel/git-auto-commit-action action minor v7.1.0 → v7.2.0
step-security/harden-runner action minor v2.19.4 → v2.22.1

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

WyriHaximus/github-action-get-previous-tag (WyriHaximus/github-action-get-previous-tag)

v2.1.0

Compare Source

v2.1.0

  • Total issues resolved: 1
  • Total pull requests resolved: 9
  • Total contributors: 3

Bug 🐞

Dependencies 📦

Enhancement ✨

actions/checkout (actions/checkout)

v7.0.1

Compare Source

astral-sh/setup-uv (astral-sh/setup-uv)

v8.3.2: 🌈 update known checksums for 0.11.28

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v8.3.1: 🌈 update known checksums for 0.11.27

Compare Source

Changes

Just a maintenance release

🧰 Maintenance

📚 Documentation

v8.3.0: 🌈 Support uv.lock as a version-file source

Compare Source

Changes

Thanks to @​somaz94 you can now use the pinned version of uv itself in uv.lock. It gets picked up automatically.
If you have pinned another version of uv in your uv.lock you can use the inputs version or version-source to override this.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v8.2.0: 🌈 New inputs quiet and download-from-astral-mirror

Compare Source

Changes

This release brings two new inputs and a few bug fixes.

New inputs

Lets talk about the new inputs first.

quiet

Pretty simple. It turns of all info loggings. Useful if you use this in a composite action and are not interested in all the details.
In the upcoming releases we will add log groups to fully implement support for "less noise"

[!NOTE]
Warnings and errors are always logged.

download-from-astral-mirror

In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting download-from-astral-mirror: false allows you to do that.

Bugfixes

When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token.
All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.

We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

⬆️ Dependency updates

github/codeql-action (github/codeql-action)

v4.38.3

Compare Source

  • Upcoming breaking change: CodeQL version 2.21.2 and earlier were discontinued on 24 September 2026 alongside GitHub Enterprise Server 3.17, and will be unsupported by the next minor release of the CodeQL Action. Added a deprecation warning for customers using these versions of CodeQL. #​4188
  • Update default CodeQL bundle version to 2.27.2. #​4203
  • Fixed a bug where the decision of whether to use a per-language bundle did not account for custom configurations that reference queries outside of compiled CodeQL packs. This issue was caught during internal testing and did not affect any customer repositories. We will resume the roll out of per-language bundles in the coming weeks. #​4184

v4.38.2

Compare Source

v4.38.1

Compare Source

  • The CodeQL Action now has experimental support for CodeQL releases for which per-language bundles are available. Per-language bundles support analysis for a single language and are therefore smaller than the combined bundles that allow analysis for all supported languages. As a result, per-language bundles take up less space on disk and are faster to download. We expect to roll this change out to everyone in the coming weeks. #​4146

v4.38.0

Compare Source

  • On GitHub-hosted runners, the CodeQL Action now deletes unused CodeQL bundles from the toolcache before downloading a different bundle, which frees up disk space for the analysis. We expect to roll this change out to everyone in September. #​4124
  • The CodeQL Action now supports CodeQL releases that are compatible with Linux Arm64 and downloads the native linux-arm64 CodeQL bundle when available. #​4072
  • Update default CodeQL bundle version to 2.27.0. #​4129

v4.37.9

Compare Source

v4.37.8

Compare Source

No user facing changes.

v4.37.7

Compare Source

v4.37.6

Compare Source

  • Changed the default filepath for the new remote file address format that was introduced in CodeQL Action 4.37.0 / 3.37.0 to .github/codeql-config.yml to align it with the suggested path that is used elsewhere. #​4070

v4.37.5

Compare Source

  • Fixed a bug where a network error while streaming the download of the CodeQL bundle could terminate the init Action instead of falling back to downloading the bundle before extracting it. #​4061

v4.37.4

Compare Source

  • This version of the CodeQL Action adds support for the tools input for the codeql-action/init step to be specified using a github-codeql-tools repository property. This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to toolcache to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for tools in the workflow definition always takes precedence unless the value of the repository property starts with !. #​4037
  • Update default CodeQL bundle version to 2.26.2. #​4051

v4.37.3

Compare Source

No user facing changes.

v4.37.2

Compare Source

  • The new address format for the config-file input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the remote= prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. #​4023
  • The CodeQL Action can now make use of configured private registries in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. #​4007

v4.37.1

Compare Source

  • Upcoming breaking change: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. #​3956
  • Update default CodeQL bundle version to 2.26.1. #​4019

v4.37.0

Compare Source

  • Update default CodeQL bundle version to 2.26.0. #​3995
  • In addition to the existing input format, the config-file input for the codeql-action/init step will soon support a new [owner/]repo[@ref][:path] format. All components except the repository name are optional. If omitted, owner defaults to the same owner as the repository the analysis is running for, ref to main, and path to .github/codeql-action.yaml. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. #​3973

v4.36.3

Compare Source

No user facing changes.

v4.36.2

Compare Source

  • Cache CodeQL CLI version information across Actions steps. #​3943
  • Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. #​3937
  • Update default CodeQL bundle version to 2.25.6. #​3948

v4.36.1

Compare Source

No user facing changes.

shivammathur/setup-php (shivammathur/setup-php)

v2.40.0

Compare Source

Changelog
  • Added support for PHP 8.7 nightly builds. This installs PHP builds from the master branch of php/php-src.
- name: Setup PHP 8.7
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.7'
  • Added support for Ubuntu 26.04 (ubuntu-26.04). (#​1083)

  • Added support for pinning tools to SHA-256 and SHA-512 checksums. (#​1098, #​1099)

- name: Setup PHP with tools pinned to checksums
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.5'
    tools: >
      composer:2.9.8@sha256:59b2c50e10cafa0d8efc19ede9a326d782f096c674a26baf98cf042ce23de890,
      phpunit:12.5.0@sha512:76430b433bd57f96e5fbbabaefc0c82e3a5b19b1a366bd836614344c441a7a87575d77faa07e0e58ecec52061af67584b036adc4311f0764bd4414bc62be4684
  • Fixed support for Couchbase, Oracle, and IBM extensions on Ubuntu 26.04. (#​1123)

  • Added support for cpx. (#​1104)

- name: Setup PHP with cpx
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.5'
    tools: cpx
  • Added support for Laravel Cloud CLI. (#​1106)
- name: Setup PHP with Laravel Cloud CLI
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.5'
    tools: laravel-cloud
  • Added configurable verbose logging using the verbose environment variable. Set it to true or v to show command output, or vv or vvv to also enable tracing. Also, deprecated the verbose and more-verbose tags in favor of this environment variable. (#​1077, #​1118, #​1119)
- name: Setup PHP with verbose logging
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.5'
  env:
    verbose: true
  • Improved support for PHP version files, including version aliases, partial versions, and comments. For example, a .php-version file containing 8.x can now be used to set up the latest stable PHP 8 version. (#​1121)
- name: Checkout
  uses: actions/checkout@v7

- name: Setup PHP from a version file
  uses: shivammathur/setup-php@v2
  with:
    php-version-file: '.php-version'
  • Improved PHP installation on macOS using cached builds from shivammathur/php-darwin. This should improve the setup-php runtime from around a minute to 5-10s.

  • Improved Homebrew extension installation, timeout handling, and retries. (#​1120)

  • Improved PHP installation on Windows using release manifests and cached builds from shivammathur/php-builder-windows.

  • Improved caching and validation of versioned extensions on Linux, macOS, and Windows. (#​1108)

  • Added opt-in support for cached PHP builds on Blacksmith and Depot runners using use_builds_cache environment variable. This is currently experimental and uses the builds cache that we maintain for GitHub hosted runners. (#​1056, #​1129)

- name: Setup PHP with cached builds
  uses: shivammathur/setup-php@v2
  with:
    php-version: '8.5'
  env:
    use_builds_cache: true
  • Switched to Homebrew extension packages for Lua and GEOS extensions on supported macOS PHP versions.

  • Deprecated support for Intel macOS and macOS 14 arm64 runners. It is recommended to upgrade to arm64 based macOS runners (macos-15 or newer). (#​1112)

  • Updated Node.js dependencies and internal GitHub Actions workflows.

For the complete list of changes, please refer to the Full Changelog

Thanks @​kmaeda-rakus, @​jrfnl, @​WendellAdriel, @​damiantw, @​ibrahimlawal-paystack, @​Perlence, and @​Sainan for the contributions.

Follow for updates

v2.37.2

Compare Source

Changelog
  • Fixed macOS setup by marking shivammathur/php and shivammathur/extensions as trusted taps.

  • Switched to Visual Studio 18 (vs18) builds for PHP 8.6 on Windows.

  • Improved looking up environment variables.

  • Tightened security in internal GitHub action workflows.

  • Updated Node.js dependencies.

For the complete list of changes, please refer to the Full Changelog

Follow for updates

softprops/action-gh-release (softprops/action-gh-release)

v3.0.3

Compare Source

3.0.3 is a maintenance release with updated dependencies. It also safely
classifies malformed GitHub API errors to avoid secondary failures (#​822).

What's Changed

Bug fixes 🐛
Other Changes 🔄
  • dependency updates

v3.0.2

Compare Source

3.0.2 is a patch release focused on release reliability and compatibility. It
reuses existing draft releases when publishing prereleases, supports replacing
release assets on Gitea, hardens streamed asset uploads, and provides clearer
release-creation diagnostics. It also includes TypeScript, coverage, and tooling
maintenance merged since 3.0.1.

This release fixes #​795, #​438, and #​803. The upload transport hardening covers the
historical failure reported in #​790, although current hosted Node 24 runners did
not reproduce it naturally. The diagnostics work is related to #​786 and does not
claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉
Bug fixes 🐛
Other Changes 🔄

v3.0.1

Compare Source

3.0.1

  • maintenance release with updated dependencies
stefanzweifel/git-auto-commit-action (stefanzweifel/git-auto-commit-action)

v7.2.0

Compare Source

Added
Fixed
Dependency Updates
step-security/harden-runner (step-security/harden-runner)

v2.22.1

Compare Source

What's Changed
  • Fixed security rules not initializing on GHES self-hosted runners
  • Fixed GHES connectivity in block mode by implicitly allowing the GHES hostname

Full Changelog: step-security/harden-runner@v2.22.0...v2.22.1

v2.22.0

Compare Source

What's Changed
  • Linux ARM64 support for community tier
  • GHES support for self-hosted VMs (enterprise tier)
  • MacOS and Windows runner deny list support for block policy (enterprise tier).

Full Changelog: step-security/harden-runner@v2.21.1...v2.22.0

v2.21.1

Compare Source

What's Changed

  • Improved performance of the disable-sudo feature.
  • Fixed an issue in the Community tier where new endpoints required by the GitHub Actions runner were not being implicitly allowed in block mode.
  • Fixed the Harden-Runner post step failing on Linux distributions that do not have a merged /usr filesystem layout (for example Debian 11), where /usr/bin/echo does not exist. This mainly affected self-hosted runners.
  • Documentation updates: clarified which features are in the Community (free) vs Enterprise tier.

Full Changelog: step-security/harden-runner@v2.21.0...v2.21.1

v2.21.0

Compare Source

What's Changed

  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0

v2.20.1

Compare Source

What's Changed

  • AWS CodeBuild-hosted runner support
  • Implicitly allow single-labeled (internal) domains in block-mode

Full Changelog: step-security/harden-runner@v2.20.0...v2.20.1

v2.20.0

Compare Source

What's Changed
  • Support for block policy for MacOS and Windows GitHub-hosted runners
  • Support for Bitrise MacOS GitHub Actions runners
  • HTTPS monitoring support for Bun for Linux runners (enterprise tier)

Full Changelog: step-security/harden-runner@v2.19.4...v2.20.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Comment thread .github/workflows/lint-workflows.yml Outdated

- name: Install the latest version of uv
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0
renovate Bot force-pushed the renovate/github-actions branch from 14adca8 to 728789d Compare June 8, 2026 16:52
Comment thread .github/workflows/phpstan.yml Outdated
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: "Install PHP"
uses: "shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc" # v2.37.1
uses: "shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240" # 2.37.2
Comment thread .github/workflows/send-pr.yml Outdated

- name: "Install PHP"
uses: "shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc" # v2.37.1
uses: "shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240" # 2.37.2
Comment thread .github/workflows/update.yml Outdated
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- name: "Install PHP"
uses: "shivammathur/setup-php@7c071dfe9dc99bdf297fa79cb49ea005b9fcadbc" # v2.37.1
uses: "shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240" # 2.37.2
renovate Bot force-pushed the renovate/github-actions branch from 728789d to a5089e4 Compare June 11, 2026 13:58
renovate Bot force-pushed the renovate/github-actions branch from a5089e4 to ef89b2d Compare June 19, 2026 15:31
Comment thread .github/workflows/release.yml Outdated

- name: "Create release"
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3.0.1
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from f87ccba to 5d48767 Compare June 28, 2026 09:45
Comment thread .github/workflows/update.yml Fixed
renovate Bot force-pushed the renovate/github-actions branch 4 times, most recently from c02c51c to 5b0628c Compare July 8, 2026 12:41
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 312ef42 to 23292f7 Compare July 17, 2026 09:56
renovate Bot force-pushed the renovate/github-actions branch from 23292f7 to 09bfb7f Compare July 20, 2026 21:10
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
egress-policy: audit

- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from fecb85e to 1ba54ba Compare July 22, 2026 06:08
renovate Bot force-pushed the renovate/github-actions branch 4 times, most recently from 369b64c to 49e1ab6 Compare August 5, 2026 10:32
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 7986565 to 7053c83 Compare August 15, 2026 10:05
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from f5ffc81 to e4a7459 Compare August 26, 2026 16:10
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 0963339 to 0dbc298 Compare August 31, 2026 02:32
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from 9170f56 to f0496cf Compare September 9, 2026 21:02
Comment thread .github/workflows/update.yml Fixed
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from d95e4c6 to 32a3708 Compare September 14, 2026 06:44
Comment thread .github/workflows/update.yml Fixed
Comment thread .github/workflows/update.yml Fixed
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from 4dd4a95 to 84da2fe Compare September 18, 2026 23:47
renovate Bot force-pushed the renovate/github-actions branch 2 times, most recently from ff33810 to a96e55a Compare October 1, 2026 05:00
- name: 'Get previous tag'
id: previous_tag
uses: "WyriHaximus/github-action-get-previous-tag@61819f33034117e6c686e6a31dba995a85afc9de" # v2.0.0
uses: "WyriHaximus/github-action-get-previous-tag@83f26fea93bc7efcbca2eb5591f5eaaf66b8f206" # v2.1.0
- name: "Commit changes"
if: github.event_name != 'pull_request'
uses: "stefanzweifel/git-auto-commit-action@04702edda442b2e678b25b537cec683a1493fcb9" # v7.1.0
uses: "stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d" # v7.2.0
renovate Bot force-pushed the renovate/github-actions branch 3 times, most recently from f525c85 to 4c96998 Compare October 8, 2026 11:01
renovate Bot force-pushed the renovate/github-actions branch from 4c96998 to 5f7bd78 Compare October 8, 2026 15:06
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL