Skip to content

chore(deps): bump all rate-limited and major dependencies#380

Merged
yacosta738 merged 3 commits into
mainfrom
copilot/update-cargo-dependencies
Apr 30, 2026
Merged

chore(deps): bump all rate-limited and major dependencies#380
yacosta738 merged 3 commits into
mainfrom
copilot/update-cargo-dependencies

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Apr 30, 2026

Implements all pending Renovate Dependency Dashboard updates — rate-limited, digest, and major upgrades — in a single batch.

Cargo

  • reqwest: 0.13.20.13.3
  • zip: 8.5.18.6.0 (lock only; range "8" unchanged)

npm

  • @astrojs/starlight: ^0.38.2^0.38.4
  • @iconify/json: ^2.2.456^2.2.468
  • @biomejs/biome: 2.4.122.4.13
  • lefthook: ^2.1.4^2.1.6
  • typescript: ^6.0.0^6.0.3
  • pnpm-workspace.yaml catalog: @dallay/agentsync 1.42.31.42.10

Dockerfile

  • Build base: rust:1.94-alpinerust:1.95-alpine

GitHub Actions — digest/patch

Action Before After
pnpm/action-setup v6.0.0 v6.0.3 (903f9c1a) — 3 workflows
actions/setup-node v6.3.0 v6.4.0 (48b55a01) — deploy-docs.yml

GitHub Actions — major upgrades

  • googleapis/release-please-action: v4.4.1v5.0.0 (breaking: Node 24 runtime only)
  • SonarSource/sonarqube-scan-action: v7.1v8.0.0 (breaking: skipSignatureVerification now defaults to false)
  • dallay/common-actions: v1v2 across 8 workflow files (breaking: callers must rename repo secret APP_IDAPP_CLIENT_ID)

⚠️ dallay/common-actions@v2 requires renaming the GitHub App secret from APP_ID to APP_CLIENT_ID in org/repo settings — workflows use secrets: inherit so no YAML change is needed beyond the version bump.

Copilot AI linked an issue Apr 30, 2026 that may be closed by this pull request
20 tasks
- reqwest: 0.13.2 → 0.13.3
- zip: 8.5.1 → 8.6.0 (Cargo.lock)
- @astrojs/starlight: ^0.38.2 → ^0.38.4
- @iconify/json: ^2.2.456 → ^2.2.468
- @biomejs/biome: 2.4.12 → 2.4.13
- lefthook: ^2.1.4 → ^2.1.6
- typescript: ^6.0.0 → ^6.0.3
- pnpm-workspace.yaml @dallay/agentsync catalog: 1.42.3 → 1.42.10
- Dockerfile: rust:1.94-alpine → rust:1.95-alpine
- pnpm/action-setup: v6.0.0 → v6.0.3 (3 workflows)
- actions/setup-node: v6.3.0 → v6.4.0 (deploy-docs.yml)
- googleapis/release-please-action: v4.4.1 → v5.0.0 (major)
- SonarSource/sonarqube-scan-action: v7.1 → v8.0.0 (major)
- dallay/common-actions: v1 → v2 (7 workflows, major)

Agent-Logs-Url: https://github.com/dallay/agentsync/sessions/8aa7ee44-5438-4012-b492-756b08349296

Co-authored-by: yacosta738 <33158051+yacosta738@users.noreply.github.com>
Copilot AI changed the title [WIP] Update cargo dependencies for better compatibility chore(deps): bump all rate-limited and major dependencies Apr 30, 2026
Copilot AI requested a review from yacosta738 April 30, 2026 11:46
@yacosta738 yacosta738 marked this pull request as ready for review April 30, 2026 12:45
@sentry
Copy link
Copy Markdown

sentry Bot commented Apr 30, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@sonarqubecloud
Copy link
Copy Markdown

@yacosta738 yacosta738 merged commit ccd3d9a into main Apr 30, 2026
26 checks passed
@yacosta738 yacosta738 deleted the copilot/update-cargo-dependencies branch April 30, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

🔗 Dependency Dashboard

2 participants