Skip to content

Update github actions - #4160

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/setup-java action patch v6.0.0 → v6.0.1
gradle/actions action minor v6.3.0 → v6.4.0
open-telemetry/shared-workflows workflow minor v0.12.0 → v0.18.0
streetsidesoftware/cspell-action action minor v9.0.1 → v9.1.0

Release Notes

actions/setup-java (actions/setup-java)

v6.0.1

Compare Source

gradle/actions (gradle/actions)

v6.4.0

Compare Source

Highlights

Gradle version support status in the Job Summary

The actions now report the support status of every Gradle version used in a workflow, as job
annotations and in the Job Summary (#​1057). Thanks to @​ov7a for the contribution.

version kind job annotation version table below the table
End-of-life — two or more major versions behind the latest release warning ⚠️ expandable section naming the affected release lines, pointing at the Gradle Security Subscription
Out of date — one major behind, or more than two minors behind on the current major notice ℹ️ one-line legend pointing at the Gradle release lifecycle docs
Current none — —

Deliberately not reported: patch releases (being on 9.7.0 when 9.7.1 exists is not flagged) and
pre-releases (release candidates, milestones and snapshots never produce annotations). The latest
Gradle release is determined from the wrapper checksum data already bundled with the action, so no
network access is required.

Note that these annotations are emitted independently of the add-job-summary setting: setting
add-job-summary: 'never' suppresses the Job Summary itself, but the warning and notice annotations
remain.

Gradle itself is now reported in the dependency graph

The dependency-submission action now applies v1.5.0 of the
GitHub Dependency Graph Gradle Plugin
(up from v1.4.2) (#​1069).

The headline change is that the Gradle Build Tool running the build is now reported as an
org.gradle:gradle-core dependency, so that GitHub can surface known vulnerabilities in the version
of Gradle used to run your build
. These are the coordinates that GitHub advisories for the Gradle
Build Tool are published against.

Details worth knowing:

  • The entry is always reported as a direct dependency with development scope.
  • It is not affected by the project, configuration or scope filters, so it appears even in graphs
    that filter aggressively.
  • Expect dependency graphs to gain this one new entry the first time a build runs after upgrading.
A new Gradle signing key, if you use dependency verification

[!IMPORTANT]
If your build has dependency verification
enabled, you must add a second trusted key before upgrading, or Dependency Graph generation will
fail signature verification.

github-dependency-graph-gradle-plugin 1.5.0 is signed with a new Gradle signing subkey, and the
key previously documented in our setup guide has been revoked upstream:

Artifact Signing key
org.gradle:github-dependency-graph-gradle-plugin 1.5.0 and later E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA (new)
org.gradle plugin versions before the rotation 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)
com.gradle Develocity Gradle plugin, including 4.5.0 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)

Because the Develocity Gradle plugin is still signed with the old key, you should trust both keys
rather than swapping one for the other — replacing the old key outright will break Develocity
injection. The documented snippet in
docs/setup-gradle.md
has been updated accordingly (#​1071):

<trusted-keys>
   <trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671">
      <trusting group="com.gradle"/>
      <trusting group="org.gradle"/>
   </trusted-key>
   <trusted-key id="E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA">
      <trusting group="org.gradle"/>
   </trusted-key>
</trusted-keys>
cache-provider: external for externally managed Gradle User Home

Builds that save and restore Gradle User Home by some other mechanism (Develocity Artifact Cache, for
example) previously had to set cache-disabled: true, which was misleading: caching wasn't disabled,
it just wasn't managed by this action, and the Job Summary reported it as "Disabled".

cache-provider: external skips Gradle User Home restore/save exactly as cache-disabled does, but
reports a distinct External status in the Job Summary explaining that caching is handled by
another provider (#​1059).

- uses: gradle/actions/setup-gradle@v6
  with:
    cache-provider: 'external'
Develocity access keys containing OIDC tokens now work

Short-lived-token handling validated the server=key[;server=key]* access key format with a regex
whose key portion was too strict, so an access key holding an OIDC token value was rejected
outright. Worse, had it passed the regex, parsing split each entry on = and kept only the second
field — silently truncating any key containing = (as JWT padding does) and sending the mangled
key to the server. Both problems are fixed (#​1061).

Job Summary attribution

Job summaries produced by setup-gradle and dependency-submission now carry a top-level heading
naming the action, so the block stays attributable when another action's summary content lands in the
same job (#​1058).

Updated defaults
  • GitHub Dependency Graph Gradle Plugin: 1.4.2 → 1.5.0
  • 5 new known-good wrapper checksums for wrapper-validation (368 → 373 entries)

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.3.0...v6.4.0

open-telemetry/shared-workflows (open-telemetry/shared-workflows)

v0.18.0

Compare Source

What's Changed

Full Changelog: open-telemetry/shared-workflows@v0.17.0...v0.18.0

v0.17.0

Compare Source

What's Changed

Full Changelog: open-telemetry/shared-workflows@v0.16.0...v0.17.0

v0.16.0

Compare Source

What's Changed

Full Changelog: open-telemetry/shared-workflows@v0.15.0...v0.16.0

v0.15.0

Compare Source

What's Changed
New Contributors

Full Changelog: open-telemetry/shared-workflows@v0.14.0...v0.15.0

v0.14.0

Compare Source

What's Changed
New Contributors

Full Changelog: open-telemetry/shared-workflows@v0.13.0...v0.14.0

v0.13.0

Compare Source

What's Changed
New Contributors

Full Changelog: open-telemetry/shared-workflows@v0.12.0...v0.13.0

streetsidesoftware/cspell-action (streetsidesoftware/cspell-action)

v9.1.0

Compare Source

Features
Updates and Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 07:59 AM, on day 2 of the month (* 0-7 2 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 00:32
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@renovate
renovate Bot requested review from a team as code owners October 2, 2026 00:32
@opentelemetry-pr-dashboard

opentelemetry-pr-dashboard Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Pull request dashboard status

Waiting on maintainers · refreshed 2026-10-02 15:27 UTC

Merge when ready.

Status above doesn't look right?
  • Just replied or pushed? Anything around or after the refresh time above may not be picked up yet — give it a few minutes.
  • Anything look wrong? Report it with what you expected; it helps us improve the dashboard.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The pinned dependency updates are consistent with the release metadata and existing workflow configurations.

Review effort: Balanced
Findings: None

What changed in this PR

Updates CI dependencies to their latest patch/minor releases using immutable commit pins.

Changes:

  • Upgrades shared security workflows to v0.17.0.
  • Updates Java, Gradle, and CSpell actions.
File Description
.github/​workflows/​zizmor.yml Updates the shared Zizmor workflow.
.github/​workflows/​ossf-scorecard.yml Updates the shared Scorecard workflow.
.github/​workflows/​downstream-codegen-check.yml Updates Java and Gradle setup actions.
.github/​workflows/​checks.yml Updates the CSpell action.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@renovate
renovate Bot force-pushed the renovate/github-actions branch from eaaa6b2 to eb73cc2 Compare October 2, 2026 14:58
@lmolkova
lmolkova enabled auto-merge October 2, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Development

Successfully merging this pull request may close these issues.

2 participants