chore(deps): update github-actions - #368
Conversation
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
Kody Code Review — 1 suggested fix. 🛠️ Open Agent Prompt |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: cachekit-io/cachekit-py/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | ||
| with: | ||
| python-version: '3.12' | ||
| python-version: '3.14' |
There was a problem hiding this comment.
Interpreter mismatch in attestation-check.yml Set up Python: switching to Python 3.14 makes the later pip download "cachekit==${VER}" --no-deps --only-binary :all: accept only cp314 wheels, but release-please.yml (lines 239-277) builds only cp310–cp313 wheels and publishes no abi3 wheel. On every scheduled run, pip fails with "No matching distribution found" and the step exits 1 with "Could not download wheel", so the weekly check goes red without verifying any attestation, which raises a false tamper alarm and defeats the tripwire. Fix: pin the interpreter to '3.13', pass --python-version 3.12 --platform manylinux_2_17_x86_64 to pip download, or add python3.14 to the release interpreter matrix first.
python-version: '3.13'Prompt for LLM
File .github/workflows/attestation-check.yml:
Line 81:
Interpreter mismatch in attestation-check.yml Set up Python: switching to Python 3.14 makes the later `pip download "cachekit==${VER}" --no-deps --only-binary :all:` accept only cp314 wheels, but release-please.yml (lines 239-277) builds only cp310–cp313 wheels and publishes no abi3 wheel. On every scheduled run, pip fails with "No matching distribution found" and the step exits 1 with "Could not download wheel", so the weekly check goes red without verifying any attestation, which raises a false tamper alarm and defeats the tripwire. Fix: pin the interpreter to '3.13', pass `--python-version 3.12 --platform manylinux_2_17_x86_64` to `pip download`, or add python3.14 to the release interpreter matrix first.
Suggested Code:
python-version: '3.13'
Talk to Kody by mentioning @kody
Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
a778510 to
a644f35
Compare
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
This PR contains the following updates:
v0.24.0→v0.24.2v10.1.0→v10.2.0v8.2.0→v8.3.20.12.12→0.12.190.12.21(+1)3.12→3.14Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
anchore/sbom-action (anchore/sbom-action)
v0.24.2Compare Source
Added Features
Additional Changes
(Full Changelog)
v0.24.1Compare Source
astral-sh/setup-uv (astral-sh/setup-uv)
v10.2.0: 🌈 Disable automatic cache saves for merge queuesCompare Source
Changes
This release contains the known-checksum of the most recent uv releases and also disabled the uploading(saving) of the cache when in a merge queue since theses caches would almost never be used.
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
astral-sh/uv (astral-sh/uv)
v0.12.19Compare Source
Released on 2026-09-24.
Python
Enhancements
uv publisherrors (#21934)Preview features
build-lazy-importspreview feature (#21967)uv.lockand ignore changes to them when checking lockfile freshness with theresolution-inputspreview feature (#21913)Bug fixes
1.0.0as satisfying===1during installed-package checks, matching resolution (#21931).okfiles in dependencies (#21891)python_versionmarkers when parsing their serialized form (#21939)Rust API
FlatDistributionsexport and itsBTreeMapconversion for downstream resolvers (#21965)Documentation
v0.12.18Compare Source
Released on 2026-09-22.
This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.
Enhancements
--output-format jsontouv pip installanduv pip sync, including for--dry-runand--check(#21893)--checktouv pip installanduv pip syncto report planned changes without modifying the environment (#21844)get_requires_for_build_*hooks correctly in build errors (#21881)Preview features
uv build --no-build-isolationwith--preview-features build-dependency-check; use--skip-dependency-checkto opt out (#21880)Performance
uv_buildeditable wheel creation by omitting compression from temporary wheels (#21918)Bug fixes
uv add,uv remove, oruv versionfails or is interrupted (#21860, #21856)dependency-metadatawhen checking whether installed requirements are satisfied (#21843)?(#21920)v0.12.17Compare Source
Released on 2026-09-18.
Enhancements
Preview features
minimum-libc-version(#21651)pylock.tomlfiles whose wheel filenames do not match their declared package names or versions (#20746)uv workspace metadataread-only unless--syncis provided (#21821)uv checklock modes when retrieving workspace metadata (#21821)Performance
Bug fixes
required-environmentsfrom selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#21825)Documentation
v0.12.16Compare Source
Released on 2026-09-17.
Python
Enhancements
build-constraint-dependenciesentries to include hashes for verifying downloaded build dependencies (#21467)platform_releasemarkers inrequired-environmentsusing macOS wheel deployment targets (#21766)Preview features
lock-without-metadataacross all dependency types while retainingpackage.metadatafor remote URL dependencies to enable offline validation (#21163)uv upgrade(#21776)uv checkto run in projects that are not managed by uv and outside workspaces (#21777)--pythonandUV_PYTHONwhen selecting the Python version foruv check(#21744)Bug fixes
pylock.tomlbefore reusing cached distributions (#21609)uv_buildbackend only when its version matches active version pins (#21742)v0.12.15Compare Source
Released on 2026-09-15.
Performance
Bug fixes
0.12.14when installing to symlinked destinations or usinguv pip install --target .(#21699)v0.12.14Compare Source
Released on 2026-09-15.
Enhancements
cause:labels (#21599, #21603)uv tool upgradeoperations (#21566)Preview features
uv export --batchinvocation with thebatch-exportpreview feature (#21618)Performance
Bug fixes
required-environmentswithin each resolver fork instead of combining incompatible wheel coverage across forks (#21672)MAX_PATHon Windows systems without long-path support enabled (#21625)uv python installfrom overwriting valid unmanaged Python symlinks with relative targets on Unix (#21639)bin/pythonoverbin/python3when discovering interpreters in Unix environments (#21559)1for expected failures and2for recognized operational and internal failures (#17110)--quiet(#21565)uv tool upgradeerrors visible with-qwhile suppressing them with-qq(#21566)v0.12.13Compare Source
Released on 2026-09-10.
Python
Enhancements
Preview features
tyexclusions whenuv checkautomatically selects members of a virtual workspace (#21555)Performance
Bug fixes
core-metadataover legacy aliases in JSON index responses (#21563)actions/python-versions (python)
v3.14.7: 3.14.7Compare Source
Python 3.14.7
v3.14.6: 3.14.6Compare Source
Python 3.14.6
v3.14.5: 3.14.5Compare Source
Python 3.14.5
v3.14.4: 3.14.4Compare Source
Python 3.14.4
v3.14.3: 3.14.3Compare Source
Python 3.14.3
v3.14.2: 3.14.2Compare Source
Python 3.14.2
v3.14.1: 3.14.1Compare Source
Python 3.14.1
v3.14.0: 3.14.0Compare Source
Python 3.14.0
v3.13.15: 3.13.15Compare Source
Python 3.13.15
v3.13.14: 3.13.14Compare Source
Python 3.13.14
v3.13.13: 3.13.13Compare Source
Python 3.13.13
v3.13.12: 3.13.12Compare Source
Python 3.13.12
v3.13.11: 3.13.11Compare Source
Python 3.13.11
v3.13.10: 3.13.10Compare Source
Python 3.13.10
v3.13.9: 3.13.9Compare Source
Python 3.13.9
v3.13.8: 3.13.8Compare Source
Python 3.13.8
v3.13.7: 3.13.7Compare Source
Python 3.13.7
v3.13.6: 3.13.6Compare Source
Python 3.13.6
v3.13.5: 3.13.5Compare Source
Python 3.13.5
v3.13.4: 3.13.4Compare Source
Python 3.13.4
v3.13.3: 3.13.3Compare Source
Python 3.13.3
v3.13.2: 3.13.2Compare Source
Python 3.13.2
v3.13.1: 3.13.1Compare Source
Python 3.13.1
v3.13.0: 3.13.0Compare Source
Python 3.13.0
Configuration
📅 Schedule: (in timezone Australia/Sydney)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
This PR updates GitHub Actions dependencies and pinned tool versions across the CI/CD workflows. It changes no library code or public APIs.
Action and tool version bumps
astral-sh/setup-uv:ci.yml(4 jobs),security-fast.ymlandsecurity-deep.yml.release-please.yml.uvversion: 0.12.12 → 0.12.19 wherever the v10setup-uvaction is used. The existing "pinned" rationale comments are unchanged.anchore/sbom-action: v0.24.0 → v0.24.2 inrelease-please.yml(the SBOM generation step).Python runtime changes
python-versionmoves from3.12to3.14foractions/setup-pythonin:attestation-check.yml(the attestation verification job)codeql.yml(Python CodeQL analysis)Impact
py3.14t) job, and the fuzzing job (pinned to 3.11) are unaffected.