Skip to content

chore(deps): bump the ci-dependencies group across 1 directory with 8 updates - #900

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dot-github/workflows/ci-dependencies-ec7b3b9539
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dot-github/workflows/ci-dependencies-ec7b3b9539

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Contributor

Bumps the ci-dependencies group with 8 updates in the /.github/workflows directory:

Package From To
Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml c6b3effa6d2e9fff97500d9688b54106f556c433 a404fd4a59dcd3add76200e68a26d1f6c548dc62
actions/checkout 6 7
astral-sh/setup-uv 9.0.0 10.1.0
Comfy-Org/github-workflows/.github/workflows/cursor-review.yml f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 a404fd4a59dcd3add76200e68a26d1f6c548dc62
Comfy-Org/github-workflows/.github/workflows/groom.yml 23c7b69392d08e57f545d393faa391e43cf4dd55 a404fd4a59dcd3add76200e68a26d1f6c548dc62
Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e a404fd4a59dcd3add76200e68a26d1f6c548dc62
actions/setup-python 6 7
codecov/codecov-action 7.0.0 7.1.1

Updates Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml from c6b3effa6d2e9fff97500d9688b54106f556c433 to a404fd4a59dcd3add76200e68a26d1f6c548dc62

Commits
  • a404fd4 test(bump-callers): make the glob-flatness guard skip /** directory exclusi...
  • 5d76700 ci(lint): fail on org repo literals not on a committed allowlist (#224)
  • f22ad8f feat(workflow-pins): assert every uses: ref is SHA-pinned, and pin the last...
  • a53cc12 test(workflow-pins): table-driven declared-vs-documented input drift harness ...
  • 60a8788 test(reviewers): one shared parser corpus for both reviewers.yml ports, plus ...
  • fd452c7 refactor(pr-risk): extract the sourceable helpers into scripts/pr-risk/lib.sh...
  • 802766b fix(cursor-review): own a per-PR concurrency group so skip-cursor-review canc...
  • 422cfa4 ci(bump-callers): add WATCHED_EXEC to the five fleets whose asset directory o...
  • df8f7a6 ci: bump groom to github-workflows@23c7b69 (#294)
  • 23c7b69 feat(groom): hoist agent-sandbox pre-exec validation out of the billed agent ...
  • Additional commits viewable in compare view

Updates actions/checkout from 6 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates astral-sh/setup-uv from 9.0.0 to 10.1.0

Release notes

Sourced from astral-sh/setup-uv's releases.

v10.1.0 🌈 New output python-runtime-idand respect NO_PROXY

Changes

This release adds more bheind the scene security improvements and also 2 small improvements.

NO_PROXY

This action now respects no_proxy/NO_PROXY environment variables which were previously ignored.

New output python-runtime-id

The new output python-runtime-id can be used to know which python version exactly was installed if you use activate-environment. See pyca/cryptography#15572 for details on why this can be useful.

🐛 Bug fixes

🚀 Enhancements

🧰 Maintenance

📚 Documentation

⬆️ Dependency updates

v10.0.1 🌈 Tolerate transient manifest timeouts

Changes

Thank you @​arguile- for making this action more resilient.

... (truncated)

Commits

Updates Comfy-Org/github-workflows/.github/workflows/cursor-review.yml from f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 to a404fd4a59dcd3add76200e68a26d1f6c548dc62

Commits
  • a404fd4 test(bump-callers): make the glob-flatness guard skip /** directory exclusi...
  • 5d76700 ci(lint): fail on org repo literals not on a committed allowlist (#224)
  • See full diff in compare view

Updates Comfy-Org/github-workflows/.github/workflows/groom.yml from 23c7b69392d08e57f545d393faa391e43cf4dd55 to a404fd4a59dcd3add76200e68a26d1f6c548dc62

Commits
  • a404fd4 test(bump-callers): make the glob-flatness guard skip /** directory exclusi...
  • 5d76700 ci(lint): fail on org repo literals not on a committed allowlist (#224)
  • f22ad8f feat(workflow-pins): assert every uses: ref is SHA-pinned, and pin the last...
  • a53cc12 test(workflow-pins): table-driven declared-vs-documented input drift harness ...
  • 60a8788 test(reviewers): one shared parser corpus for both reviewers.yml ports, plus ...
  • fd452c7 refactor(pr-risk): extract the sourceable helpers into scripts/pr-risk/lib.sh...
  • 802766b fix(cursor-review): own a per-PR concurrency group so skip-cursor-review canc...
  • 422cfa4 ci(bump-callers): add WATCHED_EXEC to the five fleets whose asset directory o...
  • df8f7a6 ci: bump groom to github-workflows@23c7b69 (#294)
  • See full diff in compare view

Updates Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml from 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e to a404fd4a59dcd3add76200e68a26d1f6c548dc62

Commits
  • a404fd4 test(bump-callers): make the glob-flatness guard skip /** directory exclusi...
  • 5d76700 ci(lint): fail on org repo literals not on a committed allowlist (#224)
  • f22ad8f feat(workflow-pins): assert every uses: ref is SHA-pinned, and pin the last...
  • a53cc12 test(workflow-pins): table-driven declared-vs-documented input drift harness ...
  • 60a8788 test(reviewers): one shared parser corpus for both reviewers.yml ports, plus ...
  • fd452c7 refactor(pr-risk): extract the sourceable helpers into scripts/pr-risk/lib.sh...
  • 802766b fix(cursor-review): own a per-PR concurrency group so skip-cursor-review canc...
  • 422cfa4 ci(bump-callers): add WATCHED_EXEC to the five fleets whose asset directory o...
  • df8f7a6 ci: bump groom to github-workflows@23c7b69 (#294)
  • 23c7b69 feat(groom): hoist agent-sandbox pre-exec validation out of the billed agent ...
  • Additional commits viewable in compare view

Updates actions/setup-python from 6 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates codecov/codecov-action from 7.0.0 to 7.1.1

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the ci-dependencies group with 8 updates in the /.github/workflows directory:

| Package | From | To |
| --- | --- | --- |
| [Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml](https://github.com/comfy-org/github-workflows) | `c6b3effa6d2e9fff97500d9688b54106f556c433` | `a404fd4a59dcd3add76200e68a26d1f6c548dc62` |
| [actions/checkout](https://github.com/actions/checkout) | `6` | `7` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `9.0.0` | `10.1.0` |
| [Comfy-Org/github-workflows/.github/workflows/cursor-review.yml](https://github.com/comfy-org/github-workflows) | `f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0` | `a404fd4a59dcd3add76200e68a26d1f6c548dc62` |
| [Comfy-Org/github-workflows/.github/workflows/groom.yml](https://github.com/comfy-org/github-workflows) | `23c7b69392d08e57f545d393faa391e43cf4dd55` | `a404fd4a59dcd3add76200e68a26d1f6c548dc62` |
| [Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml](https://github.com/comfy-org/github-workflows) | `3b2c8ca1f52056b54453a659fdb4473cfc88aa0e` | `a404fd4a59dcd3add76200e68a26d1f6c548dc62` |
| [actions/setup-python](https://github.com/actions/setup-python) | `6` | `7` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `7.0.0` | `7.1.1` |



Updates `Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml` from c6b3effa6d2e9fff97500d9688b54106f556c433 to a404fd4a59dcd3add76200e68a26d1f6c548dc62
- [Commits](Comfy-Org/github-workflows@c6b3eff...a404fd4)

Updates `actions/checkout` from 6 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

Updates `astral-sh/setup-uv` from 9.0.0 to 10.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
- [Commits](astral-sh/setup-uv@c771a70...bec219d)

Updates `Comfy-Org/github-workflows/.github/workflows/cursor-review.yml` from f22ad8f888fdef6f0a50bfdfa96bb20f74f651a0 to a404fd4a59dcd3add76200e68a26d1f6c548dc62
- [Commits](Comfy-Org/github-workflows@f22ad8f...a404fd4)

Updates `Comfy-Org/github-workflows/.github/workflows/groom.yml` from 23c7b69392d08e57f545d393faa391e43cf4dd55 to a404fd4a59dcd3add76200e68a26d1f6c548dc62
- [Commits](Comfy-Org/github-workflows@23c7b69...a404fd4)

Updates `Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml` from 3b2c8ca1f52056b54453a659fdb4473cfc88aa0e to a404fd4a59dcd3add76200e68a26d1f6c548dc62
- [Commits](Comfy-Org/github-workflows@3b2c8ca...a404fd4)

Updates `actions/setup-python` from 6 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6...v7)

Updates `codecov/codecov-action` from 7.0.0 to 7.1.1
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@fb8b358...303a32d)

---
updated-dependencies:
- dependency-name: Comfy-Org/github-workflows/.github/workflows/agents-md-integrity.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: astral-sh/setup-uv
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/cursor-review.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/groom.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: Comfy-Org/github-workflows/.github/workflows/public-repo-hygiene.yml
  dependency-version: a404fd4a59dcd3add76200e68a26d1f6c548dc62
  dependency-type: direct:production
  dependency-group: ci-dependencies
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-dependencies
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 19, 2026
@coderabbitai

coderabbitai Bot commented Sep 19, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: cdc298f1-082b-4d5a-af2f-4c1be3255455

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants