Skip to content

chore(deps): bump the actions group with 3 updates - #47

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-7a64ec186f
Aug 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-7a64ec186f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 3 updates: github/codeql-action, dawidd6/action-send-mail and trufflesecurity/trufflehog.

Updates github/codeql-action from 4.37.6 to 4.37.7

Release notes

Sourced from github/codeql-action's releases.

v4.37.7

  • Update default CodeQL bundle version to 2.26.3. #4085
Changelog

Sourced from github/codeql-action's changelog.

4.37.7 - 13 Aug 2026

  • Update default CodeQL bundle version to 2.26.3. #4085
Commits
  • ff2f1c6 Merge pull request #4093 from github/update-v4.37.7-be7a3dbb8
  • 951a133 Update changelog for v4.37.7
  • be7a3db Merge pull request #4087 from github/dependabot/npm_and_yarn/npm-minor-0aa561...
  • 9310334 Merge pull request #4086 from github/mbg/thread-action-state-to-codeql
  • b4d8a54 Rebuild
  • ab5db25 Bump the npm-minor group across 1 directory with 8 updates
  • 38055a3 Drop logger from databaseInitCluster in interface
  • 1f87aed Merge pull request #4085 from github/update-bundle/codeql-bundle-v2.26.3
  • dc1b98a Make logger available to getCodeQLForCmd
  • 6f0220e Merge pull request #4084 from github/navntoft/bump-undici
  • Additional commits viewable in compare view

Updates dawidd6/action-send-mail from 6e502825a508b867ab2954ad6343b68787624c01 to 0bbdab096651ee93f37ec02383e088183d41ff0b

Commits
  • 0bbdab0 build(deps): bump nodemailer from 9.0.4 to 9.0.5 (#309)
  • 62b29de build(deps): bump nodemailer from 9.0.3 to 9.0.4 (#308)
  • 8de3c31 node_modules: update (#307)
  • 5cdad7c build(deps): bump undici from 6.27.0 to 6.28.0 (#306)
  • 2e600f3 build(deps): bump brace-expansion from 5.0.7 to 5.0.9 (#305)
  • 12335b9 build(deps): bump brace-expansion from 5.0.6 to 5.0.7 (#304)
  • c50dc4c build(deps): bump nodemailer from 9.0.1 to 9.0.3 (#303)
  • 994f270 build(deps): bump undici from 6.24.1 to 6.27.0 (#301)
  • 94de994 fix: Use extended HELLO with github.com domain (#302)
  • See full diff in compare view

Updates trufflesecurity/trufflehog from 3.96.0 to 3.97.0

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.0

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.96.0...v3.97.0

Commits
  • bcfcf73 fix(detectors/harness): allow underscore in PAT account segment (#5153)
  • f567838 Add AWS Secrets Manager metadata type (#5210)
  • ee476c7 update huggingface to fix unbounded resources bug (#5204)
  • 37ed218 fix blogger detector to use Google API prefix instead of generic hex string (...
  • 55db46b Add custom endpoint support to the S3 source (#5202)
  • 96b593f fix(jiratoken): stop 202 reverification retry loop (#5200)
  • f9daad8 Add SolarWinds Observability detector (#5199)
  • 8b5a47c Deprecated bingsubscriptionkey detector (#5179)
  • 3539500 Anthropic detector: surface API error detail on non-2xx verification (#5180)
  • 58cb799 Deprecate AppOptics detector (#5198)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 3 updates: [github/codeql-action](https://github.com/github/codeql-action), [dawidd6/action-send-mail](https://github.com/dawidd6/action-send-mail) and [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog).


Updates `github/codeql-action` from 4.37.6 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.6...v4.37.7)

Updates `dawidd6/action-send-mail` from 6e502825a508b867ab2954ad6343b68787624c01 to 0bbdab096651ee93f37ec02383e088183d41ff0b
- [Release notes](https://github.com/dawidd6/action-send-mail/releases)
- [Commits](dawidd6/action-send-mail@6e50282...0bbdab0)

Updates `trufflesecurity/trufflehog` from 3.96.0 to 3.97.0
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@v3.96.0...v3.97.0)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.37.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: dawidd6/action-send-mail
  dependency-version: 0bbdab096651ee93f37ec02383e088183d41ff0b
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions labels Aug 22, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner August 22, 2026 17:34
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions labels Aug 22, 2026
@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 7cc7bb8 into main Aug 22, 2026
1 check passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-7a64ec186f branch August 22, 2026 19:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant