build(deps): bump DataDog/dd-octo-sts-action from 1.0.4 to 1.0.5 - #769
dd-octo-sts[bot] merged 1 commit into
Conversation
Bumps [DataDog/dd-octo-sts-action](https://github.com/datadog/dd-octo-sts-action) from 1.0.4 to 1.0.5. - [Release notes](https://github.com/datadog/dd-octo-sts-action/releases) - [Commits](DataDog/dd-octo-sts-action@96a2546...c85802a) --- updated-dependencies: - dependency-name: DataDog/dd-octo-sts-action dependency-version: 1.0.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2c1b5aff38
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| core.setOutput('approved', exists ? 'true' : 'false'); | ||
|
|
||
| - uses: DataDog/dd-octo-sts-action@96a25462dbcb10ebf0bfd6e2ccc917d2ab235b9a # v1.0.4 | ||
| - uses: DataDog/dd-octo-sts-action@c85802a58e202b7e764b5441e4378c76043c8108 # v1.0.5 |
There was a problem hiding this comment.
Upgrade the composite action invocation too
This updates only the two direct workflow invocations even though .github/actions/upsert-pr-comment/action.yml:27 still pins v1.0.4 and is actively called by both ci.yml:231 and codecheck.yml:55. Consequently, those CI paths continue running the old action and do not receive v1.0.5's dependency vulnerability upgrades; update the composite action's pin to the same verified SHA as part of this bump.
Useful? React with 👍 / 👎.
Scan-Build Report
Bug Summary
Reports
|
||||||||||||||||||||||||||||||||||||
CI Test ResultsRun: #36587150241 | Commit:
Status Overview
Legend: ✅ passed | ❌ failed | ⚪ skipped | 🚫 cancelled Summary: Total: 32 | Passed: 32 | Failed: 0 Updated: 2026-09-29 16:06:33 UTC |
Bumps DataDog/dd-octo-sts-action from 1.0.4 to 1.0.5.
Release notes
Sourced from DataDog/dd-octo-sts-action's releases.
Commits
c85802aMerge pull request #26 from DataDog/qiwen.chen/add-client-version-headers48b1149update readme example31e598eAdd client name/version headers to STS exchange requestsd557589Merge pull request #17 from DataDog/feature/oidc-claims-debug8641d85Fix token hash encoding10bd475deduplicate JWT parsinge5d6667Merge remote-tracking branch 'origin/main' into feature/oidc-claims-debug19f21aeMerge pull request #25 from DataDog/dependabot/npm_and_yarn/npm_and_yarn-8455...95aa0f7Bump brace-expansion in the npm_and_yarn group across 1 directoryf62c2a0Merge pull request #22 from DataDog/engraver-auto-version-upgrade/minorpatch/...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)