[llvm] Update [Github] Update GHA Dependencies (PR #226856)
Mend Renovate via llvm-commits
llvm-commits at lists.llvm.org
Sun Sep 27 23:23:24 PDT 2026
https://github.com/renovate-bot updated https://github.com/llvm/llvm-project/pull/226856
>From 8fad016183d9281c5e6a1a0e62f824972a064cf5 Mon Sep 17 00:00:00 2001
From: Mend Renovate <bot at renovateapp.com>
Date: Mon, 28 Sep 2026 06:23:09 +0000
Subject: [PATCH] Update [Github] Update GHA Dependencies
---
.github/workflows/ci-post-commit-analyzer.yml | 2 +-
.github/workflows/gha-codeql.yml | 4 ++--
.github/workflows/libc-fullbuild-tests.yml | 2 +-
.github/workflows/libc-overlay-tests.yml | 4 ++--
.github/workflows/libcxx-build-containers.yml | 2 +-
.github/workflows/mlir-spirv-tests.yml | 2 +-
.github/workflows/release-binaries.yml | 2 +-
.github/workflows/release-tasks.yml | 2 +-
.github/workflows/scorecard.yml | 4 ++--
.github/workflows/spirv-tests.yml | 2 +-
.github/workflows/sycl-tests.yml | 2 +-
.github/workflows/upload-release-artifact/action.yml | 2 +-
.github/workflows/zizmor.yml | 2 +-
13 files changed, 16 insertions(+), 16 deletions(-)
diff --git a/.github/workflows/ci-post-commit-analyzer.yml b/.github/workflows/ci-post-commit-analyzer.yml
index 639ac4c65d1b1..a88888aa9c962 100644
--- a/.github/workflows/ci-post-commit-analyzer.yml
+++ b/.github/workflows/ci-post-commit-analyzer.yml
@@ -46,7 +46,7 @@ jobs:
persist-credentials: false
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
# A full build of llvm, clang, lld, and lldb takes about 250MB
# of ccache space. There's not much reason to have more than this,
diff --git a/.github/workflows/gha-codeql.yml b/.github/workflows/gha-codeql.yml
index bde5ca511e8e4..24c659df20933 100644
--- a/.github/workflows/gha-codeql.yml
+++ b/.github/workflows/gha-codeql.yml
@@ -30,9 +30,9 @@ jobs:
sparse-checkout: |
.github/
- name: Initialize CodeQL
- uses: github/codeql-action/init at 99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
+ uses: github/codeql-action/init at 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
languages: actions
queries: security-extended
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze at 99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
+ uses: github/codeql-action/analyze at 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
diff --git a/.github/workflows/libc-fullbuild-tests.yml b/.github/workflows/libc-fullbuild-tests.yml
index 6bec66da492d5..9faffa87eb8d2 100644
--- a/.github/workflows/libc-fullbuild-tests.yml
+++ b/.github/workflows/libc-fullbuild-tests.yml
@@ -138,7 +138,7 @@ jobs:
# Do not use direct GHAC access even though it is supported by sccache. GHAC rejects
# frequent small object writes.
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 1G
key: libc_fullbuild_v3_${{ matrix.target }}_${{ matrix.build_type }}_${{ matrix.c_compiler }}
diff --git a/.github/workflows/libc-overlay-tests.yml b/.github/workflows/libc-overlay-tests.yml
index 6f2804c5615e7..aec119654c168 100644
--- a/.github/workflows/libc-overlay-tests.yml
+++ b/.github/workflows/libc-overlay-tests.yml
@@ -64,7 +64,7 @@ jobs:
# Do not use direct GHAC access even though it is supported by sccache. GHAC rejects
# frequent small object writes.
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 1G
key: libc_overlay_build_v2_${{ matrix.os }}_${{ matrix.compiler.c_compiler }}
@@ -155,7 +155,7 @@ jobs:
persist-credentials: false
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 1G
key: libc_qemu_overlay_${{ matrix.arch }}_${{ matrix.c_compiler }}
diff --git a/.github/workflows/libcxx-build-containers.yml b/.github/workflows/libcxx-build-containers.yml
index aaeb02b47c28d..5a0108a9cc3a1 100644
--- a/.github/workflows/libcxx-build-containers.yml
+++ b/.github/workflows/libcxx-build-containers.yml
@@ -51,7 +51,7 @@ jobs:
TAG: ${{ github.sha }}
- name: Log in to GitHub Container Registry
- uses: docker/login-action at af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
+ uses: docker/login-action at dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
diff --git a/.github/workflows/mlir-spirv-tests.yml b/.github/workflows/mlir-spirv-tests.yml
index b3d275d7bf305..1631bc37fcf00 100644
--- a/.github/workflows/mlir-spirv-tests.yml
+++ b/.github/workflows/mlir-spirv-tests.yml
@@ -32,7 +32,7 @@ jobs:
with:
persist-credentials: false
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 2G
key: spirv-mlir-ubuntu-26.04
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 1844da1ba90e6..1971d06961f5b 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -226,7 +226,7 @@ jobs:
# get changed unexpectedly.
- uses: actions/setup-python at 5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
- python-version: '3.14.6'
+ python-version: '3.14.7'
# For some reason this is needed on Windows or else the build system can't find python3.lib.
- name: Setup Python library path
diff --git a/.github/workflows/release-tasks.yml b/.github/workflows/release-tasks.yml
index bebce9618711b..b7c8f1f22765c 100644
--- a/.github/workflows/release-tasks.yml
+++ b/.github/workflows/release-tasks.yml
@@ -129,7 +129,7 @@ jobs:
llvm/utils/lit/dist
- name: Upload lit to pypi.org
- uses: pypa/gh-action-pypi-publish at cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
+ uses: pypa/gh-action-pypi-publish at dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
with:
packages-dir: llvm/utils/lit/dist/
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 6a4ae0b02c27d..6baa6104fa4d5 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -36,7 +36,7 @@ jobs:
persist-credentials: false
- name: "Run analysis"
- uses: ossf/scorecard-action at 4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3
+ uses: ossf/scorecard-action at 2d1146689b8cda280b9bc96326124645441f03bc # v2.4.4
with:
results_file: results.sarif
results_format: sarif
@@ -57,6 +57,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning"
- uses: github/codeql-action/upload-sarif at 99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
+ uses: github/codeql-action/upload-sarif at 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
with:
sarif_file: results.sarif
diff --git a/.github/workflows/spirv-tests.yml b/.github/workflows/spirv-tests.yml
index 34a4267eaf039..45a958676804e 100644
--- a/.github/workflows/spirv-tests.yml
+++ b/.github/workflows/spirv-tests.yml
@@ -28,7 +28,7 @@ jobs:
with:
persist-credentials: false
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 2G
key: spirv-ubuntu-26.04
diff --git a/.github/workflows/sycl-tests.yml b/.github/workflows/sycl-tests.yml
index 1c29be7186b64..4587f6a5530d8 100644
--- a/.github/workflows/sycl-tests.yml
+++ b/.github/workflows/sycl-tests.yml
@@ -27,7 +27,7 @@ jobs:
with:
persist-credentials: false
- name: Setup ccache
- uses: hendrikmuhs/ccache-action at d62db5f07c26379fc4b4e0916f098a92573c3b03 # v1.2.23
+ uses: hendrikmuhs/ccache-action at f09c25b45002a07be2955cbe52e8cee55643f89d # v1.2.24
with:
max-size: 2G
key: sycl-ubuntu-26.04
diff --git a/.github/workflows/upload-release-artifact/action.yml b/.github/workflows/upload-release-artifact/action.yml
index 30385a393203b..96bd2031074f7 100644
--- a/.github/workflows/upload-release-artifact/action.yml
+++ b/.github/workflows/upload-release-artifact/action.yml
@@ -79,7 +79,7 @@ runs:
id: provenance
# TODO(boomanaiden154): This is now a thin wrapper around actions/attest.
# We should eventually move over to that.
- uses: actions/attest-build-provenance at 0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
+ uses: actions/attest-build-provenance at 4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: ${{ steps.download-artifact.outputs.download-path }}/*
diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml
index b5a9a6a60b235..e8b3a19529d05 100644
--- a/.github/workflows/zizmor.yml
+++ b/.github/workflows/zizmor.yml
@@ -26,4 +26,4 @@ jobs:
persist-credentials: false
- name: Run zizmor
- uses: zizmorcore/zizmor-action at 3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
+ uses: zizmorcore/zizmor-action at cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
More information about the llvm-commits
mailing list