[ci]: Bump the ci-dependencies group with 6 updates #7385

Open
dependabot[bot] opened 11:24am on August 2, 2026 wants to merge 1 commit into microsoft/lightgbm main from
dependabot/github_actions/ci-dependencies-8208df3302
Diff Delta:
0
About 1 Diff Delta/hour
Classified as:  General

dependabot-bot's Description of Work

Bumps the ci-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| actions/checkout | 6.0.3 | 7.0.1 |
| lycheeverse/lychee-action | 2.8.0 | 2.9.0 |
| prefix-dev/setup-pixi | 0.9.6 | 0.10.0 |
| r-lib/actions/setup-pandoc | 2.12.0 | 2.12.1 |
| r-lib/actions/setup-tinytex | 2.12.0 | 2.12.1 |
| release-drafter/release-drafter | 7.4.0 | 7.5.1 |

Updates actions/checkout from 6.0.3 to 7.0.1

Release notes

Sourced from actions/checkout's releases.



v7.0.1


What's Changed



Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1


v7.0.0


What's Changed



New Contributors



Full Changelog: https://github.com/actions/checkout/compare/v6.0.3...v7.0.0


v6.1.0


What's Changed



https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change


Full Changelog: https://github.com/actions/checkout/compare/v6.0.3...v6.1.0


Changelog

Sourced from actions/checkout's changelog.



Changelog


v7.0.1



v7.0.0



v6.0.3



v6.0.2



v6.0.1



v6.0.0



v5.0.1



v5.0.0



v4.3.1



v4.3.0



v4.2.2



v4.2.1



<!-- raw HTML omitted -->

... (truncated)

Commits


Updates lycheeverse/lychee-action from 2.8.0 to 2.9.0

Release notes

Sourced from lycheeverse/lychee-action's releases.



v2.9.0


Summary


This release updates the default lychee version from v0.23.0 to v0.24.2.


The main reason for this release is compatibility with the new lychee 0.24.x release artifacts. Starting with lychee v0.24.0, the archive layout changed, and the lychee binary may now be packaged inside a subdirectory. lychee-action now detects that layout automatically, so users can upgrade without changing their workflows.


If you use:


uses: lycheeverse/lychee-action@v2


you will get the new version once the floating v2 tag has been updated. If you pin exact versions, update to:


uses: lycheeverse/[email protected]


What’s new from lychee v0.24.x


Better diagnostics


lychee now reports line and column numbers for detected links. This makes broken link reports easier to act on, especially in larger documentation sites or generated reports.


Text fragment checking


lychee can now check URL text fragments, such as links containing #:~:text=.... This helps catch links that point to a valid page but no longer points to the intended highlighted text.


Sitemap support


lychee can now read sitemap.xml inputs. This is useful for checking published websites or generated documentation sites where the sitemap is the easiest source of URLs to validate.


JUnit output


lychee now supports JUnit output. This makes it easier to integrate link checking results with CI systems and test reporting tools that understand JUnit XML.


Redirect and remap visibility


lychee can now show redirects and remaps more clearly. This helps explain why a URL was checked as a different final URL and makes debugging link-checking behavior easier.


Multiple config files


lychee now supports multiple configuration files and expanded config handling. This is useful for repositories that split documentation, website, or package-specific link-checking settings.


Timeout handling


lychee can now accept timeouts explicitly. This gives users more control over how strict their link checks should be for flaky or slow endpoints.


Fixes and reliability improvements


<!-- raw HTML omitted -->

... (truncated)

Commits


Updates prefix-dev/setup-pixi from 0.9.6 to 0.10.0

Release notes

Sourced from prefix-dev/setup-pixi's releases.



v0.10.0


<!-- raw HTML omitted -->

What's Changed


💥 Breaking changes



⬆️ Dependency updates



New Contributors



Full Changelog: https://github.com/prefix-dev/setup-pixi/compare/v0.9.6...v0.10.0


Commits


Updates r-lib/actions/setup-pandoc from 2.12.0 to 2.12.1

Changelog

Sourced from r-lib/actions/setup-pandoc's changelog.




v2.12.1 (2026-06-23)




  • [setup-r] now avoids a warning about an url.parse() deprecation
    (#1074).




  • [setup-r-dependencies] now uses quarto-dev/quarto-actions v2.2.0
    (@​jdblischak, #1076).




  • Examples: test-coverage.yaml now uses codecov/codecov-action v7
    (@​shikokuchuo, #1081).




  • New example claude-investigate.yaml workflow (@​DavisVaughan, #1084).





v2.12.0 (2026-04-29)




  • All node.js actions use node 24 now. Relatedly, all example workflows
    use recent versions of actions that use node 24.




  • [setup-r] now uses use-public-rspm: true by default on Linux and
    Windows. macOS binaries require further opt-in with
    use-public-rspm: always.




  • It is now possible to require actions to be pinned to a full-length
    commit SHA in repositories using r-lib/actions (#1070).




  • [setup-pandoc][setup-r-dependencies] now default to Pandoc
    version 3.8.3.




  • [setup-r-dependencies] now includes the R architecture in the
    cache key, so caches for macos-15 (Apple Silicon) and
    macos-15-intel (Rosetta/x86_64) no longer collide (#1035).




  • [setup-r] run apt-get update without -qq on Linux, to make
    debugging update failures easier (#1058).





v2.11.4 (2025-10-08)




  • [setup-r] correctly installs Rtools again on aarch64 Windows,
    as needed.



v2.11.3 (2025-03-24)




  • [setup-r] now supports Rtools45, and installs it by default
    for R >= 4.5.0.



v2.11.2 (2025-02-19)




  • [setup-r] now installs gfortran 14.2 for R 4.5.0 and later (#965).




  • [setup-r] now does not use PPM on aarch64 Linux, because PPM




<!-- raw HTML omitted -->

... (truncated)

Commits


Updates r-lib/actions/setup-tinytex from 2.12.0 to 2.12.1

Changelog

Sourced from r-lib/actions/setup-tinytex's changelog.




v2.12.1 (2026-06-23)




  • [setup-r] now avoids a warning about an url.parse() deprecation
    (#1074).




  • [setup-r-dependencies] now uses quarto-dev/quarto-actions v2.2.0
    (@​jdblischak, #1076).




  • Examples: test-coverage.yaml now uses codecov/codecov-action v7
    (@​shikokuchuo, #1081).




  • New example claude-investigate.yaml workflow (@​DavisVaughan, #1084).





v2.12.0 (2026-04-29)




  • All node.js actions use node 24 now. Relatedly, all example workflows
    use recent versions of actions that use node 24.




  • [setup-r] now uses use-public-rspm: true by default on Linux and
    Windows. macOS binaries require further opt-in with
    use-public-rspm: always.




  • It is now possible to require actions to be pinned to a full-length
    commit SHA in repositories using r-lib/actions (#1070).




  • [setup-pandoc][setup-r-dependencies] now default to Pandoc
    version 3.8.3.




  • [setup-r-dependencies] now includes the R architecture in the
    cache key, so caches for macos-15 (Apple Silicon) and
    macos-15-intel (Rosetta/x86_64) no longer collide (#1035).




  • [setup-r] run apt-get update without -qq on Linux, to make
    debugging update failures easier (#1058).





v2.11.4 (2025-10-08)




  • [setup-r] correctly installs Rtools again on aarch64 Windows,
    as needed.



v2.11.3 (2025-03-24)




  • [setup-r] now supports Rtools45, and installs it by default
    for R >= 4.5.0.



v2.11.2 (2025-02-19)




  • [setup-r] now installs gfortran 14.2 for R 4.5.0 and later (#965).




  • [setup-r] now does not use PPM on aarch64 Linux, because PPM




<!-- raw HTML omitted -->

... (truncated)

Commits


Updates release-drafter/release-drafter from 7.4.0 to 7.5.1

Release notes

Sourced from release-drafter/release-drafter's releases.



v7.5.1


What's Changed


Bug Fixes



  • fix: use PR changed files as the source of truth for path filtering (#1640) @​cchanche


Full Changelog: https://github.com/release-drafter/release-drafter/compare/v7.5.0...v7.5.1


v7.5.0


What's Changed


New



Bug Fixes



Dependency Updates



Full Changelog: https://github.com/release-drafter/release-drafter/compare/v7.4.0...v7.5.0


Commits



  • 4d75298 chore: release v7.5.1


  • 87be2bf fix: use PR changed files as the source of truth for path filtering (#1640)


  • 73b95fa chore: release v7.5.0


  • 46fd415 Fix/align increments to semver lib from 0.0.0 (#1636)


  • ee02572 chore: upgrade various deps


  • cd91445 build(deps): bump undici from 6.24.1 to 6.27.0 (#1637)


  • 33c969b fix: require actual matches for category mode only (#1639)


  • 5d6d314 ci: support label 'dependencies' for dependabot

  • See full diff in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions

12 total changed files
Loading changes...
You've reached the end of this PR review
You have reached the final “why is this here?”