This pull request's diff hasn't been prepared yet. Log in with GitHub to have us prepare it for review.

[ci]: Bump the ci-dependencies group with 5 updates #7480

Merged
dependabot[bot] opened 11:25am on October 2, 2026 wanted to merge 2 commits into microsoft/lightgbm main from
dependabot/github_actions/ci-dependencies-7d0b8655e7

Pull Request Overview

  • Opened on October 1, 2026
  • Status Merged
  • Commit count 2 with first commit October 1, 2026

Total Delta

0 Total Diff Delta

Open Days

Open 2 weekdays

Test Delta

0 Diff Delta in Test Files
Breakdown by Phase

How long has this pull request spent in each phase of its lifecycle?

Fraction of total time Business days Phase
 
0.0 days Authoring 1 commit before pull request opened for review
 
1.0 day Awaiting first review
Set up deploy tracking to begin tracking full PR start-to-deploy times

Total time for pull request 1.0 business day from first commit authored to merge
Deploy tracking has not been set up

Author avatar

[ci]: Bump the ci-dependencies group with 5 updates

Bumps the ci-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| re-actors/alls-green | 1.2.2 | 1.3.0 |
| docker/build-push-action | 7.3.0 | 7.4.0 |
| prefix-dev/setup-pixi | 0.10.1 | 0.10.2 |
| r-lib/actions/setup-pandoc | 2.12.1 | 2.13.0 |
| r-lib/actions/setup-tinytex | 2.12.1 | 2.13.0 |

Updates re-actors/alls-green from 1.2.2 to 1.3.0

Release notes

Sourced from re-actors/alls-green's releases.



v1.3.0


<!-- raw HTML omitted -->

🛡️ What's Unmessed



[!caution]


There was a small command injection risk in prior versions. I consider it very low because of the specifics of the action use case. But still, do upgrade, okay?


@​illera88💰 fixed this template injection bug in #37 by passing inputs via env vars.


See GHSA-gj76-h2ch-5m76 for more detail that was first reported by @​Corbynx010💰 while I was at EuroPython.



✨ What's Improved


I did a bunch of internal refactoring including hints of what @​max-sixty💰 reported in #23. And took a small patch of @​krokofant💰 in. This involved a bunch of preparatory infra work with testing infra.


One notable improvement is that now thanks to @​tomasr8💰's and @​hugovk💰's UX suggestions in #31, the gate status output is colored in the console and should be easier to scan in the log output per line. They entries now have leading ✓/❌ acceptance marks and the actual incoming job outcomes are labeled with 🟢/🔴/⬜/⚫.


🐛 What's Fixed


The job-statuses summary could print "Some of the allowed to be skipped jobs did not succeed" based on the wrong condition — it's now tied to allowed-skips as intended, not allowed-failures.


💪 New Contributors



🪞 Full Diff: https://github.com/re-actors/alls-green/compare/v1.2.2...v1.3.0


🧔‍♂️ Release Manager: @​webknjaz 🇺🇦


💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.


GH Sponsors badge


Commits



  • b5b5b37 Merge pull request #38 from re-actors/pre-commit-ci-update-config


  • bd6edd6 [pre-commit.ci] pre-commit autoupdate


  • 3967c81 💅 Make the output easier to scan


  • e68df08 💅 Style job statuses title with a 🔮


  • 62d37b2 🧪 Unxfail 'success-of-some-allowed-to-skip-or-fail'


  • 7b5df6d 💅 Add a Codecov badge to README


  • 2410c4c 🐛 Correct reporting failed skipped jobs


  • 6457593 💅 Add a GH Sponsors badge


  • a617895 💅 Add a pre-commit.ci badge


  • 8de05dc 🧪 Force ctrace core in coveragepy

  • Additional commits viewable in compare view


Updates docker/build-push-action from 7.3.0 to 7.4.0

Release notes

Sourced from docker/build-push-action's releases.



v7.4.0



Full Changelog: https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0


Commits



  • c3c9e26 Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t...


  • 459b674 [dependabot skip] chore: update generated content


  • 4dedcb2 chore(deps): Bump @​docker/actions-toolkit from 0.99.0 to 0.100.0


  • 379bf63 Merge pull request #1620 from crazy-max/buildx-error-message


  • 9877975 chore: update generated content


  • 7ed0556 use the shared Buildx error summary helper


  • 91670ba Merge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t...


  • 80dbc86 [dependabot skip] chore: update generated content


  • 50cac3a chore(deps): Bump @​docker/actions-toolkit from 0.98.0 to 0.99.0


  • 03b4d6c Merge pull request #1617 from crazy-max/fix-metadata-workflow-commands

  • Additional commits viewable in compare view


Updates prefix-dev/setup-pixi from 0.10.1 to 0.10.2

Release notes

Sourced from prefix-dev/setup-pixi's releases.



v0.10.2


<!-- raw HTML omitted -->

What's Changed


✨ New features



Full Changelog: https://github.com/prefix-dev/setup-pixi/compare/v0.10.1...v0.10.2


Commits


Updates r-lib/actions/setup-pandoc from 2.12.1 to 2.13.0

Changelog

Sourced from r-lib/actions/setup-pandoc's changelog.



'v2.14.0` (2026-09-21)




  • [setup-r]: use-public-rspm: true now sets up P3M (https://p3m.dev)
    on macOS as well, for all repositories.




  • [setup-r] now installs flang 23 on R 4.7.0 (current R-devel) and
    later, as this is what CRAN uses now (#1107, @​andrjohns).




  • [check-r-package] now uses the correct check directory when showing
    the testthat output (#1109, @​NotAFlightRisk).





v2.13.0 (2026-08-28)




  • [setup-r] now retries r-hub.io HTTP failures (#1088, @​nbenn).




  • [setup-r] now sets the correct RTOOLS environment variables on
    aarch64 Windows (@​vjymisal0, #1104).




  • [setup-r] keep repositories if they are set by the build.
    E.g. aarch64 Windows builds now set them (@​jeroen, #1101).




  • [setup-r] now retries transient failures when resolving the R
    version from api.r-hub.io, rather than failing the job on the first
    timeout or server error (@​nbenn, #1086).




  • [setup-r-dependencies] now switches back to classic sudo, if
    available, on Linux. This fixes installing pak on Ubuntu 26.04 runners
    (@​jeroen, #1096).





v2.12.1 (2026-06-23)




  • [setup-r] now avoids a warning about an url.parse() deprecation
    (#1074).




  • [setup-r-dependencies] now uses quarto-dev/quarto-actions v2.2.0
    (@​jdblischak, #1076).




  • Examples: test-coverage.yaml now uses codecov/codecov-action v7
    (@​shikokuchuo, #1081).




  • New example claude-investigate.yaml workflow (@​DavisVaughan, #1084).





v2.12.0 (2026-04-29)




  • All node.js actions use node 24 now. Relatedly, all example workflows
    use recent versions of actions that use node 24.




  • [setup-r] now uses use-public-rspm: true by default on Linux and
    Windows. macOS binaries require further opt-in with
    use-public-rspm: always.




<!-- raw HTML omitted -->

... (truncated)

Commits



  • 465b7d8 NEWS for 2.13.0 (#1105)


  • d06a540 [setup-r] retry transient r-hub.io request failures (#1088)


  • ed9aa85 fix(setup-r): export correct RTOOLS HOME env vars on Windows ARM64 and x64 (#...


  • c86f32c setup-r-dependencies: set JAVA_HOME on Windows runners from Java 21 env vars ...


  • 2a66450 setup-r-dependencies: switch back to classic sudo on runners with sudo-rs (#1...


  • 5cc1f0d Fix minor typo (#1098)


  • 33d09fb fix: Remove stray ::group:: (#1103)


  • aae88a2 Special-case CRAN mirror for Windows ARM64 (#1101)


  • b7484da [setup-r] Support installing RTools without installing R (#1093)

  • See full diff in compare view


Updates r-lib/actions/setup-tinytex from 2.12.1 to 2.13.0

Changelog

Sourced from r-lib/actions/setup-tinytex's changelog.



'v2.14.0` (2026-09-21)




  • [setup-r]: use-public-rspm: true now sets up P3M (https://p3m.dev)
    on macOS as well, for all repositories.




  • [setup-r] now installs flang 23 on R 4.7.0 (current R-devel) and
    later, as this is what CRAN uses now (#1107, @​andrjohns).




  • [check-r-package] now uses the correct check directory when showing
    the testthat output (#1109, @​NotAFlightRisk).





v2.13.0 (2026-08-28)




  • [setup-r] now retries r-hub.io HTTP failures (#1088, @​nbenn).




  • [setup-r] now sets the correct RTOOLS environment variables on
    aarch64 Windows (@​vjymisal0, #1104).




  • [setup-r] keep repositories if they are set by the build.
    E.g. aarch64 Windows builds now set them (@​jeroen, #1101).




  • [setup-r] now retries transient failures when resolving the R
    version from api.r-hub.io, rather than failing the job on the first
    timeout or server error (@​nbenn, #1086).




  • [setup-r-dependencies] now switches back to classic sudo, if
    available, on Linux. This fixes installing pak on Ubuntu 26.04 runners
    (@​jeroen, #1096).





v2.12.1 (2026-06-23)




  • [setup-r] now avoids a warning about an url.parse() deprecation
    (#1074).




  • [setup-r-dependencies] now uses quarto-dev/quarto-actions v2.2.0
    (@​jdblischak, #1076).




  • Examples: test-coverage.yaml now uses codecov/codecov-action v7
    (@​shikokuchuo, #1081).




  • New example claude-investigate.yaml workflow (@​DavisVaughan, #1084).





v2.12.0 (2026-04-29)




  • All node.js actions use node 24 now. Relatedly, all example workflows
    use recent versions of actions that use node 24.




  • [setup-r] now uses use-public-rspm: true by default on Linux and
    Windows. macOS binaries require further opt-in with
    use-public-rspm: always.




<!-- raw HTML omitted -->

... (truncated)

Commits



  • 465b7d8 NEWS for 2.13.0 (#1105)


  • d06a540 [setup-r] retry transient r-hub.io request failures (#1088)


  • ed9aa85 fix(setup-r): export correct RTOOLS HOME env vars on Windows ARM64 and x64 (#...


  • c86f32c setup-r-dependencies: set JAVA_HOME on Windows runners from Java 21 env vars ...


  • 2a66450 setup-r-dependencies: switch back to classic sudo on runners with sudo-rs (#1...


  • 5cc1f0d Fix minor typo (#1098)


  • 33d09fb fix: Remove stray ::group:: (#1103)


  • aae88a2 Special-case CRAN mirror for Windows ARM64 (#1101)


  • b7484da [setup-r] Support installing RTools without installing R (#1093)

  • See full diff in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions

PR was closed without comments.