Skip to content

Bump the actions group with 11 updates - #377

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions-9eef8402e4
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/github_actions/actions-9eef8402e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 17, 2026 •

Copy link
Copy Markdown

Bumps the actions group with 11 updates:

Package From To
actions/checkout 2 7
actions/cache 2 6
game-ci/unity-builder 2.1.2 6.0.0
actions/upload-artifact 2.3.1 7.0.1
actions/setup-python 3 7
actions/download-artifact 3.0.2 8.0.1
huggingface/doc-builder/.github/workflows/build_main_documentation.yml 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
huggingface/doc-builder/.github/workflows/build_pr_documentation.yml 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
huggingface/doc-builder/.github/workflows/delete_doc_comment.yml 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
pypa/cibuildwheel 2.10.1 4.2.1
pypa/gh-action-pypi-publish 1.5.1 1.14.2

Updates actions/checkout from 2 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Commits

Updates actions/cache from 2 to 6

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Updates game-ci/unity-builder from 2.1.2 to 6.0.0

Release notes

Sourced from game-ci/unity-builder's releases.

v6.0.0 - Thin wrapper around game-ci/cli

unity-builder is now a thin wrapper around game-ci/cli: the same Docker/build orchestration you can also run locally with the CLI directly, rather than this action's own separate implementation. Promoted from the v6.0.0-beta.1 pre-release (announced in #845) after several weeks of community testing and no reported regressions against @v5.

Inputs, secrets, and project layout are unchanged from @v5 - this should be a drop-in upgrade for the vast majority of workflows.

Since the beta

  • unityVersion overrides (matrix builds testing one project against several Unity versions) are now correctly passed through as --engineVersion instead of being silently ignored (#847).

Still true from the beta's known gaps

  • providerStrategy values other than "local" throw - same behavior as @v5 without the orchestrator plugin installed, not new.

See the v6.0.0-beta.1 announcement for the full technical background, and #844 for the implementation writeup.

If you're currently pinned to @v6.0.0-beta.1 explicitly (rather than floating @v6), you can safely move to @v6 or this exact tag - no changes needed.

v6.0.0-beta.1 — Thin wrapper around game-ci/cli (pre-release)

This is a pre-release for testers only. It does not affect @v5, @v4, or any other tag you're already using.

What's changing

This is a preview of the next major version of unity-builder — a rewrite as a genuine thin wrapper around game-ci/cli. Instead of running its own Docker orchestration logic, the action now downloads the game-ci CLI binary and shells out to its build command. Same underlying build behavior, much smaller/simpler action codebase, and CI now genuinely exercises the same code path a developer running the CLI locally would use.

Full details: unity-builder#844.

How to try it

Pin cliVersion explicitly to the release this was verified against, so your test run is deterministic even if a newer cli release ships mid-beta:

- uses: game-ci/unity-builder@v6.0.0-beta.1
  with:
    targetPlatform: WebGL
    cliVersion: v0.1.8

Everything else (inputs, secrets, project structure) stays the same as @v5 — swap the version tag and see if your existing workflow still works as expected.

Known gaps in this pre-release

  • unityVersion overrides are ignored. The CLI always auto-detects the Unity version from your project's ProjectSettings/ProjectVersion.txt. If your workflow explicitly sets unityVersion to something other than the project's actual version, that override won't take effect (you'll get a core.warning in the log, not a silent difference).
  • providerStrategy values other than "local" throw an error — same as today's @v5 without the separately-installed orchestrator plugin, not a new regression, but called out in case it affects your setup.
  • Not yet live-tested against a real runner by us beyond local vitest/ncc build checks — this release exists specifically so that can happen against real projects before the actual v6 cut.

What we need from testers

  • Try your actual build workflow against @v6.0.0-beta.1 (a separate branch/workflow file is safest, not a change to your main CI).
  • Report back in the tracking issue — what worked, what broke, anything that felt different from @v5, even if it's minor.

... (truncated)

Commits
  • eb1b9fb Thin wrapper: invoke game-ci/cli as a subprocess (#844)
  • d829bfc chore: v5 prep — dep bumps, linux64 extension, legacy CLI removal, Cli→Plugin...
  • 2240bed fix: update action runtime from Node.js 20 to Node.js 24 (#827)
  • 16c5c20 chore: quality-tightening (oxfmt + oxlint + tsc + vitest + husky + actionlint...
  • 821ba97 Generalize unity-builder plugin contract (#832)
  • 365bdb5 chore: migrate to mise + bump yarn to 4.14.1 (#830)
  • c7a43cd Adds support for useHostNetwork the unity-builder (#828)
  • d10fd10 fix: remove concurrency block from reusable workflow to prevent deadlock (#829)
  • ef0555f Orchestrator Extraction — Remove Orchestrator Code, Add Plugin Loader (#819)
  • 4a7fc08 Fix failing windows builds in CI (#820)
  • Additional commits viewable in compare view

Updates actions/upload-artifact from 2.3.1 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Updates actions/setup-python from 3 to 7

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Updates actions/download-artifact from 3.0.2 to 8.0.1

Release notes

Sourced from actions/download-artifact's releases.

v8.0.1

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v7.0.0

v7 - What's new

[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

... (truncated)

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

Updates huggingface/doc-builder/.github/workflows/build_main_documentation.yml from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/build_main_documentation.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates huggingface/doc-builder/.github/workflows/build_pr_documentation.yml from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/build_pr_documentation.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates huggingface/doc-builder/.github/workflows/delete_doc_comment.yml from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169

Changelog

Sourced from huggingface/doc-builder/.github/workflows/delete_doc_comment.yml's changelog.

Release checklist

  1. Checkout the release branch (for a patch the current release branch, for a new minor version, create one):
    git checkout -b vXX.xx-release
    The -b is only necessary for creation (so remove it when doing a patch).
  2. Change the version in src/doc_builder/__init__.py and pyproject.toml to the proper value.
  3. Commit these changes with the message: "Release: v<VERSION>".
  4. Add a tag in git to mark the release:
    git tag v<VERSION> -m 'Adds tag v<VERSION> for pypi'
    Push the tag and release commit to git:
    git push --tags origin vXX.xx-release
  5. Build the source distribution and the wheel in the top-level directory:
    rm -rf dist
    uv build
  6. Upload the package to the pypi test server first:
    twine upload dist/* -r testpypi
  7. Check that you can install it in a virtualenv by running:
    pip install hf-doc-builder
    pip uninstall hf-doc-builder
    pip install -i https://test.pypi.org/simple/ hf-doc-builder
    It's recommended to check that there are no issues building the docs, so try running a command like doc-builder.
  8. Upload the final version to actual pypi:
    twine upload dist/* -r pypi
  9. Add release notes to the tag in github once everything is looking hunky-dory.
  10. Go back to the main branch and update the version in src/doc_builder/__init__.py and pyproject.toml to the new version ".dev" and push to main.
Commits
  • 17ccdf1 chore: enable Dependabot weekly GitHub Actions bumps (#790)
  • 47c6b58 fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)
  • cf20b09 Revert "Comment out schedule for search engine population (#826)" (#827)
  • 9978a41 Comment out schedule for search engine population (#826)
  • c2d27f6 Fix vectorless Meilisearch document payload (#825)
  • 953aa44 Add vectorless full-text docs ingestion (#824)
  • 1b16dac Remove setup.py in favor of pyproject.toml (#816)
  • bcd143e Check anchors in links (#820)
  • 68667a5 fix(kit): accept a lowercase region in language codes (pt-br) (#823)
  • 0ab9ea0 Ship a pre-commit hook for doc-builder style (#818)
  • Additional commits viewable in compare view

Updates pypa/cibuildwheel from 2.10.1 to 4.2.1

Release notes

Sourced from pypa/cibuildwheel's releases.

v4.2.1

  • 🐛 Respects the NuGet package sources configured on the machine when installing CPython on Windows, instead of always falling back to nuget.org (#2966)
  • 🐛 Fixes a NameError on Pyodide when an already-compatible wheel was reused, which made the test step fail (#2968)
  • 🛠 Updates the Android Python versions, and the Android testbed's Gradle version, making it compatible with Java 25 (#2962)
  • 🛠 Updates dependencies including CPython 3.15.0rc2 (#2965, #2970, #2976, #2981, #2985)

v4.2.0

  • 🌟 CPython 3.15 wheels are now built by default - without the "cpython-prerelease" enable set. It's time to build and upload these wheels to PyPI! This release includes CPython 3.15.0rc1, which is guaranteed to be ABI compatible with the final release. (#2944)
  • ✨ Adds Pyodide 3.15 support with the cp315-pyodide_wasm32 build identifier, using Pyodide 315.0.0a2. These are also stable wrt. the final release. (#295...

    Description has been truncated

Bumps the actions group with 11 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `2` | `7` |
| [actions/cache](https://github.com/actions/cache) | `2` | `6` |
| [game-ci/unity-builder](https://github.com/game-ci/unity-builder) | `2.1.2` | `6.0.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `2.3.1` | `7.0.1` |
| [actions/setup-python](https://github.com/actions/setup-python) | `3` | `7` |
| [actions/download-artifact](https://github.com/actions/download-artifact) | `3.0.2` | `8.0.1` |
| [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) | `90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [huggingface/doc-builder/.github/workflows/delete_doc_comment.yml](https://github.com/huggingface/doc-builder) | `90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` |
| [pypa/cibuildwheel](https://github.com/pypa/cibuildwheel) | `2.10.1` | `4.2.1` |
| [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.5.1` | `1.14.2` |


Updates `actions/checkout` from 2 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](actions/checkout@v2...v7)

Updates `actions/cache` from 2 to 6
- [Release notes](https://github.com/actions/cache/releases)
- [Commits](actions/cache@v2...v6)

Updates `game-ci/unity-builder` from 2.1.2 to 6.0.0
- [Release notes](https://github.com/game-ci/unity-builder/releases)
- [Commits](game-ci/unity-builder@9f79830...eb1b9fb)

Updates `actions/upload-artifact` from 2.3.1 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v2.3.1...043fb46)

Updates `actions/setup-python` from 3 to 7
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v3...v7)

Updates `actions/download-artifact` from 3.0.2 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@9bc31d5...3e5f45b)

Updates `huggingface/doc-builder/.github/workflows/build_main_documentation.yml` from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@90b4ee2...17ccdf1)

Updates `huggingface/doc-builder/.github/workflows/build_pr_documentation.yml` from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@90b4ee2...17ccdf1)

Updates `huggingface/doc-builder/.github/workflows/delete_doc_comment.yml` from 90b4ee2c10b81b5c1a6367c4e6fc9e2fb510a7e3 to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
- [Release notes](https://github.com/huggingface/doc-builder/releases)
- [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md)
- [Commits](huggingface/doc-builder@90b4ee2...17ccdf1)

Updates `pypa/cibuildwheel` from 2.10.1 to 4.2.1
- [Release notes](https://github.com/pypa/cibuildwheel/releases)
- [Changelog](https://github.com/pypa/cibuildwheel/blob/main/docs/changelog.md)
- [Commits](pypa/cibuildwheel@v2.10.1...v4.2.1)

Updates `pypa/gh-action-pypi-publish` from 1.5.1 to 1.14.2
- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)
- [Commits](pypa/gh-action-pypi-publish@v1.5.1...v1.14.2)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: game-ci/unity-builder
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: huggingface/doc-builder/.github/workflows/delete_doc_comment.yml
  dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169
  dependency-type: direct:production
  dependency-group: actions
- dependency-name: pypa/cibuildwheel
  dependency-version: 4.2.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: pypa/gh-action-pypi-publish
  dependency-version: 1.14.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 17, 2026
Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants