Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 20, 2025

Bumps guibranco/github-infisical-secrets-check-action from 4.1.18 to 4.1.23.

Release notes

Sourced from guibranco/github-infisical-secrets-check-action's releases.

Release v4.1.23

Release 4.1.23 of github-infisical-secrets-check-action

What's Changed

Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.22...v4.1.23

Release v4.1.22

Release 4.1.22 of github-infisical-secrets-check-action

What's Changed

Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.21...v4.1.22

Release v4.1.21

Release 4.1.21 of github-infisical-secrets-check-action

What's Changed

Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.20...v4.1.21

Release v4.1.20

Release 4.1.20 of github-infisical-secrets-check-action Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.19...v4.1.20

Release v4.1.23

Release 4.1.23 of github-infisical-secrets-check-action

What's Changed

Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.18...latest

Release v4.1.19

Release 4.1.19 of github-infisical-secrets-check-action

What's Changed

Full Changelog: guibranco/github-infisical-secrets-check-action@v4.1.18...v4.1.19

Commits
  • f90018b Bump guibranco/github-file-reader-action-v2 in the actions-minor group (#130)
  • 5b2213b Update Infisical CLI version fetching and download URLs (#132)
  • ca11419 Change download URL for Infisical CLI
  • 896741c Update asset naming convention in action.yml
  • 41f1633 Update tag name prefix in action.yml (#131)
  • da198fd Bump guibranco/github-file-reader-action-v2 in the actions-minor group (#128)
  • c09d15c Toggle makeLatest option in CI workflow
  • bd9afa1 Update release action names in CI workflow (#129)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @guibranco.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Description by Korbit AI

What change is being made?

Upgrade guibranco/github-infisical-secrets-check-action from v4.1.18 to v4.1.23 in the Infisical secrets check workflow.

Why are these changes being made?

Apply the latest fixes and improvements from the action (bug fixes and reliability enhancements).

Is this description stale? Ask me to generate a new description by commenting /korbit-generate-pr-description

Bumps [guibranco/github-infisical-secrets-check-action](https://github.com/guibranco/github-infisical-secrets-check-action) from 4.1.18 to 4.1.23.
- [Release notes](https://github.com/guibranco/github-infisical-secrets-check-action/releases)
- [Commits](guibranco/github-infisical-secrets-check-action@v4.1.18...v4.1.23)

---
updated-dependencies:
- dependency-name: guibranco/github-infisical-secrets-check-action
  dependency-version: 4.1.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 20, 2025

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@semanticdiff-com
Copy link

semanticdiff-com bot commented Oct 20, 2025

Review changes with  SemanticDiff

Changed Files
File Status
  .github/workflows/infisical-secrets-check.yml  0% smaller

@pr-code-reviewer
Copy link

pr-code-reviewer bot commented Oct 20, 2025

👋 Hi there!

Everything looks good!


Automatically generated with the help of gpt-3.5-turbo.
Feedback? Please don't hesitate to drop me an email at [email protected].

@korbit-ai
Copy link

korbit-ai bot commented Oct 20, 2025

By default, I don't review pull requests opened by bots. If you would like me to review this pull request anyway, you can request a review via the /korbit-review command in a comment.

@codara-ai-code-review
Copy link

Potential issues, bugs, and flaws that can introduce unwanted behavior:

  1. .github/workflows/infisical-secrets-check.yml - Upgrading to a newer version of a GitHub Action (v4.1.23 from v4.1.18) may introduce breaking changes. Ensure to review the release notes of the github-infisical-secrets-check-action to confirm that the new version does not change the expected behavior, configurations, or outputs of your workflow.

Code suggestions and improvements for better exception handling, logic, standardization, and consistency:

  1. .github/workflows/infisical-secrets-check.yml - It is advisable to specify a particular version of the action rather than using the latest one, as this helps maintain predictable behavior in future runs. Consider pinning to a more specific commit hash or using a @latest tag if you want to always get the most recent updates without worrying about breaking changes.

@guibranco guibranco enabled auto-merge (squash) October 20, 2025 22:14
@gstraccini gstraccini bot added the ☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) label Oct 20, 2025
Copy link
Member

@guibranco guibranco left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved by gstraccini[bot]

@gstraccini gstraccini bot added the 🤖 bot Automated processes or integrations label Oct 20, 2025
@guibranco
Copy link
Member

@dependabot squash and merge

@github-actions github-actions bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Oct 20, 2025
@deepsource-io
Copy link

deepsource-io bot commented Oct 20, 2025

Here's the code health analysis summary for commits f06bde7..05ce9f5. View details on DeepSource ↗.

Analysis Summary

AnalyzerStatusSummaryLink
DeepSource Test coverage LogoTest coverage✅ SuccessView Check ↗
DeepSource Secrets LogoSecrets✅ SuccessView Check ↗
DeepSource C# LogoC#✅ SuccessView Check ↗

Code Coverage Report

MetricAggregateC#
Branch Coverage100%100%
Composite Coverage0%0%
Line Coverage0%0%

💡 If you’re a repository administrator, you can configure the quality gates from the settings.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Oct 20, 2025

Beginning January 27, 2026, Dependabot will no longer support the @dependabot squash and merge command. Please use GitHub's native pull request controls instead. Please see the changelog announcement for additional details.

@coderabbitai
Copy link

coderabbitai bot commented Oct 20, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link

Infisical secrets check: ✅ No secrets leaked!

💻 Scan logs
10:14PM INF scanning for exposed secrets...
10:14PM INF 95 commits scanned.
10:14PM INF scan completed in 19.1ms
10:14PM INF no leaks found

@guibranco guibranco merged commit 4134fbe into main Oct 20, 2025
18 of 19 checks passed
@guibranco guibranco deleted the dependabot/github_actions/guibranco/github-infisical-secrets-check-action-4.1.23 branch October 20, 2025 22:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) 🤖 bot Automated processes or integrations size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants