Skip to content

Bump ASFHyP3/actions/.github/workflows/reusable-bump-version.yml from 0.21.1 to 0.22.0 - #273

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/github_actions/ASFHyP3/actions/dot-github/workflows/reusable-bump-version.yml-0.22.0
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/github_actions/ASFHyP3/actions/dot-github/workflows/reusable-bump-version.yml-0.22.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps ASFHyP3/actions/.github/workflows/reusable-bump-version.yml from 0.21.1 to 0.22.0.

Release notes

Sourced from ASFHyP3/actions/.github/workflows/reusable-bump-version.yml's releases.

Actions v0.22.0

Added

  • reusable-pixi-tasks.yml: A reusable pixi task runner for running a matrix of pixi tasks in pixi environments.
  • reusable-pixi-version-info.yml: A reusable version info workflow that uses pixi as the environment manager instead of mamba/conda.
  • The reusable docker workflows (AWS ECR and GHCR) now accept these new optional inputs:
    • fetch_depth, to specify the number of commits fetched when checking out
    • provenance, to specify whether to generate provenance attestations for the build or not
    • platforms, a comma-separated list of target platforms to build for
    • build_args, a new-line separated list of docker build arguments like "arg=value" The default values of these arguments a set to maintain backwards compatibility of this workflow.
  • The reusable docker workflows now provide these outputs:
    • image_repository, the image repository the docker image was pushed to and includes the image registry
    • image_uri, the full URI of the docker image including the image registry, repository, and tag

Changed

  • ⚠️ The reusable docker AWS ECR workflow now uses OIDC for authentication.
  • The reusable docker workflows (AWS ECR and GHCR) will now only add test and latest image tags when the calling event is a push event, instead of doing so for any not pull_request event, allowing workflow_dispatch events to build images without potentially clobbering the test or latest tag.
Changelog

Sourced from ASFHyP3/actions/.github/workflows/reusable-bump-version.yml's changelog.

[0.22.0]

Added

  • reusable-pixi-tasks.yml: A reusable pixi task runner for running a matrix of pixi tasks in pixi environments.
  • reusable-pixi-version-info.yml: A reusable version info workflow that uses pixi as the environment manager instead of mamba/conda.
  • The reusable docker workflows (AWS ECR and GHCR) now accept these new optional inputs:
    • fetch_depth, to specify the number of commits fetched when checking out
    • provenance, to specify whether to generate provenance attestations for the build or not
    • platforms, a comma-separated list of target platforms to build for
    • build_args, a new-line separated list of docker build arguments like "arg=value" The default values of these arguments a set to maintain backwards compatibility of this workflow.
  • The reusable docker workflows now provide these outputs:
    • image_repository, the image repository the docker image was pushed to and includes the image registry
    • image_uri, the full URI of the docker image including the image registry, repository, and tag

Changed

  • ⚠️ The reusable docker AWS ECR workflow now uses OIDC for authentication.
  • The reusable docker workflows (AWS ECR and GHCR) will now only add test and latest image tags when the calling event is a push event, instead of doing so for any not pull_request event, allowing workflow_dispatch events to build images without potentially clobbering the test or latest tag.
Commits
  • 9bde558 Merge pull request #342 from ASFHyP3/develop
  • f11a676 Merge pull request #339 from ASFHyP3/dependabot/github_actions/github-actions...
  • 1d942b0 Updated wording for clarity and consistency in the README.
  • 378b387 Bump the github-actions-deps group across 1 directory with 4 updates
  • dec1f12 Merge pull request #340 from ASFHyP3/support-docker-lambdas
  • c5abe5f Merge branch 'develop' into support-docker-lambdas
  • 563a6a3 Merge pull request #341 from ASFHyP3/support-pixi
  • 7ca8685 doc pixi tasks
  • 2360736 Add alternate pixi-based version info workflow
  • 498f354 Add fast fail input
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ASFHyP3/actions/.github/workflows/reusable-bump-version.yml](https://github.com/asfhyp3/actions) from 0.21.1 to 0.22.0.
- [Release notes](https://github.com/asfhyp3/actions/releases)
- [Changelog](https://github.com/ASFHyP3/actions/blob/develop/CHANGELOG.md)
- [Commits](ASFHyP3/actions@v0.21.1...v0.22.0)

---
updated-dependencies:
- dependency-name: ASFHyP3/actions/.github/workflows/reusable-bump-version.yml
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Bump the minor version number of this project labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code minor Bump the minor version number of this project

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants