chore(deps): bump the github-actions group with 5 updates - #289
Merged
dustinbyrne merged 2 commits intoSep 30, 2026
Merged
Conversation
Bumps the github-actions group with 5 updates: | Package | From | To | | --- | --- | --- | | [github/codeql-action/init](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.38.0` | `4.38.1` | | [pnpm/setup](https://github.com/pnpm/setup) | `2.1.0` | `3.0.0` | | [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.323.0` | `1.326.0` | | [PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.yml](https://github.com/posthog/posthog-sdk-test-harness) | `1.5.0` | `1.8.0` | Updates `github/codeql-action/init` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.1 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...1c5b675) Updates `pnpm/setup` from 2.1.0 to 3.0.0 - [Release notes](https://github.com/pnpm/setup/releases) - [Commits](pnpm/setup@703c526...fbda4c8) Updates `ruby/setup-ruby` from 1.323.0 to 1.326.0 - [Release notes](https://github.com/ruby/setup-ruby/releases) - [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb) - [Commits](ruby/setup-ruby@984c0c8...762794c) Updates `PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.yml` from 1.5.0 to 1.8.0 - [Release notes](https://github.com/posthog/posthog-sdk-test-harness/releases) - [Changelog](https://github.com/PostHog/posthog-sdk-test-harness/blob/main/CHANGELOG.md) - [Commits](PostHog/posthog-sdk-test-harness@e487249...6054eaa) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: pnpm/setup dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: ruby/setup-ruby dependency-version: 1.326.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.yml dependency-version: 1.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
posthog-ruby-async Compliance ReportDate: 2026-09-30T23:13:38.792085+00:00
|
| Test | Status | Duration |
|---|---|---|
| Format Validation.Event Has Required Fields | ✅ | 109ms |
| Format Validation.Event Has Uuid | ✅ | 106ms |
| Format Validation.Event Has Lib Properties | ✅ | 109ms |
| Format Validation.Distinct Id Is String | ✅ | 106ms |
| Format Validation.Token Is Present | ✅ | 106ms |
| Format Validation.Custom Properties Preserved | ✅ | 106ms |
| Format Validation.Event Has Timestamp | ✅ | 106ms |
| Format Validation.Non Utc Event Timestamp Is Converted To Utc | ✅ | 7ms |
| Retry Behavior.Retries On 503 | ✅ | 5311ms |
| Retry Behavior.Does Not Retry On 400 | ✅ | 2110ms |
| Retry Behavior.Does Not Retry On 401 | ✅ | 2110ms |
| Retry Behavior.Respects Retry After Header | ✅ | 8117ms |
| Retry Behavior.Implements Backoff | ✅ | 15520ms |
| Retry Behavior.Retries On 500 | ✅ | 5210ms |
| Retry Behavior.Retries On 502 | ✅ | 5213ms |
| Retry Behavior.Retries On 504 | ✅ | 5211ms |
| Retry Behavior.Max Retries Respected | ✅ | 15623ms |
| Deduplication.Generates Unique Uuids | ✅ | 114ms |
| Deduplication.Preserves Uuid On Retry | ✅ | 5212ms |
| Deduplication.Preserves Uuid And Timestamp On Retry | ✅ | 10317ms |
| Deduplication.Preserves Uuid And Timestamp On Batch Retry | ✅ | 5215ms |
| Deduplication.No Duplicate Events In Batch | ✅ | 111ms |
| Deduplication.Different Events Have Different Uuids | ✅ | 108ms |
| Compression.Sends Gzip When Enabled | ✅ | 107ms |
| Batch Format.Uses Proper Batch Structure | ✅ | 107ms |
| Batch Format.Flush With No Events Sends Nothing | ✅ | 4ms |
| Batch Format.Multiple Events Batched Together | ✅ | 112ms |
| Error Handling.Does Not Retry On 403 | ✅ | 2109ms |
| Error Handling.Does Not Retry On 413 | ✅ | 2108ms |
| Error Handling.Retries On 408 | ✅ | 5212ms |
Feature_Flags Tests
View Details
| Test | Status | Duration |
|---|---|---|
| Request Payload.Request With Person Properties Device Id | ✅ | 108ms |
| Request Payload.Flags Request Uses V2 Query Param | ✅ | 107ms |
| Request Payload.Flags Request Hits Flags Path Not Decide | ✅ | 107ms |
| Request Payload.Flags Request Omits Authorization Header | ✅ | 107ms |
| Request Payload.Token In Flags Body Matches Init | ✅ | 108ms |
| Request Payload.Groups Round Trip | ✅ | 107ms |
| Request Payload.Groups Default To Empty Object | ✅ | 107ms |
| Request Payload.Disable Geoip False Propagates As Geoip Disable False | ✅ | 107ms |
| Request Payload.Disable Geoip Omitted Defaults To False | ❌ | 107ms |
| Request Payload.Flag Keys To Evaluate Contains Only Requested Key | ✅ | 107ms |
| Request Lifecycle.No Flags Request On Init Alone | ✅ | 4ms |
| Request Lifecycle.No Flags Request On Normal Capture | ✅ | 106ms |
| Request Lifecycle.Two Flag Calls Produce Two Remote Requests | ✅ | 114ms |
| Request Lifecycle.Mock Response Value Is Returned To Caller | ✅ | 108ms |
| Retry Behavior.Retries Flags On 502 | ✅ | 209ms |
| Retry Behavior.Retries Flags On 504 | ✅ | 248ms |
| Side Effect Events.Get Feature Flag Captures Feature Flag Called Event | ✅ | 108ms |
Failures
request_payload.disable_geoip_omitted_defaults_to_false
Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']
posthog-ruby-sync Compliance ReportDate: 2026-09-30T23:13:43.828145+00:00
|
| Test | Status | Duration |
|---|---|---|
| Format Validation.Event Has Required Fields | ✅ | 10ms |
| Format Validation.Event Has Uuid | ✅ | 6ms |
| Format Validation.Event Has Lib Properties | ✅ | 7ms |
| Format Validation.Distinct Id Is String | ✅ | 9ms |
| Format Validation.Token Is Present | ✅ | 7ms |
| Format Validation.Custom Properties Preserved | ✅ | 7ms |
| Format Validation.Event Has Timestamp | ✅ | 7ms |
| Format Validation.Non Utc Event Timestamp Is Converted To Utc | ✅ | 7ms |
| Retry Behavior.Retries On 503 | ✅ | 5231ms |
| Retry Behavior.Does Not Retry On 400 | ✅ | 2011ms |
| Retry Behavior.Does Not Retry On 401 | ✅ | 2011ms |
| Retry Behavior.Respects Retry After Header | ✅ | 8015ms |
| Retry Behavior.Implements Backoff | ✅ | 15370ms |
| Retry Behavior.Retries On 500 | ✅ | 5116ms |
| Retry Behavior.Retries On 502 | ✅ | 5117ms |
| Retry Behavior.Retries On 504 | ✅ | 5117ms |
| Retry Behavior.Max Retries Respected | ✅ | 15587ms |
| Deduplication.Generates Unique Uuids | ✅ | 24ms |
| Deduplication.Preserves Uuid On Retry | ✅ | 5159ms |
| Deduplication.Preserves Uuid And Timestamp On Retry | ✅ | 10372ms |
| Deduplication.Preserves Uuid And Timestamp On Batch Retry | ✅ | 5157ms |
| Deduplication.No Duplicate Events In Batch | ✅ | 19ms |
| Deduplication.Different Events Have Different Uuids | ✅ | 9ms |
| Compression.Sends Gzip When Enabled | ✅ | 7ms |
| Batch Format.Uses Proper Batch Structure | ✅ | 5ms |
| Batch Format.Flush With No Events Sends Nothing | ✅ | 4ms |
| Batch Format.Multiple Events Batched Together | ❌ | 18ms |
| Error Handling.Does Not Retry On 403 | ✅ | 2007ms |
| Error Handling.Does Not Retry On 413 | ✅ | 2010ms |
| Error Handling.Retries On 408 | ✅ | 5152ms |
Failures
batch_format.multiple_events_batched_together
Expected 1 requests, got 5
Feature_Flags Tests
View Details
| Test | Status | Duration |
|---|---|---|
| Request Payload.Request With Person Properties Device Id | ✅ | 9ms |
| Request Payload.Flags Request Uses V2 Query Param | ✅ | 7ms |
| Request Payload.Flags Request Hits Flags Path Not Decide | ✅ | 6ms |
| Request Payload.Flags Request Omits Authorization Header | ✅ | 8ms |
| Request Payload.Token In Flags Body Matches Init | ✅ | 9ms |
| Request Payload.Groups Round Trip | ✅ | 8ms |
| Request Payload.Groups Default To Empty Object | ✅ | 9ms |
| Request Payload.Disable Geoip False Propagates As Geoip Disable False | ✅ | 6ms |
| Request Payload.Disable Geoip Omitted Defaults To False | ❌ | 7ms |
| Request Payload.Flag Keys To Evaluate Contains Only Requested Key | ✅ | 6ms |
| Request Lifecycle.No Flags Request On Init Alone | ✅ | 3ms |
| Request Lifecycle.No Flags Request On Normal Capture | ✅ | 5ms |
| Request Lifecycle.Two Flag Calls Produce Two Remote Requests | ✅ | 9ms |
| Request Lifecycle.Mock Response Value Is Returned To Caller | ✅ | 6ms |
| Retry Behavior.Retries Flags On 502 | ✅ | 110ms |
| Retry Behavior.Retries Flags On 504 | ✅ | 111ms |
| Side Effect Events.Get Feature Flag Captures Feature Flag Called Event | ✅ | 9ms |
Failures
request_payload.disable_geoip_omitted_defaults_to_false
Field 'geoip_disable' not found in /flags request body at path 'geoip_disable'. Available keys: ['distinct_id', 'groups', 'person_properties', 'group_properties', 'flag_keys_to_evaluate', 'token']
dustinbyrne
approved these changes
Sep 30, 2026
dustinbyrne
enabled auto-merge (squash)
September 30, 2026 23:11
dustinbyrne
deleted the
dependabot/github_actions/github-actions-8e03a7db6a
branch
September 30, 2026 23:12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the github-actions group with 5 updates:
4.38.04.38.14.38.04.38.12.1.03.0.01.323.01.326.01.5.01.8.0Updates
github/codeql-action/initfrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
github/codeql-action/analyzefrom 4.38.0 to 4.38.1Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
1c5b675Merge pull request #4152 from github/update-v4.38.1-a65b83a73a97cdcaAdd changelog entry for #4146cc6c691Update changelog for v4.38.1a65b83aMerge pull request #4146 from github/henrymercer/per-language-bundles-pr07fa87dClarify the latest-nightly eligibility exceptionf18f353Describe the bundle URL resolverecec9b5Share per-language telemetry fields without renaming79fe3a1Move download telemetry into the status-report directoryead1f7dRename the platform module549d498Simplify per-language platform eligibility checksUpdates
pnpm/setupfrom 2.1.0 to 3.0.0Release notes
Sourced from pnpm/setup's releases.
Commits
fbda4c8docs(README): update versionc868a7dfix: require-lockfile no longer accepts a lockfile pnpm will not use (#60)463911bfix: avoid deprecated shell spawning for pnpm commands (#52)6598286docs: add private registry authentication recipes (#61)c5b2e24feat!: automatically detect Node.js version files (#49)f37addefix!: include runid in cache key, restore freshest lockfile match (#43)Updates
ruby/setup-rubyfrom 1.323.0 to 1.326.0Release notes
Sourced from ruby/setup-ruby's releases.
Commits
762794cAdd ruby-3.4.11e8944e8Add jruby-10.0.7.0,jruby-10.1.2.0a0102e0Add truffleruby-40.0.0,truffleruby+graalvm-40.0.0Updates
PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.ymlfrom 1.5.0 to 1.8.0Release notes
Sourced from PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.yml's releases.
Changelog
Sourced from PostHog/posthog-sdk-test-harness/.github/workflows/test-sdk-action.yml's changelog.
... (truncated)
Commits
6054eaachore: Release v1.8.0 [skip ci]1e1a41echore(flags): add person boolean evaluation corpus (#60)0aa3f2echore: Release v1.7.1 [skip ci]1d1d5e7fix: add actionable v2 assertion diagnostics (#64)85b07bachore: Release v1.7.0 [skip ci]ba3f732ci: release v2 harness image alongside v1 (#62)2dfb1d6feat: add opt-in Gherkin v2 harness and Node CI pilot (#59)9c492aachore(deps): bump dtolnay/rust-toolchain in the github-actions group (#61)c32f495chore: Release v1.6.0 [skip ci]b6f033atest(flags): add targeted-release and percentage-rollout config fixtures (#58)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions