chore(deps): Bump anthropics/claude-code-action from 1.0.140 to 1.0.183 - #906
Conversation
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
|
A newer version of anthropics/claude-code-action exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.140 to 1.0.183. - [Release notes](https://github.com/anthropics/claude-code-action/releases) - [Commits](anthropics/claude-code-action@fbda2eb...be7b93b) --- updated-dependencies: - dependency-name: anthropics/claude-code-action dependency-version: 1.0.183 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
8eb3504 to
d86dd1b
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — rebase (applied)Rebase completed and pushed. |
|
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: d86dd1b94ec4239c45826dd3f6434624a280c9bb
Review mode: triage-approved (single reviewer)
Summary
Dependabot bump of anthropics/claude-code-action from 1.0.140 to 1.0.183 in two workflow files. Pure SHA pin update: both changed lines swap fbda2eb1 for be7b93b1. I verified via the GitHub API that the annotated tag v1.0.183 dereferences to commit be7b93b1907a4abad570368f3c74b6fe3807510b, which matches the new pin exactly. Triage's low-risk assessment is confirmed.
Linked issue analysis
No linked issues — routine Dependabot dependency update, none expected.
Findings
- Pin integrity verified: v1.0.183 tag → commit be7b93b1907a4abad570368f3c74b6fe3807510b (matches both changed lines).
- Version comments: feature-ideation-reusable.yml correctly updates
# v1.0.140→# v1.0.183; compliance-audit-and-improvement.yml keeps its generic# v1comment (unchanged, acceptable). - No workflow logic, permissions, triggers, or secrets handling changed.
- MCP secret-scanning tool not available in this run; gitleaks CI check passed (SUCCESS), and the diff contains no secret material.
- Dependabot notes a newer version exists (PR was rebased by dev-lead automation); a follow-up PR will arrive normally — not a blocker.
CI status
All required checks green: ShellCheck, Lint, CodeQL, SonarCloud (quality gate passed), gitleaks secret scan, agent-shield, bats, Agent Security Scan, dependency-audit — all SUCCESS. Cancelled dev-lead dispatch/relay/resume jobs are superseded automation runs, not failures. mergeStateStatus BLOCKED only due to pending review requirement.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
3f9d24a
into
main
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: d86dd1b94ec4239c45826dd3f6434624a280c9bb
Review mode: triage-approved (single reviewer)
Summary
Dependabot bump of anthropics/claude-code-action from 1.0.140 to 1.0.183 across two workflow files. Pure SHA-pin update, no other changes. New pinned SHA be7b93b1907a4abad570368f3c74b6fe3807510b was independently verified via the GitHub API to match the commit the upstream v1.0.183 annotated tag points to (repo standard: SHAs looked up, never guessed). Confirms the triage low-risk assessment.
Linked issue analysis
No linked issues — standard Dependabot dependency update; not applicable.
Findings
- Pinned SHA verified against upstream: v1.0.183 tag dereferences to be7b93b1907a4abad570368f3c74b6fe3807510b — matches the diff exactly in both files.
- Upstream range (1.0.140 → 1.0.183) contains routine Claude Code/SDK version bumps and fixes; no breaking changes affecting the two call sites (inputs
claude_code_oauth_token/promptunchanged). - Minor, non-blocking: version comment in compliance-audit-and-improvement.yml reads
# v1while feature-ideation-reusable.yml reads# v1.0.183— pre-existing comment-style inconsistency, cosmetic only. - Secret-scanning MCP tool not available in this run; the gitleaks CI check passed (SUCCESS). No secrets touched by the diff.
- No unresolved review threads; existing reviews are approvals (dependabot-automerge bot and donpetry-bot).
CI status
All checks green: Lint, ShellCheck, bats, CodeQL, Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud, CodeRabbit, dependency-audit — all SUCCESS or intentionally SKIPPED. A few dev-lead dispatch/ci-relay runs show CANCELLED but were superseded by later SUCCESS runs of the same checks.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.



Bumps anthropics/claude-code-action from 1.0.140 to 1.0.183.
Release notes
Sourced from anthropics/claude-code-action's releases.
... (truncated)
Commits
be7b93bchore: bump Claude Code to 2.1.220 and Agent SDK to 0.3.220e0cf66dchore: bump Claude Code to 2.1.219 and Agent SDK to 0.3.21944423bdchore: bump Claude Code to 2.1.218 and Agent SDK to 0.3.218b00a341fix: share one exchanged WIF credential across spawned Claude processes (#1407)fa7e2f0chore: bump Claude Code to 2.1.217 and Agent SDK to 0.3.217b76a077chore: bump Claude Code to 2.1.216 and Agent SDK to 0.3.216af0559echore: bump Claude Code to 2.1.215 and Agent SDK to 0.3.2153553f84chore: bump Claude Code to 2.1.214 and Agent SDK to 0.3.214700e7f8chore: bump Claude Code to 2.1.212 and Agent SDK to 0.3.2123e807ecfix: handle null comment/review author from deleted accounts (#1490)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)