Skip to content

chore(deps): Bump anthropics/claude-code-action from 1.0.140 to 1.0.183 - #906

Merged
petry-projects-dependabot-automrg[bot] merged 1 commit into
mainfrom
dependabot/github_actions/anthropics/claude-code-action-1.0.183
Sep 10, 2026
Merged

chore(deps): Bump anthropics/claude-code-action from 1.0.140 to 1.0.183#906
petry-projects-dependabot-automrg[bot] merged 1 commit into
mainfrom
dependabot/github_actions/anthropics/claude-code-action-1.0.183

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor

Bumps anthropics/claude-code-action from 1.0.140 to 1.0.183.

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.183

Full Changelog: anthropics/claude-code-action@v1...v1.0.183

v1.0.182

Full Changelog: anthropics/claude-code-action@v1...v1.0.182

v1.0.181

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.181

v1.0.180

Full Changelog: anthropics/claude-code-action@v1...v1.0.180

v1.0.179

Full Changelog: anthropics/claude-code-action@v1...v1.0.179

v1.0.178

Full Changelog: anthropics/claude-code-action@v1...v1.0.178

v1.0.177

Full Changelog: anthropics/claude-code-action@v1...v1.0.177

v1.0.176

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1...v1.0.176

v1.0.175

... (truncated)

Commits
  • be7b93b chore: bump Claude Code to 2.1.220 and Agent SDK to 0.3.220
  • e0cf66d chore: bump Claude Code to 2.1.219 and Agent SDK to 0.3.219
  • 44423bd chore: bump Claude Code to 2.1.218 and Agent SDK to 0.3.218
  • b00a341 fix: share one exchanged WIF credential across spawned Claude processes (#1407)
  • fa7e2f0 chore: bump Claude Code to 2.1.217 and Agent SDK to 0.3.217
  • b76a077 chore: bump Claude Code to 2.1.216 and Agent SDK to 0.3.216
  • af0559e chore: bump Claude Code to 2.1.215 and Agent SDK to 0.3.215
  • 3553f84 chore: bump Claude Code to 2.1.214 and Agent SDK to 0.3.214
  • 700e7f8 chore: bump Claude Code to 2.1.212 and Agent SDK to 0.3.212
  • 3e807ec fix: handle null comment/review author from deleted accounts (#1490)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Dependency update PRs security Security-related PRs and issues labels Jul 26, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 26, 2026 08:12
@codeant-ai

codeant-ai Bot commented Jul 26, 2026

Copy link
Copy Markdown

Skipping PR review because a bot author is detected.

If you want to trigger CodeAnt AI, comment @codeant-ai review to trigger a manual review.

@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot enabled auto-merge (squash) July 26, 2026 08:12
@sonarqubecloud

Copy link
Copy Markdown

@dependabot @github

dependabot Bot commented on behalf of github Aug 9, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of anthropics/claude-code-action exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@don-petry
don-petry disabled auto-merge September 10, 2026 12:03
Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.140 to 1.0.183.
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@fbda2eb...be7b93b)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.183
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@don-petry
don-petry force-pushed the dependabot/github_actions/anthropics/claude-code-action-1.0.183 branch from 8eb3504 to d86dd1b Compare September 10, 2026 12:05
@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d82644e8-3719-48cb-9b7a-a265ec43fb49

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@don-petry

Copy link
Copy Markdown
Contributor

Dev-Lead — rebase (applied)

Rebase completed and pushed.

@sonarqubecloud

Copy link
Copy Markdown

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: d86dd1b94ec4239c45826dd3f6434624a280c9bb
Review mode: triage-approved (single reviewer)

Summary

Dependabot bump of anthropics/claude-code-action from 1.0.140 to 1.0.183 in two workflow files. Pure SHA pin update: both changed lines swap fbda2eb1 for be7b93b1. I verified via the GitHub API that the annotated tag v1.0.183 dereferences to commit be7b93b1907a4abad570368f3c74b6fe3807510b, which matches the new pin exactly. Triage's low-risk assessment is confirmed.

Linked issue analysis

No linked issues — routine Dependabot dependency update, none expected.

Findings

  • Pin integrity verified: v1.0.183 tag → commit be7b93b1907a4abad570368f3c74b6fe3807510b (matches both changed lines).
  • Version comments: feature-ideation-reusable.yml correctly updates # v1.0.140# v1.0.183; compliance-audit-and-improvement.yml keeps its generic # v1 comment (unchanged, acceptable).
  • No workflow logic, permissions, triggers, or secrets handling changed.
  • MCP secret-scanning tool not available in this run; gitleaks CI check passed (SUCCESS), and the diff contains no secret material.
  • Dependabot notes a newer version exists (PR was rebased by dev-lead automation); a follow-up PR will arrive normally — not a blocker.

CI status

All required checks green: ShellCheck, Lint, CodeQL, SonarCloud (quality gate passed), gitleaks secret scan, agent-shield, bats, Agent Security Scan, dependency-audit — all SUCCESS. Cancelled dev-lead dispatch/relay/resume jobs are superseded automation runs, not failures. mergeStateStatus BLOCKED only due to pending review requirement.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot merged commit 3f9d24a into main Sep 10, 2026
29 of 35 checks passed
@petry-projects-dependabot-automrg
petry-projects-dependabot-automrg Bot deleted the dependabot/github_actions/anthropics/claude-code-action-1.0.183 branch September 10, 2026 12:11

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: d86dd1b94ec4239c45826dd3f6434624a280c9bb
Review mode: triage-approved (single reviewer)

Summary

Dependabot bump of anthropics/claude-code-action from 1.0.140 to 1.0.183 across two workflow files. Pure SHA-pin update, no other changes. New pinned SHA be7b93b1907a4abad570368f3c74b6fe3807510b was independently verified via the GitHub API to match the commit the upstream v1.0.183 annotated tag points to (repo standard: SHAs looked up, never guessed). Confirms the triage low-risk assessment.

Linked issue analysis

No linked issues — standard Dependabot dependency update; not applicable.

Findings

  • Pinned SHA verified against upstream: v1.0.183 tag dereferences to be7b93b1907a4abad570368f3c74b6fe3807510b — matches the diff exactly in both files.
  • Upstream range (1.0.140 → 1.0.183) contains routine Claude Code/SDK version bumps and fixes; no breaking changes affecting the two call sites (inputs claude_code_oauth_token / prompt unchanged).
  • Minor, non-blocking: version comment in compliance-audit-and-improvement.yml reads # v1 while feature-ideation-reusable.yml reads # v1.0.183 — pre-existing comment-style inconsistency, cosmetic only.
  • Secret-scanning MCP tool not available in this run; the gitleaks CI check passed (SUCCESS). No secrets touched by the diff.
  • No unresolved review threads; existing reviews are approvals (dependabot-automerge bot and donpetry-bot).

CI status

All checks green: Lint, ShellCheck, bats, CodeQL, Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud, CodeRabbit, dependency-audit — all SUCCESS or intentionally SKIPPED. A few dev-lead dispatch/ci-relay runs show CANCELLED but were superseded by later SUCCESS runs of the same checks.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency update PRs security Security-related PRs and issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants