From a303f846a4fe5afa2a4deb7eca4bc6d235770f3f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 3 Aug 2026 09:53:27 -0400 Subject: [PATCH] chore: bump the minor-and-patch group with 3 updates (#39183) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps the minor-and-patch group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) and [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials). Updates `actions/checkout` from 7.0.0 to 7.0.1
Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates `pypa/gh-action-pypi-publish` from 1.14.0 to 1.14.2
Release notes

Sourced from pypa/gh-action-pypi-publish's releases.

v1.14.2

🛠️ Urgh… Another release!? Again? Explain yourself!

Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.

[!tip] So what most people will find useful is @​takluyver💰's update of Twine to v7 that we use internally (#416). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.

🧐 Tell me why..

TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like aio-libs/aiohttp#13226 around July 23. On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.

I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.

Over the course of investigation, @​facutuesca💰 found and fixed a related underlying cache invalidation bug in sigstore/sigstore-python#1838, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.

Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: https://publishing-five-minute-timeout.tiiny.site.

🫶 New Contributors

🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​davidbrochart💰 and @​Dreamsorcerer💰 for turning my attention (in #415 and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. @​bdraco💰 came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. @​miketheman💰 confirmed the Warehouse-side details. Also, @​jku💰 and @​woodruffw💰 helped work through, review and release the Sigstore ecosystem upstream libs.

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and [on GitHub][release discussion].

[![GH Sponsors badge]][GH Sponsors URL]

... (truncated)

Commits

Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.3
Release notes

Sourced from aws-actions/configure-aws-credentials's releases.

v6.2.3

6.2.3 (2026-07-22)

Bug Fixes

v6.2.2

6.2.2 (2026-07-07)

Miscellaneous Chores

Changelog

Sourced from aws-actions/configure-aws-credentials's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

6.2.3 (2026-07-22)

Bug Fixes

6.2.2 (2026-07-07)

Miscellaneous Chores

6.2.1 (2026-06-26)

Bug Fixes

6.2.0 (2026-06-01)

Features

Bug Fixes

6.1.3 (2026-05-28)

Bug Fixes

6.1.2 (2026-05-26)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .../workflows/_compile_integration_test.yml | 2 +- .github/workflows/_lint.yml | 2 +- .github/workflows/_refresh_model_profiles.yml | 4 ++-- .github/workflows/_release.yml | 22 +++++++++---------- .github/workflows/_test.yml | 2 +- .github/workflows/_test_pydantic.yml | 2 +- .github/workflows/_test_vcr.yml | 2 +- .github/workflows/bump_uv_pin.yml | 2 +- .github/workflows/check_agents_sync.yml | 2 +- .github/workflows/check_diffs.yml | 6 ++--- .github/workflows/check_extras_sync.yml | 2 +- .github/workflows/check_release_deps.yml | 2 +- .github/workflows/check_versions.yml | 2 +- .github/workflows/close_unchecked_issues.yml | 2 +- .github/workflows/codspeed.yml | 4 ++-- .github/workflows/integration_tests.yml | 12 +++++----- .github/workflows/pr_labeler.yml | 2 +- .github/workflows/pr_labeler_backfill.yml | 2 +- .github/workflows/tag-external-issues.yml | 4 ++-- 19 files changed, 39 insertions(+), 39 deletions(-) diff --git a/.github/workflows/_compile_integration_test.yml b/.github/workflows/_compile_integration_test.yml index 7d0b366cbb..0df37f8b55 100644 --- a/.github/workflows/_compile_integration_test.yml +++ b/.github/workflows/_compile_integration_test.yml @@ -35,7 +35,7 @@ jobs: timeout-minutes: 20 name: "Python ${{ inputs.python-version }}" steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ inputs.python-version }} + UV" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/_lint.yml b/.github/workflows/_lint.yml index fb7900fc89..953b878c18 100644 --- a/.github/workflows/_lint.yml +++ b/.github/workflows/_lint.yml @@ -38,7 +38,7 @@ jobs: timeout-minutes: 20 steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ inputs.python-version }} + UV" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/_refresh_model_profiles.yml b/.github/workflows/_refresh_model_profiles.yml index 95b7d1b8a8..ef29805ab9 100644 --- a/.github/workflows/_refresh_model_profiles.yml +++ b/.github/workflows/_refresh_model_profiles.yml @@ -91,11 +91,11 @@ jobs: runs-on: ubuntu-latest steps: - name: "📋 Checkout" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "📋 Checkout langchain-profiles CLI" if: inputs.cli-path == '' - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: langchain-ai/langchain ref: ${{ inputs.cli-ref }} diff --git a/.github/workflows/_release.yml b/.github/workflows/_release.yml index ecdb14bb93..4d0f46575b 100644 --- a/.github/workflows/_release.yml +++ b/.github/workflows/_release.yml @@ -152,7 +152,7 @@ jobs: version: ${{ steps.check-version.outputs.version }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Set up Python + uv uses: "./.github/actions/uv_setup" @@ -293,7 +293,7 @@ jobs: outputs: release-body: ${{ steps.generate-release-body.outputs.release-body }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: langchain-ai/langchain path: langchain @@ -391,7 +391,7 @@ jobs: contents: read timeout-minutes: 20 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 # We explicitly *don't* set up caching here. This ensures our tests are # maximally sensitive to catching breakage. @@ -556,7 +556,7 @@ jobs: id-token: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 with: @@ -564,7 +564,7 @@ jobs: path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/ - name: Publish to test PyPI - uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 with: packages-dir: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/ verbose: true @@ -613,7 +613,7 @@ jobs: AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME }} LANGCHAIN_TESTS_USER_AGENT: ${{ secrets.LANGCHAIN_TESTS_USER_AGENT }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 # We implement this conditional as Github Actions does not have good support # for conditionally needing steps. https://github.com/actions/runner/issues/491 @@ -773,11 +773,11 @@ jobs: # No API keys needed for now - deepagents `make test` only runs unit tests steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: path: langchain - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: ${{ matrix.package.repo }} path: ${{ matrix.package.name }} @@ -840,7 +840,7 @@ jobs: working-directory: ${{ env.EFFECTIVE_WORKING_DIR }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Set up Python + uv uses: "./.github/actions/uv_setup" @@ -854,7 +854,7 @@ jobs: path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/ - name: Publish package distributions to PyPI - uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1 + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 with: packages-dir: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/ verbose: true @@ -885,7 +885,7 @@ jobs: working-directory: ${{ env.EFFECTIVE_WORKING_DIR }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Set up Python + uv uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/_test.yml b/.github/workflows/_test.yml index 7869f67870..1b0cd7bd6b 100644 --- a/.github/workflows/_test.yml +++ b/.github/workflows/_test.yml @@ -33,7 +33,7 @@ jobs: name: "Python ${{ inputs.python-version }}" steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ inputs.python-version }} + UV" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/_test_pydantic.yml b/.github/workflows/_test_pydantic.yml index 6d72a3797f..5f53928a3a 100644 --- a/.github/workflows/_test_pydantic.yml +++ b/.github/workflows/_test_pydantic.yml @@ -36,7 +36,7 @@ jobs: name: "Pydantic ~=${{ inputs.pydantic-version }}" steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ inputs.python-version }} + UV" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/_test_vcr.yml b/.github/workflows/_test_vcr.yml index 2948014c5d..2fe1870b46 100644 --- a/.github/workflows/_test_vcr.yml +++ b/.github/workflows/_test_vcr.yml @@ -34,7 +34,7 @@ jobs: timeout-minutes: 20 name: "Python ${{ inputs.python-version }}" steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ inputs.python-version }} + UV" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/bump_uv_pin.yml b/.github/workflows/bump_uv_pin.yml index e38268c37b..2c2a3a4c0a 100644 --- a/.github/workflows/bump_uv_pin.yml +++ b/.github/workflows/bump_uv_pin.yml @@ -33,7 +33,7 @@ jobs: contents: write pull-requests: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Resolve current and latest uv versions id: versions diff --git a/.github/workflows/check_agents_sync.yml b/.github/workflows/check_agents_sync.yml index 851a33ae43..2d895d8ca5 100644 --- a/.github/workflows/check_agents_sync.yml +++ b/.github/workflows/check_agents_sync.yml @@ -27,7 +27,7 @@ jobs: runs-on: ubuntu-latest steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🔍 Check CLAUDE.md and AGENTS.md are in sync" run: | diff --git a/.github/workflows/check_diffs.yml b/.github/workflows/check_diffs.yml index fde5b2990f..6307c94250 100644 --- a/.github/workflows/check_diffs.yml +++ b/.github/workflows/check_diffs.yml @@ -46,7 +46,7 @@ jobs: if: ${{ !contains(github.event.pull_request.labels.*.name, 'ci-ignore') }} steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Setup Python 3.11" uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: @@ -159,7 +159,7 @@ jobs: run: working-directory: ${{ matrix.job-configs.working-directory }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python ${{ matrix.job-configs.python-version }} + UV" uses: "./.github/actions/uv_setup" @@ -195,7 +195,7 @@ jobs: if: github.repository_owner == 'langchain-ai' runs-on: ubuntu-latest steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Setup Python 3.11" uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/check_extras_sync.yml b/.github/workflows/check_extras_sync.yml index f76bfe46c6..089e80a23a 100644 --- a/.github/workflows/check_extras_sync.yml +++ b/.github/workflows/check_extras_sync.yml @@ -30,7 +30,7 @@ jobs: timeout-minutes: 2 steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Set up Python and uv" uses: "./.github/actions/uv_setup" diff --git a/.github/workflows/check_release_deps.yml b/.github/workflows/check_release_deps.yml index aef6b9b761..28b0ad047c 100644 --- a/.github/workflows/check_release_deps.yml +++ b/.github/workflows/check_release_deps.yml @@ -50,7 +50,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: fetch-depth: 0 diff --git a/.github/workflows/check_versions.yml b/.github/workflows/check_versions.yml index 1b69843ffb..e99d4a1b3c 100644 --- a/.github/workflows/check_versions.yml +++ b/.github/workflows/check_versions.yml @@ -23,7 +23,7 @@ jobs: runs-on: ubuntu-latest steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - uses: astral-sh/setup-uv@0ca8f610542aa7f4acaf39e65cf4eb3c35091883 # v7 with: diff --git a/.github/workflows/close_unchecked_issues.yml b/.github/workflows/close_unchecked_issues.yml index b980eefb08..28b9ac9388 100644 --- a/.github/workflows/close_unchecked_issues.yml +++ b/.github/workflows/close_unchecked_issues.yml @@ -36,7 +36,7 @@ jobs: issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Generate GitHub App token id: app-token diff --git a/.github/workflows/codspeed.yml b/.github/workflows/codspeed.yml index 9badd47acc..ff3c97a817 100644 --- a/.github/workflows/codspeed.yml +++ b/.github/workflows/codspeed.yml @@ -32,7 +32,7 @@ jobs: if: ${{ github.repository_owner == 'langchain-ai' && !contains(github.event.pull_request.labels.*.name, 'codspeed-ignore') }} steps: - name: "📋 Checkout Code" - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "🐍 Setup Python 3.11" uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: @@ -62,7 +62,7 @@ jobs: job-configs: ${{ fromJson(needs.build.outputs.codspeed) }} fail-fast: false steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: "📦 Install UV Package Manager" uses: astral-sh/setup-uv@0ca8f610542aa7f4acaf39e65cf4eb3c35091883 # v7 diff --git a/.github/workflows/integration_tests.yml b/.github/workflows/integration_tests.yml index 633b931df9..a6d234226f 100644 --- a/.github/workflows/integration_tests.yml +++ b/.github/workflows/integration_tests.yml @@ -172,12 +172,12 @@ jobs: working-directory: ${{ fromJSON(needs.compute-matrix.outputs.matrix).working-directory }} steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: path: langchain # These libraries exist outside of the monorepo and need to be checked out separately - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: langchain-ai/langchain-google path: langchain-google @@ -186,12 +186,12 @@ jobs: uses: google-github-actions/auth@7c6bc770dae815cd3e89ee6cdf493a5fab2cc093 # v3 with: credentials_json: "${{ secrets.GOOGLE_CREDENTIALS }}" - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: langchain-ai/langchain-aws path: langchain-aws - name: "🔐 Configure AWS Credentials" - uses: aws-actions/configure-aws-credentials@254c19bd240aabef8777f48595e9d2d7b972184b # v6 + uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6 with: aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }} aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }} @@ -371,11 +371,11 @@ jobs: path: libs/deepagents steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: path: langchain - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 with: repository: ${{ matrix.package.repo }} path: ${{ matrix.package.name }} diff --git a/.github/workflows/pr_labeler.yml b/.github/workflows/pr_labeler.yml index ff0c851cef..9982500310 100644 --- a/.github/workflows/pr_labeler.yml +++ b/.github/workflows/pr_labeler.yml @@ -52,7 +52,7 @@ jobs: steps: # Checks out the BASE branch (safe for pull_request_target — never # the PR head). Needed to load .github/scripts/pr-labeler*. - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Generate GitHub App token if: github.event.action == 'opened' diff --git a/.github/workflows/pr_labeler_backfill.yml b/.github/workflows/pr_labeler_backfill.yml index 83450caf9d..31f5343f53 100644 --- a/.github/workflows/pr_labeler_backfill.yml +++ b/.github/workflows/pr_labeler_backfill.yml @@ -27,7 +27,7 @@ jobs: issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Generate GitHub App token id: app-token diff --git a/.github/workflows/tag-external-issues.yml b/.github/workflows/tag-external-issues.yml index ef584b7f6d..ef5a83cc24 100644 --- a/.github/workflows/tag-external-issues.yml +++ b/.github/workflows/tag-external-issues.yml @@ -51,7 +51,7 @@ jobs: issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Generate GitHub App token id: app-token @@ -119,7 +119,7 @@ jobs: issues: write steps: - - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v6 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6 - name: Generate GitHub App token id: app-token