Skip to content

[action] Bump actions/setup-python from 6 to 7 - #156

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-python-7
Open

[action] Bump actions/setup-python from 6 to 7#156
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-python-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-python from 6 to 7.

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 28, 2026
@dependabot
dependabot Bot requested a review from rasa as a code owner July 28, 2026 15:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

MegaLinter analysis: Error

Descriptor Linter Files Fixed Errors Warnings Elapsed time
❌ ACTION actionlint 3 1 0 0.42s
⚠️ ACTION zizmor 3 3 19 0 1.41s
⚠️ COPYPASTE jscpd yes 6 no 0.48s
✅ EDITORCONFIG editorconfig-checker 3 0 0 0.03s
✅ REPOSITORY betterleaks yes no no 0.99s
✅ REPOSITORY checkov yes no no 18.48s
⚠️ REPOSITORY devskim yes 118 68 14.09s
✅ REPOSITORY dustilock yes no no 0.7s
✅ REPOSITORY gitleaks yes no no 2.2s
✅ REPOSITORY git_diff yes no no 0.02s
✅ REPOSITORY grype yes no no 62.81s
✅ REPOSITORY kingfisher yes no no 8.25s
⚠️ REPOSITORY osv-scanner yes 5 no 2.05s
✅ REPOSITORY secretlint yes no no 1.17s
✅ REPOSITORY syft yes no no 2.79s
✅ REPOSITORY trivy yes no no 11.67s
✅ REPOSITORY trivy-sbom yes no no 0.22s
✅ REPOSITORY trufflehog yes no no 4.01s
✅ SPELL cspell 4 0 0 3.67s
✅ SPELL lychee 3 0 0 0.93s
✅ YAML prettier 3 3 0 0 0.58s
✅ YAML v8r 3 0 0 5.82s
✅ YAML yamllint 3 0 0 0.63s

Detailed Issues

❌ ACTION / actionlint - 1 error
.github/workflows/black.yml:30:12: workflow command "set-output" was deprecated. use `echo "{name}={value}" >> $GITHUB_OUTPUT` instead: https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions [deprecated-commands]
   |
30 |       run: |
   |            ^
⚠️ REPOSITORY / devskim - 118 errors
plementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/htmlhelp.json"},"region":{"startLine":30,"startColumn":16,"endLine":30,"endColumn":39,"charOffset":845,"charLength":23,"snippet":{"text":"http://go.microsoft.com","rendered":{"text":"http://go.microsoft.com","markdown":"`http://go.microsoft.com`"}},"sourceLanguage":"json"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"bucket/htmlhelp.json"},"replacements":[{"deletedRegion":{"charOffset":845,"charLength":23},"insertedContent":{"text":"https://go.microsoft.com"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/htmlhelp.json"},"region":{"startLine":7,"startColumn":12,"endLine":7,"endColumn":78,"charOffset":292,"charLength":66,"snippet":{"text":"\"b2b3140d42a818870c1ab13c1c7b8d4536f22bd994fa90aade89729a6009a3ae\"","rendered":{"text":"\"b2b3140d42a818870c1ab13c1c7b8d4536f22bd994fa90aade89729a6009a3ae\"","markdown":"`\"b2b3140d42a818870c1ab13c1c7b8d4536f22bd994fa90aade89729a6009a3ae\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS137138","message":{"text":"Insecure URL"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/htmlhelp.json"},"region":{"startLine":6,"startColumn":12,"endLine":6,"endColumn":35,"charOffset":218,"charLength":23,"snippet":{"text":"http://go.microsoft.com","rendered":{"text":"http://go.microsoft.com","markdown":"`http://go.microsoft.com`"}},"sourceLanguage":"json"}}}],"fixes":[{"description":{"text":"An HTTP-based URL without TLS was detected."},"artifactChanges":[{"artifactLocation":{"uri":"bucket/htmlhelp.json"},"replacements":[{"deletedRegion":{"charOffset":218,"charLength":23},"insertedContent":{"text":"https://go.microsoft.com"}}]}]}],"properties":{"tags":["ThreatModel.Integration.HTTP"],"DevSkimSeverity":"Moderate","DevSkimConfidence":"High"},"level":"warning"},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/wolcmd.json"},"region":{"startLine":8,"startColumn":12,"endLine":8,"endColumn":78,"charOffset":274,"charLength":66,"snippet":{"text":"\"02c0c776854ecd7e4fbca4b05b0fbebd3a1d1535a396e0d9e0fb9ee828b93298\"","rendered":{"text":"\"02c0c776854ecd7e4fbca4b05b0fbebd3a1d1535a396e0d9e0fb9ee828b93298\"","markdown":"`\"02c0c776854ecd7e4fbca4b05b0fbebd3a1d1535a396e0d9e0fb9ee828b93298\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/seterlvl.json"},"region":{"startLine":7,"startColumn":12,"endLine":7,"endColumn":78,"charOffset":259,"charLength":66,"snippet":{"text":"\"d4e732fe122c16450100f964c340594c21455bf7e108529027520c2974ebb971\"","rendered":{"text":"\"d4e732fe122c16450100f964c340594c21455bf7e108529027520c2974ebb971\"","markdown":"`\"d4e732fe122c16450100f964c340594c21455bf7e108529027520c2974ebb971\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/usbtreeview.json"},"region":{"startLine":19,"startColumn":20,"endLine":19,"endColumn":86,"charOffset":771,"charLength":66,"snippet":{"text":"\"779c095aaf9e8574436a2e3e9dadddf692b4bff2e17c0e82c2e547370262b2a1\"","rendered":{"text":"\"779c095aaf9e8574436a2e3e9dadddf692b4bff2e17c0e82c2e547370262b2a1\"","markdown":"`\"779c095aaf9e8574436a2e3e9dadddf692b4bff2e17c0e82c2e547370262b2a1\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/usbtreeview.json"},"region":{"startLine":14,"startColumn":20,"endLine":14,"endColumn":86,"charOffset":539,"charLength":66,"snippet":{"text":"\"2e2e44eeed022670043967820fbea91a8f13eca6f5ba4f49b4394f5a79b91261\"","rendered":{"text":"\"2e2e44eeed022670043967820fbea91a8f13eca6f5ba4f49b4394f5a79b91261\"","markdown":"`\"2e2e44eeed022670043967820fbea91a8f13eca6f5ba4f49b4394f5a79b91261\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/usbtreeview.json"},"region":{"startLine":9,"startColumn":20,"endLine":9,"endColumn":86,"charOffset":307,"charLength":66,"snippet":{"text":"\"3a8a0c7aab6950a49b661bdbc9b96c04ceed82160f88aac6e01149b1c83409cf\"","rendered":{"text":"\"3a8a0c7aab6950a49b661bdbc9b96c04ceed82160f88aac6e01149b1c83409cf\"","markdown":"`\"3a8a0c7aab6950a49b661bdbc9b96c04ceed82160f88aac6e01149b1c83409cf\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/git-all.json"},"region":{"startLine":13,"startColumn":20,"endLine":13,"endColumn":86,"charOffset":655,"charLength":66,"snippet":{"text":"\"7692d9af16b08150e28dae6c63106a46995fb44e5f4c85182ac7eb1b840543c5\"","rendered":{"text":"\"7692d9af16b08150e28dae6c63106a46995fb44e5f4c85182ac7eb1b840543c5\"","markdown":"`\"7692d9af16b08150e28dae6c63106a46995fb44e5f4c85182ac7eb1b840543c5\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/git-all.json"},"region":{"startLine":9,"startColumn":20,"endLine":9,"endColumn":86,"charOffset":397,"charLength":66,"snippet":{"text":"\"c45a7dfa2bde34059f6dbd85f49a95d73d5aea29305f51b79595e56e4f323a3d\"","rendered":{"text":"\"c45a7dfa2bde34059f6dbd85f49a95d73d5aea29305f51b79595e56e4f323a3d\"","markdown":"`\"c45a7dfa2bde34059f6dbd85f49a95d73d5aea29305f51b79595e56e4f323a3d\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}},{"ruleId":"DS173237","level":"error","message":{"text":"Do not store tokens or keys in source code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bucket/dskwipe.json"},"region":{"startLine":7,"startColumn":12,"endLine":7,"endColumn":78,"charOffset":253,"charLength":66,"snippet":{"text":"\"59badf8aa3b8416361d96361863cca495bb6469288d5b9902567b385a444754a\"","rendered":{"text":"\"59badf8aa3b8416361d96361863cca495bb6469288d5b9902567b385a444754a\"","markdown":"`\"59badf8aa3b8416361d96361863cca495bb6469288d5b9902567b385a444754a\"`"}},"sourceLanguage":"json"}}}],"properties":{"tags":["Implementation.Privacy.Token"],"DevSkimSeverity":"Important","DevSkimConfidence":"Medium"}}],"columnKind":"utf16CodeUnits"}]}

(Truncated to last 8000 characters out of 155660)
⚠️ COPYPASTE / jscpd - 6 errors
Using config from .github/linters/.jscpd.json
Clone found (powershell)
 - bin/checkhashes.ps1 [38:25 - 43:43] (6 lines, 57 tokens)
   bin/checkver.ps1 [56:17 - 61:43]
Clone found (powershell)
 - bin/checkhashes.ps1 [58:1 - 68:50] (11 lines, 61 tokens)
   bin/checkver.ps1 [72:1 - 82:50]
Clone found (powershell)
 - bin/checkurls.ps1 [28:51 - 36:6] (9 lines, 65 tokens)
   bin/checkver.ps1 [52:96 - 60:6]
Clone found (powershell)
 - bin/checkurls.ps1 [28:51 - 35:46] (8 lines, 63 tokens)
   bin/describe.ps1 [9:29 - 16:46]
Clone found (powershell)
 - bin/describe.ps1 [8:33 - 24:67] (17 lines, 120 tokens)
   bin/formatjson.ps1 [7:34 - 23:67]
Clone found (python)
 - jsonfmt.py [19:1 - 29:31] (11 lines, 50 tokens)
   validate.py [26:1 - 36:31]
┌────────────┬────────────────┬─────────────┬──────────────┬──────────────┬──────────────────┬───────────────────┐
│ Format     │ Files analyzed │ Total lines │ Total tokens │ Clones found │ Duplicated lines │ Duplicated tokens │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ ini        │ 2              │ 60          │ 136          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ powershell │ 11             │ 471         │ 3103         │ 5            │ 46 (9.77%)       │ 366 (11.80%)      │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ python     │ 9              │ 1927        │ 8304         │ 1            │ 10 (0.52%)       │ 50 (0.60%)        │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ toml       │ 2              │ 75          │ 276          │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ txt        │ 3              │ 275         │ 2699         │ 0            │ 0 (0.00%)        │ 0 (0.00%)         │
├────────────┼────────────────┼─────────────┼──────────────┼──────────────┼──────────────────┼───────────────────┤
│ Total:     │ 27             │ 2808        │ 14518        │ 6            │ 56 (1.99%)       │ 416 (2.87%)       │
└────────────┴────────────────┴─────────────┴──────────────┴──────────────┴──────────────────┴───────────────────┘
Found 6 clones.
HTML report saved to megalinter-reports/copy-paste/jscpd-report.html
ERROR: jscpd found too many duplicates (2.0%) over threshold (0.5%)
time: 65.849ms
⚠️ REPOSITORY / osv-scanner - 5 errors
Scanning dir .
Starting filesystem walk for root: /
Scanned requirements.txt file and found 5 packages
End status: 38 dirs visited, 274 inodes visited, 1 Extract calls, 6.51555ms elapsed, 6.5157ms wall time

Total 1 package affected by 5 known vulnerabilities (0 Critical, 1 High, 4 Medium, 0 Low, 0 Unknown) from 1 ecosystem.
5 vulnerabilities can be fixed.

+-------------------------------------+------+-----------+----------+---------+---------------+------------------+
| OSV URL                             | CVSS | ECOSYSTEM | PACKAGE  | VERSION | FIXED VERSION | SOURCE           |
+-------------------------------------+------+-----------+----------+---------+---------------+------------------+
| https://osv.dev/PYSEC-2018-28       | 7.5  | PyPI      | requests | 2.9.2   | 2.20.0        | requirements.txt |
| https://osv.dev/GHSA-x84v-xcm2-53pg |      |           |          |         |               |                  |
| https://osv.dev/PYSEC-2023-74       | 6.1  | PyPI      | requests | 2.9.2   | 2.31.0        | requirements.txt |
| https://osv.dev/GHSA-j8r2-6x86-q33q |      |           |          |         |               |                  |
| https://osv.dev/PYSEC-2026-1872     | 5.3  | PyPI      | requests | 2.9.2   | 2.32.4        | requirements.txt |
| https://osv.dev/GHSA-9hjg-9r4m-mvj7 |      |           |          |         |               |                  |
| https://osv.dev/PYSEC-2026-1873     | 5.6  | PyPI      | requests | 2.9.2   | 2.32.0        | requirements.txt |
| https://osv.dev/GHSA-9wx4-h78v-vm56 |      |           |          |         |               |                  |
| https://osv.dev/PYSEC-2026-2275     | 5.5  | PyPI      | requests | 2.9.2   | 2.33.0        | requirements.txt |
| https://osv.dev/GHSA-gc5v-m9x4-r6x2 |      |           |          |         |               |                  |
+-------------------------------------+------+-----------+----------+---------+---------------+------------------+
⚠️ ACTION / zizmor - 19 errors
INFO zizmor: 🌈 zizmor v1.25.0
 INFO audit: zizmor: 🌈 completed .github/workflows/black.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/pydeps.yml
 INFO audit: zizmor: 🌈 completed .github/workflows/update-readme.yml
warning[excessive-permissions]: overly broad permissions
  --> .github/workflows/black.yml:9:3
   |
 9 | /   black:
10 | |     runs-on: ubuntu-latest
11 | |     steps:
12 | |       - name: STEP actions/setup-python@v7
...  |
53 | |           github_token: ${{ secrets.GITHUB_TOKEN }}
54 | |           branch: ${{ github.ref }}
   | |                                    ^
   | |                                    |
   | |____________________________________this job
   |                                      default permissions used due to no permissions: block
   |
   = note: audit confidence → Medium
   = help: audit documentation → https://docs.zizmor.sh/audits/#excessive-permissions

error[unpinned-uses]: unpinned action reference
  --> .github/workflows/black.yml:51:15
   |
51 |         uses: ad-m/github-push-action@master
   |               ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#unpinned-uses

help[artipacked]: credential persistence through GitHub Actions artifacts
  --> .github/workflows/pydeps.yml:74:9
   |
74 |         - uses: actions/checkout@v7
   |  _________^
75 | |         with:
76 | |           show-progress: false
   | |______________________________^ does not set persist-credentials: false
   |
   = note: audit confidence → Low
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#artipacked

warning[excessive-permissions]: overly broad permissions
   --> .github/workflows/pydeps.yml:50:3
    |
 50 | /   pydeps:
 51 | |     runs-on: ${{ matrix.os }}
 52 | |     defaults:
 53 | |       run:
...   |
218 | | # cspell:ignore pipreqs
    | |                        ^
    | |                        |
    | |________________________this job
    |                          default permissions used due to no permissions: block
    |
    = note: audit confidence → Medium
    = help: audit documentation → https://docs.zizmor.sh/audits/#excessive-permissions

error[template-injection]: code injection via template expansion
  --> .github/workflows/pydeps.yml:82:21
   |
80 |         run: |
   |         --- this run block
81 |           # Gather list of "**/*requirements*.txt" files
82 |           mask="${{ inputs.mask || env.DEFAULT_MASK }}"
   |                     ^^^^^^^^^^^ may expand into attacker-controllable code
   |
   = note: audit confidence → High
   = help: audit documentation → https://docs.zizmor.sh/audits/#template-injection

error[template-injection]: code injection via template expansion
   --> .github/workflows/pydeps.yml:105:21
    |
101 |         run: |
    |         --- this run block
...
105 |           mask="${{ inputs.mask || env.DEFAULT_MASK }}"
    |                     ^^^^^^^^^^^ may expand into attacker-controllable code
    |
    = note: audit confidence → High
    = help: audit documentation → https://docs.zizmor.sh/audits/#template-injection

help[artipacked]: credential persistence through GitHub Actions artifacts
  --> .github/workflows/update-readme.yml:23:7
   |
23 |     - uses: actions/checkout@v7
   |       ^^^^^^^^^^^^^^^^^^^^^^^^^ does not set persist-credentials: false
   |
   = note: audit confidence → Low
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#artipacked

warning[excessive-permissions]: overly broad permissions
  --> .github/workflows/update-readme.yml:12:3
   |
12 | /   update-readme:
13 | |     name: update-readme
14 | |     # if: github.event_name == 'workflow_dispatch' || github.event.pull_request.merged == true
15 | |     runs-on: ubuntu-latest
...  |
36 | | # eof
   | |      ^
   | |      |
   | |______this job
   |        default permissions used due to no permissions: block
   |
   = note: audit confidence → Medium
   = help: audit documentation → https://docs.zizmor.sh/audits/#excessive-permissions

error[unpinned-uses]: unpinned action reference
  --> .github/workflows/update-readme.yml:27:13
   |
27 |     - uses: EndBug/add-and-commit@v10
   |             ^^^^^^^^^^^^^^^^^^^^^^^^^ action is not pinned to a hash (required by blanket policy)
   |
   = note: audit confidence → High
   = note: this finding has an auto-fix
   = help: audit documentation → https://docs.zizmor.sh/audits/#unpinned-uses

19 findings (10 suppressed, 3 unsafe fixes): 0 informational, 2 low, 3 medium, 4 high
No fixes available to apply (3 held back by safe mode). Use --fix=unsafe or --fix=all to apply unsafe fixes.

Notices

📣 MegaLinter 9.5.0 is out! Discover the new features and security recommendations in the release announcement. (Skip this info by defining SECURITY_SUGGESTIONS: false)

See detailed reports in MegaLinter artifacts
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security
Show us your support by starring ⭐ the repository

Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-python-7 branch from 1f9bd60 to 0a741f7 Compare August 14, 2026 13:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants