Skip to content

chore(deps): bump codecov/codecov-action from 5.5.1 to 6.0.0#805

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/codecov/codecov-action-6.0.0
Closed

chore(deps): bump codecov/codecov-action from 5.5.1 to 6.0.0#805
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/codecov/codecov-action-6.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 27, 2026

Bumps codecov/codecov-action from 5.5.1 to 6.0.0.

Release notes

Sourced from codecov/codecov-action's releases.

v6.0.0

⚠️ This version introduces support for node24 which make cause breaking changes for systems that do not currently support node24. ⚠️

What's Changed

Full Changelog: codecov/codecov-action@v5.5.4...v6.0.0

v5.5.4

This is a mirror of v5.5.2. v6 will be released which requires node24

What's Changed

Full Changelog: codecov/codecov-action@v5.5.3...v5.5.4

v5.5.3

What's Changed

Full Changelog: codecov/codecov-action@v5.5.2...v5.5.3

v5.5.2

What's Changed

New Contributors

Full Changelog: codecov/codecov-action@v5.5.1...v5.5.2

Changelog

Sourced from codecov/codecov-action's changelog.

v5.5.2

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2

v5.5.1

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.5.0..v5.5.1

v5.5.0

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.4.3..v5.5.0

v5.4.3

What's Changed

Full Changelog: https://github.com/codecov/codecov-action/compare/v5.4.2..v5.4.3

v5.4.2

... (truncated)

Commits

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
codecov/codecov-action [>= 4.a, < 5]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 5.5.1 to 6.0.0.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@5a10915...57e3a13)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies One or more dependencies are being bumped github_actions Pull requests that update GitHub Actions code labels Mar 27, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 27, 2026 08:53
@dependabot dependabot bot added dependencies One or more dependencies are being bumped github_actions Pull requests that update GitHub Actions code labels Mar 27, 2026
kishore7snehil added a commit that referenced this pull request Mar 30, 2026
…rop Python 3.8; replace Snyk with SCA scan (#808)

## Changes

### Python 3.8 Support Dropped

Python 3.8 reached end-of-life in October 2024. Several security-patched
dependency versions (`aiohttp`, `cryptography`, `urllib3`) require
Python >=3.9, making it impossible to keep 3.8 support while applying
security fixes. The previous minimum (`>=3.8`) allowed installation on
Python versions that can only resolve to **vulnerable** dependency
versions.

- Changed `python` from `^3.8` to `>=3.9.2,<4.0` (3.9.0 and 3.9.1 are
excluded by `cryptography` due to known bugs in those patch releases)
- Removed `Programming Language :: Python :: 3.8` classifier from
`pyproject.toml`
- Updated `README.md`, `v5_MIGRATION_GUIDE.md`, and
`github_discussion_v5_announcement.md` to reflect Python >=3.9

### Dependency Updates

#### Python Dependencies - From Dependabot PRs
- Bump `ruff` from `0.11.5` to `0.15.8`
([#806](#806))
- Bump `responses` upper bound from `<0.26.0` to `<0.28.0`
([#786](#786))

#### Python Dependencies - From Security Review
- Update `aiohttp` from `>=3.10.11` to `>=3.11.18` - fixes multiple
CVEs; previous minimum resolved to versions with known vulnerabilities
on Python 3.8
- Update `cryptography` from `>=43.0.1` to `>=44.0.0` - fixes known
vulnerabilities in older versions
- Update `urllib3` from `>=2.2.3` to `>=2.3.0` - fixes known
vulnerabilities; requires Python >=3.9

#### GitHub Actions
- Bump `codecov/codecov-action` from `5.5.1` to `6.0.0` (SHA pin
updated) ([#805](#805))

#### CI Workflow Changes
- Added `sca_scan.yml` - new SCA scan using `auth0/devsecops-tooling`
reusable workflow with `requirements.txt`
- Removed `snyk.yml` - replaced by the new `sca_scan.yml` reusable
workflow
- Removed `docs.yml` - documentation build workflow removed
- Added `.claude/` to `.gitignore`
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 30, 2026

Looks like codecov/codecov-action is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Mar 30, 2026
@dependabot dependabot bot deleted the dependabot/github_actions/codecov/codecov-action-6.0.0 branch March 30, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies One or more dependencies are being bumped github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants