Skip to content

build(deps): bump the pre-commit-monthly group with 4 updates - #3005

Merged
leofang merged 3 commits into
mainfrom
dependabot/pre_commit/pre-commit-monthly-7d02eb1b3d
Oct 3, 2026
Merged

leofang merged 3 commits into
mainfrom
dependabot/pre_commit/pre-commit-monthly-7d02eb1b3d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the pre-commit-monthly group with 4 updates: https://github.com/NVIDIA/security-workflows, https://github.com/astral-sh/ruff-pre-commit, https://github.com/pre-commit/mirrors-mypy and https://github.com/MarcoGorelli/cython-lint.

Updates https://github.com/NVIDIA/security-workflows from v0.3.0 to 0.4.0

Release notes

Sourced from https://github.com/NVIDIA/security-workflows's releases.

v0.4.0 — Per-language CodeQL build modes

CodeQL SAST now resolves a build mode per language instead of applying one value to every matrix leg, so language sets with conflicting requirements work in a single call. '["go","rust"]' was previously impossible — Go rejects build-mode: none and Rust supports nothing else — and now resolves each leg correctly. languages entries may also be objects carrying a per-language build-mode or runs-on, which makes swift usable since it requires a macOS runner. A new resolve job validates the language set before any analysis starts. Additive. Callers passing a plain string array need no change, declared permissions are unchanged, and the analyze job keeps the name CodeQL (<language>) so required status checks continue to match. A new non-required check, Resolve language matrix, appears alongside it. Full notes: CHANGELOG.md

Changelog

Sourced from https://github.com/NVIDIA/security-workflows's changelog.

Changelog

All notable changes to the workflows in this repository will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning. See README.md for the SHA-pinning contract that consumers are expected to follow.

[0.4.0] - 2026-08-19

Additive release. Callers passing languages: '["actions","python"]' need no change; the declared permissions: are unchanged, and the analyze job keeps the name CodeQL (<language>) so required status checks continue to match.

Added

  • SAST (CodeQL) — build mode is resolved per language instead of one value applied to every matrix leg, so sets with conflicting requirements work in a single call. '["go","rust"]' could not previously be expressed (go needs autobuild, rust supports only none). Substitutions are reported as job-log notices and the resolved matrix is written to the job summary.
  • SAST (CodeQL) — languages entries may be objects carrying a per-language build-mode or runs-on: '[{"language":"swift","runs-on":"macos-14"},"rust"]'. Per-entry runs-on makes swift usable, as it requires a macOS runner.
  • SAST (CodeQL) — a resolve job validates the language set before any analysis starts, rejecting unknown languages, manual mode, unsupported explicit modes, duplicate languages, malformed JSON, and empty lists. New resolve-runs-on input (default ubuntu-latest); the suite passes suite-runs-on through to it.
  • Documentation — the workflow catalogue now lists the accepted languages values with per-language buildless support, plus the two coverage gaps: no shell analyzer (use shellcheck) and no CUDA analyzer (c-cpp skips .cu / .cuh).

Changed

  • SAST (CodeQL) — build-mode is now a preference applied where the language supports it; an explicit per-language mode is exact and errors if CodeQL rejects it. No existing caller changes behaviour.
  • SAST (CodeQL) — the analyze job keeps the name CodeQL (<language>), so required status checks still match. A new non-required check, Resolve language matrix, appears alongside it.

Fixed

  • Documentation — build-mode was described as working "for every language": go and swift reject none, Kotlin requires autobuild, and rust supports only none.
  • Documentation — the CodeQL prerequisite said Default setup must be off entirely. The conflict is per language: both publish /language:<lang>, so only an overlap collides. Default setup on other languages can coexist, as it already does on this repository.
  • Documentation — the catalogue gave CodeQL's runs-on default as linux-amd64-cpu4 (actual: ubuntu-latest) and required an nv-gha-runners label for every workflow, which does not apply to CodeQL.

[0.3.0] - 2026-08-11

Added

  • Security suite reusable workflow — https://github.com/NVIDIA/security-workflows/blob/main/.github/workflows/security-suite.yml runs the scans a caller enables (enable-secret-scan, enable-sast-scan) in parallel behind one pinned reference. Every scan is opt-in, including scans added in future releases, so onboarding a repository to the suite never turns on a scan it did not ask for; category-prefixed inputs preserve the child workflows' runner and policy configuration. A suite call that enables nothing warns instead of failing.
  • SAST (CodeQL) reusable workflow — https://github.com/NVIDIA/security-workflows/blob/main/.github/workflows/sast-scan-codeql.yml. Generic, matrix-driven CodeQL analysis (languages, build-mode, queries, packs, config-file, runs-on inputs) with the github/codeql-action steps pinned by SHA. Positioned as the customization-tier lever — the fleet baseline for CodeQL is GitHub Default setup via org/enterprise Security Configurations. See .github/workflows/README.md for prerequisites (GHAS/code scanning, Default-setup conflict) and usage.

Changed

  • Secret-scan (Pulse) — the reusable workflow no longer uploads SARIF on CI self-test runs (ci_test_setup: true), so the disposable RSA fixture no longer publishes a code-scanning alert to the default-branch Security tab. Real consumer scans are unaffected.
  • Secret-scan (pre-commit) — secret-scan-trufflehog now installs the SHA-256-pinned TruffleHog release in pre-commit's isolated Python environment rather than the per-user cache.

Fixed

  • Secret-scan (pre-commit) — secret-scan-trufflehog no longer fails on pytest function names. A Lob API key is test_ followed by 35 characters, so TruffleHog's Lob detector matched names such as test_gpu_conf_compute_attestation_report and its verifier reported them as verified, the one result class the hook blocks on. Lob is now excluded from the hook's detector set.

[0.2.0] - 2026-07-24

Changed

  • Secret-scan (pre-commit) — the secret-scan-trufflehog hook is now self-installing: on first use it downloads a pinned, checksum-verified TruffleHog release (3.95.9) into a per-user cache and reuses it thereafter, so contributors no longer install trufflehog manually. The archive is fetched over HTTPS and verified against a per-platform SHA-256 pinned from the release's cosign-signed checksums.txt; the hook fails closed on any mismatch. Supports Linux/macOS/Windows (amd64/arm64).

... (truncated)

Commits
  • c736f04 docs(release): stamp v0.4.0
  • 2c53008 feat(sast): resolve CodeQL build mode per language.
  • 725e63e docs(sast): document accepted CodeQL languages and fix runner docs. (#20)
  • See full diff in compare view

Updates https://github.com/astral-sh/ruff-pre-commit from v0.15.9 to 0.16.9

Release notes

Sourced from https://github.com/astral-sh/ruff-pre-commit's releases.

v0.16.9

See: https://github.com/astral-sh/ruff/releases/tag/0.16.9

Commits

Updates https://github.com/pre-commit/mirrors-mypy from v1.20.0 to 2.3.1

Commits

Updates https://github.com/MarcoGorelli/cython-lint from v0.19.0 to 0.21.1

Release notes

Sourced from https://github.com/MarcoGorelli/cython-lint's releases.

v0.21.1

Fixed compat with Cython 3.3

Commits
  • eb2f695 Bump version to 0.21.1
  • fec544b Merge pull request #202 from ap--/fix/dict-comprehension-cython-3.3
  • 2fa16b7 Update cython_lint/cython_lint.py
  • 09eba7a Apply suggestion from @​MarcoGorelli
  • 286b9e6 refactor: drop packaging dependency for Cython version check
  • f29c9e6 fix: support Cython 3.3 DictComprehensionAppendNode layout
  • 4e5b339 test: add regression test for comprehensions without late binding closures
  • 008c7ca Merge pull request #199 from MarcoGorelli/pre-commit-ci-update-config
  • ae8cebb [pre-commit.ci] pre-commit autoupdate
  • e810551 Merge pull request #172 from MarcoGorelli/pyright
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the pre-commit-monthly group with 4 updates: [https://github.com/NVIDIA/security-workflows](https://github.com/NVIDIA/security-workflows), [https://github.com/astral-sh/ruff-pre-commit](https://github.com/astral-sh/ruff-pre-commit), [https://github.com/pre-commit/mirrors-mypy](https://github.com/pre-commit/mirrors-mypy) and [https://github.com/MarcoGorelli/cython-lint](https://github.com/MarcoGorelli/cython-lint).


Updates `https://github.com/NVIDIA/security-workflows` from v0.3.0 to 0.4.0
- [Release notes](https://github.com/NVIDIA/security-workflows/releases)
- [Changelog](https://github.com/NVIDIA/security-workflows/blob/main/CHANGELOG.md)
- [Commits](NVIDIA/security-workflows@711025b...c736f04)

Updates `https://github.com/astral-sh/ruff-pre-commit` from v0.15.9 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff-pre-commit/releases)
- [Commits](astral-sh/ruff-pre-commit@c60c980...a56c0b9)

Updates `https://github.com/pre-commit/mirrors-mypy` from v1.20.0 to 2.3.1
- [Commits](pre-commit/mirrors-mypy@8e5c807...7ff8d35)

Updates `https://github.com/MarcoGorelli/cython-lint` from v0.19.0 to 0.21.1
- [Release notes](https://github.com/MarcoGorelli/cython-lint/releases)
- [Commits](MarcoGorelli/cython-lint@7c6152f...eb2f695)

---
updated-dependencies:
- dependency-name: https://github.com/NVIDIA/security-workflows
  dependency-version: 0.4.0
  dependency-type: direct:production
  dependency-group: pre-commit-monthly
- dependency-name: https://github.com/astral-sh/ruff-pre-commit
  dependency-version: 0.16.9
  dependency-type: direct:production
  dependency-group: pre-commit-monthly
- dependency-name: https://github.com/pre-commit/mirrors-mypy
  dependency-version: 2.3.1
  dependency-type: direct:production
  dependency-group: pre-commit-monthly
- dependency-name: https://github.com/MarcoGorelli/cython-lint
  dependency-version: 0.21.1
  dependency-type: direct:production
  dependency-group: pre-commit-monthly
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added CI/CD CI/CD infrastructure dependencies Pull requests that update a dependency file labels Oct 2, 2026
@copy-pr-bot

copy-pr-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@leofang

leofang commented Oct 3, 2026

Copy link
Copy Markdown
Member

pre-commit.ci autofix

@github-actions github-actions Bot added the cuda.core Everything related to the cuda.core module label Oct 3, 2026
@leofang

leofang commented Oct 3, 2026

Copy link
Copy Markdown
Member

/ok to test e03cba4

@leofang
leofang enabled auto-merge (squash) October 3, 2026 00:42
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
Doc Preview CI
Preview removed because the pull request was closed or merged.

@leofang
leofang merged commit 6869849 into main Oct 3, 2026
223 of 226 checks passed
@leofang
leofang deleted the dependabot/pre_commit/pre-commit-monthly-7d02eb1b3d branch October 3, 2026 01:58
github-actions Bot pushed a commit that referenced this pull request Oct 3, 2026
Removed preview folders for the following PRs:
- PR #2880
- PR #2917
- PR #2947
- PR #2965
- PR #2996
- PR #2998
- PR #3003
- PR #3005
- PR #3008
- PR #3010
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI/CD CI/CD infrastructure cuda.core Everything related to the cuda.core module dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant