Skip to content

chore(deps): bump openhoo/hoonarqube/actions/analyze from 0.3.1 to 0.4.2 in the actions group - #28

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-24df9e7400
Open

chore(deps): bump openhoo/hoonarqube/actions/analyze from 0.3.1 to 0.4.2 in the actions group#28
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-24df9e7400

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown

Bumps the actions group with 1 update: openhoo/hoonarqube/actions/analyze.

Updates openhoo/hoonarqube/actions/analyze from 0.3.1 to 0.4.2

Release notes

Sourced from openhoo/hoonarqube/actions/analyze's releases.

hoonarqube 0.4.2

0.4.2 (2026-09-04)

Performance

  • hoonarqube: parallelize file analysis (#22) (48d89b5)

Other Changes

  • release: add immutable asset recovery (#21) (82a1f39)

hoonarqube 0.4.1

0.4.1 (2026-09-04)

Bug Fixes

  • hoonarqube: harden CodeQL parity and validation (#19) (50ca924)

hoonarqube 0.4.0

0.4.0 (2026-09-04)

Features

  • github-quality: add CodeQL analysis profile (#15) (90357d9)

Bug Fixes

  • hoonarqube: align GitHub CodeQL parity (68058d3)
  • release: repair version synchronization (4b01d0a)
Changelog

Sourced from openhoo/hoonarqube/actions/analyze's changelog.

Changelog

0.4.2 (2026-09-04)

Performance

  • hoonarqube: parallelize file analysis (#22) (48d89b5)

Other Changes

  • release: add immutable asset recovery (#21) (82a1f39)

0.4.1 (2026-09-04)

Bug Fixes

  • hoonarqube: harden CodeQL parity and validation (#19) (50ca924)

0.4.0 (2026-09-04)

Features

  • github-quality: add CodeQL analysis profile (#15) (90357d9)

Bug Fixes

  • hoonarqube: align GitHub CodeQL parity (68058d3)
  • release: repair version synchronization (4b01d0a)

Unreleased

Bug Fixes

  • github-quality: align conservative CodeQL detectors, scope and dataflow semantics, registry coverage, Sonar/SARIF locations, path handling, and action gating; add adversarial regression coverage across every analyzer
  • release: synchronize xtask path dependencies during version bumps while keeping CI dogfood pinned to an already-published binary

Performance

  • analyzers: parallelize file analysis across available CPUs with deterministic output and serial fallback; remove redundant parsing, semantic indexing, and tree walks across every language while reducing each JavaScript/TypeScript analyzer stack from 128 MiB to 16 MiB

  • ci: shard quality tests, pin dogfood analysis to the released binary, replace the 2.2 GB mixed target cache with dependency-aware Rust caching, and remove a duplicate full-repository analysis pass

  • rust: keep the deep macro-token regression without making the normal

... (truncated)

Commits
  • f41ab5b chore(release): hoonarqube 0.4.2 (#23)
  • 48d89b5 perf(hoonarqube): parallelize file analysis (#22)
  • 82a1f39 ci(release): add immutable asset recovery (#21)
  • 90aa7e1 chore(release): hoonarqube 0.4.1 (#20)
  • 50ca924 fix(hoonarqube): harden CodeQL parity and validation (#19)
  • 088ec8d chore(release): hoonarqube 0.4.0
  • 4b01d0a fix(release): repair version synchronization
  • 68058d3 fix(hoonarqube): align GitHub CodeQL parity
  • 90357d9 feat(github-quality): add CodeQL analysis profile (#15)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [openhoo/hoonarqube/actions/analyze](https://github.com/openhoo/hoonarqube).


Updates `openhoo/hoonarqube/actions/analyze` from 0.3.1 to 0.4.2
- [Release notes](https://github.com/openhoo/hoonarqube/releases)
- [Changelog](https://github.com/openhoo/hoonarqube/blob/main/CHANGELOG.md)
- [Commits](openhoo/hoonarqube@03b34bc...f41ab5b)

---
updated-dependencies:
- dependency-name: openhoo/hoonarqube/actions/analyze
  dependency-version: 0.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 7, 2026
@github-code-quality

Copy link
Copy Markdown

Code Coverage Overview

Languages: Go

Go / code-coverage/go

The overall line coverage in commit 710ddb5 in the dependabot/github_ac... branch remains at 75%, unchanged from commit 96fe3e8 in the main branch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants