Update all dependencies (#461) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/checkout](https://redirect.github.com/actions/checkout) | action | major | `v6.0.3` → `v7.0.1` | | [actions/setup-python](https://redirect.github.com/actions/setup-python) | action | major | `v6.3.0` → `v7.0.0` | | [jackdewinter/pymarkdown](https://redirect.github.com/jackdewinter/pymarkdown) | repository | patch | `v0.9.38` → `v0.9.39` | | [tiobe/tics-github-action](https://redirect.github.com/tiobe/tics-github-action) | action | minor | `v3.11.0` → `v3.12.0` | | [zizmorcore/zizmor-pre-commit](https://redirect.github.com/zizmorcore/zizmor-pre-commit) | repository | minor | `v1.28.0` → `v1.29.0` | Note: The `pre-commit` manager in Renovate is not supported by the `pre-commit` maintainers or community. Please do not report any problems there, instead [create a Discussion in the Renovate repository](https://redirect.github.com/renovatebot/renovate/discussions/new) if you have any questions. --- ### Release Notes <details> <summary>actions/checkout (actions/checkout)</summary> ### [`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701) [Compare Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1) - Bump github/codeql-action from 3 to 4 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2475](https://redirect.github.com/actions/checkout/pull/2475) - Bump actions/setup-node from 4 to 6 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2477](https://redirect.github.com/actions/checkout/pull/2477) - Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2478](https://redirect.github.com/actions/checkout/pull/2478) - Bump docker/login-action from 3.3.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2479](https://redirect.github.com/actions/checkout/pull/2479) - Bump actions/checkout from 6 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2488](https://redirect.github.com/actions/checkout/pull/2488) - Bump actions/upload-artifact from 4 to 7 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2476](https://redirect.github.com/actions/checkout/pull/2476) - eslint 9 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2474](https://redirect.github.com/actions/checkout/pull/2474) - Bump the minor-actions-dependencies group with 2 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2499](https://redirect.github.com/actions/checkout/pull/2499) - skip running unsafe pr check if input is default by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2518](https://redirect.github.com/actions/checkout/pull/2518) - trim only ascii whitespace for branch by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2521](https://redirect.github.com/actions/checkout/pull/2521) - escape values passed to --unset by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2530](https://redirect.github.com/actions/checkout/pull/2530) ### [`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2454](https://redirect.github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2458](https://redirect.github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2460](https://redirect.github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2461](https://redirect.github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://redirect.github.com/actions/core) and [@​actions/tool-cache](https://redirect.github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2459](https://redirect.github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://redirect.github.com/aiqiaoy) in [#​2463](https://redirect.github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​2462](https://redirect.github.com/actions/checkout/pull/2462) ### [`v6.1.0`](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0) [Compare Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0) </details> <details> <summary>actions/setup-python (actions/setup-python)</summary> ### [`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0) [Compare Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0) </details> <details> <summary>jackdewinter/pymarkdown (jackdewinter/pymarkdown)</summary> ### [`v0.9.39`](https://redirect.github.com/jackdewinter/pymarkdown/releases/tag/v0.9.39): Version 0.9.39 - 2026-07-11 [Compare Source](https://redirect.github.com/jackdewinter/pymarkdown/compare/v0.9.38...v0.9.39) This release focused on some internal cleanup work and a major change! Please check out our [improved API documentation](https://pymarkdown.readthedocs.io/en/latest/api/pymarkdownapi/) along with a new [support document](https://pymarkdown.readthedocs.io/en/latest/api/) giving what we believe is a solid walk-through of the existing Python PyMarkdownApi. #### Added - [Issue 1553](https://redirect.github.com/jackdewinter/pymarkdown/issues/1553) - Added new documentation around how APIs are listed in the documentation. - Added a completely redone document showing how to the PyMarkdownApi. #### Changed - [Issue 1625](https://redirect.github.com/jackdewinter/pymarkdown/issues/1625) - Changed how HTML tokens are generated for testing, to make more streamlined </details> <details> <summary>tiobe/tics-github-action (tiobe/tics-github-action)</summary> ### [`v3.12.0`](https://redirect.github.com/tiobe/tics-github-action/releases/tag/v3.12.0) [Compare Source](https://redirect.github.com/tiobe/tics-github-action/compare/v3.11.0...v3.12.0) <!-- Release notes generated using configuration in .github/release.yml at main --> #### What's Changed ##### Features - RM-37915: Added TQI impact table to the summary by [@​janssen-tiobe](https://redirect.github.com/janssen-tiobe) in [#​528](https://redirect.github.com/tiobe/tics-github-action/pull/528) **Full Changelog**: <https://github.com/tiobe/tics-github-action/compare/v3.11.0...v3.12.0> </details> <details> <summary>zizmorcore/zizmor-pre-commit (zizmorcore/zizmor-pre-commit)</summary> ### [`v1.29.0`](https://redirect.github.com/zizmorcore/zizmor-pre-commit/releases/tag/v1.29.0) [Compare Source](https://redirect.github.com/zizmorcore/zizmor-pre-commit/compare/v1.28.0...v1.29.0) #### New Features 🌈[🔗](https://docs.zizmor.sh/release-notes/#new-features) - zizmor now has **experimental** support for auditing pre-commit inputs, meaning both pre-commit configuration and hook definitions ([#​2209](https://redirect.github.com/zizmorcore/zizmor/issues/2209)) - New audit: [insecure-url-scheme](https://docs.zizmor.sh/audits/#insecure-url-scheme) detects usages of insecure (i.e. plaintext) protocols when making network requests. The initial version of this audit is limited to pre-commit inputs only ([#​2228](https://redirect.github.com/zizmorcore/zizmor/issues/2228)) - zizmor now supports GitHub's "self-repository" reference syntax for local actions, e.g. `uses: $/foo/bar` instead of a manual checkout and `uses: ./foo/bar` ([#​2248](https://redirect.github.com/zizmorcore/zizmor/issues/2248)) #### Changes ⚠️[🔗](https://docs.zizmor.sh/release-notes/#changes) - The [unpinned-uses](https://docs.zizmor.sh/audits/#unpinned-uses) and [unpinned-images](https://docs.zizmor.sh/audits/#unpinned-images) audits have been separated more cleanly: [unpinned-uses](https://docs.zizmor.sh/audits/#unpinned-uses) is now principally responsible for Git-style `uses:` clauses, whereas [unpinned-images](https://docs.zizmor.sh/audits/#unpinned-images) is now responsible for `docker://`-style `uses:` clauses (in addition to already checking other image references) ([#​2222](https://redirect.github.com/zizmorcore/zizmor/issues/2222)) #### Removals 🌅[🔗](https://docs.zizmor.sh/release-notes/#removals) - `--collect=workflows-only` and `--collect=actions-only` have been fully removed. Use `--collect=workflows` and `--collect=actions` for the replacement behavior ([#​2242](https://redirect.github.com/zizmorcore/zizmor/issues/2242)) #### Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes) - Fixed a bug where zizmor would reject a valid workflow definition for containing a literal jobs.<job>.outputs.<name> value for being a non-string ([#​2220](https://redirect.github.com/zizmorcore/zizmor/issues/2220)) - Fixed a bug where the [github-app](https://docs.zizmor.sh/audits/#github-app) audit would incorrectly flag some usages as needing a repositories: key, despite requesting organization-level-only permissions ([#​2227](https://redirect.github.com/zizmorcore/zizmor/issues/2227)) - Fixed a class of bugs where zizmor would discover the user's configuration in unintuitive ways. When auditing from a Git repository, zizmor now uses the repository root to discover configuration consistently ([#​2234](https://redirect.github.com/zizmorcore/zizmor/issues/2234)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/wlcs). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->