Update all dependencies (#461)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/checkout](https://redirect.github.com/actions/checkout) |
action | major | `v6.0.3` → `v7.0.1` |
|
[actions/setup-python](https://redirect.github.com/actions/setup-python)
| action | major | `v6.3.0` → `v7.0.0` |
|
[jackdewinter/pymarkdown](https://redirect.github.com/jackdewinter/pymarkdown)
| repository | patch | `v0.9.38` → `v0.9.39` |
|
[tiobe/tics-github-action](https://redirect.github.com/tiobe/tics-github-action)
| action | minor | `v3.11.0` → `v3.12.0` |
|
[zizmorcore/zizmor-pre-commit](https://redirect.github.com/zizmorcore/zizmor-pre-commit)
| repository | minor | `v1.28.0` → `v1.29.0` |

Note: The `pre-commit` manager in Renovate is not supported by the
`pre-commit` maintainers or community. Please do not report any problems
there, instead [create a Discussion in the Renovate
repository](https://redirect.github.com/renovatebot/renovate/discussions/new)
if you have any questions.

---

### Release Notes

<details>
<summary>actions/checkout (actions/checkout)</summary>

###
[`v7.0.1`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v7.0.0...v7.0.1)

- Bump github/codeql-action from 3 to 4 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2475](https://redirect.github.com/actions/checkout/pull/2475)
- Bump actions/setup-node from 4 to 6 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2477](https://redirect.github.com/actions/checkout/pull/2477)
- Bump docker/build-push-action from 6.5.0 to 7.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2478](https://redirect.github.com/actions/checkout/pull/2478)
- Bump docker/login-action from 3.3.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2479](https://redirect.github.com/actions/checkout/pull/2479)
- Bump actions/checkout from 6 to 7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2488](https://redirect.github.com/actions/checkout/pull/2488)
- Bump actions/upload-artifact from 4 to 7 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2476](https://redirect.github.com/actions/checkout/pull/2476)
- eslint 9 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2474](https://redirect.github.com/actions/checkout/pull/2474)
- Bump the minor-actions-dependencies group with 2 updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2499](https://redirect.github.com/actions/checkout/pull/2499)
- skip running unsafe pr check if input is default by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2518](https://redirect.github.com/actions/checkout/pull/2518)
- trim only ascii whitespace for branch by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2521](https://redirect.github.com/actions/checkout/pull/2521)
- escape values passed to --unset by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2530](https://redirect.github.com/actions/checkout/pull/2530)

###
[`v7.0.0`](https://redirect.github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.1.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run
by [@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2454](https://redirect.github.com/actions/checkout/pull/2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2458](https://redirect.github.com/actions/checkout/pull/2458)
- Bump flatted from 3.3.1 to 3.4.2 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2460](https://redirect.github.com/actions/checkout/pull/2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2461](https://redirect.github.com/actions/checkout/pull/2461)
- Bump [@&#8203;actions/core](https://redirect.github.com/actions/core)
and
[@&#8203;actions/tool-cache](https://redirect.github.com/actions/tool-cache)
and Remove uuid by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2459](https://redirect.github.com/actions/checkout/pull/2459)
- upgrade module to esm and update dependencies by
[@&#8203;aiqiaoy](https://redirect.github.com/aiqiaoy) in
[#&#8203;2463](https://redirect.github.com/actions/checkout/pull/2463)
- Bump the minor-npm-dependencies group across 1 directory with 3
updates by
[@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot] in
[#&#8203;2462](https://redirect.github.com/actions/checkout/pull/2462)

###
[`v6.1.0`](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)

[Compare
Source](https://redirect.github.com/actions/checkout/compare/v6.0.3...v6.1.0)

</details>

<details>
<summary>actions/setup-python (actions/setup-python)</summary>

###
[`v7.0.0`](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)

[Compare
Source](https://redirect.github.com/actions/setup-python/compare/v6.3.0...v7.0.0)

</details>

<details>
<summary>jackdewinter/pymarkdown (jackdewinter/pymarkdown)</summary>

###
[`v0.9.39`](https://redirect.github.com/jackdewinter/pymarkdown/releases/tag/v0.9.39):
Version 0.9.39 - 2026-07-11

[Compare
Source](https://redirect.github.com/jackdewinter/pymarkdown/compare/v0.9.38...v0.9.39)

This release focused on some internal cleanup work and a major change!
Please check out our [improved API
documentation](https://pymarkdown.readthedocs.io/en/latest/api/pymarkdownapi/)
along with a new [support
document](https://pymarkdown.readthedocs.io/en/latest/api/) giving what
we believe is a solid walk-through of the existing Python PyMarkdownApi.

#### Added

- [Issue
1553](https://redirect.github.com/jackdewinter/pymarkdown/issues/1553)
- Added new documentation around how APIs are listed in the
documentation.
  - Added a completely redone document showing how to the PyMarkdownApi.

#### Changed

- [Issue
1625](https://redirect.github.com/jackdewinter/pymarkdown/issues/1625)
- Changed how HTML tokens are generated for testing, to make more
streamlined

</details>

<details>
<summary>tiobe/tics-github-action (tiobe/tics-github-action)</summary>

###
[`v3.12.0`](https://redirect.github.com/tiobe/tics-github-action/releases/tag/v3.12.0)

[Compare
Source](https://redirect.github.com/tiobe/tics-github-action/compare/v3.11.0...v3.12.0)

<!-- Release notes generated using configuration in .github/release.yml
at main -->

#### What's Changed

##### Features

- RM-37915: Added TQI impact table to the summary by
[@&#8203;janssen-tiobe](https://redirect.github.com/janssen-tiobe) in
[#&#8203;528](https://redirect.github.com/tiobe/tics-github-action/pull/528)

**Full Changelog**:
<https://github.com/tiobe/tics-github-action/compare/v3.11.0...v3.12.0>

</details>

<details>
<summary>zizmorcore/zizmor-pre-commit
(zizmorcore/zizmor-pre-commit)</summary>

###
[`v1.29.0`](https://redirect.github.com/zizmorcore/zizmor-pre-commit/releases/tag/v1.29.0)

[Compare
Source](https://redirect.github.com/zizmorcore/zizmor-pre-commit/compare/v1.28.0...v1.29.0)

#### New Features
🌈[🔗](https://docs.zizmor.sh/release-notes/#new-features)

- zizmor now has **experimental** support for auditing pre-commit
inputs, meaning both pre-commit configuration and hook definitions
([#&#8203;2209](https://redirect.github.com/zizmorcore/zizmor/issues/2209))

- New audit:
[insecure-url-scheme](https://docs.zizmor.sh/audits/#insecure-url-scheme)
detects usages of insecure (i.e. plaintext) protocols when making
network requests. The initial version of this audit is limited to
pre-commit inputs only
([#&#8203;2228](https://redirect.github.com/zizmorcore/zizmor/issues/2228))

- zizmor now supports GitHub's "self-repository" reference syntax for
local actions, e.g. `uses: $/foo/bar` instead of a manual checkout and
`uses: ./foo/bar`
([#&#8203;2248](https://redirect.github.com/zizmorcore/zizmor/issues/2248))

#### Changes ⚠️[🔗](https://docs.zizmor.sh/release-notes/#changes)

- The [unpinned-uses](https://docs.zizmor.sh/audits/#unpinned-uses) and
[unpinned-images](https://docs.zizmor.sh/audits/#unpinned-images) audits
have been separated more cleanly:
[unpinned-uses](https://docs.zizmor.sh/audits/#unpinned-uses) is now
principally responsible for Git-style `uses:` clauses, whereas
[unpinned-images](https://docs.zizmor.sh/audits/#unpinned-images) is now
responsible for `docker://`-style `uses:` clauses (in addition to
already checking other image references)
([#&#8203;2222](https://redirect.github.com/zizmorcore/zizmor/issues/2222))

#### Removals 🌅[🔗](https://docs.zizmor.sh/release-notes/#removals)

- `--collect=workflows-only` and `--collect=actions-only` have been
fully removed. Use `--collect=workflows` and `--collect=actions` for the
replacement behavior
([#&#8203;2242](https://redirect.github.com/zizmorcore/zizmor/issues/2242))

#### Bug Fixes 🐛[🔗](https://docs.zizmor.sh/release-notes/#bug-fixes)

- Fixed a bug where zizmor would reject a valid workflow definition for
containing a literal jobs.<job>.outputs.<name> value for being a
non-string
([#&#8203;2220](https://redirect.github.com/zizmorcore/zizmor/issues/2220))

- Fixed a bug where the
[github-app](https://docs.zizmor.sh/audits/#github-app) audit would
incorrectly flag some usages as needing a repositories: key, despite
requesting organization-level-only permissions
([#&#8203;2227](https://redirect.github.com/zizmorcore/zizmor/issues/2227))

- Fixed a class of bugs where zizmor would discover the user's
configuration in unintuitive ways. When auditing from a Git repository,
zizmor now uses the repository root to discover configuration
consistently
([#&#8203;2234](https://redirect.github.com/zizmorcore/zizmor/issues/2234))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get
[config
help](https://redirect.github.com/renovatebot/renovate/discussions) if
that's undesired.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/canonical/wlcs).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zLjIiLCJ1cGRhdGVkSW5WZXIiOiI0NC4zLjIiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->