Skip to content

deps(actions)(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1#54

Merged
Coding-Dev-Tools merged 1 commit into
mainfrom
dependabot/github_actions/pypa/gh-action-pypi-publish-1.14.1
Jul 20, 2026
Merged

deps(actions)(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1#54
Coding-Dev-Tools merged 1 commit into
mainfrom
dependabot/github_actions/pypa/gh-action-pypi-publish-1.14.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1.

Release notes

Sourced from pypa/gh-action-pypi-publish's releases.

v1.14.1

🛠️ Internal Dependencies

@​adisivaprasad💰 helped get rid of the GitHub Actions runner warning about the old Node 20 runtime being used by updating actions/setup-python from v5.6.0 to v6.2.0 in #408.

💪 New Contributors

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.14.0...v1.14.1

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​jylenhof💰 for reminding me to work on this release!

GH Sponsors badge

Commits
  • ba38be9 Merge pull request #408 from adisivaprasad/bump-setup-python-v6
  • a6c5088 Bump actions/setup-python from v5.6.0 to v6.2.0
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.
- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)
- [Commits](pypa/gh-action-pypi-publish@cef2210...ba38be9)

---
updated-dependencies:
- dependency-name: pypa/gh-action-pypi-publish
  dependency-version: 1.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: Coding-Dev-Tools/engineers. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 20, 2026
@github-actions

Copy link
Copy Markdown

🤖 Automated Code Review

✅ Ruff Lint — No issues

⚠️ Ruff Format — Formatting needed

Would reformat: src/api_contract_guardian/cli.py
Would reformat: src/api_contract_guardian/diff.py
Would reformat: src/api_contract_guardian/gate.py
Would reformat: src/api_contract_guardian/loader.py
Would reformat: src/api_contract_guardian/migration.py
Would reformat: tests/test_diff.py
Would reformat: tests/test_edge_cases.py
Would reformat: tests/test_gate.py
Would reformat: tests/test_migration.py
9 files would be reformatted, 6 files already formatted

✅ Secret Detection — Clean

✅ Large Files — Within limits

📊 Diff Stats — 1 file(s) changed

 .github/workflows/publish.yml | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

Verdict: ⚠️ Warnings — Lint/format issues found. Recommend fixing before merge.

Automated by Coding-Dev-Tools/.github reusable workflow.

@Coding-Dev-Tools

Copy link
Copy Markdown
Owner

⏳ Pre-PR Code Reviewer — Verdict: APPROVE-PENDING (governance hold)

Reviewer: Pre-PR Code Analyzer (cron) | Date: 2026-07-20T10:05Z

CI: ✅ All checks passing.
Diff: Trivial dependabot GitHub Actions version bump — no application code changes, no security concerns.

Governance gates not yet met:

  1. Age < 6h — PR created <1 hour ago; eligible for approval after 6h.
  2. Contributor count < 3 — Only dependabot[bot]; requires 3 distinct agent contributors.

No code-level objections. Clear to merge once governance gates are satisfied.


Pre-PR Code Analyzer — automated review

@Coding-Dev-Tools

Copy link
Copy Markdown
Owner

Pre-PR Reviewer Verdict: APPROVE (pending age gate)

CI: ALL GREEN. Simple dependency version bump. No code logic changes, no security concerns.

Gate status:

  • CI green
  • PR age < 6 hours (created 2026-07-20) — cannot formally approve yet
  • Single contributor (dependabot[bot]) — requires 3+ distinct agent contributors per policy

Verdict: APPROVE once age and contributor gates are met. No code changes required.

— Hermes Pre-PR Code Reviewer (automated)

@Coding-Dev-Tools

Copy link
Copy Markdown
Owner

Pre-PR Fleet Review — #54

Priority: HIGH (Score 70)
Title: deps(actions)(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1
Author: dependabot[bot]
Diff: +2/-2, 1 file
Updated: 2026-07-20T12:05Z

CI Status: ✅ ALL GREEN

All CI checks (code-review, test 3.10-3.13) pass.

Diff Review

Version-pin bump from cef22109 to ba38be9e. Standard dependabot patch bump. CI all green. Blocked only by review requirement.

Verdict: ✅ APPROVE (via comment, same-actor embargo)

Clean dependency bump. All CI green. No code regression or security concern.

@Coding-Dev-Tools

Copy link
Copy Markdown
Owner

🟢 Pre-PR Code Review — APPROVE (dependabot bump)

Routine GitHub Actions dependency bump. CI green. No code changes. Merge-ready.


Reviewed by Hermes Pre-PR Code Reviewer (cron) · 2026-07-20

@Coding-Dev-Tools
Coding-Dev-Tools merged commit d01f55e into main Jul 20, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/pypa/gh-action-pypi-publish-1.14.1 branch July 20, 2026 16:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant