build(deps): bump actions/setup-dotnet from 5.4.0 to 6.0.0#94
build(deps): bump actions/setup-dotnet from 5.4.0 to 6.0.0#94dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5.4.0 to 6.0.0. - [Release notes](https://github.com/actions/setup-dotnet/releases) - [Commits](actions/setup-dotnet@v5.4.0...v6) --- updated-dependencies: - dependency-name: actions/setup-dotnet dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
|
||
| - name: Setup .NET | ||
| uses: actions/setup-dotnet@v5.4.0 | ||
| uses: actions/setup-dotnet@v6.0.0 |
There was a problem hiding this comment.
📝 Info: Mixed pinning styles for setup-dotnet across workflows
The bump uses two different pinning styles: SHA-pinned (a98b56852c35b8e3190ac28c8c2271da59106c68) in auto-pr-from-main.yml and code-quality.yml, versus mutable version tags (v6.0.0) in ci-build-test.yml, publish-all.yml, and security-scan.yml. This inconsistency is pre-existing (the same files were SHA vs tag pinned before this PR) and the SHA correctly corresponds to the v6.0.0 release per the PR description, so it is not a bug. Worth noting only for future hardening consistency.
Was this helpful? React with 👍 or 👎 to provide feedback.
|
Qodana Community for .NETIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked View the detailed Qodana reportTo be able to view the detailed Qodana report, you can either:
To get - name: 'Qodana Scan'
uses: JetBrains/qodana-action@v2026.1.3
with:
upload-result: trueContact Qodana teamContact us at qodana-support@jetbrains.com
|



Bumps actions/setup-dotnet from 5.4.0 to 6.0.0.
Release notes
Sourced from actions/setup-dotnet's releases.
Commits
a98b568chore(deps): bump@actions/cacheto 6.2.0 (#756)afb2931Bump actions/checkout from 6.0.3 to 7.0.0 (#751)6df8cefMigrate to ESM and upgrade dependencies (#752)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)