Skip to content

chore(deps): update actions/github-script action to v9#111

Open
nbl-renovate[bot] wants to merge 1 commit intomainfrom
renovate/actions-github-script-9.x
Open

chore(deps): update actions/github-script action to v9#111
nbl-renovate[bot] wants to merge 1 commit intomainfrom
renovate/actions-github-script-9.x

Conversation

@nbl-renovate
Copy link
Copy Markdown
Contributor

@nbl-renovate nbl-renovate bot commented Apr 10, 2026

This PR contains the following updates:

Package Type Update Change
actions/github-script action major v8.0.0v9.0.0

Release Notes

actions/github-script (actions/github-script)

v9.0.0

Compare Source

New features:

  • getOctokit factory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients with getOctokit for details and examples.
  • Orchestration ID in user-agent — The ACTIONS_ORCHESTRATION_ID environment variable is automatically appended to the user-agent string for request tracing.

Breaking changes:

  • require('@​actions/github') no longer works in scripts. The upgrade to @actions/github v9 (ESM-only) means require('@​actions/github') will fail at runtime. If you previously used patterns like const { getOctokit } = require('@​actions/github') to create secondary clients, use the new injected getOctokit function instead — it's available directly in the script context with no imports needed.
  • getOctokit is now an injected function parameter. Scripts that declare const getOctokit = ... or let getOctokit = ... will get a SyntaxError because JavaScript does not allow const/let redeclaration of function parameters. Use the injected getOctokit directly, or use var getOctokit = ... if you need to redeclare it.
  • If your script accesses other @actions/github internals beyond the standard github/octokit client, you may need to update those references for v9 compatibility.
What's Changed
New Contributors

Full Changelog: actions/github-script@v8.0.0...v9.0.0


Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "before 4am on Monday,Tuesday,Wednesday,Thursday,Friday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@nbl-renovate nbl-renovate bot added the dependencies Pull requests that update a dependency file label Apr 10, 2026
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 10, 2026

Vulnerability Scan: Passed

Image: netbox-mcp-server:scan

Source Library CVE Severity Installed Fixed Title
Python Pygments CVE-2026-4539 ⚪ LOW 2.19.2 2.20.0 pygments: Pygments: Denial of Service via inefficient regular expression process
Python cryptography CVE-2026-39892 🟡 MEDIUM 46.0.6 46.0.7 cryptography: Cryptography: Buffer overflow via non-contiguous buffer in API
Python python-multipart CVE-2026-40347 🟡 MEDIUM 0.0.22 0.0.26 python-multipart affected by Denial of Service via large multipart preamble or e

Commit: 46812b7

@nbl-renovate nbl-renovate bot force-pushed the renovate/actions-github-script-9.x branch from 5078e5b to c4bcded Compare April 16, 2026 12:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants