July 6, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.32.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 30 — CI-config and vendored-tree false positives (see RULES_CHANGELOG.md), found when numpy scored critical/90 on its own infrastructure files: CI/CD pipeline configuration (.circleci/, .github/workflows/, .gitlab-ci.yml, Jenkinsfile, …) is demoted to needs_review — a CI job runs on the project’s build service, never on the consumer’s machine, so numpy’s docs-deploy SSH setup is not component behavior and can no longer feed ST-COMBO-EXFIL. Install-time hooks (setup.py, npm postinstall) are unaffected and stay fully scored. vendored-* directories (numpy’s vendored-meson/, which bundles the meson build system with meson’s own CI docker scripts) are now skipped like vendor/ and node_modules. Effect: numpy critical/90 → low/20; recall floors unchanged.
July 6, 2026
OpenTelemetry for GitHub Workflows, Jobs and Steps
Version updated for https://github.com/plengauer/Thoth to version v5.59.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Stop masking super-linter failures and harden OTel super-linter patching by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3507 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3627 Update actions/checkout action to v7 by @plengauer in https://github.com/plengauer/Thoth/pull/3663 Update actions/setup-java action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3677 Pin dependencies by @plengauer in https://github.com/plengauer/Thoth/pull/3670 Update otel/opentelemetry-collector-contrib Docker tag to v0.155.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3681 Update Gradle to v9.6.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3674 Update actions/cache action to v5.1.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3675 Update actions/setup-python action to v6.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3678 Update github/gh-aw-actions action to v0.81.6 by @plengauer in https://github.com/plengauer/Thoth/pull/3680 Update actions/attest-build-provenance action to v4.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3672 Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3679 Update plengauer/opentelemetry-github action to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3682 Fix renovate of copilot instrumentation by @plengauer in https://github.com/plengauer/Thoth/pull/3684 Update actions/setup-dotnet action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3676 Update Demo injection_deep_java by @plengauer in https://github.com/plengauer/Thoth/pull/3686 Update Demo _complex_download_github_releases by @plengauer in https://github.com/plengauer/Thoth/pull/3687 Update Demo injection_deep_node by @plengauer in https://github.com/plengauer/Thoth/pull/3688 Update Demo injection_inner_xargs_parallel by @plengauer in https://github.com/plengauer/Thoth/pull/3689 Update Demo observe_subprocesses by @plengauer in https://github.com/plengauer/Thoth/pull/3690 Update Demo injection_deep_python by @plengauer in https://github.com/plengauer/Thoth/pull/3691 Update Demo injection_docker_renovate by @plengauer in https://github.com/plengauer/Thoth/pull/3692 Deploy OpenTelemetry by @plengauer in https://github.com/plengauer/Thoth/pull/3685 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3709 Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 by @plengauer in https://github.com/plengauer/Thoth/pull/3705 Update docker/setup-buildx-action action to v4.2.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3707 Update github/codeql-action action to v4.36.3 by @plengauer in https://github.com/plengauer/Thoth/pull/3706 Update github/gh-aw-actions action to v0.82.2 by @plengauer in https://github.com/plengauer/Thoth/pull/3697 Unbreak agentic workflow recompilation with current gh-aw schema by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3704 Re-disable slim images by @plengauer in https://github.com/plengauer/Thoth/pull/3703 Update plengauer/autorerun action to v0.38.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3702 Update docker/build-push-action action to v7.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3700 Update actions/cache action to v6 by @plengauer in https://github.com/plengauer/Thoth/pull/3683 Update dependency traceloop-sdk to v0.62.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3695 Update renovatebot/github-action action to v46.1.17 by @plengauer in https://github.com/plengauer/Thoth/pull/3694 Update dependency org.junit.jupiter:junit-jupiter to v6.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3693 Rename quality job by @plengauer in https://github.com/plengauer/Thoth/pull/3696 Automatic Version Bump by @plengauer in https://github.com/plengauer/Thoth/pull/3698 Full Changelog: https://github.com/plengauer/Thoth/compare/v5...v5.59.0
July 6, 2026
Multi-Style Contribution Snake
Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v06.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐍 Multi-Style Snake Daily Update Automated daily release to the GitHub Marketplace.
Version Details:
Tag: v06.07.26 Release Date: $(date +’%A, %B %d, 20%y') Included Features:
5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds) Automated Month Labels above grids Dynamic Username Detection Auto-generated Asset Gallery
July 6, 2026
websec-validator
Version updated for https://github.com/raccioly/websec-validator to version v0.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor: the browser-vuln trio (XSS / clickjacking / CSRF) closes the classic-web-vuln gap, and a new enterprise / CI integration surface turns websec from a CLI-a-human-runs into a truth source a pipeline, dashboard, or any MCP agent can consume — SARIF, a --fail-on gate, git-diff baselining, a GitHub Action, an MCP server, and versioned output schemas. All stdlib, zero new runtime deps.
July 6, 2026
SpecGuard CI
Version updated for https://github.com/Sawaiz-zip/spec-guard to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed SpecGuard v0.4.0 Semantic governance gate for spec files — classifies PR changes against a locked project goal/scope and blocks unauthorized drift.
Highlights since v0.3.0 GitHub App — native check runs, fork-PR governance, and agent-identity handling for PRs that don’t come through the classic CI workflow (specs/006-github-app/) Advanced governance — section-level locking (govern just part of a file), monorepo multi-scope support (independent verdicts per package), and audit-trail JSON export (specs/007-advanced/) Approval commands — /specguard approve comment command and MCP containment for agent-driven approvals (specs/005-approval-commands/) Version metadata now consistent across pyproject.toml, __init__.py, and action.yml (all 0.4.0) Using this release - uses: Sawaiz-zip/spec-guard@v0 with: anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }} specguard-ci==0.4.0 is published on PyPI; the composite action pins to it directly.
July 6, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.16.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.16.0 Released 2026-07-05.
An output-economy and worker-reliability release: response-style profiles wired end to end, ledger-attributed savings you can recompute, a three-arm cost-and-quality A/B harness, proactive context compaction with signed receipts, schema-enforced worker outcomes, and pinned team manifests. Plus a batch of contributor reliability fixes.
July 6, 2026
Jekyll Redirects for Cloudflare
Version updated for https://github.com/SocksTheWolf/jekyll-cloudflare-redirects to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Just some minor logging changes, nothing major. Should be the final release for awhile.
July 6, 2026
Papyrus Markdown Export
Version updated for https://github.com/thomas-worm/papyrus-export-markdown to version v1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed papyrus-export-markdown This initial release provides a GitHub action that can export documentation from Papyrus projects in Markdown format. It iterates over a package tree and exports documentation and diagrams.
July 6, 2026
Auto Version
Version updated for https://github.com/twopow/auto-version-action to version v1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/twopow/auto-version-action/compare/v1...v1.4
July 5, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.2