SIGN IN SIGN UP

ci(deps): bump getsentry/github-workflows/validate-pr from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to 36c729264d2edc29ebae61950c50e1e9f043ad7e (#24949)

Bumps
[getsentry/github-workflows/validate-pr](https://github.com/getsentry/github-workflows)
from 4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613 to
36c729264d2edc29ebae61950c50e1e9f043ad7e.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md">getsentry/github-workflows/validate-pr's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>3.4.1</h2>
<h3>Fixes</h3>
<ul>
<li>Danger - Add <code>skip-checkout</code> to preserve a caller's
prepared workspace, including generated custom Dangerfiles. Checkout
remains enabled by default. (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/175">#175</a>)</li>
<li>Updater - Preserve CMake and submodule pins ahead of the selected
release, while reporting divergent histories and Git errors (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/174">#174</a>)</li>
<li>Danger - Harden <code>extra-install-packages</code> handling: pass
the package list into the container via env var instead of host-shell
string interpolation (defense in depth) (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/169">#169</a>)</li>
<li>Updater - Avoid cleanup races in temporary ancestry repositories by
disabling background Git maintenance; preserve original Git errors if
cleanup also fails (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/177">#177</a>)</li>
<li>Sentry-CLI integration test action - Skip the reverse DNS lookup on
server start, which made each start take ~35 s on macOS (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/178">#178</a>)</li>
</ul>
<h2>3.4.0</h2>
<h3>Features</h3>
<ul>
<li>Validate PR - Action is advisory: it posts a single friendly comment
on community PRs that don't reference an issue with maintainer
discussion. PRs are not closed and no labels are applied. Recommended
trigger is <code>types: [opened]</code>.</li>
<li>Validate PR - Skip validation for PRs with fewer than 100 lines
changed, excluding common lock files (<code>Cargo.lock</code>,
<code>yarn.lock</code>, <code>package-lock.json</code>,
<code>Pipfile.lock</code>, etc.). Tiny PRs no longer go through the
issue-discussion loop.</li>
<li>Add validate-pr composite action for validating non-maintainer PRs
against contribution guidelines (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/153">#153</a>)</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Complete script injection hardening across all actions: move
remaining step outputs to env vars, validate Danger version against
semver (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/152">#152</a>)</li>
<li>Updater - Trigger CI for new PRs without changelog updates (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/166">#166</a>)</li>
<li>Updater - Select the first branch when multiple branches point at
<code>HEAD</code> (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/165">#165</a>)</li>
</ul>
<h3>Dependencies</h3>
<ul>
<li>Bump Danger JS from v13.0.4 to v13.0.5 (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/160">#160</a>)
<ul>
<li><a
href="https://github.com/danger/danger-js/blob/main/CHANGELOG.md#1305">changelog</a></li>
<li><a
href="https://github.com/danger/danger-js/compare/13.0.4...13.0.5">diff</a></li>
</ul>
</li>
</ul>
<h2>3.3.0</h2>
<h3>Features</h3>
<ul>
<li>Updater - Support CMake <code>GIT_TAG</code> with variable
references like <code>${FOO_REF}</code>, resolving and updating the
corresponding <code>set()</code> definition (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/149">#149</a>)</li>
</ul>
<h2>3.2.1</h2>
<h3>Fixes</h3>
<ul>
<li>Sentry-CLI integration test action - Accept chunked ProGuard uploads
for compatibility with Sentry CLI 3.x (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/140">#140</a>)</li>
</ul>
<h2>3.2.0</h2>
<h3>Features</h3>
<ul>
<li>Danger - Add support for repository-specific dangerfiles (<a
href="https://redirect.github.com/getsentry/github-workflows/pull/129">#129</a>)
<ul>
<li>Add <code>extra-dangerfile</code> input parameter to run custom
Danger checks alongside shared workflow checks</li>
</ul>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/getsentry/github-workflows/commit/36c729264d2edc29ebae61950c50e1e9f043ad7e"><code>36c7292</code></a>
Merge remote-tracking branch 'remotes/origin/release/3.4.1'</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/959162c159b866489d3fabe93327f48f9b8cb7ee"><code>959162c</code></a>
release: 3.4.1</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/573d8afcdd715790814cf6a43b8a254fbb1e8877"><code>573d8af</code></a>
fix(sentry-cli): Skip reverse DNS lookup on dummy server start (<a
href="https://redirect.github.com/getsentry/github-workflows/issues/178">#178</a>)</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/6651df0475fb6f9eb0f309554920f3d9572bfd2a"><code>6651df0</code></a>
fix(updater): prevent maintenance from racing ancestry cleanup (<a
href="https://redirect.github.com/getsentry/github-workflows/issues/177">#177</a>)</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/45c8e3ad80a43dc92cfbaa64b8870fac55afdf84"><code>45c8e3a</code></a>
chore: cleanup changelog (<a
href="https://redirect.github.com/getsentry/github-workflows/issues/176">#176</a>)</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/229617d8c3aa13db7ce38aad6d749063c96222d2"><code>229617d</code></a>
fix(danger): preserve prepared workspaces with optional checkout (<a
href="https://redirect.github.com/getsentry/github-workflows/issues/175">#175</a>)</li>
<li><a
href="https://github.com/getsentry/github-workflows/commit/14b30d68079860432ca2dd3a2880c0cbdd708c53"><code>14b30d6</code></a>
fix(updater): distinguish newer pins from divergent history (<a
href="https://redirect.github.com/getsentry/github-workflows/issues/174">#174</a>)</li>
<li>See full diff in <a
href="https://github.com/getsentry/github-workflows/compare/4013fc6e1aeb1be1f9d3b4d232624f0ec1afa613...36c729264d2edc29ebae61950c50e1e9f043ad7e">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
D
dependabot[bot] committed
d672d69410d52ce50ca07967c4ea56f20ac7ec0d
Parent: 760fa50
Committed by GitHub <noreply@github.com> on 10/2/2026, 9:57:27 AM