220 Commits
Author SHA1 Message Date
github-actions[bot]andeifinger 3906fcf994 chore: update known checksums for 0.16.7 (#420)
chore: update known checksums for 0.16.7

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-09-11 06:31:56 +00:00
github-actions[bot]andeifinger c890b57484 chore: update known checksums for 0.16.6 (#416)
chore: update known checksums for 0.16.6

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-09-04 07:37:34 +00:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 6f8f9a9d5f chore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.6.0 (#404)
Bumps
[release-drafter/release-drafter](https://github.com/release-drafter/release-drafter)
from 7.3.0 to 7.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-drafter/release-drafter/releases">release-drafter/release-drafter's
releases</a>.</em></p>
<blockquote>
<h2>v7.6.0</h2>
<h1>What's Changed</h1>
<h2>New</h2>
<ul>
<li>feat: resolve release commitish refs to commit SHAs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1649">#1649</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>feat: add new contributors list (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1645">#1645</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>feat: support pull request co-authors (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1646">#1646</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>feat: support per-key merge strategies in <code>_extends</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1642">#1642</a>)
<a
href="https://github.com/ReneWerner87"><code>@​ReneWerner87</code></a>,
<a href="https://github.com/cchanche"><code>@​cchanche</code></a>, <a
href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>fix: .github in legacy <code>_extends</code> refs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1650">#1650</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>fix: normalize release target branch refs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1648">#1648</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>fix: duplicate and skipped release contributors (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1644">#1644</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
</ul>
<h2>Maintenance</h2>
<ul>
<li>chore(deps): update dependency typescript to 7.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1667">#1667</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>ci(deps): update github/codeql-action digest to 7188fc3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1654">#1654</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>ci(deps): update actions/stale digest to 1e223db (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1653">#1653</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore(deps): update dependency <code>@​types/node</code> to 24.13.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1661">#1661</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore(deps): update vitest to 4.1.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1656">#1656</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore(deps): update graphql-codegen (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1663">#1663</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore(deps): update dependency vite to 8.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1662">#1662</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a></li>
<li>chore(deps): update dependency nock to 14.0.16 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1655">#1655</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore(deps): update dependency <code>@​biomejs/biome</code> to 2.5.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1660">#1660</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>ci(deps): update actions/checkout action to v7.0.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1669">#1669</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>ci(deps): update actions/setup-node action to v7.0.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1670">#1670</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
<li>chore: update generated GraphQL types (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1641">#1641</a>)
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a>,
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>fix(deps): update dependency graphql to 16.14.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1657">#1657</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a></li>
<li>fix(deps): update dependency yaml to 2.9.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1666">#1666</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a></li>
<li>fix(deps): update dependency semver to 7.8.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1659">#1659</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a></li>
<li>fix(deps): update dependency ignore to 7.0.6 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1658">#1658</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions"><code>@​github-actions[bot]</code></a></li>
<li>chore(deps): update dependency <code>@​biomejs/biome</code> to 2.5.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1660">#1660</a>)
<a
href="https://github.com/apps/renovate"><code>@​renovate[bot]</code></a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/ReneWerner87"><code>@​ReneWerner87</code></a>
made their first contribution in <a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1642">#1642</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.5.1...v7.6.0">https://github.com/release-drafter/release-drafter/compare/v7.5.1...v7.6.0</a></p>
<h2>v7.5.1</h2>
<h1>What's Changed</h1>
<h2>Bug Fixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/eada3c96a64734dd381cfbda23511034e328ddb0"><code>eada3c9</code></a>
chore: release v7.6.0</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/4621843980a0844866eefbe4d5f92e680fce5d81"><code>4621843</code></a>
migrate biome config</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e9aeda788e59684f9fe90b4ca1a32f60f0b3bf29"><code>e9aeda7</code></a>
chore(deps): update dependency typescript to 7.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1667">#1667</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/c943e7c8b72b3d6c5fab33cfd024317893d5c320"><code>c943e7c</code></a>
fix(deps): update dependency graphql to 16.14.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1657">#1657</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/b9af92564053e016d0bf080da7c24704c159ee4e"><code>b9af925</code></a>
fix(deps): update dependency yaml to 2.9.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1666">#1666</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/f4aa1589c4bd889abd152b42a03071c0695716b8"><code>f4aa158</code></a>
ci(deps): update github/codeql-action digest to 7188fc3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1654">#1654</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/93973850c385e1ad1901d254003cf654b2fb7f4a"><code>9397385</code></a>
ci(deps): update actions/stale digest to 1e223db (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1653">#1653</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/5dd9f212bc0430df55c6f9b360720a2d08ddc157"><code>5dd9f21</code></a>
chore(deps): update dependency <code>@​types/node</code> to 24.13.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1661">#1661</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/903a9a10909a48b47c20e26c545bac26676d69cd"><code>903a9a1</code></a>
chore(deps): update vitest to 4.1.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1656">#1656</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/2796d1b6a0ad34872845939207b3af9aac1b346f"><code>2796d1b</code></a>
fix(deps): update dependency semver to 7.8.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1659">#1659</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/release-drafter/release-drafter/compare/c2e2804cc59f45f57076a99af580d0fedb697927...eada3c96a64734dd381cfbda23511034e328ddb0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=release-drafter/release-drafter&package-manager=github_actions&previous-version=7.3.0&new-version=7.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-03 16:43:22 +05:30
eifinger-bot 127e6a115e Use JSON for known checksums (#415)
Ports the hardening from astral-sh/setup-uv#1025 to ruff-action.\n\nThis
stores generated checksums as JSON data behind a small typed TypeScript
wrapper, preventing values sourced from release metadata from being
mixed into generated executable code. It also updates the checksum
workflow and packaged action artifacts, and adds a regression test for
code-like keys and escaped checksum values.\n\nTests: npm run build, npm
run check, npm test, npm run package
2026-08-28 16:15:05 -04:00
github-actions[bot]andeifinger 6d5deb5cee chore: update known checksums for 0.16.4/0.16.5 (#412)
chore: update known checksums for 0.16.5

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-08-28 07:54:42 +00:00
zaniebotandzaniebot 46b5b9699e Enforce the npm version floor with legacy clients (#411)
`devEngines` is ignored by npm releases such as `10.8.2`, so those
clients can install dependencies without applying the seven-day
`min-release-age` setting added in #401. Declare the same minimum in
`engines.npm` and enable `engine-strict` to make that legacy installer
requirement fatal. Keep `devEngines` for its earlier checks on newer npm
versions, and pin the build and checksum workflows to Node.js `24.19.0`
so their bundled `npm` supports the policy.

Related: astral-sh/setup-uv#1026 and astral-sh/ruff#27844 enforce the
same legacy-aware `npm` version floor. astral-sh/ruff-action#400 covers
Dependabot's update cooldown, and astral-sh/ruff-action#402 separately
verifies registry signatures and available provenance.

---------

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
2026-08-20 17:36:55 +02:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 848ccd1cb2 chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.6.0 (#408)
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action)
from 0.5.6 to 0.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.6.0</h2>
<p>zizmor 1.27.0 is now the default version used by the action.</p>
<h2>What's Changed</h2>
<ul>
<li>Fold Docker image pull output into a collapsed Actions log group by
<a href="https://github.com/woodruffw"><code>@​woodruffw</code></a> with
<a href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/132">zizmorcore/zizmor-action#132</a></li>
<li>Readme: document missing inputs by <a
href="https://github.com/staabm"><code>@​staabm</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/130">zizmorcore/zizmor-action#130</a></li>
<li>ci: block version sync workflow on forks by <a
href="https://github.com/shaanmajid"><code>@​shaanmajid</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/129">zizmorcore/zizmor-action#129</a></li>
<li>Sync zizmor versions by <a
href="https://github.com/github-actions"><code>@​github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/137">zizmorcore/zizmor-action#137</a></li>
<li>Add <code>collect</code> input by <a
href="https://github.com/woodruffw"><code>@​woodruffw</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/139">zizmorcore/zizmor-action#139</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/woodruffw"><code>@​woodruffw</code></a>
with <a href="https://github.com/Copilot"><code>@​Copilot</code></a>
made their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/132">zizmorcore/zizmor-action#132</a></li>
<li><a href="https://github.com/staabm"><code>@​staabm</code></a> made
their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/130">zizmorcore/zizmor-action#130</a></li>
<li><a
href="https://github.com/shaanmajid"><code>@​shaanmajid</code></a> made
their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/129">zizmorcore/zizmor-action#129</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0">https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0</a></p>
<h2>v0.5.7</h2>
<p>1.26.1 is now available via the action
1.26.1 is now the default version of zizmor used by the action</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/6599ee8b7a49aef6a770f63d261d214911a7ce02"><code>6599ee8</code></a>
Add <code>collect</code> input (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/139">#139</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/bec05c80b8586b8cbc030450e4fa4e82b83a9427"><code>bec05c8</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/137">#137</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/cf5954948fbc9d5b9460b774e281e3387b989ea6"><code>cf59549</code></a>
Add issue templates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/135">#135</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/f72bf176f67e8007f87b16d80f9880ece648aa65"><code>f72bf17</code></a>
chore(deps): bump github/codeql-action/upload-sarif (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/134">#134</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/b2a6fac1a76b42abf3794cd06cef23af2f13e590"><code>b2a6fac</code></a>
ci: block version sync workflow on forks (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/129">#129</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/2d88f441dcd818e199d649f55e9a347196a52262"><code>2d88f44</code></a>
Readme: document missing inputs (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/130">#130</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/d81e2769a6bdcb1d076bf52b5e7e663c881f94e7"><code>d81e276</code></a>
Fold Docker image pull output into a collapsed Actions log group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/132">#132</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/8c13c5382c13a16f7ece1f965891708b819d28b2"><code>8c13c53</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/133">#133</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/2f8e9c6f609a49998258063502592a555c964847"><code>2f8e9c6</code></a>
README: bump versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/128">#128</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/192e21d79ab29983730a13d1382995c2307fbcaa"><code>192e21d</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/127">#127</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...6599ee8b7a49aef6a770f63d261d214911a7ce02">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=zizmorcore/zizmor-action&package-manager=github_actions&previous-version=0.5.6&new-version=0.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-20 09:02:44 +02:00
zaniebotandzaniebot 1f30a84c67 Harden npm install defaults (#401)
CI already disables npm lifecycle scripts, but ordinary installs from
the repository still run them. Add `.npmrc` defaults that disable those
scripts and apply the same seven-day `min-release-age` policy used by
`setup-uv`. Require npm `11.10.0` or newer through `devEngines` so older
versions cannot silently ignore the age setting. Explicit project
commands such as `npm run package` remain available.

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
2026-08-18 19:12:36 +02:00
zaniebotandzaniebot d3ef2489b0 Add a 30-day Dependabot cooldown (#400)
The repository has no explicit Dependabot cooldown, so routine updates
do not follow the 30-day policy used by `setup-uv`. Add
`cooldown.default-days: 30` for npm and GitHub Actions while retaining
the daily schedule. Dependabot security updates remain outside the
cooldown.

Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com>
2026-08-18 19:08:54 +02:00
github-actions[bot]andeifinger 81a72f25c9 chore: update known checksums for 0.16.3 (#399)
chore: update known checksums for 0.16.3

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-08-14 05:36:13 +00:00
github-actions[bot]andeifinger 2ce112e5ca chore: update known checksums for 0.16.2 (#398)
chore: update known checksums for 0.16.2

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-08-09 08:26:38 +00:00
github-actions[bot]andeifinger 28ec38735d chore: update known checksums for 0.16.1 (#397)
chore: update known checksums for 0.16.1

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-07-31 09:11:18 +02:00
project516 2957f9e73d docs: unify ruff-action versions in README (#396) 2026-07-24 18:20:31 +00:00
github-actions[bot]andeifinger 5b168050b9 chore: update known checksums for 0.16.0 (#395)
chore: update known checksums for 0.16.0

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-07-24 06:30:28 +00:00
github-actions[bot]andeifinger 3bb5cd7c3c chore: update known checksums for 0.15.22 (#393)
chore: update known checksums for 0.15.22

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-07-17 06:19:01 +00:00
github-actions[bot]andeifinger 8d2a42ddf5 chore: update known checksums for 0.15.21 (#391)
chore: update known checksums for 0.15.21

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-07-13 09:04:22 +02:00
Kevin Stillhammer 278981a28c Add option to skip Astral mirror downloads (#387)
## Summary
- add `download-from-astral-mirror` input defaulting to `true`
- skip mirror URL rewriting and download directly from GitHub Releases
when disabled
- document the input and add unit coverage

Fixes #384

Refs: pi-session 019f31bc-bd1c-7276-9b4e-9734fa0aa367

## Testing
- npm run build
- npm run check
- npm run test:unit
v4.1.0
2026-07-05 10:17:44 +00:00
Kevin Stillhammer c35f46c92b chore: roll up Dependabot updates (#386)
## Summary
- roll up remaining open Dependabot npm updates for @octokit/core and
@octokit/plugin-rest-endpoint-methods
- roll up remaining GitHub Actions pin updates for CodeQL, zizmor,
release-drafter, setup-node, and create-pull-request
- regenerate bundled dist files

## Validation
- npm run all

Refs: pi-session 019f31b8-93d9-7f9b-b3e9-5aaac6bab959
2026-07-05 12:04:11 +02:00
somaz f3db229c84 feat: support uv.lock as version-file (#379)
Adds `uv.lock` as a supported `version-file` format, alongside the
existing
`pyproject.toml` and `requirements.txt`. A `uv.lock` pins the exact
resolved
ruff version, so reading it gives a reproducible install that matches
the
project's lockfile — the single source of truth — instead of the
lower-bound /
range typically declared in `pyproject.toml`.

The parser reads the `[[package]]` entry whose `name` is `ruff` and
returns its
`version`. If ruff is absent or the file cannot be parsed, the action
warns and
falls back to `latest` (same behaviour as the other formats).

Validation:
- `npm run all` — tsc typecheck clean, biome clean, dist rebuilt, jest
65/65 pass
- Added unit tests (`__tests__/version/file-parser.test.ts`) + a
`uv.lock` fixture
- Added an integration job (`test-default-version-from-uv-lock`) that
runs the
  action against the fixture and asserts ruff 0.9.5 is installed

closes #375
2026-07-05 11:56:05 +02:00
Kevin Stillhammer 270e80dfe7 Fix wildcard src input (#368)
Fixes: #355
2026-07-05 11:55:02 +02:00
Kevin Stillhammer 5fedeebdb3 Add Dependabot rollup skill (#385)
## Summary
- add the dependabot-pr-rollup skill copied from setup-uv
- adapt the workflow notes for ruff-action's npm and GitHub Actions
Dependabot updates

## Testing
- npm run all

Refs: pi-session 019f317d-08f2-7aac-a6d5-56a44288d94c
2026-07-05 11:49:16 +02:00
github-actions[bot]andeifinger 99fe79f472 chore: update known checksums for 0.15.20 (#383)
chore: update known checksums for 0.15.20

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-06-26 08:39:54 +02:00
github-actions[bot]andeifinger 32ad1b993e chore: update known checksums for 0.15.19 (#382)
chore: update known checksums for 0.15.19

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-06-24 07:16:05 +00:00
github-actions[bot]andeifinger f78e087041 chore: update known checksums for 0.15.18 (#381)
chore: update known checksums for 0.15.18

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-06-19 05:45:18 +00:00
github-actions[bot]andeifinger 2f88679623 chore: update known checksums for 0.15.17 (#380)
chore: update known checksums for 0.15.17

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-06-12 05:57:40 +00:00
github-actions[bot]andeifinger b79a7ac759 chore: update known checksums for 0.15.16 (#378)
chore: update known checksums for 0.15.16

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-06-05 06:27:01 +00:00
github-actions[bot]andeifinger 30c0929868 chore: update known checksums for 0.15.15 (#377)
chore: update known checksums for 0.15.15

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-05-29 09:11:56 +00:00
github-actions[bot]andeifinger b4bf7655a0 chore: update known checksums for 0.15.14 (#376)
chore: update known checksums for 0.15.14

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-05-22 05:57:48 +00:00
Frederick Wagner 7f78e88b21 Use v4.0.0 in README.md (#371)
This change should reduce confusion from `@4` not working.
2026-05-20 13:18:52 +02:00
github-actions[bot]andeifinger 8c228c72ff chore: update known checksums for 0.15.13 (#372)
chore: update known checksums for 0.15.13

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-05-15 06:36:00 +00:00
Zanie Blue 248b6d6da3 Update the release process to match setup-uv (#364) 2026-04-27 10:31:05 -05:00
github-actions[bot]andeifinger ecaa98070e chore: update known checksums for 0.15.12 (#365)
chore: update known checksums for 0.15.12

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-04-25 07:00:01 +00:00
github-actions[bot]andeifinger a9cfed68e4 chore: update known checksums for 0.15.11 (#360)
chore: update known checksums for 0.15.11

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-04-17 07:31:01 +00:00
Kevin Stillhammer eb44a0e99b Draft commitish releases (#359) 2026-04-16 20:31:36 +02:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 2915b93f0d Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 (#356)
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action)
from 0.5.2 to 0.5.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.3</h2>
<ul>
<li><code>1.24.0</code> and <code>1.24.1</code> are now available via
the action</li>
<li><code>1.24.1</code> is now the default version of zizmor used by the
action</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/b1d7e1fb5de872772f31590499237e7cce841e8e"><code>b1d7e1f</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/102">#102</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/a195b57475917ddcb70845e5ffe1c3a15dbbdedc"><code>a195b57</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/100">#100</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/629d5d01fe5939a6aeae25c1bd1acd2cfa28e9b2"><code>629d5d0</code></a>
chore(deps): bump github/codeql-action in the github-actions group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/99">#99</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/453d591467e8199b1d5c6883b6ec5c22a12aac72"><code>453d591</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/98">#98</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/ea2c18b942410df0b22bed3b94c361c407518d45"><code>ea2c18b</code></a>
Bump pins (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/97">#97</a>)</li>
<li>See full diff in <a
href="https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f31590499237e7cce841e8e">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=zizmorcore/zizmor-action&package-manager=github_actions&previous-version=0.5.2&new-version=0.5.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-14 07:51:55 +02:00
Kevin Stillhammer 0ce1b0bf8b refactor version resolving (#353) v4.0.0 2026-04-12 13:44:40 +02:00
Kevin Stillhammer 9b8caf6c41 Add manifest-file input (#352) 2026-04-11 19:14:05 +02:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 535554df96 Bump release-drafter/release-drafter from 6.2.0 to 7.2.0 (#350)
Bumps
[release-drafter/release-drafter](https://github.com/release-drafter/release-drafter)
from 6.2.0 to 7.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-drafter/release-drafter/releases">release-drafter/release-drafter's
releases</a>.</em></p>
<blockquote>
<h2>v7.2.0</h2>
<h1>What's Changed</h1>
<h2>New</h2>
<ul>
<li>feat: allow always collapsing a category (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1444">#1444</a>)
<a href="https://github.com/mhanberg"><code>@​mhanberg</code></a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>fix: improve advanced substitutions in replacers (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1555">#1555</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>fix: support repo-only _extends and prevent .github/ path doubling
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1577">#1577</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
</ul>
<h2>Maintenance</h2>
<ul>
<li>chore(deps): update dependency typescript to 6.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1587">#1587</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update vitest to 4.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1585">#1585</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>ci(deps): update peter-evans/create-pull-request action to v8 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1588">#1588</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency vite to 8.0.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1579">#1579</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency nock to 14.0.12 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1583">#1583</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@​types/node</code> to 24.12.2
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1582">#1582</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@​biomejs/biome</code> to
2.4.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1581">#1581</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore: move codegen to monthly scheduled workflow (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1578">#1578</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
<li>chore: replace vite-tsconfig-paths plugin with native
resolve.tsconfigPaths (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1571">#1571</a>)
<a href="https://github.com/jetersen"><code>@​jetersen</code></a></li>
</ul>
<h2>Documentation</h2>
<ul>
<li>docs: fix autolabeler example tag (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1568">#1568</a>)
<a href="https://github.com/cchanche"><code>@​cchanche</code></a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>build(deps): bump lodash and
<code>@​graphql-codegen/plugin-helpers</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1589">#1589</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>fix(deps): update dependency <code>@​actions/github</code> to 9.1.0
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1586">#1586</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency yaml to 2.8.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1580">#1580</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update node.js to v24.14.1 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1584">#1584</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@​biomejs/biome</code> to
2.4.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1581">#1581</a>)
@<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.1.1...v7.2.0">https://github.com/release-drafter/release-drafter/compare/v7.1.1...v7.2.0</a></p>
<h2>v7.1.1</h2>
<h1>What's Changed</h1>
<h2>Bug Fixes</h2>
<ul>
<li>fix: remove disable-releaser and disable-autolabeler from
action.yaml (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1564">#1564</a>)
<a href="https://github.com/cchanche"><code>@​cchanche</code></a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.1.0...v7.1.1">https://github.com/release-drafter/release-drafter/compare/v7.1.0...v7.1.1</a></p>
<h2>v7.1.0</h2>
<h1>What's Changed</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/5de93583980a40bd78603b6dfdcda5b4df377b32"><code>5de9358</code></a>
7.2.0</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e50d61c7deb94fc176ad7d31d7b71f60307829b2"><code>e50d61c</code></a>
chore: rebuild dist</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/d3a61d3b778db0d18c3511a1d8a5585188fdb99f"><code>d3a61d3</code></a>
chore: fix npm audit vulnerabilities</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/8bfa2791ec73890e3087b933c9db62d0a294a461"><code>8bfa279</code></a>
build(deps): bump lodash and
<code>@​graphql-codegen/plugin-helpers</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1589">#1589</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/c2a8a67ac931b548feeee49fe78975bd87720a0e"><code>c2a8a67</code></a>
chore: remove engine-strict from .npmrc to fix Dependabot
resolution</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e51e4adf1695870d57ae9cf3fa8cc37064d6304d"><code>e51e4ad</code></a>
chore(deps): update dependency typescript to 6.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1587">#1587</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/0e7bd548468b9ce7f0b082417f6ec32bc47173ae"><code>0e7bd54</code></a>
fix(deps): update dependency <code>@​actions/github</code> to 9.1.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1586">#1586</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/9c0b0a8cf19d3415f835a04b1987cd2451aaac85"><code>9c0b0a8</code></a>
chore(deps): update dependency yaml to 2.8.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1580">#1580</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/b27f820cbc98c923f216e773d35bc7f4e8efd9ed"><code>b27f820</code></a>
chore(deps): update vitest to 4.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1585">#1585</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/eb9053430f473e03512e92caee9608b0db01ebd7"><code>eb90534</code></a>
ci(deps): update peter-evans/create-pull-request action to v8 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1588">#1588</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/release-drafter/release-drafter/compare/6db134d15f3909ccc9eefd369f02bd1e9cffdf97...5de93583980a40bd78603b6dfdcda5b4df377b32">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=release-drafter/release-drafter&package-manager=github_actions&previous-version=6.2.0&new-version=7.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 11:41:10 +02:00
github-actions[bot]andeifinger 2186c6ecae chore: update known checksums for 0.15.10 (#351)
chore: update known checksums for 0.15.10

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-04-10 11:34:56 +00:00
Zanie Blue 26892dbe43 Add a release workflow (#349)
Mirroring https://github.com/astral-sh/setup-uv/pull/839
2026-04-09 14:10:29 +02:00
github-actions[bot]andeifinger d7f6ad639a chore: update known checksums for 0.15.9 (#348)
chore: update known checksums for 0.15.9

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-04-03 07:00:21 +00:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 5b5935861b Bump eifinger/actionlint-action from 1.10.0 to 1.10.2 (#347)
Bumps
[eifinger/actionlint-action](https://github.com/eifinger/actionlint-action)
from 1.10.0 to 1.10.2.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/1fc89649be682d16ec5cf65ea16e269eb88d3982"><code>1fc8964</code></a>
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/34">#34</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/77c97feb783dfe1768d10f9dda219af0936f44a7"><code>77c97fe</code></a>
build(deps): bump release-drafter/release-drafter from 6.2.0 to 7.1.1
(<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/40">#40</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/bc5a34046e0b08d672f8a517047621ce16320c2b"><code>bc5a340</code></a>
chore: bump actionlint to 1.7.12 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/41">#41</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/7802e0cc3ab3f81cbffb36fb0bf1a3621d994b89"><code>7802e0c</code></a>
Remove oracle-aarch64 from workflows (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/36">#36</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/8d9ad94ef799fdd386147ebbed32e940280f3dcd"><code>8d9ad94</code></a>
set default actionlint version to 1.7.11 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/35">#35</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/4863b27ac4c7ab9e9c69405b36b49b7b4d97ead9"><code>4863b27</code></a>
build(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0
(<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/33">#33</a>)</li>
<li>See full diff in <a
href="https://github.com/eifinger/actionlint-action/compare/447fbfe7533062b7a9ea55f790f2396fba6d052a...1fc89649be682d16ec5cf65ea16e269eb88d3982">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eifinger/actionlint-action&package-manager=github_actions&previous-version=1.10.0&new-version=1.10.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 07:39:51 +02:00
Kevin Stillhammer 0be154b683 Migrate to ESMBundler and node 24 (#345) 2026-03-28 15:52:59 +00:00
github-actions[bot]andeifinger f611dfc122 chore: update known checksums for 0.15.8 (#344)
chore: update known checksums for 0.15.8

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-03-27 06:13:56 +00:00
github-actions[bot]andeifinger d40baf4d10 chore: update known checksums for 0.15.7 (#342)
chore: update known checksums for 0.15.7

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-03-20 06:47:13 +00:00
github-actions[bot]andeifinger 18ddc929c7 chore: update known checksums for 0.15.6 (#337)
chore: update known checksums for 0.15.6

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-03-13 07:28:50 +01:00
dependabot[bot]anddependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> 25445a5bce Bump zizmorcore/zizmor-action from 0.4.1 to 0.5.2 (#333)
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action)
from 0.4.1 to 0.5.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.2</h2>
<h2>What's Changed</h2>
<ul>
<li>zizmor 1.23.1 is now the default used by this action.</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.1...v0.5.2">https://github.com/zizmorcore/zizmor-action/compare/v0.5.1...v0.5.2</a></p>
<h2>v0.5.1</h2>
<h2>What's Changed</h2>
<ul>
<li>zizmor 1.23.0 is now the default used by this action.</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.0...v0.5.1">https://github.com/zizmorcore/zizmor-action/compare/v0.5.0...v0.5.1</a></p>
<h2>v0.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Expose <code>output-file</code> as an output when
<code>advanced-security: true</code> by <a
href="https://github.com/unlobito"><code>@​unlobito</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/87">zizmorcore/zizmor-action#87</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/unlobito"><code>@​unlobito</code></a>
made their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/87">zizmorcore/zizmor-action#87</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.4.1...v0.5.0">https://github.com/zizmorcore/zizmor-action/compare/v0.4.1...v0.5.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8"><code>71321a2</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/96">#96</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/5ed31db0964a9d37608edd5b0675de2b52070662"><code>5ed31db</code></a>
Bump pins (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/95">#95</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/195d10ad90f31d8cd6ea1efd6ecc12969ddbe73f"><code>195d10a</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/94">#94</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/c65bc8876171b6d82748ec98b77c0193b1226b94"><code>c65bc88</code></a>
chore(deps): bump github/codeql-action in the github-actions group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/93">#93</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/c2c887f84674f9c15123e2905d2d307675d8bc01"><code>c2c887f</code></a>
chore(deps): bump zizmorcore/zizmor-action in the github-actions group
(<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/91">#91</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/5507ab0c02a9ac3996895e1598d6b3385ea7d525"><code>5507ab0</code></a>
Bump pins in README (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/90">#90</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/0dce2577a4760a2749d8cfb7a84b7d5585ebcb7d"><code>0dce257</code></a>
chore(deps): bump peter-evans/create-pull-request (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/88">#88</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/fb9497493b591ad90176d3ecac5ca4aeff8c9faf"><code>fb94974</code></a>
Expose <code>output-file</code> as an output when
<code>advanced-security: true</code> (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/87">#87</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/867562a69bb7adcc63dd1e8c003600a58b5f70e2"><code>867562a</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/85">#85</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/7462f075f718787753331c6d98ca9ef8eb41e735"><code>7462f07</code></a>
Bump pins in README (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/84">#84</a>)</li>
<li>See full diff in <a
href="https://github.com/zizmorcore/zizmor-action/compare/135698455da5c3b3e55f73f4419e481ab68cdd95...71321a20a9ded102f6e9ce5718a2fcec2c4f70d8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=zizmorcore/zizmor-action&package-manager=github_actions&previous-version=0.4.1&new-version=0.5.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 08:05:39 +01:00
github-actions[bot]andeifinger cb58d827d0 chore: update known checksums for 0.15.5 (#331)
chore: update known checksums for 0.15.5

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-03-06 08:28:19 +01:00
github-actions[bot]andeifinger 845ce6a88f chore: update known checksums for 0.15.4 (#328)
chore: update known checksums for 0.15.4

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-02-27 08:11:36 +01:00
github-actions[bot]andeifinger 48f37fab2d chore: update known checksums for 0.15.2 (#325)
chore: update known checksums for 0.15.2

Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com>
2026-02-20 06:59:59 +00:00