github-actions[bot] and eifinger
3906fcf994
chore: update known checksums for 0.16.7 ( #420 )
...
chore: update known checksums for 0.16.7
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-09-11 06:31:56 +00:00
github-actions[bot] and eifinger
c890b57484
chore: update known checksums for 0.16.6 ( #416 )
...
chore: update known checksums for 0.16.6
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-09-04 07:37:34 +00:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
6f8f9a9d5f
chore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.6.0 ( #404 )
...
Bumps
[release-drafter/release-drafter](https://github.com/release-drafter/release-drafter )
from 7.3.0 to 7.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-drafter/release-drafter/releases ">release-drafter/release-drafter's
releases</a>.</em></p>
<blockquote>
<h2>v7.6.0</h2>
<h1>What's Changed</h1>
<h2>New</h2>
<ul>
<li>feat: resolve release commitish refs to commit SHAs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1649 ">#1649</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>feat: add new contributors list (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1645 ">#1645</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>feat: support pull request co-authors (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1646 ">#1646</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>feat: support per-key merge strategies in <code>_extends</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1642 ">#1642</a>)
<a
href="https://github.com/ReneWerner87 "><code>@ReneWerner87</code></a>,
<a href="https://github.com/cchanche "><code>@cchanche</code></a>, <a
href="https://github.com/jetersen "><code>@jetersen</code></a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>fix: .github in legacy <code>_extends</code> refs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1650 ">#1650</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>fix: normalize release target branch refs (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1648 ">#1648</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>fix: duplicate and skipped release contributors (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1644 ">#1644</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
</ul>
<h2>Maintenance</h2>
<ul>
<li>chore(deps): update dependency typescript to 7.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1667 ">#1667</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>ci(deps): update github/codeql-action digest to 7188fc3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1654 ">#1654</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>ci(deps): update actions/stale digest to 1e223db (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1653 ">#1653</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore(deps): update dependency <code>@types/node</code> to 24.13.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1661 ">#1661</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore(deps): update vitest to 4.1.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1656 ">#1656</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore(deps): update graphql-codegen (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1663 ">#1663</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore(deps): update dependency vite to 8.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1662 ">#1662</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a></li>
<li>chore(deps): update dependency nock to 14.0.16 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1655 ">#1655</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore(deps): update dependency <code>@biomejs/biome</code> to 2.5.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1660 ">#1660</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>ci(deps): update actions/checkout action to v7.0.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1669 ">#1669</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>ci(deps): update actions/setup-node action to v7.0.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1670 ">#1670</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
<li>chore: update generated GraphQL types (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1641 ">#1641</a>)
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a>,
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>fix(deps): update dependency graphql to 16.14.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1657 ">#1657</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a></li>
<li>fix(deps): update dependency yaml to 2.9.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1666 ">#1666</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a></li>
<li>fix(deps): update dependency semver to 7.8.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1659 ">#1659</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a></li>
<li>fix(deps): update dependency ignore to 7.0.6 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1658 ">#1658</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a>,
<a
href="https://github.com/apps/github-actions "><code>@github-actions[bot]</code></a></li>
<li>chore(deps): update dependency <code>@biomejs/biome</code> to 2.5.3
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1660 ">#1660</a>)
<a
href="https://github.com/apps/renovate "><code>@renovate[bot]</code></a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/ReneWerner87 "><code>@ReneWerner87</code></a>
made their first contribution in <a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1642 ">#1642</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.5.1...v7.6.0 ">https://github.com/release-drafter/release-drafter/compare/v7.5.1...v7.6.0 </a></p>
<h2>v7.5.1</h2>
<h1>What's Changed</h1>
<h2>Bug Fixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/eada3c96a64734dd381cfbda23511034e328ddb0 "><code>eada3c9</code></a>
chore: release v7.6.0</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/4621843980a0844866eefbe4d5f92e680fce5d81 "><code>4621843</code></a>
migrate biome config</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e9aeda788e59684f9fe90b4ca1a32f60f0b3bf29 "><code>e9aeda7</code></a>
chore(deps): update dependency typescript to 7.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1667 ">#1667</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/c943e7c8b72b3d6c5fab33cfd024317893d5c320 "><code>c943e7c</code></a>
fix(deps): update dependency graphql to 16.14.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1657 ">#1657</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/b9af92564053e016d0bf080da7c24704c159ee4e "><code>b9af925</code></a>
fix(deps): update dependency yaml to 2.9.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1666 ">#1666</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/f4aa1589c4bd889abd152b42a03071c0695716b8 "><code>f4aa158</code></a>
ci(deps): update github/codeql-action digest to 7188fc3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1654 ">#1654</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/93973850c385e1ad1901d254003cf654b2fb7f4a "><code>9397385</code></a>
ci(deps): update actions/stale digest to 1e223db (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1653 ">#1653</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/5dd9f212bc0430df55c6f9b360720a2d08ddc157 "><code>5dd9f21</code></a>
chore(deps): update dependency <code>@types/node</code> to 24.13.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1661 ">#1661</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/903a9a10909a48b47c20e26c545bac26676d69cd "><code>903a9a1</code></a>
chore(deps): update vitest to 4.1.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1656 ">#1656</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/2796d1b6a0ad34872845939207b3af9aac1b346f "><code>2796d1b</code></a>
fix(deps): update dependency semver to 7.8.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1659 ">#1659</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/release-drafter/release-drafter/compare/c2e2804cc59f45f57076a99af580d0fedb697927...eada3c96a64734dd381cfbda23511034e328ddb0 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-03 16:43:22 +05:30
eifinger-bot
127e6a115e
Use JSON for known checksums ( #415 )
...
Ports the hardening from astral-sh/setup-uv#1025 to ruff-action.\n\nThis
stores generated checksums as JSON data behind a small typed TypeScript
wrapper, preventing values sourced from release metadata from being
mixed into generated executable code. It also updates the checksum
workflow and packaged action artifacts, and adds a regression test for
code-like keys and escaped checksum values.\n\nTests: npm run build, npm
run check, npm test, npm run package
2026-08-28 16:15:05 -04:00
github-actions[bot] and eifinger
6d5deb5cee
chore: update known checksums for 0.16.4/0.16.5 ( #412 )
...
chore: update known checksums for 0.16.5
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-08-28 07:54:42 +00:00
zaniebot and zaniebot
46b5b9699e
Enforce the npm version floor with legacy clients ( #411 )
...
`devEngines` is ignored by npm releases such as `10.8.2`, so those
clients can install dependencies without applying the seven-day
`min-release-age` setting added in #401 . Declare the same minimum in
`engines.npm` and enable `engine-strict` to make that legacy installer
requirement fatal. Keep `devEngines` for its earlier checks on newer npm
versions, and pin the build and checksum workflows to Node.js `24.19.0`
so their bundled `npm` supports the policy.
Related: astral-sh/setup-uv#1026 and astral-sh/ruff#27844 enforce the
same legacy-aware `npm` version floor. astral-sh/ruff-action#400 covers
Dependabot's update cooldown, and astral-sh/ruff-action#402 separately
verifies registry signatures and available provenance.
---------
Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com >
2026-08-20 17:36:55 +02:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
848ccd1cb2
chore(deps): bump zizmorcore/zizmor-action from 0.5.6 to 0.6.0 ( #408 )
...
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action )
from 0.5.6 to 0.6.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases ">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.6.0</h2>
<p>zizmor 1.27.0 is now the default version used by the action.</p>
<h2>What's Changed</h2>
<ul>
<li>Fold Docker image pull output into a collapsed Actions log group by
<a href="https://github.com/woodruffw "><code>@woodruffw</code></a> with
<a href="https://github.com/Copilot "><code>@Copilot</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/132 ">zizmorcore/zizmor-action#132</a></li>
<li>Readme: document missing inputs by <a
href="https://github.com/staabm "><code>@staabm</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/130 ">zizmorcore/zizmor-action#130</a></li>
<li>ci: block version sync workflow on forks by <a
href="https://github.com/shaanmajid "><code>@shaanmajid</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/129 ">zizmorcore/zizmor-action#129</a></li>
<li>Sync zizmor versions by <a
href="https://github.com/github-actions "><code>@github-actions</code></a>[bot]
in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/137 ">zizmorcore/zizmor-action#137</a></li>
<li>Add <code>collect</code> input by <a
href="https://github.com/woodruffw "><code>@woodruffw</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/139 ">zizmorcore/zizmor-action#139</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/woodruffw "><code>@woodruffw</code></a>
with <a href="https://github.com/Copilot "><code>@Copilot</code></a>
made their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/132 ">zizmorcore/zizmor-action#132</a></li>
<li><a href="https://github.com/staabm "><code>@staabm</code></a> made
their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/130 ">zizmorcore/zizmor-action#130</a></li>
<li><a
href="https://github.com/shaanmajid "><code>@shaanmajid</code></a> made
their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/129 ">zizmorcore/zizmor-action#129</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0 ">https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0 </a></p>
<h2>v0.5.7</h2>
<p>1.26.1 is now available via the action
1.26.1 is now the default version of zizmor used by the action</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/6599ee8b7a49aef6a770f63d261d214911a7ce02 "><code>6599ee8</code></a>
Add <code>collect</code> input (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/139 ">#139</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/bec05c80b8586b8cbc030450e4fa4e82b83a9427 "><code>bec05c8</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/137 ">#137</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/cf5954948fbc9d5b9460b774e281e3387b989ea6 "><code>cf59549</code></a>
Add issue templates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/135 ">#135</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/f72bf176f67e8007f87b16d80f9880ece648aa65 "><code>f72bf17</code></a>
chore(deps): bump github/codeql-action/upload-sarif (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/134 ">#134</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/b2a6fac1a76b42abf3794cd06cef23af2f13e590 "><code>b2a6fac</code></a>
ci: block version sync workflow on forks (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/129 ">#129</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/2d88f441dcd818e199d649f55e9a347196a52262 "><code>2d88f44</code></a>
Readme: document missing inputs (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/130 ">#130</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/d81e2769a6bdcb1d076bf52b5e7e663c881f94e7 "><code>d81e276</code></a>
Fold Docker image pull output into a collapsed Actions log group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/132 ">#132</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/8c13c5382c13a16f7ece1f965891708b819d28b2 "><code>8c13c53</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/133 ">#133</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/2f8e9c6f609a49998258063502592a555c964847 "><code>2f8e9c6</code></a>
README: bump versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/128 ">#128</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/192e21d79ab29983730a13d1382995c2307fbcaa "><code>192e21d</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/127 ">#127</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/zizmorcore/zizmor-action/compare/5f14fd08f7cf1cb1609c1e344975f152c7ee938d...6599ee8b7a49aef6a770f63d261d214911a7ce02 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-20 09:02:44 +02:00
zaniebot and zaniebot
1f30a84c67
Harden npm install defaults ( #401 )
...
CI already disables npm lifecycle scripts, but ordinary installs from
the repository still run them. Add `.npmrc` defaults that disable those
scripts and apply the same seven-day `min-release-age` policy used by
`setup-uv`. Require npm `11.10.0` or newer through `devEngines` so older
versions cannot silently ignore the age setting. Explicit project
commands such as `npm run package` remain available.
Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com >
2026-08-18 19:12:36 +02:00
zaniebot and zaniebot
d3ef2489b0
Add a 30-day Dependabot cooldown ( #400 )
...
The repository has no explicit Dependabot cooldown, so routine updates
do not follow the 30-day policy used by `setup-uv`. Add
`cooldown.default-days: 30` for npm and GitHub Actions while retaining
the daily schedule. Dependabot security updates remain outside the
cooldown.
Co-authored-by: zaniebot <242828183+zaniebot@users.noreply.github.com >
2026-08-18 19:08:54 +02:00
github-actions[bot] and eifinger
81a72f25c9
chore: update known checksums for 0.16.3 ( #399 )
...
chore: update known checksums for 0.16.3
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-08-14 05:36:13 +00:00
github-actions[bot] and eifinger
2ce112e5ca
chore: update known checksums for 0.16.2 ( #398 )
...
chore: update known checksums for 0.16.2
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-08-09 08:26:38 +00:00
github-actions[bot] and eifinger
28ec38735d
chore: update known checksums for 0.16.1 ( #397 )
...
chore: update known checksums for 0.16.1
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-07-31 09:11:18 +02:00
project516
2957f9e73d
docs: unify ruff-action versions in README ( #396 )
2026-07-24 18:20:31 +00:00
github-actions[bot] and eifinger
5b168050b9
chore: update known checksums for 0.16.0 ( #395 )
...
chore: update known checksums for 0.16.0
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-07-24 06:30:28 +00:00
github-actions[bot] and eifinger
3bb5cd7c3c
chore: update known checksums for 0.15.22 ( #393 )
...
chore: update known checksums for 0.15.22
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-07-17 06:19:01 +00:00
github-actions[bot] and eifinger
8d2a42ddf5
chore: update known checksums for 0.15.21 ( #391 )
...
chore: update known checksums for 0.15.21
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-07-13 09:04:22 +02:00
Kevin Stillhammer
278981a28c
Add option to skip Astral mirror downloads ( #387 )
...
## Summary
- add `download-from-astral-mirror` input defaulting to `true`
- skip mirror URL rewriting and download directly from GitHub Releases
when disabled
- document the input and add unit coverage
Fixes #384
Refs: pi-session 019f31bc-bd1c-7276-9b4e-9734fa0aa367
## Testing
- npm run build
- npm run check
- npm run test:unit
v4.1.0
2026-07-05 10:17:44 +00:00
Kevin Stillhammer
c35f46c92b
chore: roll up Dependabot updates ( #386 )
...
## Summary
- roll up remaining open Dependabot npm updates for @octokit/core and
@octokit/plugin-rest-endpoint-methods
- roll up remaining GitHub Actions pin updates for CodeQL, zizmor,
release-drafter, setup-node, and create-pull-request
- regenerate bundled dist files
## Validation
- npm run all
Refs: pi-session 019f31b8-93d9-7f9b-b3e9-5aaac6bab959
2026-07-05 12:04:11 +02:00
somaz
f3db229c84
feat: support uv.lock as version-file ( #379 )
...
Adds `uv.lock` as a supported `version-file` format, alongside the
existing
`pyproject.toml` and `requirements.txt`. A `uv.lock` pins the exact
resolved
ruff version, so reading it gives a reproducible install that matches
the
project's lockfile — the single source of truth — instead of the
lower-bound /
range typically declared in `pyproject.toml`.
The parser reads the `[[package]]` entry whose `name` is `ruff` and
returns its
`version`. If ruff is absent or the file cannot be parsed, the action
warns and
falls back to `latest` (same behaviour as the other formats).
Validation:
- `npm run all` — tsc typecheck clean, biome clean, dist rebuilt, jest
65/65 pass
- Added unit tests (`__tests__/version/file-parser.test.ts`) + a
`uv.lock` fixture
- Added an integration job (`test-default-version-from-uv-lock`) that
runs the
action against the fixture and asserts ruff 0.9.5 is installed
closes #375
2026-07-05 11:56:05 +02:00
Kevin Stillhammer
270e80dfe7
Fix wildcard src input ( #368 )
...
Fixes : #355
2026-07-05 11:55:02 +02:00
Kevin Stillhammer
5fedeebdb3
Add Dependabot rollup skill ( #385 )
...
## Summary
- add the dependabot-pr-rollup skill copied from setup-uv
- adapt the workflow notes for ruff-action's npm and GitHub Actions
Dependabot updates
## Testing
- npm run all
Refs: pi-session 019f317d-08f2-7aac-a6d5-56a44288d94c
2026-07-05 11:49:16 +02:00
github-actions[bot] and eifinger
99fe79f472
chore: update known checksums for 0.15.20 ( #383 )
...
chore: update known checksums for 0.15.20
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-06-26 08:39:54 +02:00
github-actions[bot] and eifinger
32ad1b993e
chore: update known checksums for 0.15.19 ( #382 )
...
chore: update known checksums for 0.15.19
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-06-24 07:16:05 +00:00
github-actions[bot] and eifinger
f78e087041
chore: update known checksums for 0.15.18 ( #381 )
...
chore: update known checksums for 0.15.18
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-06-19 05:45:18 +00:00
github-actions[bot] and eifinger
2f88679623
chore: update known checksums for 0.15.17 ( #380 )
...
chore: update known checksums for 0.15.17
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-06-12 05:57:40 +00:00
github-actions[bot] and eifinger
b79a7ac759
chore: update known checksums for 0.15.16 ( #378 )
...
chore: update known checksums for 0.15.16
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-06-05 06:27:01 +00:00
github-actions[bot] and eifinger
30c0929868
chore: update known checksums for 0.15.15 ( #377 )
...
chore: update known checksums for 0.15.15
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-05-29 09:11:56 +00:00
github-actions[bot] and eifinger
b4bf7655a0
chore: update known checksums for 0.15.14 ( #376 )
...
chore: update known checksums for 0.15.14
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-05-22 05:57:48 +00:00
Frederick Wagner
7f78e88b21
Use v4.0.0 in README.md ( #371 )
...
This change should reduce confusion from `@4` not working.
2026-05-20 13:18:52 +02:00
github-actions[bot] and eifinger
8c228c72ff
chore: update known checksums for 0.15.13 ( #372 )
...
chore: update known checksums for 0.15.13
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-05-15 06:36:00 +00:00
Zanie Blue
248b6d6da3
Update the release process to match setup-uv ( #364 )
2026-04-27 10:31:05 -05:00
github-actions[bot] and eifinger
ecaa98070e
chore: update known checksums for 0.15.12 ( #365 )
...
chore: update known checksums for 0.15.12
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-04-25 07:00:01 +00:00
github-actions[bot] and eifinger
a9cfed68e4
chore: update known checksums for 0.15.11 ( #360 )
...
chore: update known checksums for 0.15.11
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-04-17 07:31:01 +00:00
Kevin Stillhammer
eb44a0e99b
Draft commitish releases ( #359 )
2026-04-16 20:31:36 +02:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2915b93f0d
Bump zizmorcore/zizmor-action from 0.5.2 to 0.5.3 ( #356 )
...
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action )
from 0.5.2 to 0.5.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases ">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.3</h2>
<ul>
<li><code>1.24.0</code> and <code>1.24.1</code> are now available via
the action</li>
<li><code>1.24.1</code> is now the default version of zizmor used by the
action</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/b1d7e1fb5de872772f31590499237e7cce841e8e "><code>b1d7e1f</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/102 ">#102</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/a195b57475917ddcb70845e5ffe1c3a15dbbdedc "><code>a195b57</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/100 ">#100</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/629d5d01fe5939a6aeae25c1bd1acd2cfa28e9b2 "><code>629d5d0</code></a>
chore(deps): bump github/codeql-action in the github-actions group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/99 ">#99</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/453d591467e8199b1d5c6883b6ec5c22a12aac72 "><code>453d591</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/98 ">#98</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/ea2c18b942410df0b22bed3b94c361c407518d45 "><code>ea2c18b</code></a>
Bump pins (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/97 ">#97</a>)</li>
<li>See full diff in <a
href="https://github.com/zizmorcore/zizmor-action/compare/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8...b1d7e1fb5de872772f31590499237e7cce841e8e ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-14 07:51:55 +02:00
Kevin Stillhammer
0ce1b0bf8b
refactor version resolving ( #353 )
v4.0.0
2026-04-12 13:44:40 +02:00
Kevin Stillhammer
9b8caf6c41
Add manifest-file input ( #352 )
2026-04-11 19:14:05 +02:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
535554df96
Bump release-drafter/release-drafter from 6.2.0 to 7.2.0 ( #350 )
...
Bumps
[release-drafter/release-drafter](https://github.com/release-drafter/release-drafter )
from 6.2.0 to 7.2.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/release-drafter/release-drafter/releases ">release-drafter/release-drafter's
releases</a>.</em></p>
<blockquote>
<h2>v7.2.0</h2>
<h1>What's Changed</h1>
<h2>New</h2>
<ul>
<li>feat: allow always collapsing a category (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1444 ">#1444</a>)
<a href="https://github.com/mhanberg "><code>@mhanberg</code></a></li>
</ul>
<h2>Bug Fixes</h2>
<ul>
<li>fix: improve advanced substitutions in replacers (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1555 ">#1555</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>fix: support repo-only _extends and prevent .github/ path doubling
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1577 ">#1577</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
</ul>
<h2>Maintenance</h2>
<ul>
<li>chore(deps): update dependency typescript to 6.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1587 ">#1587</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update vitest to 4.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1585 ">#1585</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>ci(deps): update peter-evans/create-pull-request action to v8 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1588 ">#1588</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency vite to 8.0.5 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1579 ">#1579</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency nock to 14.0.12 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1583 ">#1583</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@types/node</code> to 24.12.2
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1582 ">#1582</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@biomejs/biome</code> to
2.4.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1581 ">#1581</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore: move codegen to monthly scheduled workflow (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1578 ">#1578</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
<li>chore: replace vite-tsconfig-paths plugin with native
resolve.tsconfigPaths (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1571 ">#1571</a>)
<a href="https://github.com/jetersen "><code>@jetersen</code></a></li>
</ul>
<h2>Documentation</h2>
<ul>
<li>docs: fix autolabeler example tag (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1568 ">#1568</a>)
<a href="https://github.com/cchanche "><code>@cchanche</code></a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>build(deps): bump lodash and
<code>@graphql-codegen/plugin-helpers</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1589 ">#1589</a>)
@<a href="https://github.com/apps/dependabot ">dependabot[bot]</a></li>
<li>fix(deps): update dependency <code>@actions/github</code> to 9.1.0
(<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1586 ">#1586</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency yaml to 2.8.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1580 ">#1580</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update node.js to v24.14.1 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1584 ">#1584</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
<li>chore(deps): update dependency <code>@biomejs/biome</code> to
2.4.10 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1581 ">#1581</a>)
@<a href="https://github.com/apps/renovate ">renovate[bot]</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.1.1...v7.2.0 ">https://github.com/release-drafter/release-drafter/compare/v7.1.1...v7.2.0 </a></p>
<h2>v7.1.1</h2>
<h1>What's Changed</h1>
<h2>Bug Fixes</h2>
<ul>
<li>fix: remove disable-releaser and disable-autolabeler from
action.yaml (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1564 ">#1564</a>)
<a href="https://github.com/cchanche "><code>@cchanche</code></a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/release-drafter/release-drafter/compare/v7.1.0...v7.1.1 ">https://github.com/release-drafter/release-drafter/compare/v7.1.0...v7.1.1 </a></p>
<h2>v7.1.0</h2>
<h1>What's Changed</h1>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/5de93583980a40bd78603b6dfdcda5b4df377b32 "><code>5de9358</code></a>
7.2.0</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e50d61c7deb94fc176ad7d31d7b71f60307829b2 "><code>e50d61c</code></a>
chore: rebuild dist</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/d3a61d3b778db0d18c3511a1d8a5585188fdb99f "><code>d3a61d3</code></a>
chore: fix npm audit vulnerabilities</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/8bfa2791ec73890e3087b933c9db62d0a294a461 "><code>8bfa279</code></a>
build(deps): bump lodash and
<code>@graphql-codegen/plugin-helpers</code> (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1589 ">#1589</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/c2a8a67ac931b548feeee49fe78975bd87720a0e "><code>c2a8a67</code></a>
chore: remove engine-strict from .npmrc to fix Dependabot
resolution</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/e51e4adf1695870d57ae9cf3fa8cc37064d6304d "><code>e51e4ad</code></a>
chore(deps): update dependency typescript to 6.0.2 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1587 ">#1587</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/0e7bd548468b9ce7f0b082417f6ec32bc47173ae "><code>0e7bd54</code></a>
fix(deps): update dependency <code>@actions/github</code> to 9.1.0 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1586 ">#1586</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/9c0b0a8cf19d3415f835a04b1987cd2451aaac85 "><code>9c0b0a8</code></a>
chore(deps): update dependency yaml to 2.8.3 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1580 ">#1580</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/b27f820cbc98c923f216e773d35bc7f4e8efd9ed "><code>b27f820</code></a>
chore(deps): update vitest to 4.1.4 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1585 ">#1585</a>)</li>
<li><a
href="https://github.com/release-drafter/release-drafter/commit/eb9053430f473e03512e92caee9608b0db01ebd7 "><code>eb90534</code></a>
ci(deps): update peter-evans/create-pull-request action to v8 (<a
href="https://redirect.github.com/release-drafter/release-drafter/issues/1588 ">#1588</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/release-drafter/release-drafter/compare/6db134d15f3909ccc9eefd369f02bd1e9cffdf97...5de93583980a40bd78603b6dfdcda5b4df377b32 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-11 11:41:10 +02:00
github-actions[bot] and eifinger
2186c6ecae
chore: update known checksums for 0.15.10 ( #351 )
...
chore: update known checksums for 0.15.10
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-04-10 11:34:56 +00:00
Zanie Blue
26892dbe43
Add a release workflow ( #349 )
...
Mirroring https://github.com/astral-sh/setup-uv/pull/839
2026-04-09 14:10:29 +02:00
github-actions[bot] and eifinger
d7f6ad639a
chore: update known checksums for 0.15.9 ( #348 )
...
chore: update known checksums for 0.15.9
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-04-03 07:00:21 +00:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
5b5935861b
Bump eifinger/actionlint-action from 1.10.0 to 1.10.2 ( #347 )
...
Bumps
[eifinger/actionlint-action](https://github.com/eifinger/actionlint-action )
from 1.10.0 to 1.10.2.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/1fc89649be682d16ec5cf65ea16e269eb88d3982 "><code>1fc8964</code></a>
build(deps): bump actions/checkout from 6.0.1 to 6.0.2 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/34 ">#34</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/77c97feb783dfe1768d10f9dda219af0936f44a7 "><code>77c97fe</code></a>
build(deps): bump release-drafter/release-drafter from 6.2.0 to 7.1.1
(<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/40 ">#40</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/bc5a34046e0b08d672f8a517047621ce16320c2b "><code>bc5a340</code></a>
chore: bump actionlint to 1.7.12 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/41 ">#41</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/7802e0cc3ab3f81cbffb36fb0bf1a3621d994b89 "><code>7802e0c</code></a>
Remove oracle-aarch64 from workflows (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/36 ">#36</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/8d9ad94ef799fdd386147ebbed32e940280f3dcd "><code>8d9ad94</code></a>
set default actionlint version to 1.7.11 (<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/35 ">#35</a>)</li>
<li><a
href="https://github.com/eifinger/actionlint-action/commit/4863b27ac4c7ab9e9c69405b36b49b7b4d97ead9 "><code>4863b27</code></a>
build(deps): bump release-drafter/release-drafter from 6.1.0 to 6.2.0
(<a
href="https://redirect.github.com/eifinger/actionlint-action/issues/33 ">#33</a>)</li>
<li>See full diff in <a
href="https://github.com/eifinger/actionlint-action/compare/447fbfe7533062b7a9ea55f790f2396fba6d052a...1fc89649be682d16ec5cf65ea16e269eb88d3982 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-31 07:39:51 +02:00
Kevin Stillhammer
0be154b683
Migrate to ESMBundler and node 24 ( #345 )
2026-03-28 15:52:59 +00:00
github-actions[bot] and eifinger
f611dfc122
chore: update known checksums for 0.15.8 ( #344 )
...
chore: update known checksums for 0.15.8
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-03-27 06:13:56 +00:00
github-actions[bot] and eifinger
d40baf4d10
chore: update known checksums for 0.15.7 ( #342 )
...
chore: update known checksums for 0.15.7
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-03-20 06:47:13 +00:00
github-actions[bot] and eifinger
18ddc929c7
chore: update known checksums for 0.15.6 ( #337 )
...
chore: update known checksums for 0.15.6
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-03-13 07:28:50 +01:00
dependabot[bot] and dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
25445a5bce
Bump zizmorcore/zizmor-action from 0.4.1 to 0.5.2 ( #333 )
...
Bumps
[zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action )
from 0.4.1 to 0.5.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/zizmorcore/zizmor-action/releases ">zizmorcore/zizmor-action's
releases</a>.</em></p>
<blockquote>
<h2>v0.5.2</h2>
<h2>What's Changed</h2>
<ul>
<li>zizmor 1.23.1 is now the default used by this action.</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.1...v0.5.2 ">https://github.com/zizmorcore/zizmor-action/compare/v0.5.1...v0.5.2 </a></p>
<h2>v0.5.1</h2>
<h2>What's Changed</h2>
<ul>
<li>zizmor 1.23.0 is now the default used by this action.</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.0...v0.5.1 ">https://github.com/zizmorcore/zizmor-action/compare/v0.5.0...v0.5.1 </a></p>
<h2>v0.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Expose <code>output-file</code> as an output when
<code>advanced-security: true</code> by <a
href="https://github.com/unlobito "><code>@unlobito</code></a> in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/87 ">zizmorcore/zizmor-action#87</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/unlobito "><code>@unlobito</code></a>
made their first contribution in <a
href="https://redirect.github.com/zizmorcore/zizmor-action/pull/87 ">zizmorcore/zizmor-action#87</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/zizmorcore/zizmor-action/compare/v0.4.1...v0.5.0 ">https://github.com/zizmorcore/zizmor-action/compare/v0.4.1...v0.5.0 </a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 "><code>71321a2</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/96 ">#96</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/5ed31db0964a9d37608edd5b0675de2b52070662 "><code>5ed31db</code></a>
Bump pins (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/95 ">#95</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/195d10ad90f31d8cd6ea1efd6ecc12969ddbe73f "><code>195d10a</code></a>
Sync zizmor versions (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/94 ">#94</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/c65bc8876171b6d82748ec98b77c0193b1226b94 "><code>c65bc88</code></a>
chore(deps): bump github/codeql-action in the github-actions group (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/93 ">#93</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/c2c887f84674f9c15123e2905d2d307675d8bc01 "><code>c2c887f</code></a>
chore(deps): bump zizmorcore/zizmor-action in the github-actions group
(<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/91 ">#91</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/5507ab0c02a9ac3996895e1598d6b3385ea7d525 "><code>5507ab0</code></a>
Bump pins in README (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/90 ">#90</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/0dce2577a4760a2749d8cfb7a84b7d5585ebcb7d "><code>0dce257</code></a>
chore(deps): bump peter-evans/create-pull-request (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/88 ">#88</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/fb9497493b591ad90176d3ecac5ca4aeff8c9faf "><code>fb94974</code></a>
Expose <code>output-file</code> as an output when
<code>advanced-security: true</code> (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/87 ">#87</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/867562a69bb7adcc63dd1e8c003600a58b5f70e2 "><code>867562a</code></a>
chore(deps): bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/85 ">#85</a>)</li>
<li><a
href="https://github.com/zizmorcore/zizmor-action/commit/7462f075f718787753331c6d98ca9ef8eb41e735 "><code>7462f07</code></a>
Bump pins in README (<a
href="https://redirect.github.com/zizmorcore/zizmor-action/issues/84 ">#84</a>)</li>
<li>See full diff in <a
href="https://github.com/zizmorcore/zizmor-action/compare/135698455da5c3b3e55f73f4419e481ab68cdd95...71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-03-09 08:05:39 +01:00
github-actions[bot] and eifinger
cb58d827d0
chore: update known checksums for 0.15.5 ( #331 )
...
chore: update known checksums for 0.15.5
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-03-06 08:28:19 +01:00
github-actions[bot] and eifinger
845ce6a88f
chore: update known checksums for 0.15.4 ( #328 )
...
chore: update known checksums for 0.15.4
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-02-27 08:11:36 +01:00
github-actions[bot] and eifinger
48f37fab2d
chore: update known checksums for 0.15.2 ( #325 )
...
chore: update known checksums for 0.15.2
Co-authored-by: eifinger <1481961+eifinger@users.noreply.github.com >
2026-02-20 06:59:59 +00:00