chore(deps): bump the minor group across 1 directory with 11 updates#1378
Merged
chore(deps): bump the minor group across 1 directory with 11 updates#1378
Conversation
Bumps the minor group with 11 updates in the / directory: | Package | From | To | | --- | --- | --- | | [PyO3/maturin-action](https://github.com/pyo3/maturin-action) | `1.49.4` | `1.50.0` | | [mislav/bump-homebrew-formula-action](https://github.com/mislav/bump-homebrew-formula-action) | `3.4` | `3.6` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.4.3` | `5.5.2` | | [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action) | `2.4.1` | `2.7.0` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.7.1` | `4.8.3` | | [docker/metadata-action](https://github.com/docker/metadata-action) | `5.7.0` | `5.10.0` | | [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) | `3.6.0` | `3.7.0` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.11.1` | `3.12.0` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.7.0` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.18.0` | `6.19.2` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.20.2` | `0.22.2` | Updates `PyO3/maturin-action` from 1.49.4 to 1.50.0 - [Release notes](https://github.com/pyo3/maturin-action/releases) - [Commits](PyO3/maturin-action@86b9d13...b1bd829) Updates `mislav/bump-homebrew-formula-action` from 3.4 to 3.6 - [Release notes](https://github.com/mislav/bump-homebrew-formula-action/releases) - [Commits](mislav/bump-homebrew-formula-action@8e2baa4...56a283f) Updates `codecov/codecov-action` from 5.4.3 to 5.5.2 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@18283e0...671740a) Updates `lycheeverse/lychee-action` from 2.4.1 to 2.7.0 - [Release notes](https://github.com/lycheeverse/lychee-action/releases) - [Commits](lycheeverse/lychee-action@82202e5...a8c4c7c) Updates `actions/dependency-review-action` from 4.7.1 to 4.8.3 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@da24556...05fe457) Updates `docker/metadata-action` from 5.7.0 to 5.10.0 - [Release notes](https://github.com/docker/metadata-action/releases) - [Commits](docker/metadata-action@902fa8e...c299e40) Updates `docker/setup-qemu-action` from 3.6.0 to 3.7.0 - [Release notes](https://github.com/docker/setup-qemu-action/releases) - [Commits](docker/setup-qemu-action@2910929...c7c5346) Updates `docker/setup-buildx-action` from 3.11.1 to 3.12.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@e468171...8d2750c) Updates `docker/login-action` from 3.4.0 to 3.7.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@74a5d14...c94ce9f) Updates `docker/build-push-action` from 6.18.0 to 6.19.2 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@2634353...10e90e3) Updates `anchore/sbom-action` from 0.20.2 to 0.22.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@cee1b8e...28d7154) --- updated-dependencies: - dependency-name: PyO3/maturin-action dependency-version: 1.50.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: mislav/bump-homebrew-formula-action dependency-version: '3.6' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: codecov/codecov-action dependency-version: 5.5.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: lycheeverse/lychee-action dependency-version: 2.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: actions/dependency-review-action dependency-version: 4.8.3 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: docker/metadata-action dependency-version: 5.10.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: docker/setup-qemu-action dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: docker/setup-buildx-action dependency-version: 3.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: docker/login-action dependency-version: 3.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: docker/build-push-action dependency-version: 6.19.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor - dependency-name: anchore/sbom-action dependency-version: 0.22.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor ... Signed-off-by: dependabot[bot] <support@github.com>
ognis1205
approved these changes
Feb 27, 2026
Contributor
ognis1205
left a comment
There was a problem hiding this comment.
CI is all green. Skimmed the release notes and nothing concerning.
LGTM
Owner
|
This broke the release workflow: https://github.com/orhun/git-cliff/actions/runs/24953294501/job/73067180121 The new maturin used by this is doing stricter sdist packaging/validation aligned with Cargo package contents. |
Owner
|
Regression is caused by: PyO3/maturin#3014 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the minor group with 11 updates in the / directory:
1.49.41.50.03.43.65.4.35.5.22.4.12.7.04.7.14.8.35.7.05.10.03.6.03.7.03.11.13.12.03.4.03.7.06.18.06.19.20.20.20.22.2Updates
PyO3/maturin-actionfrom 1.49.4 to 1.50.0Release notes
Sourced from PyO3/maturin-action's releases.
Commits
b1bd829Update dependencies to latest versions with ESM and Node 24 (#409)e8dfe2dBump peter-evans/create-pull-request from 8.0.0 to 8.1.0 (#407)a7a0737Bump actions/setup-python from 6.1.0 to 6.2.0 (#406)0177072Bump actions/setup-node from 6.1.0 to 6.2.0 (#405)0584c36Bump zizmorcore/zizmor-action from 0.3.0 to 0.4.1 (#404)06e22d5Bump actions/checkout from 6.0.1 to 6.0.2 (#403)f8fa3c6Allow build loongarch64 and riscv64 for musllinux (#408)1511a23Document how to harden release pipelines (#400)47fbb7aAdd alias for riscv on manylinux (#399)9fc14beUpdate versions-manifest.json (#398)Updates
mislav/bump-homebrew-formula-actionfrom 3.4 to 3.6Release notes
Sourced from mislav/bump-homebrew-formula-action's releases.
Commits
56a283fMerge branch 'main' into v398374deMerge remote-tracking branch 'origin/main'00e28eblib675180dMerge branch 'main' into v38949e92Remove summary heading elementc19295cMerge pull request #276 from mislav/dependabot/npm_and_yarn/eslint-a4a0c64de15641e4ebuild(deps-dev): bump the eslint group with 3 updates7e65662Merge pull request #272 from mislav/dependabot/npm_and_yarn/types/node-24.3.05c66f13build(deps-dev): bump@types/nodefrom 24.1.0 to 24.3.09c70962Merge pull request #275 from mislav/dependabot/npm_and_yarn/eslint-6126e969a6Updates
codecov/codecov-actionfrom 5.4.3 to 5.5.2Release notes
Sourced from codecov/codecov-action's releases.
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
671740achore(release): 5.5.2 (#1902)96b38e9chore:disable_searchalignment (#1881)9b6d1f8check gpg only when skip-validation = false (#1894)5a10915chore(release): 5.5.1 (#1873)3e0ce21fix: overwrite pr number on fork (#1871)c4741c8build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)17370e8build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)18fdacffix: update to use local app/ dir (#1872)206148cdocs: fix typo in README (#1866)3cb13a1Document acodecov-cliversion reference example (#1774)Updates
lycheeverse/lychee-actionfrom 2.4.1 to 2.7.0Release notes
Sourced from lycheeverse/lychee-action's releases.
Commits
a8c4c7c[create-pull-request] automated change (#312)44b353bUpgrade checkout action from v4 to v5 (#310)e79a91bBump peter-evans/create-issue-from-file from 5 to 6 (#307)885c65f[create-pull-request] automated change (#306)01a5c94Update lycheeVersion to v0.20.0 (#304)1478291Bump actions/checkout from 4 to 5 (#303)0c3ab05Remove deprecrated flag--exclude-mail5c4ee84[create-pull-request] automated change (#300)74c50ae[create-pull-request] automated change (#296)Updates
actions/dependency-review-actionfrom 4.7.1 to 4.8.3Release notes
Sourced from actions/dependency-review-action's releases.
... (truncated)
Commits
05fe457Merge pull request #1054 from actions/ahpook/release-4.8.33a8496cUpdate generated package files for v4.8.30f22a01Update CONTRIBUTING for new release process58be343Updating package versions for 4.8.39284e0cMerge pull request #931 from actions/dependabot/npm_and_yarn/spdx-licenses-20...8b76656Bump spdx-expression-parse in the spdx-licenses group across 1 directory43f5f02Merge pull request #1052 from actions/juxtin/fix-long-summariesf0033fcMerge pull request #1053 from actions/dependabot/npm_and_yarn/fast-xml-parser...b379e2eBump fast-xml-parser from 5.3.5 to 5.3.62e1cf54Properly truncate long summaries and catch errorsUpdates
docker/metadata-actionfrom 5.7.0 to 5.10.0Release notes
Sourced from docker/metadata-action's releases.
Commits
c299e40Merge pull request #569 from docker/dependabot/npm_and_yarn/docker/actions-to...f015d79chore: update generated content121bcc2chore(deps): Bump@docker/actions-toolkitfrom 0.67.0 to 0.68.0f7b6bf4Merge pull request #564 from docker/dependabot/npm_and_yarn/js-yaml-3.14.20b95c6bMerge pull request #565 from docker/dependabot/github_actions/actions/checkout-617f70d7Merge pull request #568 from motoki317/docs/fix-to-24h-schedule-patternafd7e6ddocs(README): Fix date format from 12h to 24h in schedule pattern602aff8chore(deps): Bump actions/checkout from 5 to 6aecb1a4chore(deps): Bump js-yaml from 3.14.1 to 3.14.28d8c7c1Merge pull request #559 from docker/dependabot/npm_and_yarn/docker/actions-to...Updates
docker/setup-qemu-actionfrom 3.6.0 to 3.7.0Release notes
Sourced from docker/setup-qemu-action's releases.
Commits
c7c5346Merge pull request #230 from docker/dependabot/npm_and_yarn/docker/actions-to...3a517a1chore: update generated contenta5b45edbuild(deps): bump@docker/actions-toolkitfrom 0.62.1 to 0.67.03a64278Merge pull request #220 from docker/dependabot/npm_and_yarn/brace-expansion-1...94906bachore: update generated content4027abfbuild(deps): bump brace-expansion from 1.1.11 to 1.1.12bee0aaaMerge pull request #221 from docker/dependabot/npm_and_yarn/tmp-0.2.40d7e257chore: update generated contentb869601build(deps): bump tmp from 0.2.3 to 0.2.43a043edMerge pull request #219 from docker/dependabot/npm_and_yarn/undici-5.29.0Updates
docker/setup-buildx-actionfrom 3.11.1 to 3.12.0Release notes
Sourced from docker/setup-buildx-action's releases.
Commits
8d2750cMerge pull request #455 from crazy-max/install-deprecatede81846bdeprecate install input65d18f8Merge pull request #454 from docker/dependabot/github_actions/actions/checkout-6000d75dbuild(deps): bump actions/checkout from 5 to 61583c0fMerge pull request #443 from nicolasleger/patch-1ed158e7doc: bump actions/checkout from 4 to 54cc794fMerge pull request #441 from docker/dependabot/github_actions/actions/checkout-54dfc3d6build(deps): bump actions/checkout from 4 to 5af1b253Merge pull request #440 from crazy-max/k3s-build3c6ab92ci: k3s test with latest buildxUpdates
docker/login-actionfrom 3.4.0 to 3.7.0Release notes
Sourced from docker/login-action's releases.