Repository navigation
ci: bump the actions group across 1 directory with 6 updates - #2
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
There was a problem hiding this comment.
Sorry @dependabot[bot], you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
|
@dependabot rebase |
074691c to
98f3d76
Compare
|
Warning Review limit reached
Next review available in: 58 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughChangesGitHub Actions workflow updates
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 8✅ Passed checks (8 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/auto-merge-dependabot.yml:
- Line 18: Pin every referenced GitHub Action to an immutable commit SHA instead
of a mutable tag: update dependabot/fetch-metadata in
.github/workflows/auto-merge-dependabot.yml (18-18); checkout, pnpm setup, and
setup-node in .github/workflows/ci.yml (12-18); checkout and all CodeQL actions
in .github/workflows/ci.yml (45-56); checkout and setup-node in
.github/workflows/playwright.yml (12-13); and upload-artifact in
.github/workflows/playwright.yml (22-22), preserving the intended action
versions.
In @.github/workflows/ci.yml:
- Line 12: Disable checkout credential persistence by adding
persist-credentials: false to the checkout steps at .github/workflows/ci.yml
lines 12-12 and 45-45, and .github/workflows/playwright.yml lines 12-12.
- Around line 12-18: Update the workflow steps using actions/checkout,
pnpm/action-setup, actions/setup-node, and every CodeQL action to reference
verified immutable 40-character commit SHAs instead of version tags. Preserve
each action’s current version and configuration while pinning all upgraded
actions consistently.
In @.github/workflows/playwright.yml:
- Around line 12-13: Update the workflow’s actions/checkout, actions/setup-node,
and actions/upload-artifact references to verified immutable 40-character commit
SHAs, replacing their mutable major-version tags while preserving the existing
action configuration.
🪄 Autofix (Beta)
❌ Autofix failed (check again to retry)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 1cd57285-fb63-48f5-bf44-035bccb62248
📒 Files selected for processing (3)
.github/workflows/auto-merge-dependabot.yml.github/workflows/ci.yml.github/workflows/playwright.yml
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: test
🧰 Additional context used
🪛 zizmor (1.26.1)
.github/workflows/auto-merge-dependabot.yml
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/playwright.yml
[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/ci.yml
[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 14-14: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 45-45: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 45-45: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 48-48: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 53-53: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 56-56: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🔍 Remote MCP GitHub Copilot
Relevant review context:
-
The bumped action majors all exist upstream:
actions/checkout@v7(latest releasev7.0.1, published 2026-07-20),actions/setup-node@v7(v7.0.0, published 2026-07-14),actions/upload-artifact@v7(v7.0.1, published 2026-04-10), anddependabot/fetch-metadata@v3(v3.1.0, published 2026-04-20). -
github/codeql-actionhas av4tag, with tagger date 2026-07-22, so the CodeQL step bump to@v4points at an existing major tag.
| - name: Fetch Dependabot metadata | ||
| id: metadata | ||
| uses: dependabot/fetch-metadata@v2 | ||
| uses: dependabot/fetch-metadata@v3 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win
Security Misconfiguration (CWE-494): Download of Code Without Integrity Check
Reachability: External
Pin every upgraded action to an immutable commit SHA. Mutable tags allow action code to change without a workflow diff; this is especially dangerous in .github/workflows/auto-merge-dependabot.yml, which runs under write permissions.
.github/workflows/auto-merge-dependabot.yml#L18-L18: pindependabot/fetch-metadata..github/workflows/ci.yml#L12-L18: pin checkout, pnpm setup, and setup-node..github/workflows/ci.yml#L45-L56: pin checkout and all CodeQL actions..github/workflows/playwright.yml#L12-L13: pin checkout and setup-node..github/workflows/playwright.yml#L22-L22: pin upload-artifact.
🧰 Tools
🪛 zizmor (1.26.1)
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
📍 Affects 3 files
.github/workflows/auto-merge-dependabot.yml#L18-L18(this comment).github/workflows/ci.yml#L12-L18.github/workflows/ci.yml#L45-L56.github/workflows/playwright.yml#L12-L13.github/workflows/playwright.yml#L22-L22
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/auto-merge-dependabot.yml at line 18, Pin every referenced
GitHub Action to an immutable commit SHA instead of a mutable tag: update
dependabot/fetch-metadata in .github/workflows/auto-merge-dependabot.yml
(18-18); checkout, pnpm setup, and setup-node in .github/workflows/ci.yml
(12-18); checkout and all CodeQL actions in .github/workflows/ci.yml (45-56);
checkout and setup-node in .github/workflows/playwright.yml (12-13); and
upload-artifact in .github/workflows/playwright.yml (22-22), preserving the
intended action versions.
Source: Linters/SAST tools
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Sensitive Data Exposure (CWE-522): Insufficiently Protected Credentials
Reachability: External
Disable checkout credential persistence in both workflows.
.github/workflows/ci.yml#L12-L12: addpersist-credentials: false..github/workflows/ci.yml#L45-L45: addpersist-credentials: false..github/workflows/playwright.yml#L12-L12: addpersist-credentials: false.
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
📍 Affects 2 files
.github/workflows/ci.yml#L12-L12(this comment).github/workflows/ci.yml#L45-L45.github/workflows/playwright.yml#L12-L12
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml at line 12, Disable checkout credential persistence
by adding persist-credentials: false to the checkout steps at
.github/workflows/ci.yml lines 12-12 and 45-45, and
.github/workflows/playwright.yml lines 12-12.
Source: Linters/SAST tools
| - uses: actions/checkout@v7 | ||
|
|
||
| - uses: pnpm/action-setup@v4 | ||
| - uses: pnpm/action-setup@v6 | ||
| with: | ||
| version: 10.8.0 | ||
|
|
||
| - uses: actions/setup-node@v4 | ||
| - uses: actions/setup-node@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Security Misconfiguration (CWE-494): Download of Code Without Integrity Check
Reachability: External
Pin all upgraded actions to full commit SHAs.
The v7/v6/v4 tags are mutable; pin checkout, pnpm setup, setup-node, and all CodeQL actions to verified 40-character commit SHAs to prevent third-party code substitution.
Also applies to: 45-56
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 14-14: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 18-18: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/ci.yml around lines 12 - 18, Update the workflow steps
using actions/checkout, pnpm/action-setup, actions/setup-node, and every CodeQL
action to reference verified immutable 40-character commit SHAs instead of
version tags. Preserve each action’s current version and configuration while
pinning all upgraded actions consistently.
Source: Linters/SAST tools
| - uses: actions/checkout@v7 | ||
| - uses: actions/setup-node@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Security Misconfiguration (CWE-494): Download of Code Without Integrity Check
Reachability: External
Pin all upgraded actions to full commit SHAs.
Pin checkout, setup-node, and upload-artifact to verified 40-character commit SHAs instead of mutable major-version tags.
Also applies to: 22-22
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 12-12: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 12-12: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 13-13: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/playwright.yml around lines 12 - 13, Update the workflow’s
actions/checkout, actions/setup-node, and actions/upload-artifact references to
verified immutable 40-character commit SHAs, replacing their mutable
major-version tags while preserving the existing action configuration.
Source: Linters/SAST tools
|
Note Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it. The agent generated fixes only for
Lines 15–21 steps:
- name: Fetch Dependabot metadata
id: metadata
- uses: dependabot/fetch-metadata@v3
+ uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
Lines 9–21 validate:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
- - uses: pnpm/action-setup@v6
+ - uses: pnpm/action-setup@b0f76dfb45f55f8421693e4803ac7bb65143bd34 # v6
with:
version: 10.8.0
- - uses: actions/setup-node@v7
+ - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: "20"
cache: pnpmLines 42–56 contents: read
security-events: write
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
- name: Initialize CodeQL
- uses: github/codeql-action/init@v4
+ uses: github/codeql-action/init@adfda868f108ac4222129de456ea554034a27db7 # v4
with:
languages: javascript-typescript
- name: Autobuild
- uses: github/codeql-action/autobuild@v4
+ uses: github/codeql-action/autobuild@adfda868f108ac4222129de456ea554034a27db7 # v4
- name: Perform CodeQL analysis
- uses: github/codeql-action/analyze@v4
+ uses: github/codeql-action/analyze@adfda868f108ac4222129de456ea554034a27db7 # v4
Lines 9–16 timeout-minutes: 60
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v7
- - uses: actions/setup-node@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
+ - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: lts/*
- name: Install dependenciesLines 19–25 run: pnpm exec playwright install --with-deps
- name: Run Playwright tests
run: pnpm exec playwright test
- - uses: actions/upload-artifact@v7
+ - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
if: ${{ !cancelled() }}
with:
name: playwright-report |
|
Note Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it. The agent generated fixes only for
Lines 15–21 steps:
- name: Fetch Dependabot metadata
id: metadata
- uses: dependabot/fetch-metadata@v3
+ uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3
with:
github-token: "${{ secrets.GITHUB_TOKEN }}"
Lines 9–21 validate:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
- - uses: pnpm/action-setup@v6
+ - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6
with:
version: 10.8.0
- - uses: actions/setup-node@v7
+ - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: "20"
cache: pnpmLines 42–56 contents: read
security-events: write
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
- name: Initialize CodeQL
- uses: github/codeql-action/init@v4
+ uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
with:
languages: javascript-typescript
- name: Autobuild
- uses: github/codeql-action/autobuild@v4
+ uses: github/codeql-action/autobuild@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
- name: Perform CodeQL analysis
- uses: github/codeql-action/analyze@v4
+ uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4
Lines 9–16 timeout-minutes: 60
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@v7
- - uses: actions/setup-node@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
+ with:
+ persist-credentials: false
+ - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: lts/*
- name: Install dependenciesLines 19–25 run: pnpm exec playwright install --with-deps
- name: Run Playwright tests
run: pnpm exec playwright test
- - uses: actions/upload-artifact@v7
+ - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
if: ${{ !cancelled() }}
with:
name: playwright-report |
98f3d76 to
d52d882
Compare
Bumps the actions group with 6 updates in the / directory: | Package | From | To | | --- | --- | --- | | [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) | `2` | `3` | | [actions/checkout](https://github.com/actions/checkout) | `4` | `7` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `4` | `6` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `7` | | [github/codeql-action](https://github.com/github/codeql-action) | `3` | `4` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` | Updates `dependabot/fetch-metadata` from 2 to 3 - [Release notes](https://github.com/dependabot/fetch-metadata/releases) - [Commits](dependabot/fetch-metadata@v2...v3) Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) Updates `pnpm/action-setup` from 4 to 6 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@v4...v6) Updates `actions/setup-node` from 4 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) Updates `github/codeql-action` from 3 to 4 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v3...v4) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: dependabot/fetch-metadata dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: github/codeql-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pnpm/action-setup dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
d52d882 to
4605c3f
Compare
Bumps the actions group with 6 updates in the / directory:
234746473447Updates
dependabot/fetch-metadatafrom 2 to 3Release notes
Sourced from dependabot/fetch-metadata's releases.
... (truncated)
Commits
25dd0e3v3.1.0 (#692)e073f50Merge pull request #705 from dependabot/dependabot/npm_and_yarn/hono-4.12.140670e16build(deps-dev): bump hono from 4.12.12 to 4.12.147a7fe10Merge pull request #702 from dependabot/dependabot/npm_and_yarn/dependencies-...5168191Updating dist build23882e1build(deps): bump@actions/githubin the dependencies group1072469Merge pull request #701 from dependabot/dependabot/github_actions/actions/cre...43f8a00build(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1b4d904aMerge pull request #703 from dependabot/dependabot/npm_and_yarn/globals-17.5.0c8046bbbuild(deps-dev): bump globals from 17.4.0 to 17.5.0Updates
actions/checkoutfrom 4 to 7Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
pnpm/action-setupfrom 4 to 6Release notes
Sourced from pnpm/action-setup's releases.
Commits
0ebf471fix: update pnpm to v11.7.0 (#267)0e279bbfix: update pnpm to 11.1.1 (#248)3e83581fix: drop patchPnpmEnv so standalone+self-update works on Windows (#258)551b42edocs(README): fixcache_dependency_pathtype (#257)739bfe4fix: self-update bootstrap to packageManager-pinned version (#233) (#256)f61705dchore: add CODEOWNERS7a5507bfix: restore inputs from state in post (#255)1155470fix: honor devEngines.packageManager.onFail=error (#252) (#254)91ab88efix: bin_dest output points to self-updated pnpm, not bootstrap (#249)e578e19fix: update pnpm to 11.0.4Updates
actions/setup-nodefrom 4 to 7Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)Updates
github/codeql-actionfrom 3 to 4Release notes
Sourced from github/codeql-action's releases.
... (truncated)
Changelog
Sourced from github/codeql-action's changelog.
... (truncated)
Commits
da21ad6RemoveNewRemoteFileAddressesFF and default to its behaviourcf46341Merge pull request #4007 from github/mbg/use-registry-proxy-for-repo-auth7db34aeRefactor looking up proxy env vars intogetRegistryProxyConfig.8125f87Remove unusedgetApiFetch7c4a258Merge pull request #4021 from github/mergeback/v4.37.1-to-main-7188fc360297913Rebuild1226301Update changelog and version after v4.37.17188fc3Merge pull request #4020 from github/update-v4.37.1-9e7c07009c8b5f69Update changelog for v4.37.19e7c070Merge pull request #4014 from github/mbg/explicit-remote-prefixUpdates
actions/upload-artifactfrom 4 to 7Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)