Skip to content

Bump metcalfc/changelog-generator from 4.7.0 to 5.0.1 - #182

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/metcalfc/changelog-generator-5.0.1
Open

Bump metcalfc/changelog-generator from 4.7.0 to 5.0.1#182
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/metcalfc/changelog-generator-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 28, 2026

Copy link
Copy Markdown
Contributor

Bumps metcalfc/changelog-generator from 4.7.0 to 5.0.1.

Release notes

Sourced from metcalfc/changelog-generator's releases.

Release v5.0.1

  • 031a640 - 5.0.1
  • 122a6c2 - Base the changelog on the previous release of the same line, and assert it ([#479](https://github.com/metcalfc/changelog-generator/issues/479))
  • 0bee5ad - fix: return the modified changelog as a real multiline output ([#478](https://github.com/metcalfc/changelog-generator/issues/478))

Release v5.0.0

Breaking change: commit subjects render as literal text

Every changelog line now wraps the commit subject in an inline-code span.

before:  - [f723555](https://github.com/metcalfc/changelog-generator/blob/HEAD/.../commit/f723555) - build(deps-dev): bump @vercel/ncc to 0.45.0 ([#470](https://github.com/metcalfc/changelog-generator/issues/470))
after:   - [f723555](https://github.com/metcalfc/changelog-generator/blob/HEAD/.../commit/f723555) - ` build(deps-dev): bump @vercel/ncc to 0.45.0 ([#470](https://github.com/metcalfc/changelog-generator/issues/470)) `

A commit subject is untrusted input. Anyone whose pull request you merge chooses that text, and this action pastes it directly into your release notes. Rendered as active Markdown, a subject could contribute links, images, @mentions, issue references, raw HTML, or additional changelog entries to a release it had no business editing. Rendering it as literal text closes that off.

What this costs you. Subjects render monospace, and [#123](https://github.com/metcalfc/changelog-generator/issues/123), [GH-123](https://github.com/metcalfc/changelog-generator/issues/123), bare commit SHAs, and :emoji: inside a subject no longer autolink. Because GitHub's squash merge appends ([#123](https://github.com/metcalfc/changelog-generator/issues/123)) to the subject by default, most lines in a typical repository lose that link. The generated commit link at the start of each line is unaffected. Control characters, line and paragraph separators, and bidirectional-control characters are replaced with spaces, so a subject can never span more than its own line.

No inputs or outputs changed, and the No Changes. sentinel is unchanged.

Staying on the previous format

v4.9.0 carries every security and dependency fix in this release -- including undici 7.29.0, which closes 12 advisories -- with the v4 output format untouched. Pin metcalfc/changelog-generator@v4 to stay there. The v4 tag will keep moving on the maintenance line.

What is in this release

Relative to v4.9.0, v5.0.0 adds only the escaping change. Both releases share everything else:

  • Render changelog subjects as literal text (#475) -- v5 only
  • Keep release tag names out of shell source (#473)
  • Verify release bundle before attestation (#474)
  • Bound the dependency overrides and clear the undici advisories (#476)
  • Stop bump:workflow rewriting pinned actions' provenance comments (#477)

... (truncated)

Commits
  • 031a640 5.0.1
  • 122a6c2 Base the changelog on the previous release of the same line, and assert it (#...
  • 0bee5ad fix: return the modified changelog as a real multiline output (#478)
  • c040ad6 5.0.0
  • 6a23679 fix: stop bump:workflow rewriting pinned actions' provenance comments (#477)
  • 8becfce fix(deps): bound the dependency overrides and clear the undici advisories (#476)
  • f723555 build(deps-dev): bump @​vercel/ncc from 0.44.1 to 0.45.0 (#470)
  • 88097f8 build(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#472)
  • 430ccb9 build(deps-dev): bump globals from 17.9.0 to 17.11.0 (#471)
  • d40422b build(deps): bump the codeql-action group with 3 updates (#469)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [metcalfc/changelog-generator](https://github.com/metcalfc/changelog-generator) from 4.7.0 to 5.0.1.
- [Release notes](https://github.com/metcalfc/changelog-generator/releases)
- [Changelog](https://github.com/metcalfc/changelog-generator/blob/main/release-notes.png)
- [Commits](metcalfc/changelog-generator@v4.7.0...v5.0.1)

---
updated-dependencies:
- dependency-name: metcalfc/changelog-generator
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants