Update github-actions (major)#691
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
792e679 to
2a2bfed
Compare
2a2bfed to
0e2bb2f
Compare
0e2bb2f to
a579dd2
Compare
a579dd2 to
2918998
Compare
2918998 to
41e62ba
Compare
ea7aa6e to
4fb0839
Compare
73c6999 to
c54d897
Compare
c54d897 to
ea45a95
Compare
| php-version: "8.5" | ||
|
|
||
| - uses: "ramsey/composer-install@3cf229dc2919194e9e36783941438d17239e8520" # v3 | ||
| - uses: "ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda" # 4.0.0 |
| - name: 'Get Previous tag' | ||
| id: previoustag | ||
| uses: "WyriHaximus/github-action-get-previous-tag@04e8485ecb6487243907e330d522ff60f02283ce" # v1.4.0 | ||
| uses: "WyriHaximus/github-action-get-previous-tag@61819f33034117e6c686e6a31dba995a85afc9de" # v2.0.0 |
|
|
||
| - name: Install the latest version of uv | ||
| uses: astral-sh/setup-uv@eac588ad8def6316056a12d4907a9d4d84ff7a3b # v7.3.0 | ||
| uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0 |
| egress-policy: audit | ||
|
|
||
| - uses: dessant/lock-threads@1bf7ec25051fe7c00bdd17e6a7cf3d7bfb7dc771 # v5.0.1 | ||
| - uses: dessant/lock-threads@7266a7ce5c1df01b1c6db85bf8cd86c737dadbe7 # v6.0.0 |
| egress-policy: audit | ||
|
|
||
| - uses: peter-evans/repository-dispatch@ff45666b9427631e3450c54a1bcbee4d9ff4d7c0 # v3.0.0 | ||
| - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1 |
ea45a95 to
e332203
Compare
e332203 to
91ae51b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.4.0→v2.0.0v4.3.0→v5.0.5v5.0.1→v6.0.2v4.3.1→v6.0.2v7.6.0→v8.1.0v0.15.2→v1.1.4v5.0.1→v6.0.1v3.0.0→v4.0.1v3→4.0.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
WyriHaximus/github-action-get-previous-tag (WyriHaximus/github-action-get-previous-tag)
v2.0.0Compare Source
Migration
Migrating from
prefixtopatterngoing from this:To:
Note the astrix (
*) at the end. That was always added by default in the previous version. And is the default forpattern. But if you specify your own pattern and it used be a prefix, you MUST add the astrix (*) at the end. It's not suffixed by default anymore because we want to give you full controll over the pattern (afterrefs/tags/) so you can do things like semver (v*[0-9].*[0-9].*[0-9]) with it without us meddling with it.v2.0.0
Bug 🐞
Dependencies 📦
Feature 🏗
Enhancement ✨
prefixintopatternthanks to @WyriHaximusv2.0Compare Source
v2Compare Source
actions/cache (actions/cache)
v5.0.5Compare Source
What's Changed
Full Changelog: actions/cache@v5...v5.0.5
v5.0.4Compare Source
v5.0.3Compare Source
What's Changed
@actions/cacheto v5.0.5 (Resolves: https://github.com/actions/cache/security/dependabot/33)@actions/coreto v2.0.3Full Changelog: actions/cache@v5...v5.0.3
v5.0.2Compare Source
v5.0.1Compare Source
v5.0.0Compare Source
v5Compare Source
actions/checkout (actions/checkout)
v6.0.2Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
v6Compare Source
astral-sh/setup-uv (astral-sh/setup-uv)
v8.1.0: 🌈 New inputno-projectCompare Source
Changes
This add the a new boolean input
no-project.It only makes sense to use in combination with
activate-environment: trueand will append--no projectto theuv venvcall. This is for example useful if you have a pyproject.toml file with parts unparseable by uv🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
v8.0.0: 🌈 Immutable releases and secure tagsCompare Source
This is the first immutable release of
setup-uv🥳All future releases are also immutable, if you want to know more about what this means checkout the docs.
This release also has two breaking changes
New format for
manifest-fileThe previously deprecated way of defining a custom version manifest to control which
uvversions are available and where to download them from got removed. The functionality is still there but you have to use the new format.No more major and minor tags
To increase security even more we will stop publishing minor tags. You won't be able to use
@v8or@v8.0any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to tj-actions.🚨 Breaking changes
🧰 Maintenance
boostsecurityio/poutine-action (boostsecurityio/poutine-action)
v1.1.4Compare Source
v1.1.3Compare Source
What's Changed
Updated to align with poutine's
v1.1.3(https://github.com/boostsecurityio/poutine/releases/tag/v1.1.3)dessant/lock-threads (dessant/lock-threads)
v6.0.1Compare Source
Learn more about this release from the changelog.
v6.0.0Compare Source
Learn more about this release from the changelog.
v6Compare Source
peter-evans/repository-dispatch (peter-evans/repository-dispatch)
v4.0.1Compare Source
What's Changed
Full Changelog: peter-evans/repository-dispatch@v4.0.0...v4.0.1
v4.0.0: Repository Dispatch v4.0.0Compare Source
⚙️ Requires Actions Runner v2.327.1 or later if you are using a self-hosted runner for Node 24 support.
What's Changed
New Contributors
Full Changelog: peter-evans/repository-dispatch@v3.0.0...v4.0.0
v4Compare Source
ramsey/composer-install (ramsey/composer-install)
v4.0.0Compare Source
What's Changed
chore: Bump actions/cache from 4.2.4 to 5.0.3 by @dependabot[bot] in #278
This necessitates a new major version because actions/cache v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1. This is a breaking change for anyone using self-hosted runners.
Full Changelog: ramsey/composer-install@3.2.1...4.0.0
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.