Skip to content

chore(deps): bump zondax/_workflows/.github/workflows/_publish-npm.yaml from 7 to 11#307

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/zondax/_workflows/dot-github/workflows/_publish-npm.yaml-11
Open

chore(deps): bump zondax/_workflows/.github/workflows/_publish-npm.yaml from 7 to 11#307
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/master/zondax/_workflows/dot-github/workflows/_publish-npm.yaml-11

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps zondax/_workflows/.github/workflows/_publish-npm.yaml from 7 to 11.

Release notes

Sourced from zondax/_workflows/.github/workflows/_publish-npm.yaml's releases.

v11

npm publish docs & diagnostics (no functional change to publishing).

  • Fix the OIDC debug step: it read ${{ env.ACTIONS_ID_TOKEN_REQUEST_URL }}, which the env context can't see (always printed set: false); now reads the shell var, and prints job_workflow_ref.
  • Document npm Trusted Publishing setup for reusable callers (configure your repo + your caller workflow filename), the documented reusable-workflow caveat, and recommend a self-contained publish workflow as the reliable fallback.

Reusable publish behavior is unchanged from v10. Consumers on @v10 can bump to @v11 for the corrected docs/diagnostic.

v9.0.0

What's Changed

Full Changelog: Zondax/_workflows@v.3.9.4...v9

Commits
  • 313c930 fix(_pulumi-wif): pin mise to known-good version (default 2026.5.18) (#107)
  • 16e9fff Merge pull request #106 from Zondax/fix/cache-clobber-clippy-rust-tests
  • 2bf2d28 fix(ledger): also re-checkout cargo config in clippy/rust_tests jobs
  • c90c53d Merge pull request #105 from Zondax/fix/cargo-config-cache-clobber
  • b9411b1 fix(ledger): re-checkout app/rust/.cargo/config.toml after Rust cache restore
  • 9e5715e docs(npm): correct trusted-publishing guidance (it works via the reusable wor...
  • 05578b6 fix(npm): correct OIDC diagnostic + document trusted-publishing limitation (#...
  • 2e076e5 feat(_release-rust): opt-in bare Windows .exe release asset (#102)
  • be3717a feat(_release-rust): opt-in Debian .deb build (#101)
  • 0febc57 feat(_release-rust): opt-in GCP-KMS code signing (#97)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [zondax/_workflows/.github/workflows/_publish-npm.yaml](https://github.com/zondax/_workflows) from 7 to 11.
- [Release notes](https://github.com/zondax/_workflows/releases)
- [Commits](Zondax/_workflows@v7...v11)

---
updated-dependencies:
- dependency-name: zondax/_workflows/.github/workflows/_publish-npm.yaml
  dependency-version: '11'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants