Conversation
…pdates Bumps the github-action-dependencies group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/setup-python](https://github.com/actions/setup-python) | `5.3.0` | `5.4.0` | | [crazy-max/ghaction-github-labeler](https://github.com/crazy-max/ghaction-github-labeler) | `5.1.0` | `5.2.0` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.12.2` | `1.12.4` | | [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter) | `6.0.0` | `6.1.0` | | [SonarSource/sonarcloud-github-action](https://github.com/sonarsource/sonarcloud-github-action) | `3.1.0` | `5.0.0` | Updates `actions/setup-python` from 5.3.0 to 5.4.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5.3.0...v5.4.0) Updates `crazy-max/ghaction-github-labeler` from 5.1.0 to 5.2.0 - [Release notes](https://github.com/crazy-max/ghaction-github-labeler/releases) - [Commits](crazy-max/ghaction-github-labeler@v5.1.0...v5.2.0) Updates `pypa/gh-action-pypi-publish` from 1.12.2 to 1.12.4 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@v1.12.2...v1.12.4) Updates `release-drafter/release-drafter` from 6.0.0 to 6.1.0 - [Release notes](https://github.com/release-drafter/release-drafter/releases) - [Commits](release-drafter/release-drafter@v6.0.0...v6.1.0) Updates `SonarSource/sonarcloud-github-action` from 3.1.0 to 5.0.0 - [Release notes](https://github.com/sonarsource/sonarcloud-github-action/releases) - [Commits](SonarSource/sonarcloud-github-action@v3.1.0...v5.0.0) --- updated-dependencies: - dependency-name: actions/setup-python dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-dependencies - dependency-name: crazy-max/ghaction-github-labeler dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-dependencies - dependency-name: pypa/gh-action-pypi-publish dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-action-dependencies - dependency-name: release-drafter/release-drafter dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-action-dependencies - dependency-name: SonarSource/sonarcloud-github-action dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-action-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
sjentoft
previously approved these changes
Apr 1, 2025
…ndencies-6ed02a6d08
|
sjentoft
approved these changes
Apr 1, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the github-action-dependencies group with 5 updates in the / directory:
5.3.05.4.05.1.05.2.01.12.21.12.46.0.06.1.03.1.05.0.0Updates
actions/setup-pythonfrom 5.3.0 to 5.4.0Release notes
Sourced from actions/setup-python's releases.
Commits
4237552Improve Advanced Usage examples (#645)709bfa5Bump requests from 2.24.0 to 2.32.2 in /tests/data (#1019)ceb20b2Bump@actions/http-clientfrom 2.2.1 to 2.2.3 (#1020)0dc2d2cBump actions/publish-immutable-action from 0.0.3 to 0.0.4 (#1014)feb9c6eBump urllib3 from 1.25.9 to 1.26.19 in /tests/data (#895)d0b4fc4Bump undici from 5.28.4 to 5.28.5 (#1012)e3dfaacConfigure Dependabot settings (#1008)b8cf3ebUse the new cache service: upgrade@actions/cacheto^4.0.0(#1007)1928ae6Update README.md (#1009)3fddbeeEnhance Workflows: Add Ubuntu-24, Remove Python 3.8 (#985)Updates
crazy-max/ghaction-github-labelerfrom 5.1.0 to 5.2.0Release notes
Sourced from crazy-max/ghaction-github-labeler's releases.
Commits
31674a3Merge pull request #225 from crazy-max/dependabot/npm_and_yarn/undici-5.28.50f4f1ecchore: update generated content44d83eeMerge pull request #227 from crazy-max/bake-v6758a909ci: update bake-action to v61c66a35chore(deps): bump undici from 5.28.4 to 5.28.5989e392Merge pull request #222 from crazy-max/dependabot/github_actions/codecov/code...ec65374ci: fix deprecated input for codecov-action765a634Merge pull request #223 from crazy-max/dependabot/npm_and_yarn/cross-spawn-7.0.698f4f2bMerge pull request #226 from pjpires/yaml-failsafe-schemac0910beUpdate generated contentUpdates
pypa/gh-action-pypi-publishfrom 1.12.2 to 1.12.4Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
... (truncated)
Commits
76f52bcMerge pull request #329 from webknjaz/maintenance/runtime-lockfile-24-02-202572de13b📌 Mass-upgrade transitive dependency pins1995f2eMerge pull request #327 from webknjaz/maintenance/twine-6.1-pep63929f40bd📦 Enable metadata 2.4 support in Twine10df67d📦 Enable support for PEP 639 metadatae0449d2🧪 Integrate a unifiedalls-greenGHA statuscebc64f🧪 Bump setuptools in smoke test to v75.8.0da900af🧪 Run smoke tests against Ubuntu 24 and 228cafb5c💰 Sync the funding config916e576Merge pull request #315 from webknjaz/refactoring/attestations-exist-bundleUpdates
release-drafter/release-drafterfrom 6.0.0 to 6.1.0Release notes
Sourced from release-drafter/release-drafter's releases.
Commits
b1476f6v6.1.0d7328d2Add config option for pull-request-limit (#1362)5faffa9docs: Fix Fork Link (#1412)a914231Ensure support new main branch name (#1079)d6eceacFix: Correctly mention bot accounts in release notes (#1376)41c11a2update schema generation and update schema to draft 07 (#1422)8296e40fix typo: therelease (#1407)0ad4f70Document action outputs introduced in #1300 (#1406)378bacbUpdate README.md (#1421)c139411Update only drafts with the same prerelease status (#1385)Updates
SonarSource/sonarcloud-github-actionfrom 3.1.0 to 5.0.0Release notes
Sourced from SonarSource/sonarcloud-github-action's releases.
Commits
ffc3010Add a link to the sonarqube-scan-action marketplace entry (#103)91eed76SCSCANGHA-39 Redirect to the SonarQube Scan Action v5.0.0f170077SCSCANGHA-37 Update CODEOWNERS (#100)02ef911Shorten description and remove mend docker check4afec88SCSCANGHA-28 Rebranding48d9e10SCSCANGHA-25 Replace the Docker action by a composite action forwarding to th...982992aAdd Jira integration9f9bba2Recommend to not use this action for analysis of Dart codeYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions