chore: bump softprops/action-gh-release from 3.0.2 to 3.0.3 in the actions group - #10
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the actions group with 1 update: [softprops/action-gh-release](https://github.com/softprops/action-gh-release). Updates `softprops/action-gh-release` from 3.0.2 to 3.0.3 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@3d0d988...efb3536) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
Note Reviewed by mtsu-patrol using glm-5.3 Patrol complete. Nothing to report within the inspected scope. Patrolled the single-line diff: the release workflow's softprops/action-gh-release pin moved from v3.0.2 (3d0d988) to v3.0.3 (efb3536). Verified against the upstream repo that efb3536… is exactly the annotated tag v3.0.3 (and upstream HEAD), so the pin comment is accurate. Diffed v3.0.2..v3.0.3: the only functional change is 1c214ab ("fix: safely classify GitHub API errors"), a refactor of error-status/type guards in src/github.ts with behavior identical to the old code (404 skip on asset delete, 403/422 handling in release creation, 'already_exists' overwrite detection, pre_receive tag-creation detection), plus routine npm dependency bumps (undici 6.27→6.28, esbuild 0.28.1→0.28.2, brace-expansion, postcss). Nothing in the delta affects draft-release creation, Commit: Coverage: .github/workflows/release.yml (full file, 231 lines); softprops/action-gh-release v3.0.2..v3.0.3 upstream delta (commit log, src/github.ts fix 1c214ab, dist/index.js stat) Limitations: Upstream is a living repo; v3.0.3 (efb3536) currently equals its master HEAD, but the workflow pins by SHA so this carries no moving-target risk.; Behavioral testing of the release job itself (tag push, draft creation) was not executed; only static diff analysis plus upstream verification of the pinned commit. |
Bumps the actions group with 1 update: softprops/action-gh-release.
Updates
softprops/action-gh-releasefrom 3.0.2 to 3.0.3Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
efb3536release 3.0.3 (#840)6441963chore(deps): bump the npm group with 2 updates (#839)e5ee6bcchore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)d1e6617chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)6403751chore(deps): bump the npm group with 2 updates (#835)7c7184bchore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)0f3f0d2chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)77fb938chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)5a6f517chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)a3c91c9chore(deps): bump the github-actions group with 2 updates (#825)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions