Repository navigation
chore(deps): update github-actions (major) - #113
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
4 times, most recently
from
August 6, 2026 18:06
41c60df to
49aa220
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
August 18, 2026 17:41
c27f8af to
9bd694c
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
3 times, most recently
from
September 1, 2026 18:36
b9b0e87 to
6944f59
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
7 times, most recently
from
September 11, 2026 17:03
62017e2 to
739751c
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
September 18, 2026 21:04
0fc8bc2 to
7181b95
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
3 times, most recently
from
September 25, 2026 18:51
ec00f47 to
20c334d
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
5 times, most recently
from
October 6, 2026 02:59
3278423 to
cae92d1
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
October 9, 2026 06:40
ff3b679 to
d873029
Compare
renovate
Bot
force-pushed
the
renovate/major-github-actions
branch
from
October 9, 2026 19:32
d873029 to
0ce31e2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v5→v7v6→v7v2→v3.0.510.33.4→12.10.112.11.2(+2)v2→v6v4→v6Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
v7.0.0Compare Source
v6.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v6 by @aiqiaoy in #2500https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: actions/checkout@v6.0.3...v6.1.0
v6.0.3Compare Source
v6.0.2Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
v5.1.0Compare Source
What's Changed
allow-unsafe-pr-checkoutto v5 by @aiqiaoy in #2501https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: actions/checkout@v5.0.1...v5.1.0
v5.0.1Compare Source
actions/setup-node (actions/setup-node)
v7.1.0Compare Source
What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency updates:
New Contributors
Full Changelog: actions/setup-node@v7.0.0...v7.1.0
v7.0.0Compare Source
What's Changed
Enhancements:
Bug fixes:
mirrorTokeningetManifestif it's provided by @deiga in #1548Documentation updates:
Dependency update:
New Contributors
Full Changelog: actions/setup-node@v6...v7.0.0
v6.5.0Compare Source
What's Changed
Full Changelog: actions/setup-node@v6.4.0...v6.5.0
v6.4.0Compare Source
What's Changed
Dependency updates:
New Contributors
Full Changelog: actions/setup-node@v6...v6.4.0
v6.3.0Compare Source
What's Changed
Enhancements:
devEnginesfield by @susnux in #1283Dependency updates:
Bug fixes:
New Contributors
Full Changelog: actions/setup-node@v6...v6.3.0
v6.2.0Compare Source
What's Changed
Documentation
Dependency updates:
New Contributors
Full Changelog: actions/setup-node@v6...v6.2.0
v6.1.0Compare Source
What's Changed
Enhancement:
Dependency updates:
Documentation update:
Full Changelog: actions/setup-node@v6...v6.1.0
marocchino/sticky-pull-request-comment (marocchino/sticky-pull-request-comment)
v3.0.5Compare Source
What's Changed
{{{content}}}placeholder by @marocchino with @Copilot in #1665Full Changelog: marocchino/sticky-pull-request-comment@v3.0.4...v3.0.5
v3.0.4Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v3.0.3...v3.0.4
v3.0.3Compare Source
What's Changed
number_forcethat overrides pull_request number by @rossjrw in #1652New Contributors
Full Changelog: marocchino/sticky-pull-request-comment@v3.0.2...v3.0.3
v3.0.2Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v3.0.1...v3.0.2
v3.0.1Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v3.0.0...v3.0.1
v3.0.0Compare Source
What's Changed
New Contributors
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.4...v3.0.0
v2.9.4Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.3...v2.9.4
v2.9.3Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.2...v2.9.3
v2.9.2Compare Source
What's Changed
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.1...v2.9.2
v2.9.1Compare Source
What's Changed
New Contributors
Full Changelog: marocchino/sticky-pull-request-comment@v2.9.0...v2.9.1
v2.9.0Compare Source
v2.8.0Compare Source
v2.7.0Compare Source
Update deps.
Add two output.
v2.6.2Compare Source
Reverted changes in version 2.6. As a result, the base_url has been removed.
v2.6.1Compare Source
Change base_url default to
${{ env.GITHUB_API_URL }}v2.6.0Compare Source
v2.5.0Compare Source
only_updateoption.owneroption.v2.4.0Compare Source
only_createoption.v2.3.1Compare Source
v2.3.0Compare Source
follow_symbolic_linksfor pathignore_emptyfor skip empty bodyv2.2.1: Update depsCompare Source
v2.2.0Compare Source
Add hide, hide_details, hide_and_recreate, hide_classsify options
v2.1.1Compare Source
v2.1.0: Set GitHub token by defaultCompare Source
Features
Bug fix
pnpm/pnpm (pnpm)
v12.10.1: pnpm 12.10.1Compare Source
This release fixes
pnpm installfailures after anoverrideschange and on a filtered frozen install withcatalogPrune. It also fixes several bugs in the experimentalnodeLinker.type: loaded, which now keeps its generated files innode_modules.Patch Changes
With
nodeLinker.type: loaded, pnpm now writes its generated files tonode_modules, which projects already ignore in git. The store manifest and loader arenode_modules/.pnpm/.store-manifest.jsonandnode_modules/.pnpm/.store-loader.mjs. Bin shims are innode_modules/.bin.Earlier versions wrote
.pnpm-store.jsonand.pnpm-store-loader.mjsto the project root, and a.pnpmdirectory to the root and to each workspace package. Delete them after reinstalling.With
nodeLinker.type: loaded, packages that ship their ownnode_modulesdirectory, such asnpmwith its bundled dependencies, now load from the store. Before, one such package in the install stopped every Node.js process from starting.With
nodeLinker.type: loaded, scripts can now run a Node.js runtime installed throughdevEngines.runtime. Before, every script that callednodere-ran its own shim until it failed with "Argument list too long".With
nodeLinker.type: loaded, Node.js processes start faster. In a project with 13,000 stored files, the startup overhead per process dropped from 67 ms to 18 ms.pnpm installno longer fails withERR_PNPM_NO_MATCHING_VERSIONafter a change tooverrideswhen the lockfile resolves an optional peer dependency to an npm alias of another package #16654.A frozen install with
catalogPruneno longer removes catalog entries thatpnpm-lock.yamlstill records. Before,pnpm install --frozen-lockfile --filterfailed withERR_PNPM_LOCKFILE_CONFIG_MISMATCHwhen some workspace projects were missing from disk #16638.pnpm install --fix-lockfileno longer removes thedeprecatedandhasBinfields from lockfile entries #6600.With
enableGlobalVirtualStore, an install that updatesnode_modulesnow repairs a package in the global virtual store that an interrupted install left without some of its dependency links or package files. Before, such an install kept the incomplete package if the project'snode_modulesalready recorded it #16642.pnpm installnow skips the Cargo and Python projects inside a nested directory that has its ownpnpm-workspace.yamlor.gitdirectory, such as a git worktree of the same workspace or a separate clone.The
Request tookwarning for package metadata now starts timing when pnpm sends the request. Before, it also counted the time the request waited for a free request slot, so large installs printed it for requests the registry answered quickly.Platinum Sponsors
Gold Sponsors
v12.10.0: pnpm 12.10.0Compare Source
This release adds an experimental
loadednode linker, letspnpm-lock.yamlrecord resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.Minor Changes
Added experimental
nodeLinker: { type: loaded }installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader.nodeLinker.excludedselects packages and their dependency trees to install in the global virtual store.lockfile.includeResolutionSettings: truemakespnpm-lock.yamlrecordautoDedupe,dedupeInjectedDeps,dedupePeerDependentsandlinkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that recordsautoDedupeis reused by later installs on any machine, sopnpm runafterpnpm install --frozen-lockfileno longer starts another install #16583.Patch Changes
Security
pnpm installnow prevents dependency versions with path traversal from writing files outside the global virtual store.pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with
version+integrity.Lockfile verification now checks the tarballs inside a
variationsresolution against the registry. Aname@versionlockfile entry with an emptyvariationsresolution is now rejected.pnpm audit signaturesnow verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.pnpm installandpnpm publishnow reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.