{"id":11390,"name":"signpath/github-action-submit-signing-request","ecosystem":"actions","repository_url":"https://github.com/signpath/github-action-submit-signing-request","issues_count":28,"created_at":"2025-06-06T23:02:02.818Z","updated_at":"2025-06-06T23:02:02.818Z","purl":"pkg:githubactions/signpath/github-action-submit-signing-request","metadata":{"id":11771822,"name":"signpath/github-action-submit-signing-request","ecosystem":"actions","description":"Submits signing request to SignPath and downloads the signed artifact","homepage":null,"licenses":null,"normalized_licenses":[],"repository_url":"https://github.com/signpath/github-action-submit-signing-request","keywords_array":[],"namespace":"SignPath","versions_count":4,"first_release_published_at":"2024-04-11T11:53:53.000Z","latest_release_published_at":"2024-12-16T15:05:31.000Z","latest_release_number":"v1.1","last_synced_at":"2025-06-07T21:07:35.624Z","created_at":"2025-06-07T21:07:34.732Z","updated_at":"2025-06-08T20:56:46.121Z","registry_url":"https://github.com/signpath/github-action-submit-signing-request","install_command":null,"documentation_url":null,"metadata":{"name":"Submit a Signing Request","author":"SignPath GmbH","branding":{"icon":"alert-triangle","color":"orange"},"description":"Submits signing request to SignPath and downloads the signed artifact","inputs":{"connector-url":{"description":"GitHub Actions SignPath connector URL","default":"https://githubactions.connectors.signpath.io","required":true},"api-token":{"description":"SignPath REST API access token. Read more in the SignPath documentation: https://about.signpath.io/redirects/connectors/api-token","required":true},"organization-id":{"description":"SignPath organization ID","required":true},"project-slug":{"description":"SignPath project slug","required":true},"signing-policy-slug":{"description":"SignPath signing policy slug","required":true},"artifact-configuration-slug":{"description":"SignPath artifact configuration slug","required":false},"github-artifact-id":{"description":"Id of the Github Actions artifact. Use `steps.\u003cstep-id\u003e.outputs.artifact-id` from the preceding actions/upload-artifact action step.","required":true},"github-token":{"description":"GitHub access token used to read job details and download the artifact. Defaults to the [`secrets.GITHUB_TOKEN`](https://docs.github.com/en/actions/security-guides/automatic-token-authentication).","default":"${{ github.token }}","required":false},"parameters":{"description":"Multiline-string of values that map to user-defined parameters in the Artifact Configuration. Use one line per parameter with the format \u003cname\u003e: \"\u003cvalue\u003e\" where \u003cvalue\u003e needs to be a valid JSON string.","required":false},"wait-for-completion-timeout-in-seconds":{"description":"Maximum time in seconds that the action will wait for the signing request to complete","default":"600","required":false},"service-unavailable-timeout-in-seconds":{"description":"Total time in seconds that the action will wait for a single service call to succeed (across several retries)","default":"600","required":false},"download-signed-artifact-timeout-in-seconds":{"description":"HTTP timeout when downloading the signed artifact.","default":"300","required":false},"wait-for-completion":{"description":"If true, the action will wait for the signing request to complete","default":"true","required":false},"output-artifact-directory":{"description":"Path where the signed artifact will be saved. If not specified, the task will not download the signed artifact from SignPath","required":false}},"outputs":{"signing-request-id":{"description":"The ID of the newly created signing request"},"signing-request-web-url":{"description":"The URL of the signing request in SignPath"},"signpath-api-url":{"description":"The base API URL of the SignPath API"},"signed-artifact-download-url":{"description":"The URL of the signed artifact in SignPath"}},"runs":{"using":"node20","main":"index.js"},"default_branch":"main","path":null},"repo_metadata":{"id":232578323,"uuid":"784627273","full_name":"SignPath/github-action-submit-signing-request","owner":"SignPath","description":null,"archived":false,"fork":false,"pushed_at":"2025-04-29T08:36:57.000Z","size":2051,"stargazers_count":2,"open_issues_count":2,"forks_count":3,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-06-07T21:07:34.374Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/SignPath.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-04-10T08:22:31.000Z","updated_at":"2025-06-02T09:57:39.000Z","dependencies_parsed_at":"2024-04-23T15:48:28.554Z","dependency_job_id":"fb03a092-9853-4dd0-b982-ee6b14a7f770","html_url":"https://github.com/SignPath/github-action-submit-signing-request","commit_stats":null,"previous_names":["signpath/github-action-submit-signing-request"],"tags_count":5,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SignPath%2Fgithub-action-submit-signing-request","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SignPath%2Fgithub-action-submit-signing-request/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SignPath%2Fgithub-action-submit-signing-request/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SignPath%2Fgithub-action-submit-signing-request/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/SignPath","download_url":"https://codeload.github.com/SignPath/github-action-submit-signing-request/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SignPath%2Fgithub-action-submit-signing-request/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":258777198,"owners_count":22756065,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"repo_metadata_updated_at":"2025-06-08T20:56:46.121Z","dependent_packages_count":0,"downloads":null,"downloads_period":null,"dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":34.34343434343434,"dependent_packages_count":0.0,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":17.17171717171717},"purl":"pkg:githubactions/signpath/github-action-submit-signing-request","advisories":[],"docker_usage_url":"https://docker.ecosyste.ms/usage/actions/signpath/github-action-submit-signing-request","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/actions/signpath/github-action-submit-signing-request","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/actions/signpath/github-action-submit-signing-request/dependencies","status":null,"funding_links":[],"critical":null,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/signpath%2Fgithub-action-submit-signing-request/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/signpath%2Fgithub-action-submit-signing-request/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/signpath%2Fgithub-action-submit-signing-request/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages/signpath%2Fgithub-action-submit-signing-request/related_packages","maintainers":[],"registry":{"name":"github actions","url":"https://github.com/marketplace/actions/","ecosystem":"actions","default":true,"packages_count":31888,"maintainers_count":0,"namespaces_count":20080,"keywords_count":6805,"github":"actions","metadata":{"funded_packages_count":3013},"icon_url":"https://github.com/actions.png","created_at":"2023-01-03T17:16:39.185Z","updated_at":"2025-06-09T06:38:42.709Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/github%20actions/namespaces"}},"unique_repositories_count":20,"unique_repositories_count_past_30_days":2,"recent_issues":[{"uuid":"4626835411","node_id":"PR_kwDOJW3Oms7kn6_j","number":616,"state":"open","title":"ci(deps):(deps): bump signpath/github-action-submit-signing-request from 1.1 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-10T00:43:37.000Z","updated_at":"2026-06-10T00:43:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps):(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Writeopia/Writeopia/pull/616","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Writeopia%2FWriteopia/issues/616","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/616/packages"},{"uuid":"4505924541","node_id":"PR_kwDOSQOM-s7egtW2","number":1,"state":"open","title":"chore(ci): bump signpath/github-action-submit-signing-request from 1.1 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-22T22:31:38.000Z","updated_at":"2026-05-22T22:32:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(ci)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Juanalejo01/eclesia-presenter/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Juanalejo01%2Feclesia-presenter/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"4371583184","node_id":"PR_kwDORZlmD87XwutZ","number":4,"state":"open","title":"ci(deps): bump signpath/github-action-submit-signing-request from 1 to 2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-03T11:09:31.000Z","updated_at":"2026-05-03T11:09:31.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1","new_version":"2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1 to 2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1...v2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1\u0026new-version=2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/skynett81/3dprintforge/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/skynett81%2F3dprintforge/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"},{"uuid":"4319224629","node_id":"PR_kwDOQhNALM7VJHEa","number":88,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-23T22:22:08.000Z","updated_at":"2026-04-23T22:22:09.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":11,"packages":[{"name":"step-security/harden-runner","old_version":"2.16.1","new_version":"2.19.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.3.0","new_version":"6.4.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.4","new_version":"5.0.5","repository_url":"https://github.com/actions/cache"},{"name":"actions/upload-artifact","old_version":"7.0.0","new_version":"7.0.1","repository_url":"https://github.com/actions/upload-artifact"},{"name":"r0adkll/upload-google-play","old_version":"1.1.3","new_version":"1.1.5","repository_url":"https://github.com/r0adkll/upload-google-play"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.2","new_version":"4.1.3","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"anthropics/claude-code-action","old_version":"1.0.89","new_version":"1.0.104","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.35.1","new_version":"4.35.2","repository_url":"https://github.com/github/codeql-action"},{"name":"cloudflare/wrangler-action","old_version":"3.14.1","new_version":"3.15.0","repository_url":"https://github.com/cloudflare/wrangler-action"},{"name":"docker/build-push-action","old_version":"7.0.0","new_version":"7.1.0","repository_url":"https://github.com/docker/build-push-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.16.1` | `2.19.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.4` | `5.0.5` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` |\n| [r0adkll/upload-google-play](https://github.com/r0adkll/upload-google-play) | `1.1.3` | `1.1.5` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.2` | `4.1.3` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.89` | `1.0.104` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.35.1` | `4.35.2` |\n| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `3.14.1` | `3.15.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.1.0` |\n\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.19.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.19.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eNew Runner Support\u003c/h3\u003e\n\u003cp\u003eHarden-Runner now supports Depot, Blacksmith, Namespace, and WarpBuild runners with the same egress monitoring, runtime monitoring, and policy enforcement available on GitHub-hosted runners.\u003c/p\u003e\n\u003ch3\u003eAutomated Incident Response for Supply Chain Attacks\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGlobal block list: Outbound connections to known malicious domains and IPs are now blocked even in audit mode.\u003c/li\u003e\n\u003cli\u003eSystem-defined detection rules: Harden-Runner will trigger lockdown mode when a high risk event is detected during an active supply chain attack (for example, a process reading the memory of the runner worker process, a common technique for stealing GitHub Actions secrets).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cp\u003eWindows and macOS: stability and reliability fixes\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.18.0...v2.19.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.18.0...v2.19.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eGlobal Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.\u003c/p\u003e\n\u003cp\u003eDeploy on Self-Hosted VM: Added \u003ccode\u003edeploy-on-self-hosted-vm\u003c/code\u003e input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/8d3c67de8e2fe68ef647c8db1e6a09f647780f40\"\u003e\u003ccode\u003e8d3c67d\u003c/code\u003e\u003c/a\u003e Release v2.19.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/661\"\u003e#661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003e\u003ccode\u003e6c3c2f2\u003c/code\u003e\u003c/a\u003e Feature/deploy on self hosted vm (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/658\"\u003e#658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/fe104658747b27e96e4f7e80cd0a94068e53901d...8d3c67de8e2fe68ef647c8db1e6a09f647780f40\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.3.0 to 6.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js versions in versions.yml and bump package to v6.4.0  by \u003ca href=\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e@​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1533\"\u003eactions/setup-node#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.4.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003e\u003ccode\u003e48b55a0\u003c/code\u003e\u003c/a\u003e Update Node.js versions in versions.yml and bump package to v6.4.0 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1533\"\u003e#1533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/ab72c7e7eba0eaa11f8cab0f5679243900c2cac9\"\u003e\u003ccode\u003eab72c7e\u003c/code\u003e\u003c/a\u003e Upgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1525\"\u003e#1525\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.4 to 5.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ts-http-runtime dependency by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1747\"\u003eactions/cache#1747\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.5\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003e\u003ccode\u003e27d5ce7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1747\"\u003e#1747\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/f280785d7b6e1884c7d12b9136eb0f4a1574fcfd\"\u003e\u003ccode\u003ef280785\u003c/code\u003e\u003c/a\u003e licensed changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/619aeb1606e195be0b36fd0ff68dcf1aff6b65a7\"\u003e\u003ccode\u003e619aeb1\u003c/code\u003e\u003c/a\u003e npm run build generated dist files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/bcf16c2893940a4899761e55c7ac3c1cf88a04f6\"\u003e\u003ccode\u003ebcf16c2\u003c/code\u003e\u003c/a\u003e Update ts-http-runtime to 0.3.5\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `r0adkll/upload-google-play` from 1.1.3 to 1.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/r0adkll/upload-google-play/releases\"\u003er0adkll/upload-google-play's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix track/tracks and releaseFile/releaseFiles deprecation handling by \u003ca href=\"https://github.com/r0adkll\"\u003e\u003ccode\u003e@​r0adkll\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/264\"\u003er0adkll/upload-google-play#264\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/v1...v1.1.5\"\u003ehttps://github.com/r0adkll/upload-google-play/compare/v1...v1.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.1.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdds info about enabling Google Play Android Developer API by \u003ca href=\"https://github.com/Rufus125\"\u003e\u003ccode\u003e@​Rufus125\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/219\"\u003er0adkll/upload-google-play#219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate service account setup instructions by \u003ca href=\"https://github.com/lacop11\"\u003e\u003ccode\u003e@​lacop11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/225\"\u003er0adkll/upload-google-play#225\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExport commited editId for further modifications by \u003ca href=\"https://github.com/Swisyn\"\u003e\u003ccode\u003e@​Swisyn\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/233\"\u003er0adkll/upload-google-play#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumping github actions due to deprecated node-version by \u003ca href=\"https://github.com/FrankBurmo\"\u003e\u003ccode\u003e@​FrankBurmo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/234\"\u003er0adkll/upload-google-play#234\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAbility to retain version codes from previous releases by \u003ca href=\"https://github.com/marin-marsic\"\u003e\u003ccode\u003e@​marin-marsic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/237\"\u003er0adkll/upload-google-play#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FAQ item for \u0026quot;Precondition check failed\u0026quot; error during production track publishing by \u003ca href=\"https://github.com/juancdominici\"\u003e\u003ccode\u003e@​juancdominici\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/240\"\u003er0adkll/upload-google-play#240\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for uploading to multiple tracks by \u003ca href=\"https://github.com/X1nto\"\u003e\u003ccode\u003e@​X1nto\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/241\"\u003er0adkll/upload-google-play#241\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Node24 by \u003ca href=\"https://github.com/osniel\"\u003e\u003ccode\u003e@​osniel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/259\"\u003er0adkll/upload-google-play#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rufus125\"\u003e\u003ccode\u003e@​Rufus125\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/219\"\u003er0adkll/upload-google-play#219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lacop11\"\u003e\u003ccode\u003e@​lacop11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/225\"\u003er0adkll/upload-google-play#225\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Swisyn\"\u003e\u003ccode\u003e@​Swisyn\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/233\"\u003er0adkll/upload-google-play#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FrankBurmo\"\u003e\u003ccode\u003e@​FrankBurmo\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/234\"\u003er0adkll/upload-google-play#234\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marin-marsic\"\u003e\u003ccode\u003e@​marin-marsic\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/237\"\u003er0adkll/upload-google-play#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juancdominici\"\u003e\u003ccode\u003e@​juancdominici\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/240\"\u003er0adkll/upload-google-play#240\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/X1nto\"\u003e\u003ccode\u003e@​X1nto\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/241\"\u003er0adkll/upload-google-play#241\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/osniel\"\u003e\u003ccode\u003e@​osniel\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/259\"\u003er0adkll/upload-google-play#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/v1...v1.1.4\"\u003ehttps://github.com/r0adkll/upload-google-play/compare/v1...v1.1.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/e738b9dd8f2476ea806d921b64aacd24f34515a5\"\u003e\u003ccode\u003ee738b9d\u003c/code\u003e\u003c/a\u003e Fix track/tracks and releaseFile/releaseFiles deprecation handling (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/264\"\u003e#264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/7f5b759879c088a86faf85d18779f7f14e79a086\"\u003e\u003ccode\u003e7f5b759\u003c/code\u003e\u003c/a\u003e Upgrade to Node24 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/259\"\u003e#259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/41571de6d8a402a9565f0fc067d3ecc5f235a4c9\"\u003e\u003ccode\u003e41571de\u003c/code\u003e\u003c/a\u003e Bump picomatch from 2.3.1 to 2.3.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/258\"\u003e#258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/c5da46087f3bfa0d1a7b55bcc4716affe820488c\"\u003e\u003ccode\u003ec5da460\u003c/code\u003e\u003c/a\u003e Bump flatted from 3.2.7 to 3.4.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/257\"\u003e#257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/2540268935c2f0a3755cf8e882dbb3c15b427943\"\u003e\u003ccode\u003e2540268\u003c/code\u003e\u003c/a\u003e Add support for uploading to multiple tracks (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/241\"\u003e#241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/4d9bcc407da90cc25912a5b3925e53335f130540\"\u003e\u003ccode\u003e4d9bcc4\u003c/code\u003e\u003c/a\u003e Bump minimatch, \u003ccode\u003e@​typescript-eslint/eslint-plugin\u003c/code\u003e and \u003ccode\u003e@​typescript-eslint/parse\u003c/code\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/0b90f0d9c4c6a17ad49934892e18f099f35fdd3e\"\u003e\u003ccode\u003e0b90f0d\u003c/code\u003e\u003c/a\u003e Bump qs from 6.14.1 to 6.14.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/254\"\u003e#254\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/e59beb0116a7cb67c48a28f202414a50ac0a78f3\"\u003e\u003ccode\u003ee59beb0\u003c/code\u003e\u003c/a\u003e Bump lodash from 4.17.21 to 4.17.23 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/253\"\u003e#253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/463a558cc257c8712c085d74fbf643930bb755f5\"\u003e\u003ccode\u003e463a558\u003c/code\u003e\u003c/a\u003e Bump qs from 6.11.2 to 6.14.1 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/252\"\u003e#252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/62b6d3171db86f8ae8e6699690f98c781a1e3bd6\"\u003e\u003ccode\u003e62b6d31\u003c/code\u003e\u003c/a\u003e Bump jws from 4.0.0 to 4.0.1 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/250\"\u003e#250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/935ef9c68bb393a8e6116b1575626a7f5be3a7fb...e738b9dd8f2476ea806d921b64aacd24f34515a5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.2 to 4.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.3\u003c/h2\u003e\n\u003cp\u003eThere is a bug in \u003ccode\u003erunuser\u003c/code\u003e that converts all \u003ccode\u003e-c\u003c/code\u003e (even after \u003ccode\u003e--\u003c/code\u003e) into \u003ccode\u003e--command\u003c/code\u003e which \u003ccode\u003ebash\u003c/code\u003e doesn't recognize. This release removes the \u003ccode\u003e-c\u003c/code\u003e flag entirely, bash would execute \u003ccode\u003e/build.sh\u003c/code\u003e as if it's a file. Hopefully, the behavior preserves. If not, maybe just switch to \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eRelevant PR: \u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51\"\u003eKSXGitHub/github-actions-deploy-aur#51\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003e\u003ccode\u003eda03e16\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ebash: --command: invalid option\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1\"\u003e\u003ccode\u003e3b403c7\u003c/code\u003e\u003c/a\u003e docs(readme): use the GitHub's note syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2\"\u003e\u003ccode\u003ee17cd79\u003c/code\u003e\u003c/a\u003e docs(readme): remove patreon\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/abe8ac26b51011c88be58c8809fd2ac674068ea5...da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.89 to 1.0.104\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.104\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.104\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.104\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.103\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.103\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.103\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.102\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: bump oven-sh/setup-bun to v2.2.0 (Node.js 24) by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1238\"\u003eanthropics/claude-code-action#1238\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: nit updates to security.md by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1240\"\u003eanthropics/claude-code-action#1240\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.102\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.102\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.101\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.100\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Claude model from opus-4-6 to opus-4-7 by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1227\"\u003eanthropics/claude-code-action#1227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pass install.sh binary path to Agent SDK after 0.2.113 bump by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1235\"\u003eanthropics/claude-code-action#1235\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.99\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.98\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.97\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.96\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: handle fork PRs by fetching via refs/pull/N/head by \u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.95\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.94\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrepend system bin dirs to PATH when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1208\"\u003eanthropics/claude-code-action#1208\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b4d67413279fc18c6e5de930ae307c4f108714eb\"\u003e\u003ccode\u003eb4d6741\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.118 and Agent SDK to 0.2.118\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/4e5d8b13ca281a6d163cdb287d8917b216e00d6f\"\u003e\u003ccode\u003e4e5d8b1\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.117 and Agent SDK to 0.2.117\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/5d5c10a4f389689f992ea10bb14dcb6fcc83146d\"\u003e\u003ccode\u003e5d5c10a\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.116 and Agent SDK to 0.2.116\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/632a368e81692f2e33c14b7133a7ef56ae6d35e1\"\u003e\u003ccode\u003e632a368\u003c/code\u003e\u003c/a\u003e docs: nit updates to security.md (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1240\"\u003e#1240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/4c682d8b65549056a671d1be4d37ac4832e53859\"\u003e\u003ccode\u003e4c682d8\u003c/code\u003e\u003c/a\u003e chore: bump oven-sh/setup-bun to v2.2.0 (Node.js 24) (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1238\"\u003e#1238\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/38ec876110f9fbf8b950c79f534430740c3ac009\"\u003e\u003ccode\u003e38ec876\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0d2971c794049856e777f4e8bb5a81623ec632d3\"\u003e\u003ccode\u003e0d2971c\u003c/code\u003e\u003c/a\u003e fix: pass install.sh binary path explicitly to Agent SDK (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1235\"\u003e#1235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c68f82cb113a70ad61a71a133e86642c51a403aa\"\u003e\u003ccode\u003ec68f82c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/78758edf84903744fffe01b3d17c12b8757b4454\"\u003e\u003ccode\u003e78758ed\u003c/code\u003e\u003c/a\u003e chore: bump model version in workflows (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1227\"\u003e#1227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3d45e8e941e1b2ad7b278c57482d9c5bf1f35b3\"\u003e\u003ccode\u003ec3d45e8\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/6e2bd52842c65e914eba5c8badd17560bd26b5de...b4d67413279fc18c6e5de930ae307c4f108714eb\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.35.1 to 4.35.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.35.2 - 15 Apr 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003e\u003ccode\u003e95e58e9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3824\"\u003e#3824\u003c/a\u003e from github/update-v4.35.2-d2e135a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/6f31bfe060e817d81e938dbec767969d20031e25\"\u003e\u003ccode\u003e6f31bfe\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d2e135a73a39154e3a231aeb49163c4661c5b8b1\"\u003e\u003ccode\u003ed2e135a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3823\"\u003e#3823\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/60abb65df09fcf213c398e064c8a80db1f15cdaf\"\u003e\u003ccode\u003e60abb65\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/5a0a562209255e956ad8aafcee303294e64eefa2\"\u003e\u003ccode\u003e5a0a562\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65216971a11ded447a6b76263d5a144519e5eee1\"\u003e\u003ccode\u003e6521697\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3820\"\u003e#3820\u003c/a\u003e from github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/3c45af2dd258e1623af1898da5c86545b514e028\"\u003e\u003ccode\u003e3c45af2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3821\"\u003e#3821\u003c/a\u003e from github/dependabot/npm_and_yarn/npm-minor-345b93...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f1c339364c12f922998186ed897e45e3b4ae8874\"\u003e\u003ccode\u003ef1c3393\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1024fc496c87e944a93e98d8cf2c09e2c7602a30\"\u003e\u003ccode\u003e1024fc4\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/9dd4cfed96030ccdfe1af4daf7a7964322704fed\"\u003e\u003ccode\u003e9dd4cfe\u003c/code\u003e\u003c/a\u003e Bump the npm-minor group across 1 directory with 6 updates\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cloudflare/wrangler-action` from 3.14.1 to 3.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/releases\"\u003ecloudflare/wrangler-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md\"\u003ecloudflare/wrangler-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/358\"\u003e#358\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cd6314a97b09d9a764e30cacd0870edc86f92986\"\u003e\u003ccode\u003ecd6314a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/penalosa\"\u003e\u003ccode\u003e@​penalosa\u003c/code\u003e\u003c/a\u003e! - Use \u003ccode\u003esecret bulk\u003c/code\u003e instead of deprecated \u003ccode\u003esecret:bulk\u003c/code\u003e command\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/351\"\u003e#351\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/4ff07f4310dc5067d84a254cd9af3d2e91df119e\"\u003e\u003ccode\u003e4ff07f4\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Use wrangler outputs for version upload and wrangler deploy\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/350\"\u003e#350\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e209094e624c6f6b418141b7e9d0ab7838d794a3\"\u003e\u003ccode\u003ee209094\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Handle failures in createGitHubDeployment and createGitHubJobSummary\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/345\"\u003e#345\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e819570b2d0a69816a1c2e9d2f2954e278748d80\"\u003e\u003ccode\u003ee819570\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - fix: Pages GitHub Deployment not triggering\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/325\"\u003e#325\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cada7a63124ded3471bef7e8001b76356b838e40\"\u003e\u003ccode\u003ecada7a6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Add GitHub deployments and job summaries for parity with pages-action\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/334\"\u003e#334\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9fed19aa4ed79946f009e8aad7437a922e62d523\"\u003e\u003ccode\u003e9fed19a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Bump default wrangler version to 3.90.0\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/319\"\u003e#319\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/59c04629408d58978884fadd18755f1a15f96157\"\u003e\u003ccode\u003e59c04629408d58978884fadd18755f1a15f96157\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/317\"\u003e#317\u003c/a\u003e: Generate a new output directory with a randomUUID in the tmpDir, so that when the action is executed multiple times, we use the artifacts from that run, opposed to the artifacts from a previous run.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/312\"\u003e#312\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\"\u003e\u003ccode\u003e122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - This reapplies \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/303\"\u003e303\u003c/a\u003e add parity with pages-action for pages deploy outputs. Thanks \u003ca href=\"https://github.com/courtney-sims\"\u003e\u003ccode\u003e@​courtney-sims\u003c/code\u003e\u003c/a\u003e! - Support pages-deployment-id, pages-environment, pages-deployment-alias-url and deployment-url outputs for Pages deploys when wrangler version is \u0026gt;=3.81.0. deployment-alias-url was also deprecated in favour of pages-deployment-alias.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003e\u003ccode\u003e9acf94a\u003c/code\u003e\u003c/a\u003e Automatic compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d181764e4b7652eb4377feec6bf15ddbb23210f0\"\u003e\u003ccode\u003ed181764\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/427\"\u003e#427\u003c/a\u003e from cloudflare/changeset-release/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/05015540800a657e380eba742bfa91a4ba2a2ca8\"\u003e\u003ccode\u003e0501554\u003c/code\u003e\u003c/a\u003e Version Packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d8f3eaa359cd9d866a9aa127280056692bc71ee0\"\u003e\u003ccode\u003ed8f3eaa\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/426\"\u003e#426\u003c/a\u003e from cloudflare/willtaylor/escalation-963-support-ver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Support version ranges and tags in wranglerVersion input\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cloudflare/wrangler-action/compare/da0e0dfe58b7a431659754fdf3f186c529afbe65...9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.0.0 to 7.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGit context \u003ca href=\"https://docs.docker.com/build/concepts/context/#url-queries\"\u003equery format\u003c/a\u003e support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.79.0 to 0.87.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.12 to 1.1.13 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1500\"\u003edocker/build-push-action#1500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.4.2 to 5.5.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1489\"\u003edocker/build-push-action#1489\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.3 to 3.4.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1491\"\u003edocker/build-push-action#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump glob from 10.3.12 to 10.5.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1490\"\u003edocker/build-push-action#1490\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump handlebars from 4.7.8 to 4.7.9 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1497\"\u003edocker/build-push-action#1497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.23 to 4.18.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1510\"\u003edocker/build-push-action#1510\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump picomatch from 4.0.3 to 4.0.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1496\"\u003edocker/build-push-action#1496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.23.0 to 6.24.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1486\"\u003edocker/build-push-action#1486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.1 to 7.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1509\"\u003edocker/build-push-action#1509\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003e\u003ccode\u003ebcafcac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1509\"\u003e#1509\u003c/a\u003e from docker/dependabot/npm_and_yarn/vite-7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/18e62f1158d9c45a4a84a58a6828d21f8ed3644b\"\u003e\u003ccode\u003e18e62f1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1510\"\u003e#1510\u003c/a\u003e from docker/dependabot/npm_and_yarn/lodash-4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/46580d2c9d43b0888270cb6fa90956e483de56fc\"\u003e\u003ccode\u003e46580d2\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/3f80b252ca2331f6ec3e890f4346b5506ee1dc81\"\u003e\u003ccode\u003e3f80b25\u003c/code\u003e\u003c/a\u003e chore(deps): Bump lodash from 4.17.23 to 4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/efeec9557c40a646afe433e39a1e94ca689103f0\"\u003e\u003ccode\u003eefeec95\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1505\"\u003e#1505\u003c/a\u003e from crazy-max/refactor-git-context\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ddf04b08eb12882258ed936fea4a2806754ff349\"\u003e\u003ccode\u003eddf04b0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1511\"\u003e#1511\u003c/a\u003e from docker/dependabot/github_actions/crazy-max-dot-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/db08d97a08e4a0d15f85d1c4e64dfd5f88cbe1a9\"\u003e\u003ccode\u003edb08d97\u003c/code\u003e\u003c/a\u003e chore(deps): Bump the crazy-max-dot-github group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ef1fb9688fc3626d0fd5e462f502cbbdc6456feb\"\u003e\u003ccode\u003eef1fb96\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1508\"\u003e#1508\u003c/a\u003e from docker/dependabot/github_actions/docker/login-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/2d8f2a1a378a5c302dcd7b2b4326cefa24180bb1\"\u003e\u003ccode\u003e2d8f2a1\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/919ac7bd7d1aa8cb13fe4de76545abea8d8b5ed2\"\u003e\u003ccode\u003e919ac7b\u003c/code\u003e\u003c/a\u003e fix test since secrets are not written to temp path anymore\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/camillanapoles/super-productivity/pull/88","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/camillanapoles%2Fsuper-productivity/issues/88","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/88/packages"},{"uuid":"4293825180","node_id":"PR_kwDOBKnnxc7T2l-3","number":7285,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group with 10 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-20T07:19:57.000Z","updated_at":"2026-04-20T07:23:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":10,"packages":[{"name":"step-security/harden-runner","old_version":"2.16.1","new_version":"2.18.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.3.0","new_version":"6.4.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.4","new_version":"5.0.5","repository_url":"https://github.com/actions/cache"},{"name":"actions/upload-artifact","old_version":"7.0.0","new_version":"7.0.1","repository_url":"https://github.com/actions/upload-artifact"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.2","new_version":"4.1.3","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"anthropics/claude-code-action","old_version":"1.0.89","new_version":"1.0.101","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.35.1","new_version":"4.35.2","repository_url":"https://github.com/github/codeql-action"},{"name":"cloudflare/wrangler-action","old_version":"3.14.1","new_version":"3.15.0","repository_url":"https://github.com/cloudflare/wrangler-action"},{"name":"docker/build-push-action","old_version":"7.0.0","new_version":"7.1.0","repository_url":"https://github.com/docker/build-push-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 10 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.16.1` | `2.18.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.4` | `5.0.5` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.2` | `4.1.3` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.89` | `1.0.101` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.35.1` | `4.35.2` |\n| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `3.14.1` | `3.15.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.1.0` |\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eGlobal Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.\u003c/p\u003e\n\u003cp\u003eDeploy on Self-Hosted VM: Added \u003ccode\u003edeploy-on-self-hosted-vm\u003c/code\u003e input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003e\u003ccode\u003e6c3c2f2\u003c/code\u003e\u003c/a\u003e Feature/deploy on self hosted vm (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/658\"\u003e#658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/fe104658747b27e96e4f7e80cd0a94068e53901d...6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.3.0 to 6.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js versions in versions.yml and bump package to v6.4.0  by \u003ca href=\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e@​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1533\"\u003eactions/setup-node#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.4.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003e\u003ccode\u003e48b55a0\u003c/code\u003e\u003c/a\u003e Update Node.js versions in versions.yml and bump package to v6.4.0 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1533\"\u003e#1533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/ab72c7e7eba0eaa11f8cab0f5679243900c2cac9\"\u003e\u003ccode\u003eab72c7e\u003c/code\u003e\u003c/a\u003e Upgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1525\"\u003e#1525\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.4 to 5.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ts-http-runtime dependency by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1747\"\u003eactions/cache#1747\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.5\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003e\u003ccode\u003e27d5ce7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1747\"\u003e#1747\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/f280785d7b6e1884c7d12b9136eb0f4a1574fcfd\"\u003e\u003ccode\u003ef280785\u003c/code\u003e\u003c/a\u003e licensed changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/619aeb1606e195be0b36fd0ff68dcf1aff6b65a7\"\u003e\u003ccode\u003e619aeb1\u003c/code\u003e\u003c/a\u003e npm run build generated dist files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/bcf16c2893940a4899761e55c7ac3c1cf88a04f6\"\u003e\u003ccode\u003ebcf16c2\u003c/code\u003e\u003c/a\u003e Update ts-http-runtime to 0.3.5\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.2 to 4.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.3\u003c/h2\u003e\n\u003cp\u003eThere is a bug in \u003ccode\u003erunuser\u003c/code\u003e that converts all \u003ccode\u003e-c\u003c/code\u003e (even after \u003ccode\u003e--\u003c/code\u003e) into \u003ccode\u003e--command\u003c/code\u003e which \u003ccode\u003ebash\u003c/code\u003e doesn't recognize. This release removes the \u003ccode\u003e-c\u003c/code\u003e flag entirely, bash would execute \u003ccode\u003e/build.sh\u003c/code\u003e as if it's a file. Hopefully, the behavior preserves. If not, maybe just switch to \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eRelevant PR: \u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51\"\u003eKSXGitHub/github-actions-deploy-aur#51\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003e\u003ccode\u003eda03e16\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ebash: --command: invalid option\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1\"\u003e\u003ccode\u003e3b403c7\u003c/code\u003e\u003c/a\u003e docs(readme): use the GitHub's note syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2\"\u003e\u003ccode\u003ee17cd79\u003c/code\u003e\u003c/a\u003e docs(readme): remove patreon\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/abe8ac26b51011c88be58c8809fd2ac674068ea5...da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.89 to 1.0.101\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.101\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.100\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Claude model from opus-4-6 to opus-4-7 by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1227\"\u003eanthropics/claude-code-action#1227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pass install.sh binary path to Agent SDK after 0.2.113 bump by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1235\"\u003eanthropics/claude-code-action#1235\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.99\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.98\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.97\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.96\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: handle fork PRs by fetching via refs/pull/N/head by \u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.95\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.94\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrepend system bin dirs to PATH when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1208\"\u003eanthropics/claude-code-action#1208\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.94\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.94\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.93\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.92\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.91\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse pinned bun binary for post-steps when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1190\"\u003eanthropics/claude-code-action#1190\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/38ec876110f9fbf8b950c79f534430740c3ac009\"\u003e\u003ccode\u003e38ec876\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0d2971c794049856e777f4e8bb5a81623ec632d3\"\u003e\u003ccode\u003e0d2971c\u003c/code\u003e\u003c/a\u003e fix: pass install.sh binary path explicitly to Agent SDK (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1235\"\u003e#1235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c68f82cb113a70ad61a71a133e86642c51a403aa\"\u003e\u003ccode\u003ec68f82c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/78758edf84903744fffe01b3d17c12b8757b4454\"\u003e\u003ccode\u003e78758ed\u003c/code\u003e\u003c/a\u003e chore: bump model version in workflows (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1227\"\u003e#1227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3d45e8e941e1b2ad7b278c57482d9c5bf1f35b3\"\u003e\u003ccode\u003ec3d45e8\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/931e62027356f4c337273719db085805456e53cc\"\u003e\u003ccode\u003e931e620\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.111 and Agent SDK to 0.2.111\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/905d4eb99ab3d43143d74fb0dcae537f29ac330a\"\u003e\u003ccode\u003e905d4eb\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.110 and Agent SDK to 0.2.110\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/5fb899572b81d2bb648d4d187173a2f423a9677c\"\u003e\u003ccode\u003e5fb8995\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.109 and Agent SDK to 0.2.109\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3bf66dbc27ae48bb05f3baa188d7a8676566a73\"\u003e\u003ccode\u003ec3bf66d\u003c/code\u003e\u003c/a\u003e fix: handle fork PRs by fetching via refs/pull/N/head (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/962\"\u003e#962\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/963\"\u003e#963\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/39431830520a7ae6c0c572f11a7707e7043325e3\"\u003e\u003ccode\u003e3943183\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.108 and Agent SDK to 0.2.108\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/6e2bd52842c65e914eba5c8badd17560bd26b5de...38ec876110f9fbf8b950c79f534430740c3ac009\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.35.1 to 4.35.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.35.2 - 15 Apr 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003e\u003ccode\u003e95e58e9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3824\"\u003e#3824\u003c/a\u003e from github/update-v4.35.2-d2e135a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/6f31bfe060e817d81e938dbec767969d20031e25\"\u003e\u003ccode\u003e6f31bfe\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d2e135a73a39154e3a231aeb49163c4661c5b8b1\"\u003e\u003ccode\u003ed2e135a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3823\"\u003e#3823\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/60abb65df09fcf213c398e064c8a80db1f15cdaf\"\u003e\u003ccode\u003e60abb65\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/5a0a562209255e956ad8aafcee303294e64eefa2\"\u003e\u003ccode\u003e5a0a562\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65216971a11ded447a6b76263d5a144519e5eee1\"\u003e\u003ccode\u003e6521697\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3820\"\u003e#3820\u003c/a\u003e from github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/3c45af2dd258e1623af1898da5c86545b514e028\"\u003e\u003ccode\u003e3c45af2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3821\"\u003e#3821\u003c/a\u003e from github/dependabot/npm_and_yarn/npm-minor-345b93...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f1c339364c12f922998186ed897e45e3b4ae8874\"\u003e\u003ccode\u003ef1c3393\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1024fc496c87e944a93e98d8cf2c09e2c7602a30\"\u003e\u003ccode\u003e1024fc4\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/9dd4cfed96030ccdfe1af4daf7a7964322704fed\"\u003e\u003ccode\u003e9dd4cfe\u003c/code\u003e\u003c/a\u003e Bump the npm-minor group across 1 directory with 6 updates\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cloudflare/wrangler-action` from 3.14.1 to 3.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/releases\"\u003ecloudflare/wrangler-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md\"\u003ecloudflare/wrangler-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/358\"\u003e#358\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cd6314a97b09d9a764e30cacd0870edc86f92986\"\u003e\u003ccode\u003ecd6314a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/penalosa\"\u003e\u003ccode\u003e@​penalosa\u003c/code\u003e\u003c/a\u003e! - Use \u003ccode\u003esecret bulk\u003c/code\u003e instead of deprecated \u003ccode\u003esecret:bulk\u003c/code\u003e command\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/351\"\u003e#351\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/4ff07f4310dc5067d84a254cd9af3d2e91df119e\"\u003e\u003ccode\u003e4ff07f4\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Use wrangler outputs for version upload and wrangler deploy\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/350\"\u003e#350\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e209094e624c6f6b418141b7e9d0ab7838d794a3\"\u003e\u003ccode\u003ee209094\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Handle failures in createGitHubDeployment and createGitHubJobSummary\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/345\"\u003e#345\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e819570b2d0a69816a1c2e9d2f2954e278748d80\"\u003e\u003ccode\u003ee819570\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - fix: Pages GitHub Deployment not triggering\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/325\"\u003e#325\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cada7a63124ded3471bef7e8001b76356b838e40\"\u003e\u003ccode\u003ecada7a6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Add GitHub deployments and job summaries for parity with pages-action\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/334\"\u003e#334\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9fed19aa4ed79946f009e8aad7437a922e62d523\"\u003e\u003ccode\u003e9fed19a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Bump default wrangler version to 3.90.0\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/319\"\u003e#319\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/59c04629408d58978884fadd18755f1a15f96157\"\u003e\u003ccode\u003e59c04629408d58978884fadd18755f1a15f96157\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/317\"\u003e#317\u003c/a\u003e: Generate a new output directory with a randomUUID in the tmpDir, so that when the action is executed multiple times, we use the artifacts from that run, opposed to the artifacts from a previous run.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/312\"\u003e#312\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\"\u003e\u003ccode\u003e122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - This reapplies \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/303\"\u003e303\u003c/a\u003e add parity with pages-action for pages deploy outputs. Thanks \u003ca href=\"https://github.com/courtney-sims\"\u003e\u003ccode\u003e@​courtney-sims\u003c/code\u003e\u003c/a\u003e! - Support pages-deployment-id, pages-environment, pages-deployment-alias-url and deployment-url outputs for Pages deploys when wrangler version is \u0026gt;=3.81.0. deployment-alias-url was also deprecated in favour of pages-deployment-alias.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003e\u003ccode\u003e9acf94a\u003c/code\u003e\u003c/a\u003e Automatic compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d181764e4b7652eb4377feec6bf15ddbb23210f0\"\u003e\u003ccode\u003ed181764\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/427\"\u003e#427\u003c/a\u003e from cloudflare/changeset-release/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/05015540800a657e380eba742bfa91a4ba2a2ca8\"\u003e\u003ccode\u003e0501554\u003c/code\u003e\u003c/a\u003e Version Packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d8f3eaa359cd9d866a9aa127280056692bc71ee0\"\u003e\u003ccode\u003ed8f3eaa\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/426\"\u003e#426\u003c/a\u003e from cloudflare/willtaylor/escalation-963-support-ver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Support version ranges and tags in wranglerVersion input\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cloudflare/wrangler-action/compare/da0e0dfe58b7a431659754fdf3f186c529afbe65...9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.0.0 to 7.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGit context \u003ca href=\"https://docs.docker.com/build/concepts/context/#url-queries\"\u003equery format\u003c/a\u003e support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.79.0 to 0.87.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.12 to 1.1.13 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1500\"\u003edocker/build-push-action#1500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.4.2 to 5.5.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1489\"\u003edocker/build-push-action#1489\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.3 to 3.4.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1491\"\u003edocker/build-push-action#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump glob from 10.3.12 to 10.5.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1490\"\u003edocker/build-push-action#1490\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump handlebars from 4.7.8 to 4.7.9 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1497\"\u003edocker/build-push-action#1497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.23 to 4.18.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1510\"\u003edocker/build-push-action#1510\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump picomatch from 4.0.3 to 4.0.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1496\"\u003edocker/build-push-action#1496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.23.0 to 6.24.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1486\"\u003edocker/build-push-action#1486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.1 to 7.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1509\"\u003edocker/build-push-action#1509\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003e\u003ccode\u003ebcafcac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1509\"\u003e#1509\u003c/a\u003e from docker/dependabot/npm_and_yarn/vite-7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/18e62f1158d9c45a4a84a58a6828d21f8ed3644b\"\u003e\u003ccode\u003e18e62f1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1510\"\u003e#1510\u003c/a\u003e from docker/dependabot/npm_and_yarn/lodash-4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/46580d2c9d43b0888270cb6fa90956e483de56fc\"\u003e\u003ccode\u003e46580d2\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/3f80b252ca2331f6ec3e890f4346b5506ee1dc81\"\u003e\u003ccode\u003e3f80b25\u003c/code\u003e\u003c/a\u003e chore(deps): Bump lodash from 4.17.23 to 4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/efeec9557c40a646afe433e39a1e94ca689103f0\"\u003e\u003ccode\u003eefeec95\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1505\"\u003e#1505\u003c/a\u003e from crazy-max/refactor-git-context\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ddf04b08eb12882258ed936fea4a2806754ff349\"\u003e\u003ccode\u003eddf04b0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1511\"\u003e#1511\u003c/a\u003e from docker/dependabot/github_actions/crazy-max-dot-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/db08d97a08e4a0d15f85d1c4e64dfd5f88cbe1a9\"\u003e\u003ccode\u003edb08d97\u003c/code\u003e\u003c/a\u003e chore(deps): Bump the crazy-max-dot-github group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ef1fb9688fc3626d0fd5e462f502cbbdc6456feb\"\u003e\u003ccode\u003eef1fb96\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1508\"\u003e#1508\u003c/a\u003e from docker/dependabot/github_actions/docker/login-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/2d8f2a1a378a5c302dcd7b2b4326cefa24180bb1\"\u003e\u003ccode\u003e2d8f2a1\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/919ac7bd7d1aa8cb13fe4de76545abea8d8b5ed2\"\u003e\u003ccode\u003e919ac7b\u003c/code\u003e\u003c/a\u003e fix test since secrets are not written to temp path anymore\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/super-productivity/super-productivity/pull/7285","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/super-productivity%2Fsuper-productivity/issues/7285","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7285/packages"},{"uuid":"4287582966","node_id":"PR_kwDORKxwDc7Tj-E7","number":105,"state":"open","title":"build(deps): Bump signpath/github-action-submit-signing-request from 2.0 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-18T10:04:16.000Z","updated_at":"2026-04-18T10:04:17.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/robertpopa22/mRemoteNG/pull/105","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/robertpopa22%2FmRemoteNG/issues/105","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/105/packages"},{"uuid":"4252191440","node_id":"PR_kwDORbirJs7R5i1_","number":20,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group across 1 directory with 9 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-13T07:26:46.000Z","updated_at":"2026-04-13T07:26:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":9,"packages":[{"name":"step-security/harden-runner","old_version":"2.14.2","new_version":"2.17.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.2.0","new_version":"6.3.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.3","new_version":"5.0.4","repository_url":"https://github.com/actions/cache"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.1","new_version":"4.1.2","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"actions/dependency-review-action","old_version":"4.8.3","new_version":"4.9.0","repository_url":"https://github.com/actions/dependency-review-action"},{"name":"treosh/lighthouse-ci-action","old_version":"12.6.1","new_version":"12.6.2","repository_url":"https://github.com/treosh/lighthouse-ci-action"},{"name":"anthropics/claude-code-action","old_version":"1.0.55","new_version":"1.0.93","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.32.4","new_version":"4.35.1","repository_url":"https://github.com/github/codeql-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 9 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.2` | `2.17.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.2.0` | `6.3.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.3` | `5.0.4` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.1` | `4.1.2` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.1` |\n| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.3` | `4.9.0` |\n| [treosh/lighthouse-ci-action](https://github.com/treosh/lighthouse-ci-action) | `12.6.1` | `12.6.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.55` | `1.0.93` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.32.4` | `4.35.1` |\n\n\nUpdates `step-security/harden-runner` from 2.14.2 to 2.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.16.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eEnterprise tier: Added support for direct IP addresses in the allow list\nCommunity tier: Migrated Harden Runner telemetry to a new endpoint\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.0...v2.16.1\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.0...v2.16.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.16.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated action.yml to use node24\u003c/li\u003e\n\u003cli\u003eSecurity fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS over HTTPS (DoH) by proxying DNS queries through a permitted resolver, allowing data exfiltration even with a restrictive allowed-endpoints list. This issue only affects the Community Tier; the Enterprise Tier is not affected. See \u003ca href=\"https://github.com/step-security/harden-runner/security/advisories/GHSA-46g3-37rh-v698\"\u003eGHSA-46g3-37rh-v698\u003c/a\u003e for details.\u003c/li\u003e\n\u003cli\u003eSecurity fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS queries over TCP to external resolvers, allowing outbound network communication that evades configured network restrictions. This issue only affects the Community Tier; the Enterprise Tier is not affected. See \u003ca href=\"https://github.com/step-security/harden-runner/security/advisories/GHSA-g699-3x6g-wm3g\"\u003eGHSA-g699-3x6g-wm3g\u003c/a\u003e for details.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.15.1...v2.16.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.15.1...v2.16.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.15.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/642\"\u003estep-security/harden-runner#642\u003c/a\u003e bug due to which post step was failing on Windows ARM runners\u003c/li\u003e\n\u003cli\u003eUpdates npm packages\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.15.0...v2.15.1\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.15.0...v2.15.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.15.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eWindows and macOS runner support\u003c/h3\u003e\n\u003cp\u003eWe are excited to announce that Harden Runner now supports \u003cstrong\u003eWindows and macOS runners\u003c/strong\u003e, extending runtime security beyond Linux for the first time.\u003c/p\u003e\n\u003cp\u003eInsights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.14.2...v2.15.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.14.2...v2.15.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/fe104658747b27e96e4f7e80cd0a94068e53901d\"\u003e\u003ccode\u003efe10465\u003c/code\u003e\u003c/a\u003e v2.16.1 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/654\"\u003e#654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594\"\u003e\u003ccode\u003efa2e9d6\u003c/code\u003e\u003c/a\u003e Release v2.16.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/646\"\u003e#646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/58077d3c7e43986b6b15fba718e8ea69e387dfcc\"\u003e\u003ccode\u003e58077d3\u003c/code\u003e\u003c/a\u003e Release v2.15.1 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/641\"\u003e#641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/a90bcbc6539c36a85cdfeb73f7e2f433735f215b\"\u003e\u003ccode\u003ea90bcbc\u003c/code\u003e\u003c/a\u003e Update readme (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f0a59d88538059e010b6ebd90b74e2740a6d05fc\"\u003e\u003ccode\u003ef0a59d8\u003c/code\u003e\u003c/a\u003e Release v2.15.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/5ef0c079ce82195b2a36a210272d6b661572d83e...f808768d1510423e83855289c910610ca9b43176\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.2.0 to 6.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport parsing \u003ccode\u003edevEngines\u003c/code\u003e field by \u003ca href=\"https://github.com/susnux\"\u003e\u003ccode\u003e@​susnux\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1283\"\u003eactions/setup-node#1283\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWhen using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix npm audit issues by \u003ca href=\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1491\"\u003eactions/setup-node#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace uuid with crypto.randomUUID() by \u003ca href=\"https://github.com/trivikr\"\u003e\u003ccode\u003e@​trivikr\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1378\"\u003eactions/setup-node#1378\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade minimatch from 3.1.2 to 3.1.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1498\"\u003eactions/setup-node#1498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove hardcoded bearer for mirror-url \u003ca href=\"https://github.com/marco-ippolito\"\u003e\u003ccode\u003e@​marco-ippolito\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1467\"\u003eactions/setup-node#1467\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eScope test lockfiles by package manager and update cache tests by \u003ca href=\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1495\"\u003eactions/setup-node#1495\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/susnux\"\u003e\u003ccode\u003e@​susnux\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1283\"\u003eactions/setup-node#1283\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.3.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/53b83947a5a98c8d113130e565377fae1a50d02f\"\u003e\u003ccode\u003e53b8394\u003c/code\u003e\u003c/a\u003e Bump minimatch from 3.1.2 to 3.1.5 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1498\"\u003e#1498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/54045abd5dcd3b0fee9ca02fa24c57545834c9cc\"\u003e\u003ccode\u003e54045ab\u003c/code\u003e\u003c/a\u003e Scope test lockfiles by package manager and update cache tests (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1495\"\u003e#1495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/c882bffdbd4df51ace6b940023952e8669c9932a\"\u003e\u003ccode\u003ec882bff\u003c/code\u003e\u003c/a\u003e Replace uuid with crypto.randomUUID() (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1378\"\u003e#1378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/774c1d62961e73038a114d59c8847023c003194d\"\u003e\u003ccode\u003e774c1d6\u003c/code\u003e\u003c/a\u003e feat(node-version-file): support parsing \u003ccode\u003edevEngines\u003c/code\u003e field (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1283\"\u003e#1283\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/efcb663fc60e97218a2b2d6d827f7830f164739e\"\u003e\u003ccode\u003eefcb663\u003c/code\u003e\u003c/a\u003e fix: remove hardcoded bearer (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1467\"\u003e#1467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/d02c89dce7e1ba9ef629ce0680989b3a1cc72edb\"\u003e\u003ccode\u003ed02c89d\u003c/code\u003e\u003c/a\u003e Fix npm audit issues (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1491\"\u003e#1491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/6044e13b5dc448c55e2357c09f80417699197238...53b83947a5a98c8d113130e565377fae1a50d02f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.3 to 5.0.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release instructions and update maintainer docs by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1696\"\u003eactions/cache#1696\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePotential fix for code scanning alert no. 52: Workflow does not contain permissions by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1697\"\u003eactions/cache#1697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix workflow permissions and cleanup workflow names / formatting by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1699\"\u003eactions/cache#1699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: Update examples to use the latest version by \u003ca href=\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix proxy integration tests by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1701\"\u003eactions/cache#1701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix cache key in examples.md for bun.lock by \u003ca href=\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate dependencies \u0026amp; patch security vulnerabilities by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1738\"\u003eactions/cache#1738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.4\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003e\u003ccode\u003e6682284\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1738\"\u003e#1738\u003c/a\u003e from actions/prepare-v5.0.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/e34039626f957d3e3e50843d15c1b20547fc90e2\"\u003e\u003ccode\u003ee340396\u003c/code\u003e\u003c/a\u003e Update RELEASES\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/8a671105293e81530f1af99863cdf94550aba1a6\"\u003e\u003ccode\u003e8a67110\u003c/code\u003e\u003c/a\u003e Add licenses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/1865903e1b0cb750dda9bc5c58be03424cc62830\"\u003e\u003ccode\u003e1865903\u003c/code\u003e\u003c/a\u003e Update dependencies \u0026amp; patch security vulnerabilities\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/565629816435f6c0b50676926c9b05c254113c0c\"\u003e\u003ccode\u003e5656298\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1722\"\u003e#1722\u003c/a\u003e from RyPeck/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/4e380d19e192ace8e86f23f32ca6fdec98a673c6\"\u003e\u003ccode\u003e4e380d1\u003c/code\u003e\u003c/a\u003e Fix cache key in examples.md for bun.lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/b7e8d49f17405cc70c1c120101943203c98d3a4b\"\u003e\u003ccode\u003eb7e8d49\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1701\"\u003e#1701\u003c/a\u003e from actions/Link-/fix-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/984a21b1cb176a0936f4edafb42be88978f93ef1\"\u003e\u003ccode\u003e984a21b\u003c/code\u003e\u003c/a\u003e Add traffic sanity check step\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/acf2f1f76affe1ef80eee8e56dfddd3b3e5f0fba\"\u003e\u003ccode\u003eacf2f1f\u003c/code\u003e\u003c/a\u003e Fix resolution\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/95a07c51324af6001b4d6ab8dff29f4dfadc2531\"\u003e\u003ccode\u003e95a07c5\u003c/code\u003e\u003c/a\u003e Add wait for proxy\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.1 to 4.1.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.2\u003c/h2\u003e\n\u003cp\u003eSwitching from \u003ccode\u003e--command\u003c/code\u003e to \u003ccode\u003e-u \u0026lt;USER\u0026gt; -- \u0026lt;COMMAND\u0026gt;\u003c/code\u003e (the recommended way), allowing the entry point to run in su-compatible mode (\u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/49\"\u003eKSXGitHub/github-actions-deploy-aur#49\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/abe8ac26b51011c88be58c8809fd2ac674068ea5\"\u003e\u003ccode\u003eabe8ac2\u003c/code\u003e\u003c/a\u003e fix: use runuser -u flag to avoid bash --command error (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/2ac5a4c1d7035885d46b10e3193393be8460b6f1...abe8ac26b51011c88be58c8809fd2ac674068ea5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/dependency-review-action` from 4.8.3 to 4.9.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/dependency-review-action/releases\"\u003eactions/dependency-review-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDependency Review Action 4.9.0\u003c/h2\u003e\n\u003cp\u003eThis feature release contains a couple of notable changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThere is a new configuration option \u003ccode\u003eshow_patched_versions\u003c/code\u003e which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks \u003ca href=\"https://github.com/felickz\"\u003e\u003ccode\u003e@​felickz\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eRuns which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch \u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eThere are a couple of fixes to purl parsing which should improve match accuracy for \u003ccode\u003eallow-package-dependency\u003c/code\u003e lists, including case (in)sensitivity and url-encoded namespaces Thanks \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompare normalized purls to account for encoding quirks by \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1056\"\u003eactions/dependency-review-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake purl comparisons case insensitive by \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1057\"\u003eactions/dependency-review-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFeat: Add \u003ccode\u003ePatched Version\u003c/code\u003e to \u003ccode\u003eVulnerabilities\u003c/code\u003e summary by \u003ca href=\"https://github.com/felickz\"\u003e\u003ccode\u003e@​felickz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1045\"\u003eactions/dependency-review-action#1045\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: only get scorecard levels if user wants to see the OpenSSF scorecard by \u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1060\"\u003eactions/dependency-review-action#1060\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/stale from 10.1.0 to 10.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1058\"\u003eactions/dependency-review-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 4 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1021\"\u003eactions/dependency-review-action#1021\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdates for release 4.9.0 by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1064\"\u003eactions/dependency-review-action#1064\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1060\"\u003eactions/dependency-review-action#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0\"\u003ehttps://github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/2031cfc080254a8a887f58cffee85186f0e49e48\"\u003e\u003ccode\u003e2031cfc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1064\"\u003e#1064\u003c/a\u003e from actions/ahpook/release-4.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/d02fa39f790d6e8a4ecafab5848251ff12c20df7\"\u003e\u003ccode\u003ed02fa39\u003c/code\u003e\u003c/a\u003e Updates for release 4.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/4038a34c4b30f7c11a7d45dc8dbea40e2211aa27\"\u003e\u003ccode\u003e4038a34\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1021\"\u003e#1021\u003c/a\u003e from actions/dependabot/github_actions/actions/check...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a632b8386b2cc2b1b99427606b513f7632d27e91\"\u003e\u003ccode\u003ea632b83\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1058\"\u003e#1058\u003c/a\u003e from actions/dependabot/github_actions/actions/stale...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/57a3d46a7be2c2e259fa3284ffc501296337f2ac\"\u003e\u003ccode\u003e57a3d46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1060\"\u003e#1060\u003c/a\u003e from jantiebot/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/5ecdc4b5781cdabdfe233d6e58ec18eac23e275d\"\u003e\u003ccode\u003e5ecdc4b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1045\"\u003e#1045\u003c/a\u003e from forks-felickz/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/e8c2f9a12c568d6f36f8d3a9935a6c71afc691f5\"\u003e\u003ccode\u003ee8c2f9a\u003c/code\u003e\u003c/a\u003e fix: remove inferrable type annotation to pass eslint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/0e129e113c878bfe7c1abf6c6d94b180cbf71086\"\u003e\u003ccode\u003e0e129e1\u003c/code\u003e\u003c/a\u003e Prettier  - Refactor summary table rendering for improved readability\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/aa60746a920d63ce55376f67d381e15edd3a714d\"\u003e\u003ccode\u003eaa60746\u003c/code\u003e\u003c/a\u003e Add 'show-patched-versions' option to configuration and update summary handling\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/e4047984002250b82268ac37f613ab74366e1d85\"\u003e\u003ccode\u003ee404798\u003c/code\u003e\u003c/a\u003e Merge upstream actions/dependency-review-action main\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/dependency-review-action/compare/05fe4576374b728f0c523d6a13d64c25081e0803...2031cfc080254a8a887f58cffee85186f0e49e48\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `treosh/lighthouse-ci-action` from 12.6.1 to 12.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/treosh/lighthouse-ci-action/releases\"\u003etreosh/lighthouse-ci-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.6.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse \u003ccode\u003enode24\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdate deps: \u003ccode\u003e@​actions/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.0.0, \u003ccode\u003e@​lhci/cli\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.15.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/3e7e23fb74242897f95c0ba9cabad3d0227b9b18\"\u003e\u003ccode\u003e3e7e23f\u003c/code\u003e\u003c/a\u003e fix interpolation test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/17aadfd8aea2cdae3bf0dbab94b1ca0926aada6c\"\u003e\u003ccode\u003e17aadfd\u003c/code\u003e\u003c/a\u003e update docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/68d5bca31325f58c95f5231c066181d98bae8e25\"\u003e\u003ccode\u003e68d5bca\u003c/code\u003e\u003c/a\u003e update lhci configs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/69dc12e77f9eefc3f70c2c62109d70e505e0cdbc\"\u003e\u003ccode\u003e69dc12e\u003c/code\u003e\u003c/a\u003e fix core import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/f18aeafd4ba541092b844d793e5a49f218e00e17\"\u003e\u003ccode\u003ef18aeaf\u003c/code\u003e\u003c/a\u003e update deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/b94e7872052e1f830b25a6fc99e3c5adebda5588\"\u003e\u003ccode\u003eb94e787\u003c/code\u003e\u003c/a\u003e use node24 as a default runner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/4198ec75af54c544d055c0efad7a45546398a325\"\u003e\u003ccode\u003e4198ec7\u003c/code\u003e\u003c/a\u003e Fix typo in input description\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/f82fba5af0cc5162589cf5563b05bc284149f197\"\u003e\u003ccode\u003ef82fba5\u003c/code\u003e\u003c/a\u003e Update README.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/847bd5ec450b5c4052a530597bf8e4bc7de36c35\"\u003e\u003ccode\u003e847bd5e\u003c/code\u003e\u003c/a\u003e README.md: bump GitHub action workflows\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/treosh/lighthouse-ci-action/compare/fcd65974f7c4c2bf0ee9d09b84d2489183c29726...3e7e23fb74242897f95c0ba9cabad3d0227b9b18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.55 to 1.0.93\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.93\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.92\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.91\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse pinned bun binary for post-steps when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1190\"\u003eanthropics/claude-code-action#1190\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.91\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.91\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.90\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: forward MCP_TIMEOUT, MCP_TOOL_TIMEOUT, MAX_MCP_OUTPUT_TOKENS to action step by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1162\"\u003eanthropics/claude-code-action#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003esecurity: reject PATH_TO_CLAUDE_CODE_EXECUTABLE with control characters by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1185\"\u003eanthropics/claude-code-action#1185\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.90\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.90\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.89\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: skip token revocation when no token was acquired by \u003ca href=\"https://github.com/Dave-London\"\u003e\u003ccode\u003e@​Dave-London\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/918\"\u003eanthropics/claude-code-action#918\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse env vars for workflow_run context values in example workflows by \u003ca href=\"https://github.com/ddworken\"\u003e\u003ccode\u003e@​ddworken\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1125\"\u003eanthropics/claude-code-action#1125\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document include/exclude_comments_by_actor inputs by \u003ca href=\"https://github.com/yuribodo\"\u003e\u003ccode\u003e@​yuribodo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1130\"\u003eanthropics/claude-code-action#1130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use correct fallback type for reviewData in fetcher by \u003ca href=\"https://github.com/MaxwellCalkin\"\u003e\u003ccode\u003e@​MaxwellCalkin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1034\"\u003eanthropics/claude-code-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStrip OIDC token request env vars from Claude session by \u003ca href=\"https://github.com/chyipin\"\u003e\u003ccode\u003e@​chyipin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1011\"\u003eanthropics/claude-code-action#1011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip retries for non-retryable errors in retryWithBackoff by \u003ca href=\"https://github.com/ei-grad\"\u003e\u003ccode\u003e@​ei-grad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1082\"\u003eanthropics/claude-code-action#1082\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: restore ripgrep execute bits after bun install --production by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1163\"\u003eanthropics/claude-code-action#1163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: allow # in branch names for PR checkout and base restore by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1167\"\u003eanthropics/claude-code-action#1167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent hang in restoreConfigFromBase on repos with .gitmodules by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1166\"\u003eanthropics/claude-code-action#1166\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: strip shell comment lines before parsing claude_args by \u003ca href=\"https://github.com/VoidChecksum\"\u003e\u003ccode\u003e@​VoidChecksum\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1055\"\u003eanthropics/claude-code-action#1055\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: snapshot PR's .claude/ to .claude-pr/ before security restore by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1172\"\u003eanthropics/claude-code-action#1172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix prettier formatting by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1171\"\u003eanthropics/claude-code-action#1171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix prettier formatting in parse-sdk-options.test.ts by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1176\"\u003eanthropics/claude-code-action#1176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pin bun runtime config and improve log hygiene by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1174\"\u003eanthropics/claude-code-action#1174\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yuribodo\"\u003e\u003ccode\u003e@​yuribodo\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1130\"\u003eanthropics/claude-code-action#1130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MaxwellCalkin\"\u003e\u003ccode\u003e@​MaxwellCalkin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1034\"\u003eanthropics/claude-code-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chyipin\"\u003e\u003ccode\u003e@​chyipin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1011\"\u003eanthropics/claude-code-action#1011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ei-grad\"\u003e\u003ccode\u003e@​ei-grad\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1082\"\u003eanthropics/claude-code-action#1082\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1163\"\u003eanthropics/claude-code-action#1163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VoidChecksum\"\u003e\u003ccode\u003e@​VoidChecksum\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1055\"\u003eanthropics/claude-code-action#1055\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.89\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.89\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.88\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.88\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.88\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b47fd721da662d48c5680e154ad16a73ed74d2e0\"\u003e\u003ccode\u003eb47fd72\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.101 and Agent SDK to 0.2.101\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c26cb6427d54362f5fd9834ac6818cbaaf82490a\"\u003e\u003ccode\u003ec26cb64\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.100 and Agent SDK to 0.2.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/657fb7c9c986158a19624b357bcbc8c6deb83598\"\u003e\u003ccode\u003e657fb7c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.98 and Agent SDK to 0.2.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/2ff1acb3ee319fa302837dad6e17c2f36c0d98ea\"\u003e\u003ccode\u003e2ff1acb\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.97 and Agent SDK to 0.2.97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b2fdd80112e5f140e097b11d7a3d9edf0b226fd0\"\u003e\u003ccode\u003eb2fdd80\u003c/code\u003e\u003c/a\u003e Use pinned bun binary for post-steps when allowed_non_write_users is set (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1190\"\u003e#1190\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/26ddc358fe3befff50c5ec2f80304c90c763f6f8\"\u003e\u003ccode\u003e26ddc35\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.96 and Agent SDK to 0.2.96\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/398370690eb38623ea077e8ccc687d81c9afe15d\"\u003e\u003ccode\u003e3983706\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.94 and Agent SDK to 0.2.94\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/6cad158a175744eb2e76f7f5fd108ec63145598c\"\u003e\u003ccode\u003e6cad158\u003c/code\u003e\u003c/a\u003e security: reject PATH_TO_CLAUDE_CODE_EXECUTABLE with control characters (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1185\"\u003e#1185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0f1fe5ef851a13d28734e675cf8504f540ba5d93\"\u003e\u003ccode\u003e0f1fe5e\u003c/code\u003e\u003c/a\u003e fix: forward MCP_TIMEOUT, MCP_TOOL_TIMEOUT, MAX_MCP_OUTPUT_TOKENS to action s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/6e2bd52842c65e914eba5c8badd17560bd26b5de\"\u003e\u003ccode\u003e6e2bd52\u003c/code\u003e\u003c/a\u003e fix: pin bun runtime config and improve log hygiene (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1174\"\u003e#1174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/edd85d61533cbba7b57ed0ca4af1750b1fdfd3c4...b47fd721da662d48c5680e154ad16a73ed74d2e0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.32.4 to 4.35.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.35.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.34.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.34.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.33.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.32.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.32.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to disable \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository property with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and the type \u0026quot;True/false\u0026quot; in the organization's settings. Then in the repository's settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to disable improved incremental analysis. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. This feature is not yet available on GitHub Enterprise Server. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3515\"\u003e#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3516\"\u003e#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which lowers the minimum disk space requirement for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e, enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3498\"\u003e#3498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which allows the \u003ccode\u003estart-proxy\u003c/code\u003e action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3512\"\u003e#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3503\"\u003e#3503\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3504\"\u003e#3504\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.5 - 02 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/c10b8064de6f491fea524254123dbe5e09572f13\"\u003e\u003ccode\u003ec10b806\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3782\"\u003e#3782\u003c/a\u003e from github/update-v4.35.1-d6d1743b8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/c5ffd0683786820677d054e3505e1c5bb4b8c227\"\u003e\u003ccode\u003ec5ffd06\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d6d1743b8ec7ecd94f78ad1ce4cb3d8d2ba58001\"\u003e\u003ccode\u003ed6d1743\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3781\"\u003e#3781\u003c/a\u003e from github/henrymercer/update-git-minimum-version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65d2efa7333ad65f97cc54be40f4cd18630f884c\"\u003e\u003ccode\u003e65d2efa\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/2437b20ab31021229573a66717323dd5c6ce9319\"\u003e\u003ccode\u003e2437b20\u003c/code\u003e\u003c/a\u003e Update minimum git version for overlay to 2.36.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ea5f71947c021286c99f61cc426a10d715fe4434\"\u003e\u003ccode\u003eea5f719\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3775\"\u003e#3775\u003c/a\u003e from github/dependabot/npm_and_yarn/node-forge-1.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/45ceeea896ba2293e10982f871198d1950ee13d6\"\u003e\u003ccode\u003e45ceeea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3777\"\u003e#3777\u003c/a\u003e from github/mergeback/v4.35.0-to-main-b8bb9f28\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/24448c98434f429f901d27db7ddae55eec5cc1c4\"\u003e\u003ccode\u003e24448c9\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7c510606312e5c68ac8b27c009e5254f226f5dfa\"\u003e\u003ccode\u003e7c51060\u003c/code\u003e\u003c/a\u003e Update changelog and version after v4.35.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b8bb9f28b8d3f992092362369c57161b755dea45\"\u003e\u003ccode\u003eb8bb9f2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3776\"\u003e#3776\u003c/a\u003e from github/update-v4.35.0-0078ad667\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/89a39a4e59826350b863aa6b6252a07ad50cf83e...c10b8064de6f491fea524254123dbe5e09572f13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/yuyu-111000/Slist/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyu-111000%2FSlist/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"},{"uuid":"4251035851","node_id":"PR_kwDOHvz5Q87R2yV3","number":1116,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-04-14T10:34:27.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-13T03:22:07.000Z","updated_at":"2026-04-14T10:34:29.000Z","time_to_close":112340,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v2.0...v2.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/GyulyVGC/sniffnet/pull/1116","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GyulyVGC%2Fsniffnet/issues/1116","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1116/packages"},{"uuid":"4244139113","node_id":"PR_kwDORKxwDc7RprEU","number":99,"state":"closed","title":"build(deps): Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-04-18T10:04:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-11T10:04:19.000Z","updated_at":"2026-04-18T10:04:20.000Z","time_to_close":604799,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/robertpopa22/mRemoteNG/pull/99","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/robertpopa22%2FmRemoteNG/issues/99","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/99/packages"},{"uuid":"4233435224","node_id":"PR_kwDOLvDTHM7RL0tv","number":53,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-04-14T15:54:00.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-09T15:54:04.000Z","updated_at":"2026-04-14T15:54:02.000Z","time_to_close":431996,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v2.0...v2.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/otsako-vpk/bloxstrap/pull/53","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/otsako-vpk%2Fbloxstrap/issues/53","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/53/packages"},{"uuid":"3546931136","node_id":"PR_kwDOLrNzL86vYmAx","number":4594,"state":"open","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.3 to 2.0","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2025-10-23T23:15:30.000Z","updated_at":"2025-10-23T23:18:19.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.3","new_version":"2.0","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.3 to 2.0.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.3...v2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.3\u0026new-version=2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/RSSNext/Folo/pull/4594","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RSSNext%2FFolo/issues/4594","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4594/packages"},{"uuid":"3532732687","node_id":"PR_kwDOQFzKOc6upbOJ","number":6,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2025-10-23T21:28:30.000Z","author_association":null,"state_reason":null,"created_at":"2025-10-20T14:45:14.000Z","updated_at":"2025-10-23T21:28:31.000Z","time_to_close":283396,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/icexghoul-art/bloxstrap-overlay/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/icexghoul-art%2Fbloxstrap-overlay/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"3395730048","node_id":"PR_kwDOPZpyu86ndzzn","number":6,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2025-09-09T18:03:57.000Z","author_association":"NONE","state_reason":null,"created_at":"2025-09-08T21:01:53.000Z","updated_at":"2025-09-09T18:03:59.000Z","time_to_close":75724,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/999MS-LLC/WaveStrap/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/999MS-LLC%2FWaveStrap/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"2751828545","node_id":"PR_kwDOMm6W4s6kBZJB","number":865,"state":"open","title":"build(deps): bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-18T03:10:26.000Z","updated_at":"2025-08-18T03:10:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Class-Widgets/Class-Widgets/pull/865","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Class-Widgets%2FClass-Widgets/issues/865","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/865/packages"},{"uuid":"3312815773","node_id":"PR_kwDOACamOs6jMTiP","number":4409,"state":"open","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-12T06:58:41.000Z","updated_at":"2025-08-25T10:30:58.012Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/geany/geany/pull/4409","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/geany%2Fgeany/issues/4409","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4409/packages"},{"uuid":"2729251698","node_id":"PR_kwDOLrNzL86irRNy","number":4313,"state":"open","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-08T00:08:55.000Z","updated_at":"2025-08-08T00:08:56.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/RSSNext/Folo/pull/4313","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RSSNext%2FFolo/issues/4313","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4313/packages"},{"uuid":"2724147390","node_id":"PR_kwDOG7WOB86iXzC-","number":920,"state":"closed","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":"2025-08-11T08:37:47.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T12:02:16.000Z","updated_at":"2025-08-11T08:37:47.000Z","time_to_close":419731,"merged_at":"2025-08-11T08:37:47.000Z","merged_by":"markuslf","closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae...ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Linuxfabrik/monitoring-plugins/pull/920","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Linuxfabrik%2Fmonitoring-plugins/issues/920","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/920/packages"},{"uuid":"2723117034","node_id":"PR_kwDOOJ8c986iT3fq","number":2,"state":"open","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T05:48:05.000Z","updated_at":"2025-08-06T05:48:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/seventeenstrap-holdings/seventeenstrap/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/seventeenstrap-holdings%2Fseventeenstrap/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"2722910760","node_id":"PR_kwDOHvz5Q86iTFIo","number":925,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2025-08-28T14:35:53.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T03:06:48.000Z","updated_at":"2025-08-28T14:35:53.000Z","time_to_close":1942145,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/GyulyVGC/sniffnet/pull/925","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GyulyVGC%2Fsniffnet/issues/925","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/925/packages"},{"uuid":"2722842513","node_id":"PR_kwDOKZNc8s6iS0eR","number":537,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":"2025-08-06T06:56:10.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T02:08:41.000Z","updated_at":"2025-08-06T06:56:10.000Z","time_to_close":17249,"merged_at":"2025-08-06T06:56:10.000Z","merged_by":"loganmc10","closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/gopher64/gopher64/pull/537","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gopher64%2Fgopher64/issues/537","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/537/packages"}],"issue_packages":[{"old_version":"1.1","new_version":"2.2","update_type":null,"path":null,"pr_created_at":"2026-06-10T00:43:37.000Z","version_change":"1.1 → 2.2","issue":{"uuid":"4626835411","node_id":"PR_kwDOJW3Oms7kn6_j","number":616,"state":"open","title":"ci(deps):(deps): bump signpath/github-action-submit-signing-request from 1.1 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-10T00:43:37.000Z","updated_at":"2026-06-10T00:43:37.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps):(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Writeopia/Writeopia/pull/616","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Writeopia%2FWriteopia/issues/616","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/616/packages"}},{"old_version":"1.1","new_version":"2.2","update_type":null,"path":null,"pr_created_at":"2026-05-22T22:31:38.000Z","version_change":"1.1 → 2.2","issue":{"uuid":"4505924541","node_id":"PR_kwDOSQOM-s7egtW2","number":1,"state":"open","title":"chore(ci): bump signpath/github-action-submit-signing-request from 1.1 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-22T22:31:38.000Z","updated_at":"2026-05-22T22:32:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(ci)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Juanalejo01/eclesia-presenter/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Juanalejo01%2Feclesia-presenter/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"1","new_version":"2","update_type":null,"path":null,"pr_created_at":"2026-05-03T11:09:31.000Z","version_change":"1 → 2","issue":{"uuid":"4371583184","node_id":"PR_kwDORZlmD87XwutZ","number":4,"state":"open","title":"ci(deps): bump signpath/github-action-submit-signing-request from 1 to 2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-03T11:09:31.000Z","updated_at":"2026-05-03T11:09:31.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"ci(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1","new_version":"2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1 to 2.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/releases\"\u003esignpath/github-action-submit-signing-request's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 2.x\u003c/h2\u003e\n\u003cp\u003eSee the \u003ca href=\"https://docs.signpath.io/changelog/?component=github_actions_action\"\u003echangelog\u003c/a\u003e for details.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1...v2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1\u0026new-version=2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/skynett81/3dprintforge/pull/4","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/skynett81%2F3dprintforge/issues/4","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4/packages"}},{"old_version":"2.0","new_version":"2.2","update_type":null,"path":null,"pr_created_at":"2026-04-23T22:22:08.000Z","version_change":"2.0 → 2.2","issue":{"uuid":"4319224629","node_id":"PR_kwDOQhNALM7VJHEa","number":88,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-23T22:22:08.000Z","updated_at":"2026-04-23T22:22:09.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":11,"packages":[{"name":"step-security/harden-runner","old_version":"2.16.1","new_version":"2.19.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.3.0","new_version":"6.4.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.4","new_version":"5.0.5","repository_url":"https://github.com/actions/cache"},{"name":"actions/upload-artifact","old_version":"7.0.0","new_version":"7.0.1","repository_url":"https://github.com/actions/upload-artifact"},{"name":"r0adkll/upload-google-play","old_version":"1.1.3","new_version":"1.1.5","repository_url":"https://github.com/r0adkll/upload-google-play"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.2","new_version":"4.1.3","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"anthropics/claude-code-action","old_version":"1.0.89","new_version":"1.0.104","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.35.1","new_version":"4.35.2","repository_url":"https://github.com/github/codeql-action"},{"name":"cloudflare/wrangler-action","old_version":"3.14.1","new_version":"3.15.0","repository_url":"https://github.com/cloudflare/wrangler-action"},{"name":"docker/build-push-action","old_version":"7.0.0","new_version":"7.1.0","repository_url":"https://github.com/docker/build-push-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 11 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.16.1` | `2.19.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.4` | `5.0.5` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` |\n| [r0adkll/upload-google-play](https://github.com/r0adkll/upload-google-play) | `1.1.3` | `1.1.5` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.2` | `4.1.3` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.89` | `1.0.104` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.35.1` | `4.35.2` |\n| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `3.14.1` | `3.15.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.1.0` |\n\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.19.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.19.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eNew Runner Support\u003c/h3\u003e\n\u003cp\u003eHarden-Runner now supports Depot, Blacksmith, Namespace, and WarpBuild runners with the same egress monitoring, runtime monitoring, and policy enforcement available on GitHub-hosted runners.\u003c/p\u003e\n\u003ch3\u003eAutomated Incident Response for Supply Chain Attacks\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGlobal block list: Outbound connections to known malicious domains and IPs are now blocked even in audit mode.\u003c/li\u003e\n\u003cli\u003eSystem-defined detection rules: Harden-Runner will trigger lockdown mode when a high risk event is detected during an active supply chain attack (for example, a process reading the memory of the runner worker process, a common technique for stealing GitHub Actions secrets).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cp\u003eWindows and macOS: stability and reliability fixes\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.18.0...v2.19.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.18.0...v2.19.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eGlobal Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.\u003c/p\u003e\n\u003cp\u003eDeploy on Self-Hosted VM: Added \u003ccode\u003edeploy-on-self-hosted-vm\u003c/code\u003e input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/8d3c67de8e2fe68ef647c8db1e6a09f647780f40\"\u003e\u003ccode\u003e8d3c67d\u003c/code\u003e\u003c/a\u003e Release v2.19.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/661\"\u003e#661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003e\u003ccode\u003e6c3c2f2\u003c/code\u003e\u003c/a\u003e Feature/deploy on self hosted vm (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/658\"\u003e#658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/fe104658747b27e96e4f7e80cd0a94068e53901d...8d3c67de8e2fe68ef647c8db1e6a09f647780f40\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.3.0 to 6.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js versions in versions.yml and bump package to v6.4.0  by \u003ca href=\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e@​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1533\"\u003eactions/setup-node#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.4.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003e\u003ccode\u003e48b55a0\u003c/code\u003e\u003c/a\u003e Update Node.js versions in versions.yml and bump package to v6.4.0 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1533\"\u003e#1533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/ab72c7e7eba0eaa11f8cab0f5679243900c2cac9\"\u003e\u003ccode\u003eab72c7e\u003c/code\u003e\u003c/a\u003e Upgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1525\"\u003e#1525\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.4 to 5.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ts-http-runtime dependency by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1747\"\u003eactions/cache#1747\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.5\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003e\u003ccode\u003e27d5ce7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1747\"\u003e#1747\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/f280785d7b6e1884c7d12b9136eb0f4a1574fcfd\"\u003e\u003ccode\u003ef280785\u003c/code\u003e\u003c/a\u003e licensed changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/619aeb1606e195be0b36fd0ff68dcf1aff6b65a7\"\u003e\u003ccode\u003e619aeb1\u003c/code\u003e\u003c/a\u003e npm run build generated dist files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/bcf16c2893940a4899761e55c7ac3c1cf88a04f6\"\u003e\u003ccode\u003ebcf16c2\u003c/code\u003e\u003c/a\u003e Update ts-http-runtime to 0.3.5\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `r0adkll/upload-google-play` from 1.1.3 to 1.1.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/r0adkll/upload-google-play/releases\"\u003er0adkll/upload-google-play's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.1.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix track/tracks and releaseFile/releaseFiles deprecation handling by \u003ca href=\"https://github.com/r0adkll\"\u003e\u003ccode\u003e@​r0adkll\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/264\"\u003er0adkll/upload-google-play#264\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/v1...v1.1.5\"\u003ehttps://github.com/r0adkll/upload-google-play/compare/v1...v1.1.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.1.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdds info about enabling Google Play Android Developer API by \u003ca href=\"https://github.com/Rufus125\"\u003e\u003ccode\u003e@​Rufus125\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/219\"\u003er0adkll/upload-google-play#219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate service account setup instructions by \u003ca href=\"https://github.com/lacop11\"\u003e\u003ccode\u003e@​lacop11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/225\"\u003er0adkll/upload-google-play#225\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExport commited editId for further modifications by \u003ca href=\"https://github.com/Swisyn\"\u003e\u003ccode\u003e@​Swisyn\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/233\"\u003er0adkll/upload-google-play#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBumping github actions due to deprecated node-version by \u003ca href=\"https://github.com/FrankBurmo\"\u003e\u003ccode\u003e@​FrankBurmo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/234\"\u003er0adkll/upload-google-play#234\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAbility to retain version codes from previous releases by \u003ca href=\"https://github.com/marin-marsic\"\u003e\u003ccode\u003e@​marin-marsic\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/237\"\u003er0adkll/upload-google-play#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FAQ item for \u0026quot;Precondition check failed\u0026quot; error during production track publishing by \u003ca href=\"https://github.com/juancdominici\"\u003e\u003ccode\u003e@​juancdominici\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/240\"\u003er0adkll/upload-google-play#240\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for uploading to multiple tracks by \u003ca href=\"https://github.com/X1nto\"\u003e\u003ccode\u003e@​X1nto\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/241\"\u003er0adkll/upload-google-play#241\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Node24 by \u003ca href=\"https://github.com/osniel\"\u003e\u003ccode\u003e@​osniel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/259\"\u003er0adkll/upload-google-play#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rufus125\"\u003e\u003ccode\u003e@​Rufus125\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/219\"\u003er0adkll/upload-google-play#219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lacop11\"\u003e\u003ccode\u003e@​lacop11\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/225\"\u003er0adkll/upload-google-play#225\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Swisyn\"\u003e\u003ccode\u003e@​Swisyn\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/233\"\u003er0adkll/upload-google-play#233\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FrankBurmo\"\u003e\u003ccode\u003e@​FrankBurmo\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/234\"\u003er0adkll/upload-google-play#234\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marin-marsic\"\u003e\u003ccode\u003e@​marin-marsic\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/237\"\u003er0adkll/upload-google-play#237\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/juancdominici\"\u003e\u003ccode\u003e@​juancdominici\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/240\"\u003er0adkll/upload-google-play#240\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/X1nto\"\u003e\u003ccode\u003e@​X1nto\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/241\"\u003er0adkll/upload-google-play#241\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/osniel\"\u003e\u003ccode\u003e@​osniel\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/pull/259\"\u003er0adkll/upload-google-play#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/v1...v1.1.4\"\u003ehttps://github.com/r0adkll/upload-google-play/compare/v1...v1.1.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/e738b9dd8f2476ea806d921b64aacd24f34515a5\"\u003e\u003ccode\u003ee738b9d\u003c/code\u003e\u003c/a\u003e Fix track/tracks and releaseFile/releaseFiles deprecation handling (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/264\"\u003e#264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/7f5b759879c088a86faf85d18779f7f14e79a086\"\u003e\u003ccode\u003e7f5b759\u003c/code\u003e\u003c/a\u003e Upgrade to Node24 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/259\"\u003e#259\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/41571de6d8a402a9565f0fc067d3ecc5f235a4c9\"\u003e\u003ccode\u003e41571de\u003c/code\u003e\u003c/a\u003e Bump picomatch from 2.3.1 to 2.3.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/258\"\u003e#258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/c5da46087f3bfa0d1a7b55bcc4716affe820488c\"\u003e\u003ccode\u003ec5da460\u003c/code\u003e\u003c/a\u003e Bump flatted from 3.2.7 to 3.4.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/257\"\u003e#257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/2540268935c2f0a3755cf8e882dbb3c15b427943\"\u003e\u003ccode\u003e2540268\u003c/code\u003e\u003c/a\u003e Add support for uploading to multiple tracks (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/241\"\u003e#241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/4d9bcc407da90cc25912a5b3925e53335f130540\"\u003e\u003ccode\u003e4d9bcc4\u003c/code\u003e\u003c/a\u003e Bump minimatch, \u003ccode\u003e@​typescript-eslint/eslint-plugin\u003c/code\u003e and \u003ccode\u003e@​typescript-eslint/parse\u003c/code\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/0b90f0d9c4c6a17ad49934892e18f099f35fdd3e\"\u003e\u003ccode\u003e0b90f0d\u003c/code\u003e\u003c/a\u003e Bump qs from 6.14.1 to 6.14.2 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/254\"\u003e#254\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/e59beb0116a7cb67c48a28f202414a50ac0a78f3\"\u003e\u003ccode\u003ee59beb0\u003c/code\u003e\u003c/a\u003e Bump lodash from 4.17.21 to 4.17.23 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/253\"\u003e#253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/463a558cc257c8712c085d74fbf643930bb755f5\"\u003e\u003ccode\u003e463a558\u003c/code\u003e\u003c/a\u003e Bump qs from 6.11.2 to 6.14.1 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/252\"\u003e#252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/r0adkll/upload-google-play/commit/62b6d3171db86f8ae8e6699690f98c781a1e3bd6\"\u003e\u003ccode\u003e62b6d31\u003c/code\u003e\u003c/a\u003e Bump jws from 4.0.0 to 4.0.1 (\u003ca href=\"https://redirect.github.com/r0adkll/upload-google-play/issues/250\"\u003e#250\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/r0adkll/upload-google-play/compare/935ef9c68bb393a8e6116b1575626a7f5be3a7fb...e738b9dd8f2476ea806d921b64aacd24f34515a5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.2 to 4.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.3\u003c/h2\u003e\n\u003cp\u003eThere is a bug in \u003ccode\u003erunuser\u003c/code\u003e that converts all \u003ccode\u003e-c\u003c/code\u003e (even after \u003ccode\u003e--\u003c/code\u003e) into \u003ccode\u003e--command\u003c/code\u003e which \u003ccode\u003ebash\u003c/code\u003e doesn't recognize. This release removes the \u003ccode\u003e-c\u003c/code\u003e flag entirely, bash would execute \u003ccode\u003e/build.sh\u003c/code\u003e as if it's a file. Hopefully, the behavior preserves. If not, maybe just switch to \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eRelevant PR: \u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51\"\u003eKSXGitHub/github-actions-deploy-aur#51\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003e\u003ccode\u003eda03e16\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ebash: --command: invalid option\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1\"\u003e\u003ccode\u003e3b403c7\u003c/code\u003e\u003c/a\u003e docs(readme): use the GitHub's note syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2\"\u003e\u003ccode\u003ee17cd79\u003c/code\u003e\u003c/a\u003e docs(readme): remove patreon\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/abe8ac26b51011c88be58c8809fd2ac674068ea5...da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.89 to 1.0.104\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.104\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.104\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.104\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.103\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.103\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.103\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.102\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore: bump oven-sh/setup-bun to v2.2.0 (Node.js 24) by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1238\"\u003eanthropics/claude-code-action#1238\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: nit updates to security.md by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1240\"\u003eanthropics/claude-code-action#1240\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.102\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.102\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.101\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.100\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Claude model from opus-4-6 to opus-4-7 by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1227\"\u003eanthropics/claude-code-action#1227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pass install.sh binary path to Agent SDK after 0.2.113 bump by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1235\"\u003eanthropics/claude-code-action#1235\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.99\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.98\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.97\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.96\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: handle fork PRs by fetching via refs/pull/N/head by \u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.95\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.94\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrepend system bin dirs to PATH when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1208\"\u003eanthropics/claude-code-action#1208\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b4d67413279fc18c6e5de930ae307c4f108714eb\"\u003e\u003ccode\u003eb4d6741\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.118 and Agent SDK to 0.2.118\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/4e5d8b13ca281a6d163cdb287d8917b216e00d6f\"\u003e\u003ccode\u003e4e5d8b1\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.117 and Agent SDK to 0.2.117\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/5d5c10a4f389689f992ea10bb14dcb6fcc83146d\"\u003e\u003ccode\u003e5d5c10a\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.116 and Agent SDK to 0.2.116\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/632a368e81692f2e33c14b7133a7ef56ae6d35e1\"\u003e\u003ccode\u003e632a368\u003c/code\u003e\u003c/a\u003e docs: nit updates to security.md (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1240\"\u003e#1240\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/4c682d8b65549056a671d1be4d37ac4832e53859\"\u003e\u003ccode\u003e4c682d8\u003c/code\u003e\u003c/a\u003e chore: bump oven-sh/setup-bun to v2.2.0 (Node.js 24) (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1238\"\u003e#1238\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/38ec876110f9fbf8b950c79f534430740c3ac009\"\u003e\u003ccode\u003e38ec876\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0d2971c794049856e777f4e8bb5a81623ec632d3\"\u003e\u003ccode\u003e0d2971c\u003c/code\u003e\u003c/a\u003e fix: pass install.sh binary path explicitly to Agent SDK (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1235\"\u003e#1235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c68f82cb113a70ad61a71a133e86642c51a403aa\"\u003e\u003ccode\u003ec68f82c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/78758edf84903744fffe01b3d17c12b8757b4454\"\u003e\u003ccode\u003e78758ed\u003c/code\u003e\u003c/a\u003e chore: bump model version in workflows (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1227\"\u003e#1227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3d45e8e941e1b2ad7b278c57482d9c5bf1f35b3\"\u003e\u003ccode\u003ec3d45e8\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/6e2bd52842c65e914eba5c8badd17560bd26b5de...b4d67413279fc18c6e5de930ae307c4f108714eb\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.35.1 to 4.35.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.35.2 - 15 Apr 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003e\u003ccode\u003e95e58e9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3824\"\u003e#3824\u003c/a\u003e from github/update-v4.35.2-d2e135a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/6f31bfe060e817d81e938dbec767969d20031e25\"\u003e\u003ccode\u003e6f31bfe\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d2e135a73a39154e3a231aeb49163c4661c5b8b1\"\u003e\u003ccode\u003ed2e135a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3823\"\u003e#3823\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/60abb65df09fcf213c398e064c8a80db1f15cdaf\"\u003e\u003ccode\u003e60abb65\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/5a0a562209255e956ad8aafcee303294e64eefa2\"\u003e\u003ccode\u003e5a0a562\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65216971a11ded447a6b76263d5a144519e5eee1\"\u003e\u003ccode\u003e6521697\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3820\"\u003e#3820\u003c/a\u003e from github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/3c45af2dd258e1623af1898da5c86545b514e028\"\u003e\u003ccode\u003e3c45af2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3821\"\u003e#3821\u003c/a\u003e from github/dependabot/npm_and_yarn/npm-minor-345b93...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f1c339364c12f922998186ed897e45e3b4ae8874\"\u003e\u003ccode\u003ef1c3393\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1024fc496c87e944a93e98d8cf2c09e2c7602a30\"\u003e\u003ccode\u003e1024fc4\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/9dd4cfed96030ccdfe1af4daf7a7964322704fed\"\u003e\u003ccode\u003e9dd4cfe\u003c/code\u003e\u003c/a\u003e Bump the npm-minor group across 1 directory with 6 updates\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cloudflare/wrangler-action` from 3.14.1 to 3.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/releases\"\u003ecloudflare/wrangler-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md\"\u003ecloudflare/wrangler-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/358\"\u003e#358\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cd6314a97b09d9a764e30cacd0870edc86f92986\"\u003e\u003ccode\u003ecd6314a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/penalosa\"\u003e\u003ccode\u003e@​penalosa\u003c/code\u003e\u003c/a\u003e! - Use \u003ccode\u003esecret bulk\u003c/code\u003e instead of deprecated \u003ccode\u003esecret:bulk\u003c/code\u003e command\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/351\"\u003e#351\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/4ff07f4310dc5067d84a254cd9af3d2e91df119e\"\u003e\u003ccode\u003e4ff07f4\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Use wrangler outputs for version upload and wrangler deploy\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/350\"\u003e#350\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e209094e624c6f6b418141b7e9d0ab7838d794a3\"\u003e\u003ccode\u003ee209094\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Handle failures in createGitHubDeployment and createGitHubJobSummary\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/345\"\u003e#345\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e819570b2d0a69816a1c2e9d2f2954e278748d80\"\u003e\u003ccode\u003ee819570\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - fix: Pages GitHub Deployment not triggering\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/325\"\u003e#325\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cada7a63124ded3471bef7e8001b76356b838e40\"\u003e\u003ccode\u003ecada7a6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Add GitHub deployments and job summaries for parity with pages-action\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/334\"\u003e#334\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9fed19aa4ed79946f009e8aad7437a922e62d523\"\u003e\u003ccode\u003e9fed19a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Bump default wrangler version to 3.90.0\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/319\"\u003e#319\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/59c04629408d58978884fadd18755f1a15f96157\"\u003e\u003ccode\u003e59c04629408d58978884fadd18755f1a15f96157\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/317\"\u003e#317\u003c/a\u003e: Generate a new output directory with a randomUUID in the tmpDir, so that when the action is executed multiple times, we use the artifacts from that run, opposed to the artifacts from a previous run.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/312\"\u003e#312\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\"\u003e\u003ccode\u003e122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - This reapplies \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/303\"\u003e303\u003c/a\u003e add parity with pages-action for pages deploy outputs. Thanks \u003ca href=\"https://github.com/courtney-sims\"\u003e\u003ccode\u003e@​courtney-sims\u003c/code\u003e\u003c/a\u003e! - Support pages-deployment-id, pages-environment, pages-deployment-alias-url and deployment-url outputs for Pages deploys when wrangler version is \u0026gt;=3.81.0. deployment-alias-url was also deprecated in favour of pages-deployment-alias.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003e\u003ccode\u003e9acf94a\u003c/code\u003e\u003c/a\u003e Automatic compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d181764e4b7652eb4377feec6bf15ddbb23210f0\"\u003e\u003ccode\u003ed181764\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/427\"\u003e#427\u003c/a\u003e from cloudflare/changeset-release/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/05015540800a657e380eba742bfa91a4ba2a2ca8\"\u003e\u003ccode\u003e0501554\u003c/code\u003e\u003c/a\u003e Version Packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d8f3eaa359cd9d866a9aa127280056692bc71ee0\"\u003e\u003ccode\u003ed8f3eaa\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/426\"\u003e#426\u003c/a\u003e from cloudflare/willtaylor/escalation-963-support-ver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Support version ranges and tags in wranglerVersion input\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cloudflare/wrangler-action/compare/da0e0dfe58b7a431659754fdf3f186c529afbe65...9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.0.0 to 7.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGit context \u003ca href=\"https://docs.docker.com/build/concepts/context/#url-queries\"\u003equery format\u003c/a\u003e support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.79.0 to 0.87.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.12 to 1.1.13 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1500\"\u003edocker/build-push-action#1500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.4.2 to 5.5.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1489\"\u003edocker/build-push-action#1489\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.3 to 3.4.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1491\"\u003edocker/build-push-action#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump glob from 10.3.12 to 10.5.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1490\"\u003edocker/build-push-action#1490\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump handlebars from 4.7.8 to 4.7.9 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1497\"\u003edocker/build-push-action#1497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.23 to 4.18.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1510\"\u003edocker/build-push-action#1510\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump picomatch from 4.0.3 to 4.0.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1496\"\u003edocker/build-push-action#1496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.23.0 to 6.24.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1486\"\u003edocker/build-push-action#1486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.1 to 7.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1509\"\u003edocker/build-push-action#1509\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003e\u003ccode\u003ebcafcac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1509\"\u003e#1509\u003c/a\u003e from docker/dependabot/npm_and_yarn/vite-7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/18e62f1158d9c45a4a84a58a6828d21f8ed3644b\"\u003e\u003ccode\u003e18e62f1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1510\"\u003e#1510\u003c/a\u003e from docker/dependabot/npm_and_yarn/lodash-4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/46580d2c9d43b0888270cb6fa90956e483de56fc\"\u003e\u003ccode\u003e46580d2\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/3f80b252ca2331f6ec3e890f4346b5506ee1dc81\"\u003e\u003ccode\u003e3f80b25\u003c/code\u003e\u003c/a\u003e chore(deps): Bump lodash from 4.17.23 to 4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/efeec9557c40a646afe433e39a1e94ca689103f0\"\u003e\u003ccode\u003eefeec95\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1505\"\u003e#1505\u003c/a\u003e from crazy-max/refactor-git-context\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ddf04b08eb12882258ed936fea4a2806754ff349\"\u003e\u003ccode\u003eddf04b0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1511\"\u003e#1511\u003c/a\u003e from docker/dependabot/github_actions/crazy-max-dot-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/db08d97a08e4a0d15f85d1c4e64dfd5f88cbe1a9\"\u003e\u003ccode\u003edb08d97\u003c/code\u003e\u003c/a\u003e chore(deps): Bump the crazy-max-dot-github group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ef1fb9688fc3626d0fd5e462f502cbbdc6456feb\"\u003e\u003ccode\u003eef1fb96\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1508\"\u003e#1508\u003c/a\u003e from docker/dependabot/github_actions/docker/login-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/2d8f2a1a378a5c302dcd7b2b4326cefa24180bb1\"\u003e\u003ccode\u003e2d8f2a1\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/919ac7bd7d1aa8cb13fe4de76545abea8d8b5ed2\"\u003e\u003ccode\u003e919ac7b\u003c/code\u003e\u003c/a\u003e fix test since secrets are not written to temp path anymore\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/camillanapoles/super-productivity/pull/88","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/camillanapoles%2Fsuper-productivity/issues/88","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/88/packages"}},{"old_version":"2.0","new_version":"2.2","update_type":null,"path":null,"pr_created_at":"2026-04-20T07:19:57.000Z","version_change":"2.0 → 2.2","issue":{"uuid":"4293825180","node_id":"PR_kwDOBKnnxc7T2l-3","number":7285,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group with 10 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-20T07:19:57.000Z","updated_at":"2026-04-20T07:23:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":10,"packages":[{"name":"step-security/harden-runner","old_version":"2.16.1","new_version":"2.18.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.3.0","new_version":"6.4.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.4","new_version":"5.0.5","repository_url":"https://github.com/actions/cache"},{"name":"actions/upload-artifact","old_version":"7.0.0","new_version":"7.0.1","repository_url":"https://github.com/actions/upload-artifact"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.2","new_version":"4.1.3","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"anthropics/claude-code-action","old_version":"1.0.89","new_version":"1.0.101","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.35.1","new_version":"4.35.2","repository_url":"https://github.com/github/codeql-action"},{"name":"cloudflare/wrangler-action","old_version":"3.14.1","new_version":"3.15.0","repository_url":"https://github.com/cloudflare/wrangler-action"},{"name":"docker/build-push-action","old_version":"7.0.0","new_version":"7.1.0","repository_url":"https://github.com/docker/build-push-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 10 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.16.1` | `2.18.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.3.0` | `6.4.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.4` | `5.0.5` |\n| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `7.0.0` | `7.0.1` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.2` | `4.1.3` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.89` | `1.0.101` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.35.1` | `4.35.2` |\n| [cloudflare/wrangler-action](https://github.com/cloudflare/wrangler-action) | `3.14.1` | `3.15.0` |\n| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.0.0` | `7.1.0` |\n\nUpdates `step-security/harden-runner` from 2.16.1 to 2.18.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.18.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eGlobal Block List: During supply chain incidents like the recent axios and trivy compromises, StepSecurity will add known malicious domains and IP addresses (IOCs) to a global block list. These will be automatically blocked, even in audit mode, providing immediate protection without requiring any workflow changes.\u003c/p\u003e\n\u003cp\u003eDeploy on Self-Hosted VM: Added \u003ccode\u003edeploy-on-self-hosted-vm\u003c/code\u003e input that allows the Harden Runner agent to be installed directly on ephemeral self-hosted Linux runner VMs at workflow runtime. This is intended as an alternative when baking the agent into the VM image is not possible.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.17.0...v2.18.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003e\u003ccode\u003e6c3c2f2\u003c/code\u003e\u003c/a\u003e Feature/deploy on self hosted vm (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/658\"\u003e#658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/fe104658747b27e96e4f7e80cd0a94068e53901d...6c3c2f2c1c457b00c10c4848d6f5491db3b629df\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.3.0 to 6.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.4.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies by \u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate Node.js versions in versions.yml and bump package to v6.4.0  by \u003ca href=\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e@​priya-kinthali\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1533\"\u003eactions/setup-node#1533\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1525\"\u003eactions/setup-node#1525\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.4.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.4.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003e\u003ccode\u003e48b55a0\u003c/code\u003e\u003c/a\u003e Update Node.js versions in versions.yml and bump package to v6.4.0 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1533\"\u003e#1533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/ab72c7e7eba0eaa11f8cab0f5679243900c2cac9\"\u003e\u003ccode\u003eab72c7e\u003c/code\u003e\u003c/a\u003e Upgrade \u003ca href=\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e dependencies (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1525\"\u003e#1525\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/53b83947a5a98c8d113130e565377fae1a50d02f...48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.4 to 5.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.5\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ts-http-runtime dependency by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1747\"\u003eactions/cache#1747\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.5\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.5\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003e\u003ccode\u003e27d5ce7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1747\"\u003e#1747\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/f280785d7b6e1884c7d12b9136eb0f4a1574fcfd\"\u003e\u003ccode\u003ef280785\u003c/code\u003e\u003c/a\u003e licensed changes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/619aeb1606e195be0b36fd0ff68dcf1aff6b65a7\"\u003e\u003ccode\u003e619aeb1\u003c/code\u003e\u003c/a\u003e npm run build generated dist files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/bcf16c2893940a4899761e55c7ac3c1cf88a04f6\"\u003e\u003ccode\u003ebcf16c2\u003c/code\u003e\u003c/a\u003e Update ts-http-runtime to 0.3.5\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/cache/compare/668228422ae6a00e4ad889ee87cd7109ec5666a7...27d5ce7f107fe9357f9df03efb73ab90386fccae\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/upload-artifact` from 7.0.0 to 7.0.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca href=\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca href=\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e from actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e Include changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e Readme: bump all the example versions to v7 (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e Update the readme with direct upload details (\u003ca href=\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.2 to 4.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.3\u003c/h2\u003e\n\u003cp\u003eThere is a bug in \u003ccode\u003erunuser\u003c/code\u003e that converts all \u003ccode\u003e-c\u003c/code\u003e (even after \u003ccode\u003e--\u003c/code\u003e) into \u003ccode\u003e--command\u003c/code\u003e which \u003ccode\u003ebash\u003c/code\u003e doesn't recognize. This release removes the \u003ccode\u003e-c\u003c/code\u003e flag entirely, bash would execute \u003ccode\u003e/build.sh\u003c/code\u003e as if it's a file. Hopefully, the behavior preserves. If not, maybe just switch to \u003ccode\u003esu\u003c/code\u003e or \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eRelevant PR: \u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/51\"\u003eKSXGitHub/github-actions-deploy-aur#51\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003e\u003ccode\u003eda03e16\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003ebash: --command: invalid option\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/51\"\u003e#51\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/3b403c740ae5e446b747b45451ec68665428dab1\"\u003e\u003ccode\u003e3b403c7\u003c/code\u003e\u003c/a\u003e docs(readme): use the GitHub's note syntax\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/e17cd797381bddd766236d808302398b090398d2\"\u003e\u003ccode\u003ee17cd79\u003c/code\u003e\u003c/a\u003e docs(readme): remove patreon\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/abe8ac26b51011c88be58c8809fd2ac674068ea5...da03e160361ce01bf087e790b6ffd196d7dccff7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.89 to 1.0.101\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.101\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.101\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.100\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Claude model from opus-4-6 to opus-4-7 by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1227\"\u003eanthropics/claude-code-action#1227\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pass install.sh binary path to Agent SDK after 0.2.113 bump by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1235\"\u003eanthropics/claude-code-action#1235\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.100\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.99\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.99\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.98\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.98\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.97\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.97\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.96\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: handle fork PRs by fetching via refs/pull/N/head by \u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/stakeswky\"\u003e\u003ccode\u003e@​stakeswky\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/963\"\u003eanthropics/claude-code-action#963\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.96\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.95\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.95\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.94\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrepend system bin dirs to PATH when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1208\"\u003eanthropics/claude-code-action#1208\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.94\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.94\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.93\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.92\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.91\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse pinned bun binary for post-steps when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1190\"\u003eanthropics/claude-code-action#1190\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/38ec876110f9fbf8b950c79f534430740c3ac009\"\u003e\u003ccode\u003e38ec876\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.114 and Agent SDK to 0.2.114\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0d2971c794049856e777f4e8bb5a81623ec632d3\"\u003e\u003ccode\u003e0d2971c\u003c/code\u003e\u003c/a\u003e fix: pass install.sh binary path explicitly to Agent SDK (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1235\"\u003e#1235\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c68f82cb113a70ad61a71a133e86642c51a403aa\"\u003e\u003ccode\u003ec68f82c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.113 and Agent SDK to 0.2.113\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/78758edf84903744fffe01b3d17c12b8757b4454\"\u003e\u003ccode\u003e78758ed\u003c/code\u003e\u003c/a\u003e chore: bump model version in workflows (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1227\"\u003e#1227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3d45e8e941e1b2ad7b278c57482d9c5bf1f35b3\"\u003e\u003ccode\u003ec3d45e8\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.112 and Agent SDK to 0.2.112\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/931e62027356f4c337273719db085805456e53cc\"\u003e\u003ccode\u003e931e620\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.111 and Agent SDK to 0.2.111\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/905d4eb99ab3d43143d74fb0dcae537f29ac330a\"\u003e\u003ccode\u003e905d4eb\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.110 and Agent SDK to 0.2.110\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/5fb899572b81d2bb648d4d187173a2f423a9677c\"\u003e\u003ccode\u003e5fb8995\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.109 and Agent SDK to 0.2.109\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c3bf66dbc27ae48bb05f3baa188d7a8676566a73\"\u003e\u003ccode\u003ec3bf66d\u003c/code\u003e\u003c/a\u003e fix: handle fork PRs by fetching via refs/pull/N/head (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/962\"\u003e#962\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/963\"\u003e#963\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/39431830520a7ae6c0c572f11a7707e7043325e3\"\u003e\u003ccode\u003e3943183\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.108 and Agent SDK to 0.2.108\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/6e2bd52842c65e914eba5c8badd17560bd26b5de...38ec876110f9fbf8b950c79f534430740c3ac009\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.35.1 to 4.35.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cp\u003eNo user facing changes.\u003c/p\u003e\n\u003ch2\u003e4.35.2 - 15 Apr 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2\"\u003e2.25.2\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3823\"\u003e#3823\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003e\u003ccode\u003e95e58e9\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3824\"\u003e#3824\u003c/a\u003e from github/update-v4.35.2-d2e135a73\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/6f31bfe060e817d81e938dbec767969d20031e25\"\u003e\u003ccode\u003e6f31bfe\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d2e135a73a39154e3a231aeb49163c4661c5b8b1\"\u003e\u003ccode\u003ed2e135a\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3823\"\u003e#3823\u003c/a\u003e from github/update-bundle/codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/60abb65df09fcf213c398e064c8a80db1f15cdaf\"\u003e\u003ccode\u003e60abb65\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/5a0a562209255e956ad8aafcee303294e64eefa2\"\u003e\u003ccode\u003e5a0a562\u003c/code\u003e\u003c/a\u003e Update default bundle to codeql-bundle-v2.25.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65216971a11ded447a6b76263d5a144519e5eee1\"\u003e\u003ccode\u003e6521697\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3820\"\u003e#3820\u003c/a\u003e from github/dependabot/github_actions/dot-github/wor...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/3c45af2dd258e1623af1898da5c86545b514e028\"\u003e\u003ccode\u003e3c45af2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3821\"\u003e#3821\u003c/a\u003e from github/dependabot/npm_and_yarn/npm-minor-345b93...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/f1c339364c12f922998186ed897e45e3b4ae8874\"\u003e\u003ccode\u003ef1c3393\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/1024fc496c87e944a93e98d8cf2c09e2c7602a30\"\u003e\u003ccode\u003e1024fc4\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/9dd4cfed96030ccdfe1af4daf7a7964322704fed\"\u003e\u003ccode\u003e9dd4cfe\u003c/code\u003e\u003c/a\u003e Bump the npm-minor group across 1 directory with 6 updates\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/c10b8064de6f491fea524254123dbe5e09572f13...95e58e9a2cdfd71adc6e0353d5c52f41a045d225\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cloudflare/wrangler-action` from 3.14.1 to 3.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/releases\"\u003ecloudflare/wrangler-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/cloudflare/wrangler-action/blob/main/CHANGELOG.md\"\u003ecloudflare/wrangler-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/426\"\u003e#426\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/WillTaylorDev\"\u003e\u003ccode\u003e@​WillTaylorDev\u003c/code\u003e\u003c/a\u003e! - Support version ranges and tags in \u003ccode\u003ewranglerVersion\u003c/code\u003e input. You can now set \u003ccode\u003ewranglerVersion\u003c/code\u003e to values like \u003ccode\u003e4\u003c/code\u003e, \u003ccode\u003e^4.0.0\u003c/code\u003e, \u003ccode\u003e4.x\u003c/code\u003e, or \u003ccode\u003elatest\u003c/code\u003e instead of only exact versions like \u003ccode\u003e4.81.0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/358\"\u003e#358\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cd6314a97b09d9a764e30cacd0870edc86f92986\"\u003e\u003ccode\u003ecd6314a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/penalosa\"\u003e\u003ccode\u003e@​penalosa\u003c/code\u003e\u003c/a\u003e! - Use \u003ccode\u003esecret bulk\u003c/code\u003e instead of deprecated \u003ccode\u003esecret:bulk\u003c/code\u003e command\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.14.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/351\"\u003e#351\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/4ff07f4310dc5067d84a254cd9af3d2e91df119e\"\u003e\u003ccode\u003e4ff07f4\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Use wrangler outputs for version upload and wrangler deploy\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/350\"\u003e#350\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e209094e624c6f6b418141b7e9d0ab7838d794a3\"\u003e\u003ccode\u003ee209094\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Handle failures in createGitHubDeployment and createGitHubJobSummary\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/345\"\u003e#345\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/e819570b2d0a69816a1c2e9d2f2954e278748d80\"\u003e\u003ccode\u003ee819570\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - fix: Pages GitHub Deployment not triggering\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.13.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/325\"\u003e#325\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/cada7a63124ded3471bef7e8001b76356b838e40\"\u003e\u003ccode\u003ecada7a6\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Add GitHub deployments and job summaries for parity with pages-action\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/334\"\u003e#334\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9fed19aa4ed79946f009e8aad7437a922e62d523\"\u003e\u003ccode\u003e9fed19a\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Bump default wrangler version to 3.90.0\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.1\u003c/h2\u003e\n\u003ch3\u003ePatch Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/319\"\u003e#319\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/59c04629408d58978884fadd18755f1a15f96157\"\u003e\u003ccode\u003e59c04629408d58978884fadd18755f1a15f96157\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - Fixes \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/317\"\u003e#317\u003c/a\u003e: Generate a new output directory with a randomUUID in the tmpDir, so that when the action is executed multiple times, we use the artifacts from that run, opposed to the artifacts from a previous run.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12.0\u003c/h2\u003e\n\u003ch3\u003eMinor Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/312\"\u003e#312\u003c/a\u003e \u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\"\u003e\u003ccode\u003e122ee5cf5b66847e0b6cfa67ecd9e03e38a67a42\u003c/code\u003e\u003c/a\u003e Thanks \u003ca href=\"https://github.com/Maximo-Guk\"\u003e\u003ccode\u003e@​Maximo-Guk\u003c/code\u003e\u003c/a\u003e! - This reapplies \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/pull/303\"\u003e303\u003c/a\u003e add parity with pages-action for pages deploy outputs. Thanks \u003ca href=\"https://github.com/courtney-sims\"\u003e\u003ccode\u003e@​courtney-sims\u003c/code\u003e\u003c/a\u003e! - Support pages-deployment-id, pages-environment, pages-deployment-alias-url and deployment-url outputs for Pages deploys when wrangler version is \u0026gt;=3.81.0. deployment-alias-url was also deprecated in favour of pages-deployment-alias.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003e\u003ccode\u003e9acf94a\u003c/code\u003e\u003c/a\u003e Automatic compilation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d181764e4b7652eb4377feec6bf15ddbb23210f0\"\u003e\u003ccode\u003ed181764\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/427\"\u003e#427\u003c/a\u003e from cloudflare/changeset-release/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/05015540800a657e380eba742bfa91a4ba2a2ca8\"\u003e\u003ccode\u003e0501554\u003c/code\u003e\u003c/a\u003e Version Packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/d8f3eaa359cd9d866a9aa127280056692bc71ee0\"\u003e\u003ccode\u003ed8f3eaa\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/cloudflare/wrangler-action/issues/426\"\u003e#426\u003c/a\u003e from cloudflare/willtaylor/escalation-963-support-ver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cloudflare/wrangler-action/commit/febbda69f8c5838bf8b07fd6b9dfc836f00962db\"\u003e\u003ccode\u003efebbda6\u003c/code\u003e\u003c/a\u003e Support version ranges and tags in wranglerVersion input\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/cloudflare/wrangler-action/compare/da0e0dfe58b7a431659754fdf3f186c529afbe65...9acf94ace14e7dc412b076f2c5c20b8ce93c79cd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `docker/build-push-action` from 7.0.0 to 7.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/docker/build-push-action/releases\"\u003edocker/build-push-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.1.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGit context \u003ca href=\"https://docs.docker.com/build/concepts/context/#url-queries\"\u003equery format\u003c/a\u003e support by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​docker/actions-toolkit\u003c/code\u003e from 0.79.0 to 0.87.0 by \u003ca href=\"https://github.com/crazy-max\"\u003e\u003ccode\u003e@​crazy-max\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1505\"\u003edocker/build-push-action#1505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump brace-expansion from 1.1.12 to 1.1.13 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1500\"\u003edocker/build-push-action#1500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump fast-xml-parser from 5.4.2 to 5.5.7 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1489\"\u003edocker/build-push-action#1489\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.3 to 3.4.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1491\"\u003edocker/build-push-action#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump glob from 10.3.12 to 10.5.0 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1490\"\u003edocker/build-push-action#1490\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump handlebars from 4.7.8 to 4.7.9 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1497\"\u003edocker/build-push-action#1497\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump lodash from 4.17.23 to 4.18.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1510\"\u003edocker/build-push-action#1510\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump picomatch from 4.0.3 to 4.0.4 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1496\"\u003edocker/build-push-action#1496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump undici from 6.23.0 to 6.24.1 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1486\"\u003edocker/build-push-action#1486\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump vite from 7.3.1 to 7.3.2 in \u003ca href=\"https://redirect.github.com/docker/build-push-action/pull/1509\"\u003edocker/build-push-action#1509\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\"\u003ehttps://github.com/docker/build-push-action/compare/v7.0.0...v7.1.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003e\u003ccode\u003ebcafcac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1509\"\u003e#1509\u003c/a\u003e from docker/dependabot/npm_and_yarn/vite-7.3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/18e62f1158d9c45a4a84a58a6828d21f8ed3644b\"\u003e\u003ccode\u003e18e62f1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1510\"\u003e#1510\u003c/a\u003e from docker/dependabot/npm_and_yarn/lodash-4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/46580d2c9d43b0888270cb6fa90956e483de56fc\"\u003e\u003ccode\u003e46580d2\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/3f80b252ca2331f6ec3e890f4346b5506ee1dc81\"\u003e\u003ccode\u003e3f80b25\u003c/code\u003e\u003c/a\u003e chore(deps): Bump lodash from 4.17.23 to 4.18.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/efeec9557c40a646afe433e39a1e94ca689103f0\"\u003e\u003ccode\u003eefeec95\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1505\"\u003e#1505\u003c/a\u003e from crazy-max/refactor-git-context\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ddf04b08eb12882258ed936fea4a2806754ff349\"\u003e\u003ccode\u003eddf04b0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1511\"\u003e#1511\u003c/a\u003e from docker/dependabot/github_actions/crazy-max-dot-...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/db08d97a08e4a0d15f85d1c4e64dfd5f88cbe1a9\"\u003e\u003ccode\u003edb08d97\u003c/code\u003e\u003c/a\u003e chore(deps): Bump the crazy-max-dot-github group with 2 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/ef1fb9688fc3626d0fd5e462f502cbbdc6456feb\"\u003e\u003ccode\u003eef1fb96\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/docker/build-push-action/issues/1508\"\u003e#1508\u003c/a\u003e from docker/dependabot/github_actions/docker/login-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/2d8f2a1a378a5c302dcd7b2b4326cefa24180bb1\"\u003e\u003ccode\u003e2d8f2a1\u003c/code\u003e\u003c/a\u003e chore: update generated content\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/docker/build-push-action/commit/919ac7bd7d1aa8cb13fe4de76545abea8d8b5ed2\"\u003e\u003ccode\u003e919ac7b\u003c/code\u003e\u003c/a\u003e fix test since secrets are not written to temp path anymore\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/docker/build-push-action/compare/d08e5c354a6adb9ed34480a06d141179aa583294...bcafcacb16a39f128d818304e6c9c0c18556b85f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/super-productivity/super-productivity/pull/7285","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/super-productivity%2Fsuper-productivity/issues/7285","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/7285/packages"}},{"old_version":"2.0","new_version":"2.2","update_type":null,"path":null,"pr_created_at":"2026-04-18T10:04:16.000Z","version_change":"2.0 → 2.2","issue":{"uuid":"4287582966","node_id":"PR_kwDORKxwDc7Tj-E7","number":105,"state":"open","title":"build(deps): Bump signpath/github-action-submit-signing-request from 2.0 to 2.2","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-18T10:04:16.000Z","updated_at":"2026-04-18T10:04:17.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.2","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003e\u003ccode\u003eb9d91ea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/signpath/github-action-submit-signing-request/issues/13\"\u003e#13\u003c/a\u003e from SignPath/release/GitHubActions/action/2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/78023dac7db883e9b2fe00b598fafd6c23aaebee\"\u003e\u003ccode\u003e78023da\u003c/code\u003e\u003c/a\u003e Build from - 890bfadb4220c27a95844d8f06642a4f01296957. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/be30b3a7ef96eb29956fac219502d48b6c9f3f44\"\u003e\u003ccode\u003ebe30b3a\u003c/code\u003e\u003c/a\u003e Build from - c2a2e867fd827ab6827cf619a300c5472747fd3e. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/f42751ce23d92b676150ffeaa0028aef0abfd38d\"\u003e\u003ccode\u003ef42751c\u003c/code\u003e\u003c/a\u003e Build from - 31e2208fed0d2f0ebd6fd43e25c617d31dd25f98. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...b9d91eadd323de506c0c81cf0c7fe7438f3360fd\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/robertpopa22/mRemoteNG/pull/105","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/robertpopa22%2FmRemoteNG/issues/105","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/105/packages"}},{"old_version":"2.0","new_version":"2.1","update_type":null,"path":null,"pr_created_at":"2026-04-13T07:26:46.000Z","version_change":"2.0 → 2.1","issue":{"uuid":"4252191440","node_id":"PR_kwDORbirJs7R5i1_","number":20,"state":"open","title":"chore(deps)(deps): bump the github-actions-minor group across 1 directory with 9 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-04-13T07:26:46.000Z","updated_at":"2026-04-13T07:26:47.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)(deps): bump","group_name":"github-actions-minor","update_count":9,"packages":[{"name":"step-security/harden-runner","old_version":"2.14.2","new_version":"2.17.0","repository_url":"https://github.com/step-security/harden-runner"},{"name":"actions/setup-node","old_version":"6.2.0","new_version":"6.3.0","repository_url":"https://github.com/actions/setup-node"},{"name":"actions/cache","old_version":"5.0.3","new_version":"5.0.4","repository_url":"https://github.com/actions/cache"},{"name":"KSXGitHub/github-actions-deploy-aur","old_version":"4.1.1","new_version":"4.1.2","repository_url":"https://github.com/ksxgithub/github-actions-deploy-aur"},{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"},{"name":"actions/dependency-review-action","old_version":"4.8.3","new_version":"4.9.0","repository_url":"https://github.com/actions/dependency-review-action"},{"name":"treosh/lighthouse-ci-action","old_version":"12.6.1","new_version":"12.6.2","repository_url":"https://github.com/treosh/lighthouse-ci-action"},{"name":"anthropics/claude-code-action","old_version":"1.0.55","new_version":"1.0.93","repository_url":"https://github.com/anthropics/claude-code-action"},{"name":"github/codeql-action","old_version":"4.32.4","new_version":"4.35.1","repository_url":"https://github.com/github/codeql-action"}],"path":null,"ecosystem":"actions"},"body":"Bumps the github-actions-minor group with 9 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.14.2` | `2.17.0` |\n| [actions/setup-node](https://github.com/actions/setup-node) | `6.2.0` | `6.3.0` |\n| [actions/cache](https://github.com/actions/cache) | `5.0.3` | `5.0.4` |\n| [KSXGitHub/github-actions-deploy-aur](https://github.com/ksxgithub/github-actions-deploy-aur) | `4.1.1` | `4.1.2` |\n| [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) | `2.0` | `2.1` |\n| [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `4.8.3` | `4.9.0` |\n| [treosh/lighthouse-ci-action](https://github.com/treosh/lighthouse-ci-action) | `12.6.1` | `12.6.2` |\n| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.55` | `1.0.93` |\n| [github/codeql-action](https://github.com/github/codeql-action) | `4.32.4` | `4.35.1` |\n\n\nUpdates `step-security/harden-runner` from 2.14.2 to 2.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/step-security/harden-runner/releases\"\u003estep-security/harden-runner's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.17.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003ePolicy Store Support\u003c/h3\u003e\n\u003cp\u003eAdded \u003ccode\u003euse-policy-store\u003c/code\u003e and \u003ccode\u003eapi-key\u003c/code\u003e inputs to fetch security policies directly from the \u003ca href=\"https://docs.stepsecurity.io/harden-runner/policy-store\"\u003eStepSecurity Policy Store\u003c/a\u003e. Policies can be defined and attached at the workflow, repo, org, or cluster (ARC) level, with the most granular policy taking precedence. This is the preferred method over the existing \u003ccode\u003epolicy\u003c/code\u003e input which requires \u003ccode\u003eid-token: write\u003c/code\u003e permission. If no policy is found in the store, the action defaults to audit mode.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.1...v2.17.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.16.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cp\u003eEnterprise tier: Added support for direct IP addresses in the allow list\nCommunity tier: Migrated Harden Runner telemetry to a new endpoint\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.16.0...v2.16.1\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.16.0...v2.16.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.16.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated action.yml to use node24\u003c/li\u003e\n\u003cli\u003eSecurity fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS over HTTPS (DoH) by proxying DNS queries through a permitted resolver, allowing data exfiltration even with a restrictive allowed-endpoints list. This issue only affects the Community Tier; the Enterprise Tier is not affected. See \u003ca href=\"https://github.com/step-security/harden-runner/security/advisories/GHSA-46g3-37rh-v698\"\u003eGHSA-46g3-37rh-v698\u003c/a\u003e for details.\u003c/li\u003e\n\u003cli\u003eSecurity fix: Fixed a medium severity vulnerability where the egress block policy could be bypassed via DNS queries over TCP to external resolvers, allowing outbound network communication that evades configured network restrictions. This issue only affects the Community Tier; the Enterprise Tier is not affected. See \u003ca href=\"https://github.com/step-security/harden-runner/security/advisories/GHSA-g699-3x6g-wm3g\"\u003eGHSA-g699-3x6g-wm3g\u003c/a\u003e for details.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.15.1...v2.16.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.15.1...v2.16.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.15.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/642\"\u003estep-security/harden-runner#642\u003c/a\u003e bug due to which post step was failing on Windows ARM runners\u003c/li\u003e\n\u003cli\u003eUpdates npm packages\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.15.0...v2.15.1\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.15.0...v2.15.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.15.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eWindows and macOS runner support\u003c/h3\u003e\n\u003cp\u003eWe are excited to announce that Harden Runner now supports \u003cstrong\u003eWindows and macOS runners\u003c/strong\u003e, extending runtime security beyond Linux for the first time.\u003c/p\u003e\n\u003cp\u003eInsights for Windows and macOS runners will be displayed in the same consistent format you are already familiar with from Linux runners, giving you a unified view of runtime activity across all platforms.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/step-security/harden-runner/compare/v2.14.2...v2.15.0\"\u003ehttps://github.com/step-security/harden-runner/compare/v2.14.2...v2.15.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f808768d1510423e83855289c910610ca9b43176\"\u003e\u003ccode\u003ef808768\u003c/code\u003e\u003c/a\u003e Feature/policy store (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/656\"\u003e#656\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/fe104658747b27e96e4f7e80cd0a94068e53901d\"\u003e\u003ccode\u003efe10465\u003c/code\u003e\u003c/a\u003e v2.16.1 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/654\"\u003e#654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/fa2e9d605c4eeb9fcad4c99c224cee0c6c7f3594\"\u003e\u003ccode\u003efa2e9d6\u003c/code\u003e\u003c/a\u003e Release v2.16.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/646\"\u003e#646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/58077d3c7e43986b6b15fba718e8ea69e387dfcc\"\u003e\u003ccode\u003e58077d3\u003c/code\u003e\u003c/a\u003e Release v2.15.1 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/641\"\u003e#641\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/a90bcbc6539c36a85cdfeb73f7e2f433735f215b\"\u003e\u003ccode\u003ea90bcbc\u003c/code\u003e\u003c/a\u003e Update readme (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/637\"\u003e#637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/step-security/harden-runner/commit/f0a59d88538059e010b6ebd90b74e2740a6d05fc\"\u003e\u003ccode\u003ef0a59d8\u003c/code\u003e\u003c/a\u003e Release v2.15.0 (\u003ca href=\"https://redirect.github.com/step-security/harden-runner/issues/639\"\u003e#639\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/step-security/harden-runner/compare/5ef0c079ce82195b2a36a210272d6b661572d83e...f808768d1510423e83855289c910610ca9b43176\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/setup-node` from 6.2.0 to 6.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/setup-node/releases\"\u003eactions/setup-node's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport parsing \u003ccode\u003edevEngines\u003c/code\u003e field by \u003ca href=\"https://github.com/susnux\"\u003e\u003ccode\u003e@​susnux\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1283\"\u003eactions/setup-node#1283\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003eWhen using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eDependency updates:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix npm audit issues by \u003ca href=\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1491\"\u003eactions/setup-node#1491\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace uuid with crypto.randomUUID() by \u003ca href=\"https://github.com/trivikr\"\u003e\u003ccode\u003e@​trivikr\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1378\"\u003eactions/setup-node#1378\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade minimatch from 3.1.2 to 3.1.5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1498\"\u003eactions/setup-node#1498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes:\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove hardcoded bearer for mirror-url \u003ca href=\"https://github.com/marco-ippolito\"\u003e\u003ccode\u003e@​marco-ippolito\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1467\"\u003eactions/setup-node#1467\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eScope test lockfiles by package manager and update cache tests by \u003ca href=\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1495\"\u003eactions/setup-node#1495\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/susnux\"\u003e\u003ccode\u003e@​susnux\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/setup-node/pull/1283\"\u003eactions/setup-node#1283\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/setup-node/compare/v6...v6.3.0\"\u003ehttps://github.com/actions/setup-node/compare/v6...v6.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/53b83947a5a98c8d113130e565377fae1a50d02f\"\u003e\u003ccode\u003e53b8394\u003c/code\u003e\u003c/a\u003e Bump minimatch from 3.1.2 to 3.1.5 (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1498\"\u003e#1498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/54045abd5dcd3b0fee9ca02fa24c57545834c9cc\"\u003e\u003ccode\u003e54045ab\u003c/code\u003e\u003c/a\u003e Scope test lockfiles by package manager and update cache tests (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1495\"\u003e#1495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/c882bffdbd4df51ace6b940023952e8669c9932a\"\u003e\u003ccode\u003ec882bff\u003c/code\u003e\u003c/a\u003e Replace uuid with crypto.randomUUID() (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1378\"\u003e#1378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/774c1d62961e73038a114d59c8847023c003194d\"\u003e\u003ccode\u003e774c1d6\u003c/code\u003e\u003c/a\u003e feat(node-version-file): support parsing \u003ccode\u003edevEngines\u003c/code\u003e field (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1283\"\u003e#1283\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/efcb663fc60e97218a2b2d6d827f7830f164739e\"\u003e\u003ccode\u003eefcb663\u003c/code\u003e\u003c/a\u003e fix: remove hardcoded bearer (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1467\"\u003e#1467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/setup-node/commit/d02c89dce7e1ba9ef629ce0680989b3a1cc72edb\"\u003e\u003ccode\u003ed02c89d\u003c/code\u003e\u003c/a\u003e Fix npm audit issues (\u003ca href=\"https://redirect.github.com/actions/setup-node/issues/1491\"\u003e#1491\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/actions/setup-node/compare/6044e13b5dc448c55e2357c09f80417699197238...53b83947a5a98c8d113130e565377fae1a50d02f\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/cache` from 5.0.3 to 5.0.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/releases\"\u003eactions/cache's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.4\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release instructions and update maintainer docs by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1696\"\u003eactions/cache#1696\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePotential fix for code scanning alert no. 52: Workflow does not contain permissions by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1697\"\u003eactions/cache#1697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix workflow permissions and cleanup workflow names / formatting by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1699\"\u003eactions/cache#1699\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: Update examples to use the latest version by \u003ca href=\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix proxy integration tests by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1701\"\u003eactions/cache#1701\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix cache key in examples.md for bun.lock by \u003ca href=\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate dependencies \u0026amp; patch security vulnerabilities by \u003ca href=\"https://github.com/Link\"\u003e\u003ccode\u003e@​Link\u003c/code\u003e\u003c/a\u003e- in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1738\"\u003eactions/cache#1738\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XZTDean\"\u003e\u003ccode\u003e@​XZTDean\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1690\"\u003eactions/cache#1690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/RyPeck\"\u003e\u003ccode\u003e@​RyPeck\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/cache/pull/1722\"\u003eactions/cache#1722\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/cache/compare/v5...v5.0.4\"\u003ehttps://github.com/actions/cache/compare/v5...v5.0.4\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003eactions/cache's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eReleases\u003c/h1\u003e\n\u003ch2\u003eHow to prepare a release\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nRelevant for maintainers with write access only.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003col\u003e\n\u003cli\u003eSwitch to a new branch from \u003ccode\u003emain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm test\u003c/code\u003e to ensure all tests are passing.\u003c/li\u003e\n\u003cli\u003eUpdate the version in \u003ca href=\"https://github.com/actions/cache/blob/main/package.json\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/package.json\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003enpm run build\u003c/code\u003e to update the compiled files.\u003c/li\u003e\n\u003cli\u003eUpdate this \u003ca href=\"https://github.com/actions/cache/blob/main/RELEASES.md\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/RELEASES.md\u003c/code\u003e\u003c/a\u003e with the new version and changes in the \u003ccode\u003e## Changelog\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed cache\u003c/code\u003e to update the license report.\u003c/li\u003e\n\u003cli\u003eRun \u003ccode\u003elicensed status\u003c/code\u003e and resolve any warnings by updating the \u003ca href=\"https://github.com/actions/cache/blob/main/.licensed.yml\"\u003e\u003ccode\u003ehttps://github.com/actions/cache/blob/main/.licensed.yml\u003c/code\u003e\u003c/a\u003e file with the exceptions.\u003c/li\u003e\n\u003cli\u003eCommit your changes and push your branch upstream.\u003c/li\u003e\n\u003cli\u003eOpen a pull request against \u003ccode\u003emain\u003c/code\u003e and get it reviewed and merged.\u003c/li\u003e\n\u003cli\u003eDraft a new release \u003ca href=\"https://github.com/actions/cache/releases\"\u003ehttps://github.com/actions/cache/releases\u003c/a\u003e use the same version number used in \u003ccode\u003epackage.json\u003c/code\u003e\n\u003col\u003e\n\u003cli\u003eCreate a new tag with the version number.\u003c/li\u003e\n\u003cli\u003eAuto generate release notes and update them to match the changes you made in \u003ccode\u003eRELEASES.md\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eToggle the set as the latest release option.\u003c/li\u003e\n\u003cli\u003ePublish the release.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003cli\u003eNavigate to \u003ca href=\"https://github.com/actions/cache/actions/workflows/release-new-action-version.yml\"\u003ehttps://github.com/actions/cache/actions/workflows/release-new-action-version.yml\u003c/a\u003e\n\u003col\u003e\n\u003cli\u003eThere should be a workflow run queued with the same version number.\u003c/li\u003e\n\u003cli\u003eApprove the run to publish the new version and update the major tags for this action.\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2\u003eChangelog\u003c/h2\u003e\n\u003ch3\u003e5.0.4\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003eminimatch\u003c/code\u003e to v3.1.5 (fixes ReDoS via globstar patterns)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003eundici\u003c/code\u003e to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003efast-xml-parser\u003c/code\u003e to v5.5.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.3\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.5 (Resolves: \u003ca href=\"https://github.com/actions/cache/security/dependabot/33\"\u003ehttps://github.com/actions/cache/security/dependabot/33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/core\u003c/code\u003e to v2.0.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.2\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@actions/cache\u003c/code\u003e to v5.0.3 \u003ca href=\"https://redirect.github.com/actions/cache/pull/1692\"\u003e#1692\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.1\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003e@azure/storage-blob\u003c/code\u003e to \u003ccode\u003e^12.29.1\u003c/code\u003e via \u003ccode\u003e@actions/cache@5.0.1\u003c/code\u003e \u003ca href=\"https://redirect.github.com/actions/cache/pull/1685\"\u003e#1685\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e5.0.0\u003c/h3\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!IMPORTANT]\n\u003ccode\u003eactions/cache@v5\u003c/code\u003e runs on the Node.js 24 runtime and requires a minimum Actions Runner version of \u003ccode\u003e2.327.1\u003c/code\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003e\u003ccode\u003e6682284\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1738\"\u003e#1738\u003c/a\u003e from actions/prepare-v5.0.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/e34039626f957d3e3e50843d15c1b20547fc90e2\"\u003e\u003ccode\u003ee340396\u003c/code\u003e\u003c/a\u003e Update RELEASES\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/8a671105293e81530f1af99863cdf94550aba1a6\"\u003e\u003ccode\u003e8a67110\u003c/code\u003e\u003c/a\u003e Add licenses\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/1865903e1b0cb750dda9bc5c58be03424cc62830\"\u003e\u003ccode\u003e1865903\u003c/code\u003e\u003c/a\u003e Update dependencies \u0026amp; patch security vulnerabilities\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/565629816435f6c0b50676926c9b05c254113c0c\"\u003e\u003ccode\u003e5656298\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1722\"\u003e#1722\u003c/a\u003e from RyPeck/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/4e380d19e192ace8e86f23f32ca6fdec98a673c6\"\u003e\u003ccode\u003e4e380d1\u003c/code\u003e\u003c/a\u003e Fix cache key in examples.md for bun.lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/b7e8d49f17405cc70c1c120101943203c98d3a4b\"\u003e\u003ccode\u003eb7e8d49\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/cache/issues/1701\"\u003e#1701\u003c/a\u003e from actions/Link-/fix-proxy-integration-tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/984a21b1cb176a0936f4edafb42be88978f93ef1\"\u003e\u003ccode\u003e984a21b\u003c/code\u003e\u003c/a\u003e Add traffic sanity check step\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/acf2f1f76affe1ef80eee8e56dfddd3b3e5f0fba\"\u003e\u003ccode\u003eacf2f1f\u003c/code\u003e\u003c/a\u003e Fix resolution\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/cache/commit/95a07c51324af6001b4d6ab8dff29f4dfadc2531\"\u003e\u003ccode\u003e95a07c5\u003c/code\u003e\u003c/a\u003e Add wait for proxy\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/cache/compare/cdf6c1fa76f9f475f3d7449005a359c84ca0f306...668228422ae6a00e4ad889ee87cd7109ec5666a7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `KSXGitHub/github-actions-deploy-aur` from 4.1.1 to 4.1.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/releases\"\u003eKSXGitHub/github-actions-deploy-aur's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.2\u003c/h2\u003e\n\u003cp\u003eSwitching from \u003ccode\u003e--command\u003c/code\u003e to \u003ccode\u003e-u \u0026lt;USER\u0026gt; -- \u0026lt;COMMAND\u0026gt;\u003c/code\u003e (the recommended way), allowing the entry point to run in su-compatible mode (\u003ca href=\"https://redirect.github.com/KSXGitHub/github-actions-deploy-aur/pull/49\"\u003eKSXGitHub/github-actions-deploy-aur#49\u003c/a\u003e).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/KSXGitHub/github-actions-deploy-aur/commit/abe8ac26b51011c88be58c8809fd2ac674068ea5\"\u003e\u003ccode\u003eabe8ac2\u003c/code\u003e\u003c/a\u003e fix: use runuser -u flag to avoid bash --command error (\u003ca href=\"https://redirect.github.com/ksxgithub/github-actions-deploy-aur/issues/49\"\u003e#49\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/ksxgithub/github-actions-deploy-aur/compare/2ac5a4c1d7035885d46b10e3193393be8460b6f1...abe8ac26b51011c88be58c8809fd2ac674068ea5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `signpath/github-action-submit-signing-request` from 2.0 to 2.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `actions/dependency-review-action` from 4.8.3 to 4.9.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/actions/dependency-review-action/releases\"\u003eactions/dependency-review-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eDependency Review Action 4.9.0\u003c/h2\u003e\n\u003cp\u003eThis feature release contains a couple of notable changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThere is a new configuration option \u003ccode\u003eshow_patched_versions\u003c/code\u003e which will add a column to the output, showing the fix version of each vulnerable dependency. Thanks \u003ca href=\"https://github.com/felickz\"\u003e\u003ccode\u003e@​felickz\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eRuns which do not display OpenSSF scorecards no longer fetch scorecard information; previously it was fetched regardless of whether or not it was displayed, causing unneccessary slowness. Great catch \u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eThere are a couple of fixes to purl parsing which should improve match accuracy for \u003ccode\u003eallow-package-dependency\u003c/code\u003e lists, including case (in)sensitivity and url-encoded namespaces Thanks \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompare normalized purls to account for encoding quirks by \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1056\"\u003eactions/dependency-review-action#1056\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake purl comparisons case insensitive by \u003ca href=\"https://github.com/juxtin\"\u003e\u003ccode\u003e@​juxtin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1057\"\u003eactions/dependency-review-action#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFeat: Add \u003ccode\u003ePatched Version\u003c/code\u003e to \u003ccode\u003eVulnerabilities\u003c/code\u003e summary by \u003ca href=\"https://github.com/felickz\"\u003e\u003ccode\u003e@​felickz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1045\"\u003eactions/dependency-review-action#1045\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: only get scorecard levels if user wants to see the OpenSSF scorecard by \u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1060\"\u003eactions/dependency-review-action#1060\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/stale from 10.1.0 to 10.2.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1058\"\u003eactions/dependency-review-action#1058\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 4 to 6 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1021\"\u003eactions/dependency-review-action#1021\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdates for release 4.9.0 by \u003ca href=\"https://github.com/ahpook\"\u003e\u003ccode\u003e@​ahpook\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1064\"\u003eactions/dependency-review-action#1064\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jantiebot\"\u003e\u003ccode\u003e@​jantiebot\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/pull/1060\"\u003eactions/dependency-review-action#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0\"\u003ehttps://github.com/actions/dependency-review-action/compare/v4.8.3...v4.9.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/2031cfc080254a8a887f58cffee85186f0e49e48\"\u003e\u003ccode\u003e2031cfc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1064\"\u003e#1064\u003c/a\u003e from actions/ahpook/release-4.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/d02fa39f790d6e8a4ecafab5848251ff12c20df7\"\u003e\u003ccode\u003ed02fa39\u003c/code\u003e\u003c/a\u003e Updates for release 4.9.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/4038a34c4b30f7c11a7d45dc8dbea40e2211aa27\"\u003e\u003ccode\u003e4038a34\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1021\"\u003e#1021\u003c/a\u003e from actions/dependabot/github_actions/actions/check...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/a632b8386b2cc2b1b99427606b513f7632d27e91\"\u003e\u003ccode\u003ea632b83\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1058\"\u003e#1058\u003c/a\u003e from actions/dependabot/github_actions/actions/stale...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/57a3d46a7be2c2e259fa3284ffc501296337f2ac\"\u003e\u003ccode\u003e57a3d46\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1060\"\u003e#1060\u003c/a\u003e from jantiebot/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/5ecdc4b5781cdabdfe233d6e58ec18eac23e275d\"\u003e\u003ccode\u003e5ecdc4b\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/actions/dependency-review-action/issues/1045\"\u003e#1045\u003c/a\u003e from forks-felickz/main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/e8c2f9a12c568d6f36f8d3a9935a6c71afc691f5\"\u003e\u003ccode\u003ee8c2f9a\u003c/code\u003e\u003c/a\u003e fix: remove inferrable type annotation to pass eslint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/0e129e113c878bfe7c1abf6c6d94b180cbf71086\"\u003e\u003ccode\u003e0e129e1\u003c/code\u003e\u003c/a\u003e Prettier  - Refactor summary table rendering for improved readability\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/aa60746a920d63ce55376f67d381e15edd3a714d\"\u003e\u003ccode\u003eaa60746\u003c/code\u003e\u003c/a\u003e Add 'show-patched-versions' option to configuration and update summary handling\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/actions/dependency-review-action/commit/e4047984002250b82268ac37f613ab74366e1d85\"\u003e\u003ccode\u003ee404798\u003c/code\u003e\u003c/a\u003e Merge upstream actions/dependency-review-action main\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/actions/dependency-review-action/compare/05fe4576374b728f0c523d6a13d64c25081e0803...2031cfc080254a8a887f58cffee85186f0e49e48\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `treosh/lighthouse-ci-action` from 12.6.1 to 12.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/treosh/lighthouse-ci-action/releases\"\u003etreosh/lighthouse-ci-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.6.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse \u003ccode\u003enode24\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdate deps: \u003ccode\u003e@​actions/core\u003c/code\u003e\u003ca href=\"https://github.com/3\"\u003e\u003ccode\u003e@​3\u003c/code\u003e\u003c/a\u003e.0.0, \u003ccode\u003e@​lhci/cli\u003c/code\u003e\u003ca href=\"https://github.com/0\"\u003e\u003ccode\u003e@​0\u003c/code\u003e\u003c/a\u003e.15.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/3e7e23fb74242897f95c0ba9cabad3d0227b9b18\"\u003e\u003ccode\u003e3e7e23f\u003c/code\u003e\u003c/a\u003e fix interpolation test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/17aadfd8aea2cdae3bf0dbab94b1ca0926aada6c\"\u003e\u003ccode\u003e17aadfd\u003c/code\u003e\u003c/a\u003e update docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/68d5bca31325f58c95f5231c066181d98bae8e25\"\u003e\u003ccode\u003e68d5bca\u003c/code\u003e\u003c/a\u003e update lhci configs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/69dc12e77f9eefc3f70c2c62109d70e505e0cdbc\"\u003e\u003ccode\u003e69dc12e\u003c/code\u003e\u003c/a\u003e fix core import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/f18aeafd4ba541092b844d793e5a49f218e00e17\"\u003e\u003ccode\u003ef18aeaf\u003c/code\u003e\u003c/a\u003e update deps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/b94e7872052e1f830b25a6fc99e3c5adebda5588\"\u003e\u003ccode\u003eb94e787\u003c/code\u003e\u003c/a\u003e use node24 as a default runner\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/4198ec75af54c544d055c0efad7a45546398a325\"\u003e\u003ccode\u003e4198ec7\u003c/code\u003e\u003c/a\u003e Fix typo in input description\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/f82fba5af0cc5162589cf5563b05bc284149f197\"\u003e\u003ccode\u003ef82fba5\u003c/code\u003e\u003c/a\u003e Update README.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/treosh/lighthouse-ci-action/commit/847bd5ec450b5c4052a530597bf8e4bc7de36c35\"\u003e\u003ccode\u003e847bd5e\u003c/code\u003e\u003c/a\u003e README.md: bump GitHub action workflows\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/treosh/lighthouse-ci-action/compare/fcd65974f7c4c2bf0ee9d09b84d2489183c29726...3e7e23fb74242897f95c0ba9cabad3d0227b9b18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anthropics/claude-code-action` from 1.0.55 to 1.0.93\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/claude-code-action/releases\"\u003eanthropics/claude-code-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.0.93\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.93\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.92\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.92\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.91\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUse pinned bun binary for post-steps when allowed_non_write_users is set by \u003ca href=\"https://github.com/OctavianGuzu\"\u003e\u003ccode\u003e@​OctavianGuzu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1190\"\u003eanthropics/claude-code-action#1190\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.91\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.91\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.90\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: forward MCP_TIMEOUT, MCP_TOOL_TIMEOUT, MAX_MCP_OUTPUT_TOKENS to action step by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1162\"\u003eanthropics/claude-code-action#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003esecurity: reject PATH_TO_CLAUDE_CODE_EXECUTABLE with control characters by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1185\"\u003eanthropics/claude-code-action#1185\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.90\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.90\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.89\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: skip token revocation when no token was acquired by \u003ca href=\"https://github.com/Dave-London\"\u003e\u003ccode\u003e@​Dave-London\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/918\"\u003eanthropics/claude-code-action#918\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse env vars for workflow_run context values in example workflows by \u003ca href=\"https://github.com/ddworken\"\u003e\u003ccode\u003e@​ddworken\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1125\"\u003eanthropics/claude-code-action#1125\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: document include/exclude_comments_by_actor inputs by \u003ca href=\"https://github.com/yuribodo\"\u003e\u003ccode\u003e@​yuribodo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1130\"\u003eanthropics/claude-code-action#1130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use correct fallback type for reviewData in fetcher by \u003ca href=\"https://github.com/MaxwellCalkin\"\u003e\u003ccode\u003e@​MaxwellCalkin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1034\"\u003eanthropics/claude-code-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStrip OIDC token request env vars from Claude session by \u003ca href=\"https://github.com/chyipin\"\u003e\u003ccode\u003e@​chyipin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1011\"\u003eanthropics/claude-code-action#1011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: skip retries for non-retryable errors in retryWithBackoff by \u003ca href=\"https://github.com/ei-grad\"\u003e\u003ccode\u003e@​ei-grad\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1082\"\u003eanthropics/claude-code-action#1082\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: restore ripgrep execute bits after bun install --production by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1163\"\u003eanthropics/claude-code-action#1163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: allow # in branch names for PR checkout and base restore by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1167\"\u003eanthropics/claude-code-action#1167\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: prevent hang in restoreConfigFromBase on repos with .gitmodules by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1166\"\u003eanthropics/claude-code-action#1166\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: strip shell comment lines before parsing claude_args by \u003ca href=\"https://github.com/VoidChecksum\"\u003e\u003ccode\u003e@​VoidChecksum\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1055\"\u003eanthropics/claude-code-action#1055\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: snapshot PR's .claude/ to .claude-pr/ before security restore by \u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1172\"\u003eanthropics/claude-code-action#1172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix prettier formatting by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1171\"\u003eanthropics/claude-code-action#1171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: fix prettier formatting in parse-sdk-options.test.ts by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1176\"\u003eanthropics/claude-code-action#1176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: pin bun runtime config and improve log hygiene by \u003ca href=\"https://github.com/ashwin-ant\"\u003e\u003ccode\u003e@​ashwin-ant\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1174\"\u003eanthropics/claude-code-action#1174\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yuribodo\"\u003e\u003ccode\u003e@​yuribodo\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1130\"\u003eanthropics/claude-code-action#1130\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MaxwellCalkin\"\u003e\u003ccode\u003e@​MaxwellCalkin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1034\"\u003eanthropics/claude-code-action#1034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chyipin\"\u003e\u003ccode\u003e@​chyipin\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1011\"\u003eanthropics/claude-code-action#1011\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ei-grad\"\u003e\u003ccode\u003e@​ei-grad\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1082\"\u003eanthropics/claude-code-action#1082\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qozle\"\u003e\u003ccode\u003e@​qozle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1163\"\u003eanthropics/claude-code-action#1163\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/VoidChecksum\"\u003e\u003ccode\u003e@​VoidChecksum\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/pull/1055\"\u003eanthropics/claude-code-action#1055\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.89\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.89\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.0.88\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/v1...v1.0.88\"\u003ehttps://github.com/anthropics/claude-code-action/compare/v1...v1.0.88\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b47fd721da662d48c5680e154ad16a73ed74d2e0\"\u003e\u003ccode\u003eb47fd72\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.101 and Agent SDK to 0.2.101\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/c26cb6427d54362f5fd9834ac6818cbaaf82490a\"\u003e\u003ccode\u003ec26cb64\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.100 and Agent SDK to 0.2.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/657fb7c9c986158a19624b357bcbc8c6deb83598\"\u003e\u003ccode\u003e657fb7c\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.98 and Agent SDK to 0.2.98\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/2ff1acb3ee319fa302837dad6e17c2f36c0d98ea\"\u003e\u003ccode\u003e2ff1acb\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.97 and Agent SDK to 0.2.97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/b2fdd80112e5f140e097b11d7a3d9edf0b226fd0\"\u003e\u003ccode\u003eb2fdd80\u003c/code\u003e\u003c/a\u003e Use pinned bun binary for post-steps when allowed_non_write_users is set (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1190\"\u003e#1190\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/26ddc358fe3befff50c5ec2f80304c90c763f6f8\"\u003e\u003ccode\u003e26ddc35\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.96 and Agent SDK to 0.2.96\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/398370690eb38623ea077e8ccc687d81c9afe15d\"\u003e\u003ccode\u003e3983706\u003c/code\u003e\u003c/a\u003e chore: bump Claude Code to 2.1.94 and Agent SDK to 0.2.94\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/6cad158a175744eb2e76f7f5fd108ec63145598c\"\u003e\u003ccode\u003e6cad158\u003c/code\u003e\u003c/a\u003e security: reject PATH_TO_CLAUDE_CODE_EXECUTABLE with control characters (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1185\"\u003e#1185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/0f1fe5ef851a13d28734e675cf8504f540ba5d93\"\u003e\u003ccode\u003e0f1fe5e\u003c/code\u003e\u003c/a\u003e fix: forward MCP_TIMEOUT, MCP_TOOL_TIMEOUT, MAX_MCP_OUTPUT_TOKENS to action s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/claude-code-action/commit/6e2bd52842c65e914eba5c8badd17560bd26b5de\"\u003e\u003ccode\u003e6e2bd52\u003c/code\u003e\u003c/a\u003e fix: pin bun runtime config and improve log hygiene (\u003ca href=\"https://redirect.github.com/anthropics/claude-code-action/issues/1174\"\u003e#1174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/claude-code-action/compare/edd85d61533cbba7b57ed0ca4af1750b1fdfd3c4...b47fd721da662d48c5680e154ad16a73ed74d2e0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `github/codeql-action` from 4.32.4 to 4.35.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003egithub/codeql-action's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.35.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.35.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.34.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.34.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.33.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.32.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.32.5\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRepositories owned by an organization can now set up the \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e custom repository property to disable \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis for CodeQL\u003c/a\u003e. First, create a custom repository property with the name \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e and the type \u0026quot;True/false\u0026quot; in the organization's settings. Then in the repository's settings, set this property to \u003ccode\u003etrue\u003c/code\u003e to disable improved incremental analysis. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. This feature is not yet available on GitHub Enterprise Server. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3507\"\u003e#3507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change so that when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e fails on a runner — potentially due to insufficient disk space — the failure is recorded in the Actions cache so that subsequent runs will automatically skip improved incremental analysis until something changes (e.g. a larger runner is provisioned or a new CodeQL version is released). We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3487\"\u003e#3487\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe minimum memory check for improved incremental analysis is now skipped for CodeQL 2.24.3 and later, which has reduced peak RAM usage. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3515\"\u003e#3515\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReduced log levels for best-effort private package registry connection check failures to reduce noise from workflow annotations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3516\"\u003e#3516\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which lowers the minimum disk space requirement for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e, enabling it to run on standard GitHub Actions runners. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3498\"\u003e#3498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded an experimental change which allows the \u003ccode\u003estart-proxy\u003c/code\u003e action to resolve the CodeQL CLI version from feature flags instead of using the linked CLI bundle version. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3512\"\u003e#3512\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe previously experimental changes from versions 4.32.3, 4.32.4, 3.32.3 and 3.32.4 are now enabled by default. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3503\"\u003e#3503\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3504\"\u003e#3504\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/github/codeql-action/blob/main/CHANGELOG.md\"\u003egithub/codeql-action's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eCodeQL Action Changelog\u003c/h1\u003e\n\u003cp\u003eSee the \u003ca href=\"https://github.com/github/codeql-action/releases\"\u003ereleases page\u003c/a\u003e for the relevant changes to the CodeQL CLI and language packs.\u003c/p\u003e\n\u003ch2\u003e[UNRELEASED]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe undocumented TRAP cache cleanup feature that could be enabled using the \u003ccode\u003eCODEQL_ACTION_CLEANUP_TRAP_CACHES\u003c/code\u003e environment variable is deprecated and will be removed in May 2026. If you are affected by this, we recommend disabling TRAP caching by passing the \u003ccode\u003etrap-caching: false\u003c/code\u003e input to the \u003ccode\u003einit\u003c/code\u003e Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3795\"\u003e#3795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eThe Git version 2.36.0 requirement for improved incremental analysis now only applies to repositories that contain submodules. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3789\"\u003e#3789\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePython analysis on GHES no longer extracts the standard library, relying instead on models of the standard library. This should result in significantly faster extraction and analysis times, while the effect on alerts should be minimal. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3794\"\u003e#3794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed a bug in the validation of OIDC configurations for private registries that was added in CodeQL Action 4.33.0 / 3.33.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3807\"\u003e#3807\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.1 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix incorrect minimum required Git version for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e: it should have been 2.36.0, not 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3781\"\u003e#3781\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.35.0 - 27 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReduced the minimum Git version required for \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e from 2.38.0 to 2.11.0. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3767\"\u003e#3767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.1\"\u003e2.25.1\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3773\"\u003e#3773\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.1 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDowngrade default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e due to issues with a small percentage of Actions and JavaScript analyses. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3762\"\u003e#3762\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.34.0 - 20 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdded an experimental change which disables TRAP caching when \u003ca href=\"https://redirect.github.com/github/roadmap/issues/1158\"\u003eimproved incremental analysis\u003c/a\u003e is enabled, since improved incremental analysis supersedes TRAP caching. This will improve performance and reduce Actions cache usage. We expect to roll this change out to everyone in March. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3569\"\u003e#3569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWe are rolling out improved incremental analysis to C/C++ analyses that use build mode \u003ccode\u003enone\u003c/code\u003e. We expect this rollout to be complete by the end of April 2026. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3584\"\u003e#3584\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.0\"\u003e2.25.0\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3585\"\u003e#3585\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.33.0 - 16 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpcoming change: Starting April 2026, the CodeQL Action will skip collecting file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. Pull request analyses will log a warning about this upcoming change. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3562\"\u003e#3562\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo opt out of this change:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRepositories owned by an organization:\u003c/strong\u003e Create a custom repository property with the name \u003ccode\u003egithub-codeql-file-coverage-on-prs\u003c/code\u003e and the type \u0026quot;True/false\u0026quot;, then set this property to \u003ccode\u003etrue\u003c/code\u003e in the repository's settings. For more information, see \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003eManaging custom properties for repositories in your organization\u003c/a\u003e. Alternatively, if you are using an advanced setup workflow, you can set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using default setup:\u003c/strong\u003e Switch to an advanced setup workflow and set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser-owned repositories using advanced setup:\u003c/strong\u003e Set the \u003ccode\u003eCODEQL_ACTION_FILE_COVERAGE_ON_PRS\u003c/code\u003e environment variable to \u003ccode\u003etrue\u003c/code\u003e in your workflow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3555\"\u003ea bug\u003c/a\u003e which caused the CodeQL Action to fail loading repository properties if a \u0026quot;Multi select\u0026quot; repository property was configured for the repository. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3557\"\u003e#3557\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe CodeQL Action now loads \u003ca href=\"https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization\"\u003ecustom repository properties\u003c/a\u003e on GitHub Enterprise Server, enabling the customization of features such as \u003ccode\u003egithub-codeql-disable-overlay\u003c/code\u003e that was previously only available on GitHub.com. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3559\"\u003e#3559\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce \u003ca href=\"https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries\"\u003eprivate package registries\u003c/a\u003e can be configured with OIDC-based authentication for organizations, the CodeQL Action will now be able to accept such configurations. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3563\"\u003e#3563\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the retry mechanism for database uploads. Previously this would fail with the error \u0026quot;Response body object should not be disturbed or locked\u0026quot;. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3564\"\u003e#3564\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA warning is now emitted if the CodeQL Action detects a repository property whose name suggests that it relates to the CodeQL Action, but which is not one of the properties recognised by the current version of the CodeQL Action. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3570\"\u003e#3570\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.6 - 05 Mar 2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate default CodeQL bundle version to \u003ca href=\"https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.24.3\"\u003e2.24.3\u003c/a\u003e. \u003ca href=\"https://redirect.github.com/github/codeql-action/pull/3548\"\u003e#3548\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.32.5 - 02 Mar 2026\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/c10b8064de6f491fea524254123dbe5e09572f13\"\u003e\u003ccode\u003ec10b806\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3782\"\u003e#3782\u003c/a\u003e from github/update-v4.35.1-d6d1743b8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/c5ffd0683786820677d054e3505e1c5bb4b8c227\"\u003e\u003ccode\u003ec5ffd06\u003c/code\u003e\u003c/a\u003e Update changelog for v4.35.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/d6d1743b8ec7ecd94f78ad1ce4cb3d8d2ba58001\"\u003e\u003ccode\u003ed6d1743\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3781\"\u003e#3781\u003c/a\u003e from github/henrymercer/update-git-minimum-version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/65d2efa7333ad65f97cc54be40f4cd18630f884c\"\u003e\u003ccode\u003e65d2efa\u003c/code\u003e\u003c/a\u003e Add changelog note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/2437b20ab31021229573a66717323dd5c6ce9319\"\u003e\u003ccode\u003e2437b20\u003c/code\u003e\u003c/a\u003e Update minimum git version for overlay to 2.36.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/ea5f71947c021286c99f61cc426a10d715fe4434\"\u003e\u003ccode\u003eea5f719\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3775\"\u003e#3775\u003c/a\u003e from github/dependabot/npm_and_yarn/node-forge-1.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/45ceeea896ba2293e10982f871198d1950ee13d6\"\u003e\u003ccode\u003e45ceeea\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3777\"\u003e#3777\u003c/a\u003e from github/mergeback/v4.35.0-to-main-b8bb9f28\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/24448c98434f429f901d27db7ddae55eec5cc1c4\"\u003e\u003ccode\u003e24448c9\u003c/code\u003e\u003c/a\u003e Rebuild\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/7c510606312e5c68ac8b27c009e5254f226f5dfa\"\u003e\u003ccode\u003e7c51060\u003c/code\u003e\u003c/a\u003e Update changelog and version after v4.35.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github/codeql-action/commit/b8bb9f28b8d3f992092362369c57161b755dea45\"\u003e\u003ccode\u003eb8bb9f2\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/github/codeql-action/issues/3776\"\u003e#3776\u003c/a\u003e from github/update-v4.35.0-0078ad667\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/github/codeql-action/compare/89a39a4e59826350b863aa6b6252a07ad50cf83e...c10b8064de6f491fea524254123dbe5e09572f13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/yuyu-111000/Slist/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yuyu-111000%2FSlist/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"}},{"old_version":"2.0","new_version":"2.1","update_type":null,"path":null,"pr_created_at":"2026-04-13T03:22:07.000Z","version_change":"2.0 → 2.1","issue":{"uuid":"4251035851","node_id":"PR_kwDOHvz5Q87R2yV3","number":1116,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-04-14T10:34:27.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-13T03:22:07.000Z","updated_at":"2026-04-14T10:34:29.000Z","time_to_close":112340,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v2.0...v2.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/GyulyVGC/sniffnet/pull/1116","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GyulyVGC%2Fsniffnet/issues/1116","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1116/packages"}},{"old_version":"2.0","new_version":"2.1","update_type":null,"path":null,"pr_created_at":"2026-04-11T10:04:19.000Z","version_change":"2.0 → 2.1","issue":{"uuid":"4244139113","node_id":"PR_kwDORKxwDc7RprEU","number":99,"state":"closed","title":"build(deps): Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-04-18T10:04:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-11T10:04:19.000Z","updated_at":"2026-04-18T10:04:20.000Z","time_to_close":604799,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/3f9250c56651ff692d6729a2fbb0603a42d7d322...bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/robertpopa22/mRemoteNG/pull/99","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/robertpopa22%2FmRemoteNG/issues/99","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/99/packages"}},{"old_version":"2.0","new_version":"2.1","update_type":null,"path":null,"pr_created_at":"2026-04-09T15:54:04.000Z","version_change":"2.0 → 2.1","issue":{"uuid":"4233435224","node_id":"PR_kwDOLvDTHM7RL0tv","number":53,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 2.0 to 2.1","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-04-14T15:54:00.000Z","author_association":null,"state_reason":null,"created_at":"2026-04-09T15:54:04.000Z","updated_at":"2026-04-14T15:54:02.000Z","time_to_close":431996,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"2.0","new_version":"2.1","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 2.0 to 2.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/bc66d86b015a46e9c6d9700de73143a82f9570ff\"\u003e\u003ccode\u003ebc66d86\u003c/code\u003e\u003c/a\u003e Build from - 67583aeca9c7106b86ea99369d665c1f74485258. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f4f73b76c67b7dcf3fddd0bdbb1a736ca9f6bcd\"\u003e\u003ccode\u003e4f4f73b\u003c/code\u003e\u003c/a\u003e Build from - c0b8e84be08d928095ffb4af2faf245a74e4ee87. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/90c2382c875a51338d44fce3ce7bd4ed0585883d\"\u003e\u003ccode\u003e90c2382\u003c/code\u003e\u003c/a\u003e Build from - b9e1fe6a1331f49f1ca4d00db98df74f06fcc01b. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/c9d1450da83494ecd9b793adbca670b4a00c493f\"\u003e\u003ccode\u003ec9d1450\u003c/code\u003e\u003c/a\u003e Build from - 1c264d783a2bcf71282c5921d50ef89bf993c2fd. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v2.0...v2.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=2.0\u0026new-version=2.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/otsako-vpk/bloxstrap/pull/53","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/otsako-vpk%2Fbloxstrap/issues/53","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/53/packages"}},{"old_version":"1.3","new_version":"2.0","update_type":null,"path":null,"pr_created_at":"2025-10-23T23:15:30.000Z","version_change":"1.3 → 2.0","issue":{"uuid":"3546931136","node_id":"PR_kwDOLrNzL86vYmAx","number":4594,"state":"open","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.3 to 2.0","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2025-10-23T23:15:30.000Z","updated_at":"2025-10-23T23:18:19.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.3","new_version":"2.0","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.3 to 2.0.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/3f9250c56651ff692d6729a2fbb0603a42d7d322\"\u003e\u003ccode\u003e3f9250c\u003c/code\u003e\u003c/a\u003e Build from - a2ec67ac30161f1c9053ad98dc28ac26acabb81d. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/92b6563ace2b00322e04c1e3a120c601bf2ac381\"\u003e\u003ccode\u003e92b6563\u003c/code\u003e\u003c/a\u003e Build from - 22bcc1863aa461d2e73157bcd922986adf315442. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.3...v2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.3\u0026new-version=2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/RSSNext/Folo/pull/4594","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RSSNext%2FFolo/issues/4594","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4594/packages"}},{"old_version":"1.1","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-10-20T14:45:14.000Z","version_change":"1.1 → 1.3","issue":{"uuid":"3532732687","node_id":"PR_kwDOQFzKOc6upbOJ","number":6,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2025-10-23T21:28:30.000Z","author_association":null,"state_reason":null,"created_at":"2025-10-20T14:45:14.000Z","updated_at":"2025-10-23T21:28:31.000Z","time_to_close":283396,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/icexghoul-art/bloxstrap-overlay/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/icexghoul-art%2Fbloxstrap-overlay/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"1.1","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-09-08T21:01:53.000Z","version_change":"1.1 → 1.3","issue":{"uuid":"3395730048","node_id":"PR_kwDOPZpyu86ndzzn","number":6,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2025-09-09T18:03:57.000Z","author_association":"NONE","state_reason":null,"created_at":"2025-09-08T21:01:53.000Z","updated_at":"2025-09-09T18:03:59.000Z","time_to_close":75724,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/999MS-LLC/WaveStrap/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/999MS-LLC%2FWaveStrap/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"1.1","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-18T03:10:26.000Z","version_change":"1.1 → 1.3","issue":{"uuid":"2751828545","node_id":"PR_kwDOMm6W4s6kBZJB","number":865,"state":"open","title":"build(deps): bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-18T03:10:26.000Z","updated_at":"2025-08-18T03:10:27.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Class-Widgets/Class-Widgets/pull/865","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Class-Widgets%2FClass-Widgets/issues/865","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/865/packages"}},{"old_version":"1.2","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-12T06:58:41.000Z","version_change":"1.2 → 1.3","issue":{"uuid":"3312815773","node_id":"PR_kwDOACamOs6jMTiP","number":4409,"state":"open","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-12T06:58:41.000Z","updated_at":"2025-08-25T10:30:58.012Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/geany/geany/pull/4409","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/geany%2Fgeany/issues/4409","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4409/packages"}},{"old_version":"1.2","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-08T00:08:55.000Z","version_change":"1.2 → 1.3","issue":{"uuid":"2729251698","node_id":"PR_kwDOLrNzL86irRNy","number":4313,"state":"open","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-08T00:08:55.000Z","updated_at":"2025-08-08T00:08:56.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/RSSNext/Folo/pull/4313","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RSSNext%2FFolo/issues/4313","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4313/packages"}},{"old_version":"1.2","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-06T12:02:16.000Z","version_change":"1.2 → 1.3","issue":{"uuid":"2724147390","node_id":"PR_kwDOG7WOB86iXzC-","number":920,"state":"closed","title":"chore(deps): bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":"2025-08-11T08:37:47.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T12:02:16.000Z","updated_at":"2025-08-11T08:37:47.000Z","time_to_close":419731,"merged_at":"2025-08-11T08:37:47.000Z","merged_by":"markuslf","closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae...ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/Linuxfabrik/monitoring-plugins/pull/920","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Linuxfabrik%2Fmonitoring-plugins/issues/920","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/920/packages"}},{"old_version":"1.1","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-06T05:48:05.000Z","version_change":"1.1 → 1.3","issue":{"uuid":"2723117034","node_id":"PR_kwDOOJ8c986iT3fq","number":2,"state":"open","title":"Bump signpath/github-action-submit-signing-request from 1.1 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":null,"author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T05:48:05.000Z","updated_at":"2025-08-06T05:48:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.1","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.1 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/4f13d373e8f0cd8d3c0465ff4877feff27aed2ae\"\u003e\u003ccode\u003e4f13d37\u003c/code\u003e\u003c/a\u003e Build from - e7d69180d2e0d3d814f31762e2f560bcf1956247. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/d0a7ae70b9f4e3553cb08f0ba41fff3522e14332\"\u003e\u003ccode\u003ed0a7ae7\u003c/code\u003e\u003c/a\u003e Build from - c35ed9d5b702cbdceddc2658f7e4005c5704083c. Original commit messag...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/17d8f4db0b3bf0515761d19d68d37b7b75bf8305\"\u003e\u003ccode\u003e17d8f4d\u003c/code\u003e\u003c/a\u003e Build from - dcd5bb4b20105e3cb6de9d44e7056837ca37dc1a. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.1...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.1\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/seventeenstrap-holdings/seventeenstrap/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/seventeenstrap-holdings%2Fseventeenstrap/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"1.2","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-06T03:06:48.000Z","version_change":"1.2 → 1.3","issue":{"uuid":"2722910760","node_id":"PR_kwDOHvz5Q86iTFIo","number":925,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2025-08-28T14:35:53.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T03:06:48.000Z","updated_at":"2025-08-28T14:35:53.000Z","time_to_close":1942145,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/GyulyVGC/sniffnet/pull/925","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GyulyVGC%2Fsniffnet/issues/925","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/925/packages"}},{"old_version":"1.2","new_version":"1.3","update_type":null,"path":null,"pr_created_at":"2025-08-06T02:08:41.000Z","version_change":"1.2 → 1.3","issue":{"uuid":"2722842513","node_id":"PR_kwDOKZNc8s6iS0eR","number":537,"state":"closed","title":"Bump signpath/github-action-submit-signing-request from 1.2 to 1.3","user":"dependabot[bot]","labels":["dependencies","github_actions"],"assignees":[],"locked":false,"comments_count":0,"pull_request":true,"closed_at":"2025-08-06T06:56:10.000Z","author_association":"CONTRIBUTOR","state_reason":null,"created_at":"2025-08-06T02:08:41.000Z","updated_at":"2025-08-06T06:56:10.000Z","time_to_close":17249,"merged_at":"2025-08-06T06:56:10.000Z","merged_by":"loganmc10","closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"signpath/github-action-submit-signing-request","old_version":"1.2","new_version":"1.3","repository_url":"https://github.com/signpath/github-action-submit-signing-request"}],"path":null,"ecosystem":"actions"},"body":"Bumps [signpath/github-action-submit-signing-request](https://github.com/signpath/github-action-submit-signing-request) from 1.2 to 1.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SignPath/github-action-submit-signing-request/commit/ced31329c0317e779dad2eec2a7c3bb46ea1343e\"\u003e\u003ccode\u003eced3132\u003c/code\u003e\u003c/a\u003e Build from - b6e25451b26e5e58273ec31542e6f3a627ed45db. Original commit messag...\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/signpath/github-action-submit-signing-request/compare/v1.2...v1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=signpath/github-action-submit-signing-request\u0026package-manager=github_actions\u0026previous-version=1.2\u0026new-version=1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/gopher64/gopher64/pull/537","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/gopher64%2Fgopher64/issues/537","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/537/packages"}}]}