Bump JS-DevTools/npm-publish from 1 to 4
Type: Pull Request
State: Open
Association: Contributor
Comments: 2
(8 months ago)
(8 months ago)
dependencies github_actions
Bumps JS-DevTools/npm-publish from 1 to 4.
Release notes
Sourced from JS-DevTools/npm-publish's releases.
v4.0.0
The
v4release updates the action runtime to Node 24, but there have been no usage changes to the action.Immutable releases have been enabled for this repository. As a security practice, we recommend pinning to an exact release:
- uses: JS-DevTools/npm-publish@v4.0.0 with: token: ${{ secrets.NPM_TOKEN }}⚠ BREAKING CHANGES
- The action now runs on Node 24 with npm 11
- The library and CLI now require Node >= 20, Node 16 and 18 are no longer supported
- The library is now ESM only
Features
Bug Fixes
- deps: bump the production group across 1 directory with 5 updates (#238) (314ae61)
- deps: update tar and semver dependencies (#194) (cd26c94)
- update dry-run and publish conflict logic for npm>=10 (#232) (62716ea)
- windows: allow spawning
npmcli on windows (#199) (f45e793), closes #198Code Refactoring
v3.1.1
Bug fixes
- include registry URL pathname in npm config (#186)
v3.1.0
Features
Performance Improvements
- action: decrease bundle size (#166)
v3.0.1
Bug fixes
... (truncated)
Changelog
Sourced from JS-DevTools/npm-publish's changelog.
Change Log (Archived)
See releases for current change log.
All notable changes will be documented in this file. NPM Publish adheres to Semantic Versioning.
Commits
7f8fe47chore(release): 4.1.199ef290fix(deps): bump tar from 7.4.3 to 7.5.1 (#249)1fe17a0chore(release): 4.1.03817accfix(action): remove erroneous requiredtokeninput check (#248)85420f2chore(release): 4.1.0612922ffeat: allow token to be optional for OIDC-based publish (#247)ad69356chore(release): 4.0.1c13368dfix: do not suppress E409 fromnpm publish(#246)b6b0bb6docs: add usage warning to steer folks to first-party tools (#241)d9dc932chore(release): 4.0.0- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
0
0
+0
-0
Package Dependencies
Technical Details
| ID: | 9882437 |
| UUID: | 3495886005 |
| Node ID: | PR_kwDODgsJYM6suceJ |
| Host: | GitHub |
| Repository: | NHSDigital/nhsuk-react-components |