build(deps): bump getsentry/craft from 2.25.4 to 2.26.2
Open
Number: #6142
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Unknown
Comments: 1
Association: Unknown
Comments: 1
Created:
April 27, 2026 at 03:53 AM UTC
(about 2 months ago)
(about 2 months ago)
Updated:
April 27, 2026 at 03:59 AM UTC
(about 2 months ago)
(about 2 months ago)
Labels:
Dependencies github_actions
Dependencies github_actions
Description:
Bumps getsentry/craft from 2.25.4 to 2.26.2.
Release notes
Sourced from getsentry/craft's releases.
2.26.2
Security 🔒
Bug Fixes 🐛
Internal Changes 🔧
- (deps) Bump astro from 5.18.1 to 6.1.6 in /docs by
@dependabotin #806- (deps-dev) Bump fast-xml-parser from 5.5.7 to 5.7.0 by
@dependabotin #8082.26.1
Security 🔒
Bug Fixes 🐛
Internal Changes 🔧
2.26.0
Security 🔒
- (ci) Pin third-party GitHub Actions to commit SHAs by
@BYKin #801- (commit-repo) Replace execSync tar with node-tar by
@BYKin #799- (gpg) Pipe private key via stdin instead of writing to /tmp by
@BYKin #798- (publish) Move publish-state file out of repo cwd by
@BYKin #797- (spawn) Strip dynamic-linker env vars from subprocess env by
@BYKin #800New Features ✨
2.25.5
Bug Fixes 🐛
Security
- Move workflow to pull_request and do not persist creds by
@geoffg-sentryin #796- Disable .craft.env reading and harden release subprocess env by
@BYKin #794
Changelog
Sourced from getsentry/craft's changelog.
Changelog
2.26.2
Security 🔒
Bug Fixes 🐛
Internal Changes 🔧
- (deps) Bump astro from 5.18.1 to 6.1.6 in /docs by
@dependabotin #806- (deps-dev) Bump fast-xml-parser from 5.5.7 to 5.7.0 by
@dependabotin #8082.26.1
Security 🔒
Bug Fixes 🐛
Internal Changes 🔧
2.26.0
Security 🔒
- (ci) Pin third-party GitHub Actions to commit SHAs by
@BYKin #801- (commit-repo) Replace execSync tar with node-tar by
@BYKin #799- (gpg) Pipe private key via stdin instead of writing to /tmp by
@BYKin #798- (publish) Move publish-state file out of repo cwd by
@BYKin #797- (spawn) Strip dynamic-linker env vars from subprocess env by
@BYKin #800New Features ✨
2.25.5
Bug Fixes 🐛
Security
... (truncated)
Commits
3dc647frelease: 2.26.23739fa1security(deps): bump uuid to ^14.0.0 (fix GHSA-w5hq-g745-h8pq) (#810)86fd3dafix(prepare): remove --allow-remote-config gate (#809)3294203build(deps): bump astro from 5.18.1 to 6.1.6 in /docs (#806)ad5568ebuild(deps-dev): bump fast-xml-parser from 5.5.7 to 5.7.0 (#808)19b7281meta: Bump new development versiona8d2fd6Merge branch 'release/2.26.1'c248b38release: 2.26.1c5c5d7asecurity(release-env): allowlist GITHUB_* and RUNNER_* by prefix (#807)2ec39c0fix(npm): tolerate workspace:* deps in version bump and bun.lock patching (#805)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Technical Details
| ID: | 15532184 |
| UUID: | 4332962084 |
| Node ID: | PR_kwDOCDbi-87V0SQ0 |
| Host: | GitHub |
| Repository: | getsentry/sentry-python |