An open index of dependabot pull requests across open source projects.

build(deps): bump getsentry/craft/.github/workflows/changelog-preview.yml from 2.26.3 to 2.26.5

Open
Number: #6275
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: May 18, 2026 at 04:27 AM UTC
(2 months ago)
Updated: May 18, 2026 at 04:34 AM UTC
(2 months ago)
Labels:
Dependencies github_actions
Description:

Bumps getsentry/craft/.github/workflows/changelog-preview.yml from 2.26.3 to 2.26.5.

Release notes

Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's releases.

2.26.5

Bug Fixes 🐛

  • (security) Bump devalue override to ^5.8.1 (CVE-2026-42570) by @​BYK in #818

2.26.4

Bug Fixes 🐛

Internal Changes 🔧

Changelog

Sourced from getsentry/craft/.github/workflows/changelog-preview.yml's changelog.

Changelog

2.26.5

Bug Fixes 🐛

  • (security) Bump devalue override to ^5.8.1 (CVE-2026-42570) by @​BYK in #818

2.26.4

Bug Fixes 🐛

Internal Changes 🔧

2.26.3

Bug Fixes 🐛

2.26.2

Security 🔒

  • (deps) Bump uuid to ^14.0.0 (fix GHSA-w5hq-g745-h8pq) by @​BYK in #810

Bug Fixes 🐛

  • (prepare) Remove --allow-remote-config gate by @​BYK in #809

Internal Changes 🔧

2.26.1

Security 🔒

  • (release-env) Allowlist GITHUB_* and RUNNER_* by prefix by @​BYK in #807

Bug Fixes 🐛

  • (npm) Tolerate workspace:* deps in version bump and bun.lock patching by @​BYK in #805

... (truncated)

Commits
  • bc2e6a9 release: 2.26.5
  • 60b80e5 fix(security): bump devalue override to ^5.8.1 (CVE-2026-42570) (#818)
  • 7bd2931 meta: Bump new development version
  • 1389909 Merge branch 'release/2.26.4'
  • 70714dd release: 2.26.4
  • a7098da fix: resolve open dependabot security alerts (#816)
  • ebbd176 build(deps-dev): bump simple-git from 3.33.0 to 3.36.0 (#814)
  • 134b650 fix(security): Prevent script injection in changelog-preview workflow (#813)
  • e04c703 meta: Bump new development version
  • 0589632 Merge branch 'release/2.26.3'
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Ecosystem:
actions
Version Change:
2.26.3 → 2.26.5
Update Type:
Patch
Technical Details
ID: 15840486
UUID: 4466260246
Node ID: PR_kwDOCDbi-87cgWB2
Host: GitHub
Repository: getsentry/sentry-python