Bump @actions/cache to v6.1.0 - handle read-only cache access - #1768
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
Updates this action to @actions/cache@5.1.0 to correctly surface “cache write denied” behavior when the workflow token has read-only cache permissions, reduces redundant warning noise in the save-only variant, and documents the new behavior.
Changes:
- Bump
@actions/cachedependency and action version to5.1.0 - Change save-only behavior to log a debug message (instead of an extra warning) when the cache is not saved
- Document read-only cache access behavior in the README and update release notes / license metadata
Show a summary per file
| File | Description |
|---|---|
src/saveImpl.ts |
Avoids emitting a generic warning in save-only when saveCache returns -1; uses core.debug instead. |
__tests__/saveOnly.test.ts |
Updates expectations to assert debug logging and no warning / failure when save resolves to -1. |
README.md |
Adds a “Read-only access” section explaining restore-vs-save behavior with read-only tokens. |
RELEASES.md |
Adds a 5.1.0 changelog entry and minor markdown formatting cleanup. |
package.json |
Bumps package version to 5.1.0 and updates @actions/cache to ^5.1.0. |
package-lock.json |
Updates locked @actions/cache and transitive deps (but currently leaves the root package version at 5.0.4). |
.licenses/npm/@actions/cache.dep.yml |
Updates tracked license metadata for @actions/cache@5.1.0. |
.licenses/npm/@azure/core-client.dep.yml |
Updates tracked license metadata for @azure/core-client@1.10.2. |
.licenses/npm/@azure/core-http-compat.dep.yml |
Updates tracked license metadata for @azure/core-http-compat@2.4.0. |
.licenses/npm/@azure/core-rest-pipeline.dep.yml |
Updates tracked license metadata for @azure/core-rest-pipeline@1.24.0. |
.licenses/npm/@azure/core-xml.dep.yml |
Updates tracked license metadata for @azure/core-xml@1.5.1. |
.licenses/npm/@azure/storage-blob.dep.yml |
Updates tracked license metadata for @azure/storage-blob@12.32.0. |
.licenses/npm/@azure/storage-common.dep.yml |
Updates tracked license metadata for @azure/storage-common@12.4.0. |
.licenses/npm/@typespec/ts-http-runtime.dep.yml |
Updates tracked license metadata for @typespec/ts-http-runtime@0.3.6. |
.licenses/npm/fast-xml-builder.dep.yml |
Updates tracked license metadata for fast-xml-builder@1.2.0. |
.licenses/npm/fast-xml-parser.dep.yml |
Updates tracked license metadata for fast-xml-parser@5.9.2. |
.licenses/npm/is-unsafe.dep.yml |
Adds tracked license metadata for new transitive dep is-unsafe@1.0.1. |
.licenses/npm/path-expression-matcher.dep.yml |
Updates tracked license metadata for path-expression-matcher@1.5.0. |
.licenses/npm/strnum.dep.yml |
Updates tracked license metadata for strnum@2.4.1. |
.licenses/npm/anynum.dep.yml |
Adds tracked license metadata for new transitive dep anynum@1.0.1. |
.licenses/npm/@nodable/entities.dep.yml |
Adds tracked license metadata for new transitive dep @nodable/entities@2.2.0. |
.licenses/npm/xml-naming.dep.yml |
Adds tracked license metadata for new transitive dep xml-naming@0.1.0. |
Copilot's findings
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 21/26 changed files
- Comments generated: 0
Link-
reviewed
Jun 19, 2026
Link-
previously approved these changes
Jun 19, 2026
joe345-str
approved these changes
Jun 20, 2026
Contributor
Author
|
I rebased to resolve conflicts from #1760 Since that change bumped the version to v6.0, this change now goes to v6.1. |
Samirat
approved these changes
Jun 23, 2026
10 tasks
luketainton
pushed a commit
to luketainton/repos_webexmemebot
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/repos/webexmemebot/pulls/595 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/repos_roboluke
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/repos/roboluke/pulls/461 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/repos_pypilot
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/repos/pypilot/pulls/459 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/luke_instant-msg-api
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/luke/instant-msg-api/pulls/268 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/actions_gha-workflows
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/actions/gha-workflows/pulls/83 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/repos_epage
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/repos/epage/pulls/230 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/repos_PwnedPW
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiXX0=--> Reviewed-on: https://git.tainton.uk/repos/PwnedPW/pulls/345 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
luketainton
pushed a commit
to luketainton/6to4_converter
that referenced
this pull request
Jun 27, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) #### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) #### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzcuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0NC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJ0eXBlL2RlcGVuZGVuY2llcyJdfQ==--> Reviewed-on: https://git.tainton.uk/repos/6to4_converter/pulls/42 Co-authored-by: renovate[bot] <renovate-bot@git.tainton.uk> Co-committed-by: renovate[bot] <renovate-bot@git.tainton.uk>
1 task
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jun 29, 2026
Bumps [actions/cache/restore](https://github.com/actions/cache) from 5.0.5 to 6.1.0. Release notes *Sourced from [actions/cache/restore's releases](https://github.com/actions/cache/releases).* > v6.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v6.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1768](https://redirect.github.com/actions/cache/pull/1768) > > **Full Changelog**: <actions/cache@v6...v6.1.0> > > v6.0.0 > ------ > > What's Changed > -------------- > > * Update packages, migrate to ESM by [`@Samirat`](https://github.com/Samirat) in [actions/cache#1760](https://redirect.github.com/actions/cache/pull/1760) > > **Full Changelog**: <actions/cache@v5...v6.0.0> > > v5.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v5.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1775](https://redirect.github.com/actions/cache/pull/1775) > > **Full Changelog**: <actions/cache@v5...v5.1.0> Changelog *Sourced from [actions/cache/restore's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).* > Releases > ======== > > How to prepare a release > ------------------------ > > > [!NOTE] > > Relevant for maintainers with write access only. > > 1. Switch to a new branch from `main`. > 2. Run `npm test` to ensure all tests are passing. > 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json). > 4. Run `npm run build` to update the compiled files. > 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section. > 6. Run `licensed cache` to update the license report. > 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions. > 8. Commit your changes and push your branch upstream. > 9. Open a pull request against `main` and get it reviewed and merged. > 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json` > 1. Create a new tag with the version number. > 2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`. > 3. Toggle the set as the latest release option. > 4. Publish the release. > 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml> > 1. There should be a workflow run queued with the same version number. > 2. Approve the run to publish the new version and update the major tags for this action. > > Changelog > --------- > > ### 6.1.0 > > * Bump `@actions/cache` to v6.1.0 to pick up [actions/toolkit#2435 Handle cache write error due to read-only token](https://redirect.github.com/actions/toolkit/pull/2435) > * Switch redundant "Cache save failed" warning to debug log in save-only > > ### 6.0.0 > > * Updated `@actions/cache` to ^6.0.1, `@actions/core` to ^3.0.1, `@actions/exec` to ^3.0.0, `@actions/io` to ^3.0.2 > * Migrated to ESM module system > * Upgraded Jest to v30 and test infrastructure to be ESM compatible > > ### 5.0.4 > > * Bump `minimatch` to v3.1.5 (fixes ReDoS via globstar patterns) > * Bump `undici` to v6.24.1 (WebSocket decompression bomb protection, header validation fixes) > * Bump `fast-xml-parser` to v5.5.6 > > ### 5.0.3 > > * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) > * Bump `@actions/core` to v2.0.3 > > ### 5.0.2 ... (truncated) Commits * [`55cc834`](actions/cache@55cc834) Merge pull request [#1768](https://redirect.github.com/actions/cache/issues/1768) from jasongin/readonly-cache * [`d8cd72f`](actions/cache@d8cd72f) Bump `@actions/cache` to v6.1.0 - handle cache write error due to RO token * [`2c8a9bd`](actions/cache@2c8a9bd) Merge pull request [#1760](https://redirect.github.com/actions/cache/issues/1760) from actions/samirat/esm\_migration\_and\_package\_update * [`e9b91fd`](actions/cache@e9b91fd) Prettier fixes * [`e4884b8`](actions/cache@e4884b8) Rebuild dist * [`10baf01`](actions/cache@10baf01) Fixed licenses * [`e39b386`](actions/cache@e39b386) Fix test mock return order * [`b692820`](actions/cache@b692820) PR feedback * [`6074912`](actions/cache@6074912) Rebuild dist bundles as ESM to match type:module * [`5a912e8`](actions/cache@5a912e8) Fix lint and jest issues * Additional commits viewable in [compare view](actions/cache@27d5ce7...55cc834) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jun 29, 2026
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0. Release notes *Sourced from [actions/cache's releases](https://github.com/actions/cache/releases).* > v6.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v6.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1768](https://redirect.github.com/actions/cache/pull/1768) > > **Full Changelog**: <actions/cache@v6...v6.1.0> > > v6.0.0 > ------ > > What's Changed > -------------- > > * Update packages, migrate to ESM by [`@Samirat`](https://github.com/Samirat) in [actions/cache#1760](https://redirect.github.com/actions/cache/pull/1760) > > **Full Changelog**: <actions/cache@v5...v6.0.0> > > v5.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v5.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1775](https://redirect.github.com/actions/cache/pull/1775) > > **Full Changelog**: <actions/cache@v5...v5.1.0> Changelog *Sourced from [actions/cache's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).* > Releases > ======== > > How to prepare a release > ------------------------ > > > [!NOTE] > > Relevant for maintainers with write access only. > > 1. Switch to a new branch from `main`. > 2. Run `npm test` to ensure all tests are passing. > 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json). > 4. Run `npm run build` to update the compiled files. > 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section. > 6. Run `licensed cache` to update the license report. > 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions. > 8. Commit your changes and push your branch upstream. > 9. Open a pull request against `main` and get it reviewed and merged. > 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json` > 1. Create a new tag with the version number. > 2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`. > 3. Toggle the set as the latest release option. > 4. Publish the release. > 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml> > 1. There should be a workflow run queued with the same version number. > 2. Approve the run to publish the new version and update the major tags for this action. > > Changelog > --------- > > ### 6.1.0 > > * Bump `@actions/cache` to v6.1.0 to pick up [actions/toolkit#2435 Handle cache write error due to read-only token](https://redirect.github.com/actions/toolkit/pull/2435) > * Switch redundant "Cache save failed" warning to debug log in save-only > > ### 6.0.0 > > * Updated `@actions/cache` to ^6.0.1, `@actions/core` to ^3.0.1, `@actions/exec` to ^3.0.0, `@actions/io` to ^3.0.2 > * Migrated to ESM module system > * Upgraded Jest to v30 and test infrastructure to be ESM compatible > > ### 5.0.4 > > * Bump `minimatch` to v3.1.5 (fixes ReDoS via globstar patterns) > * Bump `undici` to v6.24.1 (WebSocket decompression bomb protection, header validation fixes) > * Bump `fast-xml-parser` to v5.5.6 > > ### 5.0.3 > > * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) > * Bump `@actions/core` to v2.0.3 > > ### 5.0.2 ... (truncated) Commits * [`55cc834`](actions/cache@55cc834) Merge pull request [#1768](https://redirect.github.com/actions/cache/issues/1768) from jasongin/readonly-cache * [`d8cd72f`](actions/cache@d8cd72f) Bump `@actions/cache` to v6.1.0 - handle cache write error due to RO token * [`2c8a9bd`](actions/cache@2c8a9bd) Merge pull request [#1760](https://redirect.github.com/actions/cache/issues/1760) from actions/samirat/esm\_migration\_and\_package\_update * [`e9b91fd`](actions/cache@e9b91fd) Prettier fixes * [`e4884b8`](actions/cache@e4884b8) Rebuild dist * [`10baf01`](actions/cache@10baf01) Fixed licenses * [`e39b386`](actions/cache@e39b386) Fix test mock return order * [`b692820`](actions/cache@b692820) PR feedback * [`6074912`](actions/cache@6074912) Rebuild dist bundles as ESM to match type:module * [`5a912e8`](actions/cache@5a912e8) Fix lint and jest issues * Additional commits viewable in [compare view](actions/cache@27d5ce7...55cc834) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jun 29, 2026
Bumps [actions/cache/save](https://github.com/actions/cache) from 5.0.5 to 6.1.0. Release notes *Sourced from [actions/cache/save's releases](https://github.com/actions/cache/releases).* > v6.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v6.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1768](https://redirect.github.com/actions/cache/pull/1768) > > **Full Changelog**: <actions/cache@v6...v6.1.0> > > v6.0.0 > ------ > > What's Changed > -------------- > > * Update packages, migrate to ESM by [`@Samirat`](https://github.com/Samirat) in [actions/cache#1760](https://redirect.github.com/actions/cache/pull/1760) > > **Full Changelog**: <actions/cache@v5...v6.0.0> > > v5.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v5.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1775](https://redirect.github.com/actions/cache/pull/1775) > > **Full Changelog**: <actions/cache@v5...v5.1.0> Changelog *Sourced from [actions/cache/save's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).* > Releases > ======== > > How to prepare a release > ------------------------ > > > [!NOTE] > > Relevant for maintainers with write access only. > > 1. Switch to a new branch from `main`. > 2. Run `npm test` to ensure all tests are passing. > 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json). > 4. Run `npm run build` to update the compiled files. > 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section. > 6. Run `licensed cache` to update the license report. > 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions. > 8. Commit your changes and push your branch upstream. > 9. Open a pull request against `main` and get it reviewed and merged. > 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json` > 1. Create a new tag with the version number. > 2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`. > 3. Toggle the set as the latest release option. > 4. Publish the release. > 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml> > 1. There should be a workflow run queued with the same version number. > 2. Approve the run to publish the new version and update the major tags for this action. > > Changelog > --------- > > ### 6.1.0 > > * Bump `@actions/cache` to v6.1.0 to pick up [actions/toolkit#2435 Handle cache write error due to read-only token](https://redirect.github.com/actions/toolkit/pull/2435) > * Switch redundant "Cache save failed" warning to debug log in save-only > > ### 6.0.0 > > * Updated `@actions/cache` to ^6.0.1, `@actions/core` to ^3.0.1, `@actions/exec` to ^3.0.0, `@actions/io` to ^3.0.2 > * Migrated to ESM module system > * Upgraded Jest to v30 and test infrastructure to be ESM compatible > > ### 5.0.4 > > * Bump `minimatch` to v3.1.5 (fixes ReDoS via globstar patterns) > * Bump `undici` to v6.24.1 (WebSocket decompression bomb protection, header validation fixes) > * Bump `fast-xml-parser` to v5.5.6 > > ### 5.0.3 > > * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) > * Bump `@actions/core` to v2.0.3 > > ### 5.0.2 ... (truncated) Commits * [`55cc834`](actions/cache@55cc834) Merge pull request [#1768](https://redirect.github.com/actions/cache/issues/1768) from jasongin/readonly-cache * [`d8cd72f`](actions/cache@d8cd72f) Bump `@actions/cache` to v6.1.0 - handle cache write error due to RO token * [`2c8a9bd`](actions/cache@2c8a9bd) Merge pull request [#1760](https://redirect.github.com/actions/cache/issues/1760) from actions/samirat/esm\_migration\_and\_package\_update * [`e9b91fd`](actions/cache@e9b91fd) Prettier fixes * [`e4884b8`](actions/cache@e4884b8) Rebuild dist * [`10baf01`](actions/cache@10baf01) Fixed licenses * [`e39b386`](actions/cache@e39b386) Fix test mock return order * [`b692820`](actions/cache@b692820) PR feedback * [`6074912`](actions/cache@6074912) Rebuild dist bundles as ESM to match type:module * [`5a912e8`](actions/cache@5a912e8) Fix lint and jest issues * Additional commits viewable in [compare view](actions/cache@27d5ce7...55cc834) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
6 tasks
This was referenced Jul 6, 2026
wu
pushed a commit
to wu/keyop-messenger
that referenced
this pull request
Jul 18, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v4` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) ##### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) ### [`v5.1.0`](https://github.com/actions/cache/releases/tag/v5.1.0) [Compare Source](actions/cache@v5.0.5...v5.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v5.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1775](actions/cache#1775) **Full Changelog**: <actions/cache@v5...v5.1.0> ### [`v5.0.5`](https://github.com/actions/cache/releases/tag/v5.0.5) [Compare Source](actions/cache@v5.0.4...v5.0.5) ##### What's Changed - Update ts-http-runtime dependency by [@​yacaovsnc](https://github.com/yacaovsnc) in [#​1747](actions/cache#1747) **Full Changelog**: <actions/cache@v5...v5.0.5> ### [`v5.0.4`](https://github.com/actions/cache/releases/tag/v5.0.4) [Compare Source](actions/cache@v5.0.3...v5.0.4) ##### What's Changed - Add release instructions and update maintainer docs by [@​Link-](https://github.com/Link-) in [#​1696](actions/cache#1696) - Potential fix for code scanning alert no. 52: Workflow does not contain permissions by [@​Link-](https://github.com/Link-) in [#​1697](actions/cache#1697) - Fix workflow permissions and cleanup workflow names / formatting by [@​Link-](https://github.com/Link-) in [#​1699](actions/cache#1699) - docs: Update examples to use the latest version by [@​XZTDean](https://github.com/XZTDean) in [#​1690](actions/cache#1690) - Fix proxy integration tests by [@​Link-](https://github.com/Link-) in [#​1701](actions/cache#1701) - Fix cache key in examples.md for bun.lock by [@​RyPeck](https://github.com/RyPeck) in [#​1722](actions/cache#1722) - Update dependencies & patch security vulnerabilities by [@​Link-](https://github.com/Link-) in [#​1738](actions/cache#1738) ##### New Contributors - [@​XZTDean](https://github.com/XZTDean) made their first contribution in [#​1690](actions/cache#1690) - [@​RyPeck](https://github.com/RyPeck) made their first contribution in [#​1722](actions/cache#1722) **Full Changelog**: <actions/cache@v5...v5.0.4> ### [`v5.0.3`](https://github.com/actions/cache/releases/tag/v5.0.3) [Compare Source](actions/cache@v5.0.2...v5.0.3) ##### What's Changed - Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) - Bump `@actions/core` to v2.0.3 **Full Changelog**: <actions/cache@v5...v5.0.3> ### [`v5.0.2`](https://github.com/actions/cache/releases/tag/v5.0.2): v.5.0.2 [Compare Source](actions/cache@v5.0.1...v5.0.2) ##### v5.0.2 ##### What's Changed When creating cache entries, 429s returned from the cache service will not be retried. ### [`v5.0.1`](https://github.com/actions/cache/releases/tag/v5.0.1) [Compare Source](actions/cache@v5...v5.0.1) > \[!IMPORTANT] > **`actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.** > > If you are using self-hosted runners, ensure they are updated before upgrading. *** ##### v5.0.1 ##### What's Changed - fix: update [@​actions/cache](https://github.com/actions/cache) for Node.js 24 punycode deprecation by [@​salmanmkc](https://github.com/salmanmkc) in [#​1685](actions/cache#1685) - prepare release v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1686](actions/cache#1686) ##### v5.0.0 ##### What's Changed - Upgrade to use node24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1630](actions/cache#1630) - Prepare v5.0.0 release by [@​salmanmkc](https://github.com/salmanmkc) in [#​1684](actions/cache#1684) **Full Changelog**: <actions/cache@v5...v5.0.1> ### [`v5.0.0`](https://github.com/actions/cache/releases/tag/v5.0.0) [Compare Source](actions/cache@v5...v5) > \[!IMPORTANT] > **`actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.** > > If you are using self-hosted runners, ensure they are updated before upgrading. *** ##### What's Changed - Upgrade to use node24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1630](actions/cache#1630) - Prepare v5.0.0 release by [@​salmanmkc](https://github.com/salmanmkc) in [#​1684](actions/cache#1684) **Full Changelog**: <actions/cache@v4.3.0...v5.0.0> ### [`v5`](actions/cache@v4.3.0...v5) [Compare Source](actions/cache@v4.3.0...v5) </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Los_Angeles) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: Renovate Bot <renovate-bot@geekfarm.org> Reviewed-on: https://git.geekfarm.org/wu/keyop-messenger/pulls/8
jimsynz
added a commit
to jimsynz/neonfs
that referenced
this pull request
Jul 19, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | | [actions/checkout](https://github.com/actions/checkout) | action | major | `v6` → `v7` | | [aes-gcm](https://github.com/RustCrypto/AEADs) | dependencies | minor | `0.10` → `0.11` | | debian | stage | patch | `trixie-20260610` → `13` | | debian | final | patch | `trixie-20260610` → `13` | | [elixir](https://elixir-lang.org/) ([source](https://github.com/elixir-lang/elixir)) | | patch | `1.20.1` → `1.20.2` | | [erlang](https://github.com/erlang/otp) | | patch | `29.0.2` → `29.0.3` | | [goreleaser/nfpm](https://github.com/goreleaser/nfpm) | | minor | `v2.46.3` → `v2.47.0` | | [ra](https://hex.pm/packages/ra) ([source](https://github.com/rabbitmq/ra)) | prod | patch | `3.1.8` → `3.1.9` | | registry.k8s.io/sig-storage/csi-resizer | | patch | `v2.2.0` → `v2.2.1` | | [req](https://hex.pm/packages/req) ([source](https://github.com/wojtekmach/req)) | dev | patch | `0.6.2` → `0.6.3` | | [req](https://hex.pm/packages/req) ([source](https://github.com/wojtekmach/req)) | dev | patch | `~> 0.5` → `~> 0.6` | | [rust](https://github.com/rust-lang/rust) | | minor | `1.96.0` → `1.97.1` | | [serde](https://serde.rs) ([source](https://github.com/serde-rs/serde)) | dependencies | patch | `1.0.228` → `1.0.229` | | [stream_data](https://hex.pm/packages/stream_data) ([source](https://github.com/whatyouhide/stream_data)) | dev | minor | `1.3.0` → `1.4.0` | | [stream_data](https://hex.pm/packages/stream_data) ([source](https://github.com/whatyouhide/stream_data)) | prod | minor | `1.3.0` → `1.4.0` | | [thiserror](https://github.com/dtolnay/thiserror) | dependencies | patch | `2.0.18` → `2.0.19` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) ##### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v6`](actions/cache@v5.1.0...v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) </details> <details> <summary>actions/checkout (actions/checkout)</summary> ### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](actions/checkout@v7.0.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2454](actions/checkout#2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2458](actions/checkout#2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2460](actions/checkout#2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2461](actions/checkout#2461) - Bump [@​actions/core](https://github.com/actions/core) and [@​actions/tool-cache](https://github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2459](actions/checkout#2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2463](actions/checkout#2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2462](actions/checkout#2462) ### [`v7`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701) [Compare Source](actions/checkout@v6.0.3...v7.0.0) - Bump github/codeql-action from 3 to 4 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2475](actions/checkout#2475) - Bump actions/setup-node from 4 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2477](actions/checkout#2477) - Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2478](actions/checkout#2478) - Bump docker/login-action from 3.3.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2479](actions/checkout#2479) - Bump actions/checkout from 6 to 7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2488](actions/checkout#2488) - Bump actions/upload-artifact from 4 to 7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2476](actions/checkout#2476) - eslint 9 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2474](actions/checkout#2474) - Bump the minor-actions-dependencies group with 2 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2499](actions/checkout#2499) - skip running unsafe pr check if input is default by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2518](actions/checkout#2518) - trim only ascii whitespace for branch by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2521](actions/checkout#2521) - escape values passed to --unset by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2530](actions/checkout#2530) </details> <details> <summary>RustCrypto/AEADs (aes-gcm)</summary> ### [`v0.11.0`](RustCrypto/AEADs@aes-gcm-v0.10.3...aes-gcm-v0.11.0) [Compare Source](RustCrypto/AEADs@aes-gcm-v0.10.3...aes-gcm-v0.11.0) </details> <details> <summary>elixir-lang/elixir (elixir)</summary> ### [`v1.20.2`](https://github.com/elixir-lang/elixir/releases/tag/v1.20.2) [Compare Source](elixir-lang/elixir@v1.20.1...v1.20.2) ##### 1. Enhancements ##### Elixir - \[Kernel.ParallelCompiler] Include per-module type checking times when compiler profiling is enabled with `profile: :time` ##### 2. Bug fixes ##### Elixir - \[Kernel] Fix binary comprehensions with sizes when options such as `:uniq` or `:into` are used - \[Kernel] Improve compiler error messages when `quote` with `unquote` is used inside a pattern or guard - \[Kernel] Restore the compiler optimization of `Kernel.put_elem/3` to emit `:erlang.setelement/3` - \[Module] Fix type checking when applying an empty function type - \[Module] Fix type checking of bitstring patterns that reuse variables - \[Module] Fix type information for `__info__(:struct)` to include the `:required` key - \[Module] Fix type operations on map and optional keys during difference/intersection, including open keys and empty intersections - \[Module] Fix typing of list types involving dynamic or empty lists - \[Module] Include bitstrings as a possible domain key in the type system - \[Module] Preserve file metadata from each clause in type system warnings - \[Module] Fix type warnings for protocol implementations whose protocol module defines additional callbacks - \[Module] Raise clearer type checking errors when an expected struct is removed or redefined during compilation ##### Mix - \[mix compile] Avoid unnecessary umbrella recompilation when a path dependency's manifest is newer but unchanged - \[mix deps.compile] Recompile fetched dependencies when their compile-time environment changes </details> <details> <summary>erlang/otp (erlang)</summary> ### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3 [Compare Source](erlang/otp@OTP-29.0.2...OTP-29.0.3) ``` Patch Package: OTP 29.0.3 Git Tag: OTP-29.0.3 Date: 2026-07-02 Trouble Report Id: OTP-20173, OTP-20183, OTP-20185, OTP-20186, OTP-20190, OTP-20191, OTP-20194, OTP-20196, OTP-20197, OTP-20198, OTP-20199, OTP-20200, OTP-20201, OTP-20206, OTP-20207, OTP-20208, OTP-20215, OTP-20216, OTP-20217, OTP-20220, OTP-20222, OTP-20226, OTP-20227, OTP-20230, OTP-20231, OTP-20232, OTP-20233 Seq num: CVE-2026-53422, CVE-2026-54886, CVE-2026-54887, CVE-2026-54891, CVE-2026-55950, CVE-2026-55952, ERIERL-1333, GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976, PR-11209, PR-11215, PR-11219, PR-11230, PR-11239, PR-11244, PR-11247, PR-11250, PR-11259, PR-11268, PR-11269, PR-11270, PR-11271, PR-11281, PR-11282, PR-11283, PR-11289, PR-11294, PR-11295, PR-11299, PR-11302, PR-11306, PR-11307, PR-11309, PR-11311 System: OTP Release: 29 Application: common_test-1.31.1, compiler-10.0.2, crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3, kernel-11.0.3, public_key-1.21.3, ssh-6.0.2, ssl-11.7.3, stdlib-8.0.2 Predecessor: OTP 29.0.2 ``` Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### common\_test-1.31.1 The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation. Own Id: OTP-20191\ Related Id(s): ERIERL-1333, [PR-11230] > #### Full runtime dependencies of common\_test-1.31.1 > > compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8 ### compiler-10.0.2 The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed. Own Id: OTP-20222\ Related Id(s): [PR-11219] > #### Full runtime dependencies of compiler-10.0.2 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### crypto-5.9.1 The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support. Own Id: OTP-20215\ Related Id(s): [PR-11302] > #### Full runtime dependencies of crypto-5.9.1 > > erts-9.0, kernel-6.0, stdlib-3.9 ### dialyzer-6.0.2 The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fix a bug with native record sets in `erl_types.erl` Own Id: OTP-20201 > #### Full runtime dependencies of dialyzer-6.0.2 > > compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0 ### erts-17.0.3 The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps. Own Id: OTP-20185\ Related Id(s): [PR-11215] - Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception. Own Id: OTP-20208\ Related Id(s): [PR-11269] - Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table. Own Id: OTP-20217\ Related Id(s): [PR-11283] - A few code generation issues for the JIT on AArch64 (ARM64) have been fixed. For all platforms, the loader will reject some invalid BEAM files earlier. Own Id: OTP-20226\ Related Id(s): [PR-11299] - On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more. Own Id: OTP-20227\ Related Id(s): [PR-11289] > #### Full runtime dependencies of erts-17.0.3 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### kernel-11.0.3 The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - inet:info/1 could crash when calling for a closing (port) socket. Own Id: OTP-20173 - Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply. This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails. Own Id: OTP-20199\ Related Id(s): [PR-11247] > #### Full runtime dependencies of kernel-11.0.3 > > crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0 ### public\_key-1.21.3 The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding. Own Id: OTP-20197\ Related Id(s): [PR-11239] > #### Full runtime dependencies of public\_key-1.21.3 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### ssh-6.0.2 The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem. Own Id: OTP-20183\ Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422] - Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue. Own Id: OTP-20186\ Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886] - Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification. Own Id: OTP-20196\ Related Id(s): [PR-11209] - Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent. Own Id: OTP-20198\ Related Id(s): [PR-11244] - The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads. Own Id: OTP-20200\ Related Id(s): [PR-11259] - Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade. Own Id: OTP-20206\ Related Id(s): [PR-11268] > #### Full runtime dependencies of ssh-6.0.2 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.3 Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown. Own Id: OTP-20190\ Related Id(s): [PR-11250] - Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window. Own Id: OTP-20194\ Related Id(s): [PR-11271], [CVE-2026-54887] - Guard TLS client for MITM injection of application data during "plain-text-window" during handshake. Own Id: OTP-20207\ Related Id(s): [PR-11270], [CVE-2026-54891] - Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs. Own Id: OTP-20216\ Related Id(s): [PR-11282], [CVE-2026-55952] - Fix race condition that could be used to DoS attack DTLS servers. Own Id: OTP-20220\ Related Id(s): [PR-11306], [CVE-2026-55950] - A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value. Own Id: OTP-20230\ Related Id(s): [PR-11307] - TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4 Own Id: OTP-20231\ Related Id(s): [PR-11309] - A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used. Own Id: OTP-20232\ Related Id(s): [PR-11311] - Correct spec for CRL API Own Id: OTP-20233\ Related Id(s): [PR-11281] > #### Full runtime dependencies of ssl-11.7.3 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.0.2 The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed. Own Id: OTP-20222\ Related Id(s): [PR-11219] > #### Full runtime dependencies of stdlib-8.0.2 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### Thanks to Cole Christensen, Nick Krichevsky, Stefan Grundmann [cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422 [cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886 [cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887 [cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891 [cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950 [cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952 [gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9 [gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976 [pr-11209]: erlang/otp#11209 [pr-11215]: erlang/otp#11215 [pr-11219]: erlang/otp#11219 [pr-11230]: erlang/otp#11230 [pr-11239]: erlang/otp#11239 [pr-11244]: erlang/otp#11244 [pr-11247]: erlang/otp#11247 [pr-11250]: erlang/otp#11250 [pr-11259]: erlang/otp#11259 [pr-11268]: erlang/otp#11268 [pr-11269]: erlang/otp#11269 [pr-11270]: erlang/otp#11270 [pr-11271]: erlang/otp#11271 [pr-11281]: erlang/otp#11281 [pr-11282]: erlang/otp#11282 [pr-11283]: erlang/otp#11283 [pr-11289]: erlang/otp#11289 [pr-11294]: erlang/otp#11294 [pr-11295]: erlang/otp#11295 [pr-11299]: erlang/otp#11299 [pr-11302]: erlang/otp#11302 [pr-11306]: erlang/otp#11306 [pr-11307]: erlang/otp#11307 [pr-11309]: erlang/otp#11309 [pr-11311]: erlang/otp#11311 </details> <details> <summary>goreleaser/nfpm (goreleaser/nfpm)</summary> ### [`v2.47.0`](https://github.com/goreleaser/nfpm/releases/tag/v2.47.0) [Compare Source](goreleaser/nfpm@v2.46.3...v2.47.0) ##### Changelog ##### New Features - [`5c2f7ca`](goreleaser/nfpm@5c2f7ca): feat: RiscV64 support ([#​1091](goreleaser/nfpm#1091)) ([@​ahqsoftwares](https://github.com/ahqsoftwares)) - [`64b788a`](goreleaser/nfpm@64b788a): feat: add Requires(Post) for RPMS ([#​1085](goreleaser/nfpm#1085)) ([@​teddelin](https://github.com/teddelin)) - [`dc96073`](goreleaser/nfpm@dc96073): feat: add fang support for styled CLI output ([#​1068](goreleaser/nfpm#1068)) ([@​caarlos0](https://github.com/caarlos0)) ##### Security updates - [`060af04`](goreleaser/nfpm@060af04): sec(deps): update golang.org/x/crypto ([@​caarlos0](https://github.com/caarlos0)) - [`f769631`](goreleaser/nfpm@f769631): sec(deps): update golang.org/x/net ([@​caarlos0](https://github.com/caarlos0)) ##### Bug fixes - [`3118ec1`](goreleaser/nfpm@3118ec1): fix: tolerate empty overrides packager clause ([#​1080](goreleaser/nfpm#1080)) ([@​dleske](https://github.com/dleske)) ##### Dependency updates - [`a2d9ce5`](goreleaser/nfpm@a2d9ce5): feat(deps): go1.26.4 ([@​caarlos0](https://github.com/caarlos0)) - [`9b16218`](goreleaser/nfpm@9b16218): fix(deps): bump alpine from 3.23.3 to 3.23.4 ([#​1075](goreleaser/nfpm#1075)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`e3102b3`](goreleaser/nfpm@e3102b3): fix(deps): bump alpine from 3.23.3 to 3.23.4 in /testdata/acceptance ([#​1076](goreleaser/nfpm#1076)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`62c555e`](goreleaser/nfpm@62c555e): fix(deps): bump alpine from 3.23.4 to 3.24.0 ([#​1098](goreleaser/nfpm#1098)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`071ae18`](goreleaser/nfpm@071ae18): fix(deps): bump alpine from 3.23.4 to 3.24.0 in /testdata/acceptance ([#​1099](goreleaser/nfpm#1099)) ([@​dependabot](https://github.com/dependabot)\[bot]) ##### Build process updates - [`4c62d34`](goreleaser/nfpm@4c62d34): ci(deps): bump github/codeql-action in the actions group ([#​1083](goreleaser/nfpm#1083)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`38a05de`](goreleaser/nfpm@38a05de): ci(deps): bump the actions group across 1 directory with 3 updates ([#​1096](goreleaser/nfpm#1096)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`6fe4da4`](goreleaser/nfpm@6fe4da4): ci(deps): bump the actions group across 1 directory with 7 updates ([#​1095](goreleaser/nfpm#1095)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`cd95f9f`](goreleaser/nfpm@cd95f9f): ci(deps): bump the actions group with 2 updates ([#​1078](goreleaser/nfpm#1078)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`8f9cbef`](goreleaser/nfpm@8f9cbef): ci(deps): bump the actions group with 3 updates ([#​1090](goreleaser/nfpm#1090)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`9ff0e2f`](goreleaser/nfpm@9ff0e2f): ci(deps): bump the actions group with 4 updates ([#​1086](goreleaser/nfpm#1086)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`2ce1832`](goreleaser/nfpm@2ce1832): ci(deps): bump the actions group with 5 updates ([#​1074](goreleaser/nfpm#1074)) ([@​dependabot](https://github.com/dependabot)\[bot]) - [`1bd2fed`](goreleaser/nfpm@1bd2fed): ci: fix docs build test ([@​caarlos0](https://github.com/caarlos0)) - [`4695cdc`](goreleaser/nfpm@4695cdc): ci: fix license check ([@​caarlos0](https://github.com/caarlos0)) - [`a40b461`](goreleaser/nfpm@a40b461): ci: update build ([@​caarlos0](https://github.com/caarlos0)) ##### Other work - [`d16d75f`](goreleaser/nfpm@d16d75f): docs(deps): update hextra ([@​caarlos0](https://github.com/caarlos0)) - [`c6a6a27`](goreleaser/nfpm@c6a6a27): docs: update cmd docs ([@​caarlos0](https://github.com/caarlos0)) **Full Changelog**: <goreleaser/nfpm@v2.46.3...v2.47.0> ##### Helping out This release is only possible thanks to **all** the support of **awesome people**! Want to be one of them? You can [sponsor](https://goreleaser.com/sponsors/) or [contribute with code](https://goreleaser.com/contributing). ##### Where to go next? - nFPM is a satellite project from GoReleaser. [Check it out](https://goreleaser.com)! - Find examples and commented usage of all options in our [website](https://nfpm.goreleaser.com/). - Reach out on [Discord](https://discord.gg/RGEBtg8vQ6) and [Twitter](https://twitter.com/goreleaser)! <a href="https://goreleaser.com"><img src="https://raw.githubusercontent.com/goreleaser/artwork/master/opencollective-header.png" with="100%" alt="GoReleaser logo"></a> </details> <details> <summary>rabbitmq/ra (ra)</summary> ### [`v3.1.9`](https://github.com/rabbitmq/ra/releases/tag/v3.1.9) [Compare Source](rabbitmq/ra@v3.1.8...v3.1.9) #### What's Changed - ci: temporary fix for windows-latest changed by [@​lshir](https://github.com/lshir) in [#​639](rabbitmq/ra#639) - Forward follower's append\_entries\_reply when it already has the snapshot by [@​kjnilsson](https://github.com/kjnilsson) in [#​641](rabbitmq/ra#641) - Fix stale `last_written`/`pending` state after log truncation, and a snapshot-send regression by [@​kjnilsson](https://github.com/kjnilsson) in [#​644](rabbitmq/ra#644) - Fix `force_shrink_members_to_current_member/1` typespec by [@​visciang](https://github.com/visciang) in [#​640](rabbitmq/ra#640) **Full Changelog**: <rabbitmq/ra@v3.1.8...v3.1.9> </details> <details> <summary>wojtekmach/req (req)</summary> ### [`v0.6.3`](https://github.com/wojtekmach/req/blob/HEAD/CHANGELOG.md#v063-2026-07-16) [Compare Source](wojtekmach/req@v0.6.2...v0.6.3) - \[`Req.Test`]: Fix race condition </details> <details> <summary>rust-lang/rust (rust)</summary> ### [`v1.97.1`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1971-2026-07-16) [Compare Source](rust-lang/rust@1.97.0...1.97.1) \========================== <a id="1.97.1"></a> - [rustc: Fix miscompilation in LLVM optimization](rust-lang/rust#159035) This backports an LLVM submodule bump to include the LLVM-side fix and a revert of the rustc change that is one known trigger for the bug. The rustc side revert should not be strictly necessary but is done out of abundance of caution. ### [`v1.97.0`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1970-2026-07-09) [Compare Source](rust-lang/rust@1.96.1...1.97.0) \========================== <a id="1.97.0-Language"></a> ## Language - [Consider `Result<T, Uninhabited>` and `ControlFlow<Uninhabited, T>` to be equivalent to `T` for must use lint](rust-lang/rust#148214) - [Add allow-by-default `dead_code_pub_in_binary` lint for unused pub items in binary crates](rust-lang/rust#149509) - [Stabilize the `div32`, `lam-bh`, `lamcas`, `ld-seq-sa` and `scq` target features](rust-lang/rust#154510) - [Stabilize `cfg(target_has_atomic_primitive_alignment)`](rust-lang/rust#155006) - [Allow trailing `self` in imports in more cases](rust-lang/rust#155137) <a id="1.97.0-Platform-Support"></a> ## Platform Support - [nvptx64-nvidia-cuda: drop support for old architectures and old ISAs](rust-lang/rust#152443) Refer to Rust's [platform support page][platform-support-doc] for more information on Rust's tiered platform support. [platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html <a id="1.97.0-Stabilized-APIs"></a> ## Stabilized APIs - [`Default for RepeatN`](https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E) - [`Copy for ffi::FromBytesUntilNulError`](https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError) - [`Send for std::fs::File` on UEFI](rust-lang/rust#154003) - [`<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one) - [`<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one) - [`<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one) - [`<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one) - [`<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width) - [`NonZero<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one) - [`NonZero<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one) - [`NonZero<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one) - [`NonZero<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one) - [`NonZero<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width) These previously stable APIs are now stable in const contexts: - [`char::is_control`](https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control) <a id="1.97.0-Cargo"></a> ## Cargo - [Stabilize `build.warnings` config.](rust-lang/cargo#16796) This controls how lint warnings from local packages are treated. Useful for enforcing a warning-free build in CI, replacing `-Dwarnings`. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#buildwarnings) - [Stabilize `resolver.lockfile-path` config.](rust-lang/cargo#16694) This allows specifying the path to the lockfile to use when resolving dependencies. Useful when working with read-only source directories. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#resolverlockfile-path) - [cargo-clean: Error when `--target-dir` doesn't look like a Cargo target directory.](rust-lang/cargo#16712) This prevents accidental deletion of non-target directories. - [Add `-m` shorthand for `--manifest-path`](rust-lang/cargo#16858) - [Remove `curl` dependency from `crates-io` crate](rust-lang/cargo#16936) <a id="1.97.0-Rustdoc"></a> ## Rustdoc - [Stabilize `--emit` flag](rust-lang/rust#146220) - [Stabilize `--remap-path-prefix`](rust-lang/rust#155307) <a id="1.97.0-Compatibility-Notes"></a> ## Compatibility Notes - [Emit a future-compatibility warning when relying on `f32: From<{float}>` to constrain `{float}`](rust-lang/rust#139087) - [Rust will use the v0 symbol mangling scheme by default.](rust-lang/rust#151994) This may cause some tools (such as debuggers or profilers, especially with old versions) to fail to demangle symbols emitted by Rust. It may also cause the formatting of text in backtraces to change. - [Prevent deref coercions in `pin!`, in order to prevent unsoundness.](rust-lang/rust#153457) The most likely case where this might impact users is: writing `pin!(x)` where `x` has type `&mut T` will now always correctly produce a value of type `Pin<&mut &mut T>`, instead of sometimes allowing a coercion that produces a value of type `Pin<&mut T>`. This coercion was previously incorrectly allowed since Rust 1.88.0. - [Deprecate `std::char` constants and functions](rust-lang/rust#153873) - [Warn on linker output by default](rust-lang/rust#153968) - [Remove hidden `f64` methods which have been deprecated since 1.0](rust-lang/rust#153975) - [report the `varargs_without_pattern` lint in deps](rust-lang/rust#154599) - [Forbid passing generic arguments to module path segments even if the module reexports a generic enum variant](rust-lang/rust#154971) - [Error on invalid macho `link_section` specifier](rust-lang/rust#155065) - The encoding of certain `enum`s [have changed](rust-lang/rust#155473). This is not a breaking change, as it only applies to `enum`s without layout guarantees, but is noted here as we've seen people impacted from having made assumptions about the layout algorithm. - [Error on `#[export_name = "..."]` where the name is empty](rust-lang/rust#155515) - [Syntactically reject tuple index shorthands in struct patterns](rust-lang/rust#155698) - [validate `#[link_name = "..."]` & `#[link(name = "...")]` parameters](rust-lang/rust#155817) - On Windows, after calling `shutdown` on a socket to shut down the write side, attempting to write to the socket will now produce a `BrokenPipe` error rather than `Other`. [Map `WSAESHUTDOWN` to `io::ErrorKind::BrokenPipe`](rust-lang/rust#156063) ### [`v1.96.1`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1961-2026-06-30) [Compare Source](rust-lang/rust@1.96.0...1.96.1) \=========================== <a id="1.96.1"></a> - [Cargo: fix timeout/retry behavior](rust-lang/cargo#17131) - [Cargo: apply patches for CVE-2025-15661, CVE-2026-55199, and CVE-2026-55200 to libssh2](rust-lang/cargo#17140) - [rustc: fix miscompilation in MIR optimization](rust-lang/rust#158214) </details> <details> <summary>serde-rs/serde (serde)</summary> ### [`v1.0.229`](https://github.com/serde-rs/serde/releases/tag/v1.0.229) [Compare Source](serde-rs/serde@v1.0.228...v1.0.229) - Update to syn 3 </details> <details> <summary>whatyouhide/stream_data (stream_data)</summary> ### [`v1.4.0`](https://github.com/whatyouhide/stream_data/blob/HEAD/CHANGELOG.md#v140) [Compare Source](whatyouhide/stream_data@v1.3.0...v1.4.0) - Require Elixir 1.14+. - Fix `StreamData.float/1` when min and max are too far apart. - Support choosing between graphemes and codepoints in `StreamData.string/2`. - Shrink `StreamData.one_of/1` towards earlier elements first (instead of smaller values for later elements). </details> <details> <summary>dtolnay/thiserror (thiserror)</summary> ### [`v2.0.19`](https://github.com/dtolnay/thiserror/releases/tag/2.0.19) [Compare Source](dtolnay/thiserror@2.0.18...2.0.19) - Update to syn 3 </details> --- ### Configuration 📅 **Schedule**: (in timezone Pacific/Auckland) - Branch creation - Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> Co-authored-by: James Harton <james@harton.dev> Reviewed-on: https://harton.dev/project-neon/neonfs/pulls/1568
fbidu
added a commit
to fbidu/cookie-py
that referenced
this pull request
Jul 21, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/cache](https://github.com/actions/cache) | | major | `v5` → `v6.1.0` | | [actions/cache](https://github.com/actions/cache) | | major | `v5.0.5` → `v6.1.0` | | [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/cache (actions/cache)</summary> ### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0) [Compare Source](actions/cache@v6.0.0...v6.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1768](actions/cache#1768) **Full Changelog**: <actions/cache@v6...v6.1.0> ### [`v6`](actions/cache@v6.0.0...v6.0.0) [Compare Source](actions/cache@v6.0.0...v6.0.0) ### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0) [Compare Source](actions/cache@v5.1.0...v6.0.0) ##### What's Changed - Update packages, migrate to ESM by [@​Samirat](https://github.com/Samirat) in [#​1760](actions/cache#1760) **Full Changelog**: <actions/cache@v5...v6.0.0> ### [`v5.1.0`](https://github.com/actions/cache/releases/tag/v5.1.0) [Compare Source](actions/cache@v5.0.5...v5.1.0) ##### What's Changed - Bump [@​actions/cache](https://github.com/actions/cache) to v5.1.0 - handle read-only cache access by [@​jasongin](https://github.com/jasongin) in [#​1775](actions/cache#1775) **Full Changelog**: <actions/cache@v5...v5.1.0> ### [`v5.0.5`](https://github.com/actions/cache/releases/tag/v5.0.5) [Compare Source](actions/cache@v5.0.4...v5.0.5) #### What's Changed - Update ts-http-runtime dependency by [@​yacaovsnc](https://github.com/yacaovsnc) in [#​1747](actions/cache#1747) **Full Changelog**: <actions/cache@v5...v5.0.5> ### [`v5.0.4`](https://github.com/actions/cache/releases/tag/v5.0.4) [Compare Source](actions/cache@v5.0.3...v5.0.4) #### What's Changed - Add release instructions and update maintainer docs by [@​Link-](https://github.com/Link-) in [#​1696](actions/cache#1696) - Potential fix for code scanning alert no. 52: Workflow does not contain permissions by [@​Link-](https://github.com/Link-) in [#​1697](actions/cache#1697) - Fix workflow permissions and cleanup workflow names / formatting by [@​Link-](https://github.com/Link-) in [#​1699](actions/cache#1699) - docs: Update examples to use the latest version by [@​XZTDean](https://github.com/XZTDean) in [#​1690](actions/cache#1690) - Fix proxy integration tests by [@​Link-](https://github.com/Link-) in [#​1701](actions/cache#1701) - Fix cache key in examples.md for bun.lock by [@​RyPeck](https://github.com/RyPeck) in [#​1722](actions/cache#1722) - Update dependencies & patch security vulnerabilities by [@​Link-](https://github.com/Link-) in [#​1738](actions/cache#1738) #### New Contributors - [@​XZTDean](https://github.com/XZTDean) made their first contribution in [#​1690](actions/cache#1690) - [@​RyPeck](https://github.com/RyPeck) made their first contribution in [#​1722](actions/cache#1722) **Full Changelog**: <actions/cache@v5...v5.0.4> ### [`v5.0.3`](https://github.com/actions/cache/releases/tag/v5.0.3) [Compare Source](actions/cache@v5.0.2...v5.0.3) #### What's Changed - Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) - Bump `@actions/core` to v2.0.3 **Full Changelog**: <actions/cache@v5...v5.0.3> ### [`v5.0.2`](https://github.com/actions/cache/releases/tag/v5.0.2): v.5.0.2 [Compare Source](actions/cache@v5.0.1...v5.0.2) ### v5.0.2 #### What's Changed When creating cache entries, 429s returned from the cache service will not be retried. ### [`v5.0.1`](https://github.com/actions/cache/releases/tag/v5.0.1) [Compare Source](actions/cache@v5...v5.0.1) > \[!IMPORTANT] > **`actions/cache@v5` runs on the Node.js 24 runtime and requires a minimum Actions Runner version of `2.327.1`.** > > If you are using self-hosted runners, ensure they are updated before upgrading. *** ### v5.0.1 #### What's Changed - fix: update [@​actions/cache](https://github.com/actions/cache) for Node.js 24 punycode deprecation by [@​salmanmkc](https://github.com/salmanmkc) in [#​1685](actions/cache#1685) - prepare release v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1686](actions/cache#1686) ### v5.0.0 #### What's Changed - Upgrade to use node24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1630](actions/cache#1630) - Prepare v5.0.0 release by [@​salmanmkc](https://github.com/salmanmkc) in [#​1684](actions/cache#1684) **Full Changelog**: <actions/cache@v5...v5.0.1> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTQuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIxNC40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJ0ZW1wbGF0ZSJdfQ==--> Reviewed-on: https://git.lx.e6a.app/tools/cookie-py/pulls/94
1 task
mergify Bot
added a commit
to robfrank/linklift
that referenced
this pull request
Aug 4, 2026
…updates [skip ci]
Bumps the github-actions group with 9 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `7.0.0` | `7.0.1` |
| [actions/cache](https://github.com/actions/cache) | `6.0.0` | `6.1.0` |
| [docker/login-action](https://github.com/docker/login-action) | `4.4.0` | `4.5.1` |
| [actions/setup-java](https://github.com/actions/setup-java) | `5.5.0` | `5.6.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` |
| [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) | `1.0.175` | `1.0.183` |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.0` | `4.37.3` |
| [ruby/setup-ruby](https://github.com/ruby/setup-ruby) | `1.319.0` | `1.321.0` |
Updates `actions/checkout` from 7.0.0 to 7.0.1
Release notes
*Sourced from [actions/checkout's releases](https://github.com/actions/checkout/releases).*
> v7.0.1
> ------
>
> What's Changed
> --------------
>
> * skip running unsafe pr check if input is default by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2518](https://redirect.github.com/actions/checkout/pull/2518)
> * trim only ascii whitespace for branch by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2521](https://redirect.github.com/actions/checkout/pull/2521)
> * escape values passed to --unset by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2530](https://redirect.github.com/actions/checkout/pull/2530)
> * Various dependency updates
>
> **Full Changelog**: <https://github.com/actions/checkout/compare/v7...v7.0.1>
Changelog
*Sourced from [actions/checkout's changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md).*
> Changelog
> =========
>
> v7.0.1
> ------
>
> * Skip running unsafe pr check if input is default by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2518](https://redirect.github.com/actions/checkout/pull/2518)
> * Trim only ascii whitespace for branch by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2521](https://redirect.github.com/actions/checkout/pull/2521)
> * Escape values passed to --unset by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2530](https://redirect.github.com/actions/checkout/pull/2530)
> * Various dependency updates
>
> v7.0.0
> ------
>
> * Block checking out fork PR for pull\_request\_target and workflow\_run by [`@aiqiaoy`](https://github.com/aiqiaoy) in [actions/checkout#2454](https://redirect.github.com/actions/checkout/pull/2454)
> * Various dependency updates
>
> v6.0.3
> ------
>
> * Fix checkout init for SHA-256 repositories by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2439](https://redirect.github.com/actions/checkout/pull/2439)
> * fix: expand merge commit SHA regex and add SHA-256 test cases by [`@yaananth`](https://github.com/yaananth) in [actions/checkout#2414](https://redirect.github.com/actions/checkout/pull/2414)
>
> v6.0.2
> ------
>
> * Fix tag handling: preserve annotations and explicit fetch-tags by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2356](https://redirect.github.com/actions/checkout/pull/2356)
>
> v6.0.1
> ------
>
> * Add worktree support for persist-credentials includeIf by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2327](https://redirect.github.com/actions/checkout/pull/2327)
>
> v6.0.0
> ------
>
> * Persist creds to a separate file by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2286](https://redirect.github.com/actions/checkout/pull/2286)
> * Update README to include Node.js 24 support details and requirements by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2248](https://redirect.github.com/actions/checkout/pull/2248)
>
> v5.0.1
> ------
>
> * Port v6 cleanup to v5 by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2301](https://redirect.github.com/actions/checkout/pull/2301)
>
> v5.0.0
> ------
>
> * Update actions checkout to use node 24 by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2226](https://redirect.github.com/actions/checkout/pull/2226)
>
> v4.3.1
> ------
>
> * Port v6 cleanup to v4 by [`@ericsciple`](https://github.com/ericsciple) in [actions/checkout#2305](https://redirect.github.com/actions/checkout/pull/2305)
>
> v4.3.0
> ------
>
> * docs: update README.md by [`@motss`](https://github.com/motss) in [actions/checkout#1971](https://redirect.github.com/actions/checkout/pull/1971)
> * Add internal repos for checking out multiple repositories by [`@mouismail`](https://github.com/mouismail) in [actions/checkout#1977](https://redirect.github.com/actions/checkout/pull/1977)
> * Documentation update - add recommended permissions to Readme by [`@benwells`](https://github.com/benwells) in [actions/checkout#2043](https://redirect.github.com/actions/checkout/pull/2043)
> * Adjust positioning of user email note and permissions heading by [`@joshmgross`](https://github.com/joshmgross) in [actions/checkout#2044](https://redirect.github.com/actions/checkout/pull/2044)
> * Update README.md by [`@nebuk89`](https://github.com/nebuk89) in [actions/checkout#2194](https://redirect.github.com/actions/checkout/pull/2194)
> * Update CODEOWNERS for actions by [`@TingluoHuang`](https://github.com/TingluoHuang) in [actions/checkout#2224](https://redirect.github.com/actions/checkout/pull/2224)
> * Update package dependencies by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/checkout#2236](https://redirect.github.com/actions/checkout/pull/2236)
>
> v4.2.2
> ------
>
> * `url-helper.ts` now leverages well-known environment variables by [`@jww3`](https://github.com/jww3) in [actions/checkout#1941](https://redirect.github.com/actions/checkout/pull/1941)
> * Expand unit test coverage for `isGhes` by [`@jww3`](https://github.com/jww3) in [actions/checkout#1946](https://redirect.github.com/actions/checkout/pull/1946)
>
> v4.2.1
> ------
>
> * Check out other refs/\* by commit if provided, fall back to ref by [`@orhantoy`](https://github.com/orhantoy) in [actions/checkout#1924](https://redirect.github.com/actions/checkout/pull/1924)
... (truncated)
Commits
* [`3d3c42e`](https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1) prep v7.0.1 release ([#2531](https://redirect.github.com/actions/checkout/issues/2531))
* [`2880268`](https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07) escape values passed to --unset ([#2530](https://redirect.github.com/actions/checkout/issues/2530))
* [`12cd223`](https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1) trim only ascii whitespace for branch ([#2521](https://redirect.github.com/actions/checkout/issues/2521))
* [`62661c4`](https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541) skip running unsafe pr check if input is default ([#2518](https://redirect.github.com/actions/checkout/issues/2518))
* [`e8d4307`](https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f) Bump the minor-actions-dependencies group with 2 updates ([#2499](https://redirect.github.com/actions/checkout/issues/2499))
* [`631c942`](https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87) eslint 9 ([#2474](https://redirect.github.com/actions/checkout/issues/2474))
* [`4f1f4ae`](https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e) Bump actions/upload-artifact from 4 to 7 ([#2476](https://redirect.github.com/actions/checkout/issues/2476))
* [`ba09753`](https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92) Bump actions/checkout from 6 to 7 ([#2488](https://redirect.github.com/actions/checkout/issues/2488))
* [`b9e0990`](https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22) Bump docker/login-action from 3.3.0 to 4.2.0 ([#2479](https://redirect.github.com/actions/checkout/issues/2479))
* [`e8cb398`](https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2) Bump docker/build-push-action from 6.5.0 to 7.2.0 ([#2478](https://redirect.github.com/actions/checkout/issues/2478))
* Additional commits viewable in [compare view](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1)
Updates `actions/cache` from 6.0.0 to 6.1.0
Release notes
*Sourced from [actions/cache's releases](https://github.com/actions/cache/releases).*
> v6.1.0
> ------
>
> What's Changed
> --------------
>
> * Bump `@actions/cache` to v6.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1768](https://redirect.github.com/actions/cache/pull/1768)
>
> **Full Changelog**: <https://github.com/actions/cache/compare/v6...v6.1.0>
Changelog
*Sourced from [actions/cache's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).*
> Releases
> ========
>
> How to prepare a release
> ------------------------
>
> > [!NOTE]
> > Relevant for maintainers with write access only.
>
> 1. Switch to a new branch from `main`.
> 2. Run `npm test` to ensure all tests are passing.
> 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json).
> 4. Run `npm run build` to update the compiled files.
> 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section.
> 6. Run `licensed cache` to update the license report.
> 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions.
> 8. Commit your changes and push your branch upstream.
> 9. Open a pull request against `main` and get it reviewed and merged.
> 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json`
> 1. Create a new tag with the version number.
> 2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`.
> 3. Toggle the set as the latest release option.
> 4. Publish the release.
> 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml>
> 1. There should be a workflow run queued with the same version number.
> 2. Approve the run to publish the new version and update the major tags for this action.
>
> Changelog
> ---------
>
> ### 6.1.0
>
> * Bump `@actions/cache` to v6.1.0 to pick up [actions/toolkit#2435 Handle cache write error due to read-only token](https://redirect.github.com/actions/toolkit/pull/2435)
> * Switch redundant "Cache save failed" warning to debug log in save-only
>
> ### 6.0.0
>
> * Updated `@actions/cache` to ^6.0.1, `@actions/core` to ^3.0.1, `@actions/exec` to ^3.0.0, `@actions/io` to ^3.0.2
> * Migrated to ESM module system
> * Upgraded Jest to v30 and test infrastructure to be ESM compatible
>
> ### 5.0.4
>
> * Bump `minimatch` to v3.1.5 (fixes ReDoS via globstar patterns)
> * Bump `undici` to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
> * Bump `fast-xml-parser` to v5.5.6
>
> ### 5.0.3
>
> * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>)
> * Bump `@actions/core` to v2.0.3
>
> ### 5.0.2
... (truncated)
Commits
* [`55cc834`](https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9) Merge pull request [#1768](https://redirect.github.com/actions/cache/issues/1768) from jasongin/readonly-cache
* [`d8cd72f`](https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337) Bump `@actions/cache` to v6.1.0 - handle cache write error due to RO token
* See full diff in [compare view](https://github.com/actions/cache/compare/2c8a9bd7457de244a408f35966fab2fb45fda9c8...55cc8345863c7cc4c66a329aec7e433d2d1c52a9)
Updates `docker/login-action` from 4.4.0 to 4.5.1
Release notes
*Sourced from [docker/login-action's releases](https://github.com/docker/login-action/releases).*
> v4.5.1
> ------
>
> * Support `dhi.io` as Docker Hub OIDC registry by [`@crazy-max`](https://github.com/crazy-max) in [docker/login-action#1054](https://redirect.github.com/docker/login-action/pull/1054)
>
> **Full Changelog**: <https://github.com/docker/login-action/compare/v4.5.0...v4.5.1>
>
> v4.5.0
> ------
>
> * [Docker Hub OIDC](https://github.com/docker/login-action#docker-hub) login support by [`@crazy-max`](https://github.com/crazy-max) in [docker/login-action#1048](https://redirect.github.com/docker/login-action/pull/1048)
> * Bump `@aws-sdk/client-ecr` and `@aws-sdk/client-ecr-public` to 3.1091.0 in [docker/login-action#1037](https://redirect.github.com/docker/login-action/pull/1037)
> * Bump `@docker/actions-toolkit` from 0.92.0 to 0.94.0 in [docker/login-action#1044](https://redirect.github.com/docker/login-action/pull/1044) [docker/login-action#1050](https://redirect.github.com/docker/login-action/pull/1050)
> * Bump brace-expansion from 1.1.13 to 1.1.16 in [docker/login-action#1046](https://redirect.github.com/docker/login-action/pull/1046)
> * Bump js-yaml from 5.2.0 to 5.2.1 in [docker/login-action#1038](https://redirect.github.com/docker/login-action/pull/1038)
>
> **Full Changelog**: <https://github.com/docker/login-action/compare/v4.4.0...v4.5.0>
Commits
* [`abd2ef4`](https://github.com/docker/login-action/commit/abd2ef45e78c5afb21d64d4ca52ee8550d9572c7) Merge pull request [#1055](https://redirect.github.com/docker/login-action/issues/1055) from crazy-max/test-registry-auth-oidc
* [`d49d3a9`](https://github.com/docker/login-action/commit/d49d3a9839fef51322fa44989a44fdc43fccfc22) Merge pull request [#1054](https://redirect.github.com/docker/login-action/issues/1054) from crazy-max/oidc-missing-dhi
* [`b58b17c`](https://github.com/docker/login-action/commit/b58b17c30b4db92a4ed049b213cae512b12e460b) test: cover Docker Hub OIDC with registry-auth
* [`be646c2`](https://github.com/docker/login-action/commit/be646c21cec26cea303e29290d5f6ba6fde8e606) chore: update generated content
* [`d77c059`](https://github.com/docker/login-action/commit/d77c059cb9956cedaa427dc022d89f39acba678f) support dhi.io as Docker Hub OIDC registry
* [`06fb636`](https://github.com/docker/login-action/commit/06fb636fac595d6fb4b28a5dfcb21a6f5091859c) Merge pull request [#1037](https://redirect.github.com/docker/login-action/issues/1037) from docker/dependabot/npm\_and\_yarn/aws-sdk-dependen...
* [`a8bc953`](https://github.com/docker/login-action/commit/a8bc9539118a762b0e5788b53a50907977cc1b8d) [dependabot skip] chore: update generated content
* [`f54b901`](https://github.com/docker/login-action/commit/f54b9019bf5074f6e3480a3ac4b834f5f4b90aab) build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
* [`77f18f6`](https://github.com/docker/login-action/commit/77f18f6713512f90ac35aaf21db0d3710f1b85a6) Merge pull request [#1049](https://redirect.github.com/docker/login-action/issues/1049) from docker/dependabot/github\_actions/codeql-actions...
* [`ec0bf28`](https://github.com/docker/login-action/commit/ec0bf287fb1e2e051c56b2f6e6a3eed487b9fe52) Merge pull request [#1050](https://redirect.github.com/docker/login-action/issues/1050) from docker/dependabot/npm\_and\_yarn/docker/actions-t...
* Additional commits viewable in [compare view](https://github.com/docker/login-action/compare/af1e73f918a031802d376d3c8bbc3fe56130a9b0...abd2ef45e78c5afb21d64d4ca52ee8550d9572c7)
Updates `actions/setup-java` from 5.5.0 to 5.6.0
Release notes
*Sourced from [actions/setup-java's releases](https://github.com/actions/setup-java/releases).*
> v5.6.0
> ------
>
> What's Changed
> --------------
>
> * Backport to v5: Add Maven compiler problem matcher for javac diagnostics by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1087](https://redirect.github.com/actions/setup-java/pull/1087)
> * feat: expose cache-primary-key output ([#597](https://redirect.github.com/actions/setup-java/issues/597)) [v5 backport] by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1089](https://redirect.github.com/actions/setup-java/pull/1089)
> * dist: Cover Tencent Kona JDK 25 ([#1108](https://redirect.github.com/actions/setup-java/issues/1108)) [v5 backport] by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1110](https://redirect.github.com/actions/setup-java/pull/1110)
> * Backport [#1111](https://redirect.github.com/actions/setup-java/issues/1111): Preserve Maven toolchains across repeated setup-java runs ([#1099](https://redirect.github.com/actions/setup-java/issues/1099)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1113](https://redirect.github.com/actions/setup-java/pull/1113)
> * Backport [#1097](https://redirect.github.com/actions/setup-java/issues/1097)/[#1098](https://redirect.github.com/actions/setup-java/issues/1098) to v5: cache Maven and Gradle wrapper distributions separately by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1122](https://redirect.github.com/actions/setup-java/pull/1122)
>
> **Full Changelog**: <https://github.com/actions/setup-java/compare/v5...v5.6.0>
Commits
* [`03ad4de`](https://github.com/actions/setup-java/commit/03ad4de0992f5dab5e18fcb136590ce7c4a0ac95) Backport [#1097](https://redirect.github.com/actions/setup-java/issues/1097)/[#1098](https://redirect.github.com/actions/setup-java/issues/1098): cache Maven and Gradle wrapper distributions separately...
* [`d229d2e`](https://github.com/actions/setup-java/commit/d229d2e858d9137cc0b3f118fa5184b9f0a44ac4) Backport [#1111](https://redirect.github.com/actions/setup-java/issues/1111): Preserve Maven toolchains across repeated setup-java runs ([#1](https://redirect.github.com/actions/setup-java/issues/1)...
* [`bbf0f69`](https://github.com/actions/setup-java/commit/bbf0f6967066506f72571a96d5d6c67ca42ab460) dist: Cover Tencent Kona JDK 25 ([#1110](https://redirect.github.com/actions/setup-java/issues/1110))
* [`513edc4`](https://github.com/actions/setup-java/commit/513edc4f8710565e4ad696f3b7d8e3bda584a46c) feat: expose cache-primary-key output ([#597](https://redirect.github.com/actions/setup-java/issues/597)) [v5 backport] ([#1089](https://redirect.github.com/actions/setup-java/issues/1089))
* [`62df799`](https://github.com/actions/setup-java/commit/62df799a9c6e3022bb466697c66c36e9a2dbf347) Add Maven compiler problem matcher for javac diagnostics ([#1087](https://redirect.github.com/actions/setup-java/issues/1087))
* [`176156a`](https://github.com/actions/setup-java/commit/176156a187714aaf460b0a3c8f21e8b4f784b978) chore: bump version to 5.6.0 for v5 release line
* [`bf7b8de`](https://github.com/actions/setup-java/commit/bf7b8deac240b9cee05eb15ccdb1d2f424a54b9f) build: rebuild dist for backported changes ([#1079](https://redirect.github.com/actions/setup-java/issues/1079), [#1083](https://redirect.github.com/actions/setup-java/issues/1083), [#1084](https://redirect.github.com/actions/setup-java/issues/1084))
* [`0173e6d`](https://github.com/actions/setup-java/commit/0173e6dd1b6e53ac3f6d68d220fa24cce79ae77c) Infer distribution from asdf .tool-versions vendor prefix ([#1084](https://redirect.github.com/actions/setup-java/issues/1084))
* [`f45cd82`](https://github.com/actions/setup-java/commit/f45cd82b67042e9e5c24cef950ea0c61736241c6) Rename jdkFile input to jdk-file with deprecated alias ([#1083](https://redirect.github.com/actions/setup-java/issues/1083))
* [`e2863ad`](https://github.com/actions/setup-java/commit/e2863ad49937c063e5a23922d1971a105f4f0140) Map Zulu x86 architecture to i686 for Azul Metadata API ([#1079](https://redirect.github.com/actions/setup-java/issues/1079))
* Additional commits viewable in [compare view](https://github.com/actions/setup-java/compare/0f481fcb613427c0f801b606911222b5b6f3083a...03ad4de0992f5dab5e18fcb136590ce7c4a0ac95)
Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.3
Release notes
*Sourced from [github/codeql-action/upload-sarif's releases](https://github.com/github/codeql-action/releases).*
> v4.37.3
> -------
>
> No user facing changes.
>
> v4.37.2
> -------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> v4.37.1
> -------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
Changelog
*Sourced from [github/codeql-action/upload-sarif's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*
> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)
>
> 4.36.1 - 02 Jun 2026
> --------------------
>
> No user facing changes.
>
> 4.36.0 - 22 May 2026
> --------------------
>
> * *Breaking change*: Bump the minimum required CodeQL bundle version to 2.19.4. [#3894](https://redirect.github.com/github/codeql-action/pull/3894)
> * Add support for SHA-256 Git object IDs. [#3893](https://redirect.github.com/github/codeql-action/pull/3893)
> * Update default CodeQL bundle version to [2.25.5](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5). [#3926](https://redirect.github.com/github/codeql-action/pull/3926)
>
> 4.35.5 - 15 May 2026
> --------------------
>
> * We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. [#3899](https://redirect.github.com/github/codeql-action/pull/3899)
... (truncated)
Commits
* [`e4fba86`](https://github.com/github/codeql-action/commit/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81) Merge pull request [#4031](https://redirect.github.com/github/codeql-action/issues/4031) from github/update-v4.37.3-72f6a9da0
* [`fb50ab5`](https://github.com/github/codeql-action/commit/fb50ab5d62a274adf3ef3e22cfe750ae87a0ede7) Update changelog for v4.37.3
* [`72f6a9d`](https://github.com/github/codeql-action/commit/72f6a9da0def52d9193d6a758f0378b65091f8d1) Merge pull request [#4030](https://redirect.github.com/github/codeql-action/issues/4030) from github/mbg/fix/no-proxy
* [`3b5ee58`](https://github.com/github/codeql-action/commit/3b5ee58597653d9cc6785f3f1277f796d81f3646) Use default `request` options instead of `undefined`
* [`bfb6be4`](https://github.com/github/codeql-action/commit/bfb6be4b5ecd3650f02f530571453e8c64ef0778) Merge pull request [#4028](https://redirect.github.com/github/codeql-action/issues/4028) from github/mergeback/v4.37.2-to-main-e0647621
* [`526ab84`](https://github.com/github/codeql-action/commit/526ab84f9858816d9cf5f7b9df4dd5e2235f0eba) Rebuild
* [`d6217b9`](https://github.com/github/codeql-action/commit/d6217b9b8c14166e4851db94c11155d03bd13c07) Update changelog and version after v4.37.2
* [`e064762`](https://github.com/github/codeql-action/commit/e0647621c2984b5ed2f768cb892365bf2a616ad1) Merge pull request [#4027](https://redirect.github.com/github/codeql-action/issues/4027) from github/update-v4.37.2-385bcdc5a
* [`e0faed8`](https://github.com/github/codeql-action/commit/e0faed839190caa67a5cd42f1cc16246028ca3df) Add a couple of change notes
* [`73aad0e`](https://github.com/github/codeql-action/commit/73aad0eaa9df172668665a150d17b8bc5a650c20) Update changelog for v4.37.2
* Additional commits viewable in [compare view](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81)
Updates `anthropics/claude-code-action` from 1.0.175 to 1.0.183
Release notes
*Sourced from [anthropics/claude-code-action's releases](https://github.com/anthropics/claude-code-action/releases).*
> v1.0.183
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.183>
>
> v1.0.182
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.182>
>
> v1.0.181
> --------
>
> What's Changed
> --------------
>
> * fix: share one exchanged WIF credential across spawned Claude processes by [`@KeisukeYamashita`](https://github.com/KeisukeYamashita) in [anthropics/claude-code-action#1407](https://redirect.github.com/anthropics/claude-code-action/pull/1407)
>
> New Contributors
> ----------------
>
> * [`@KeisukeYamashita`](https://github.com/KeisukeYamashita) made their first contribution in [anthropics/claude-code-action#1407](https://redirect.github.com/anthropics/claude-code-action/pull/1407)
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.181>
>
> v1.0.180
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.180>
>
> v1.0.179
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.179>
>
> v1.0.178
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.178>
>
> v1.0.177
> --------
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.177>
>
> v1.0.176
> --------
>
> What's Changed
> --------------
>
> * docs: fix dead example links in custom-automations.md by [`@evol1228`](https://github.com/evol1228) in [anthropics/claude-code-action#1513](https://redirect.github.com/anthropics/claude-code-action/pull/1513)
> * test: cover prepareContext validation error branches by [`@farmer-data`](https://github.com/farmer-data) in [anthropics/claude-code-action#1460](https://redirect.github.com/anthropics/claude-code-action/pull/1460)
> * fix: sanitize {{label}} in branch name templates by [`@pa-arth`](https://github.com/pa-arth) in [anthropics/claude-code-action#1492](https://redirect.github.com/anthropics/claude-code-action/pull/1492)
> * fix(sanitizer): strip alt text from reference-style markdown images by [`@HumphreySun98`](https://github.com/HumphreySun98) in [anthropics/claude-code-action#1488](https://redirect.github.com/anthropics/claude-code-action/pull/1488)
> * fix: map claude\_args model to SDK options by [`@Epochex`](https://github.com/Epochex) in [anthropics/claude-code-action#1474](https://redirect.github.com/anthropics/claude-code-action/pull/1474)
> * fix: allow leading underscore in branch names (valid per git-check-ref-format) by [`@riley-mete-db`](https://github.com/riley-mete-db) in [anthropics/claude-code-action#1486](https://redirect.github.com/anthropics/claude-code-action/pull/1486)
> * fix(format): filter out thinking\_tokens system messages from step summary by [`@anishesg`](https://github.com/anishesg) in [anthropics/claude-code-action#1479](https://redirect.github.com/anthropics/claude-code-action/pull/1479)
> * docs: map custom\_instructions to --append-system-prompt ([#1480](https://redirect.github.com/anthropics/claude-code-action/issues/1480)) by [`@farmer-data`](https://github.com/farmer-data) in [anthropics/claude-code-action#1484](https://redirect.github.com/anthropics/claude-code-action/pull/1484)
> * fix: handle null comment/review author from deleted accounts by [`@pa-arth`](https://github.com/pa-arth) in [anthropics/claude-code-action#1490](https://redirect.github.com/anthropics/claude-code-action/pull/1490)
>
> New Contributors
> ----------------
>
> * [`@evol1228`](https://github.com/evol1228) made their first contribution in [anthropics/claude-code-action#1513](https://redirect.github.com/anthropics/claude-code-action/pull/1513)
> * [`@pa-arth`](https://github.com/pa-arth) made their first contribution in [anthropics/claude-code-action#1492](https://redirect.github.com/anthropics/claude-code-action/pull/1492)
> * [`@HumphreySun98`](https://github.com/HumphreySun98) made their first contribution in [anthropics/claude-code-action#1488](https://redirect.github.com/anthropics/claude-code-action/pull/1488)
> * [`@Epochex`](https://github.com/Epochex) made their first contribution in [anthropics/claude-code-action#1474](https://redirect.github.com/anthropics/claude-code-action/pull/1474)
> * [`@riley-mete-db`](https://github.com/riley-mete-db) made their first contribution in [anthropics/claude-code-action#1486](https://redirect.github.com/anthropics/claude-code-action/pull/1486)
> * [`@anishesg`](https://github.com/anishesg) made their first contribution in [anthropics/claude-code-action#1479](https://redirect.github.com/anthropics/claude-code-action/pull/1479)
>
> **Full Changelog**: <https://github.com/anthropics/claude-code-action/compare/v1...v1.0.176>
Commits
* [`be7b93b`](https://github.com/anthropics/claude-code-action/commit/be7b93b1907a4abad570368f3c74b6fe3807510b) chore: bump Claude Code to 2.1.220 and Agent SDK to 0.3.220
* [`e0cf66d`](https://github.com/anthropics/claude-code-action/commit/e0cf66d1d257526b5d07f141838c338921cb8455) chore: bump Claude Code to 2.1.219 and Agent SDK to 0.3.219
* [`44423bd`](https://github.com/anthropics/claude-code-action/commit/44423bdec74b97d67543eb16c110546762c110b2) chore: bump Claude Code to 2.1.218 and Agent SDK to 0.3.218
* [`b00a341`](https://github.com/anthropics/claude-code-action/commit/b00a3414fdd32aea80a12cbd5ccfacecb48eff4f) fix: share one exchanged WIF credential across spawned Claude processes ([#1407](https://redirect.github.com/anthropics/claude-code-action/issues/1407))
* [`fa7e2f0`](https://github.com/anthropics/claude-code-action/commit/fa7e2f0a29a126f0b81cdcf360561b36e44cf608) chore: bump Claude Code to 2.1.217 and Agent SDK to 0.3.217
* [`b76a077`](https://github.com/anthropics/claude-code-action/commit/b76a0776ae74036e77cd11018083743453d7ad35) chore: bump Claude Code to 2.1.216 and Agent SDK to 0.3.216
* [`af0559e`](https://github.com/anthropics/claude-code-action/commit/af0559ee4f514d1ef21826982bed13f7edc3c35e) chore: bump Claude Code to 2.1.215 and Agent SDK to 0.3.215
* [`3553f84`](https://github.com/anthropics/claude-code-action/commit/3553f84341b92da26052e28acf1aa898f9511f32) chore: bump Claude Code to 2.1.214 and Agent SDK to 0.3.214
* [`700e7f8`](https://github.com/anthropics/claude-code-action/commit/700e7f8316990de46bed556429765647af760efc) chore: bump Claude Code to 2.1.212 and Agent SDK to 0.3.212
* [`3e807ec`](https://github.com/anthropics/claude-code-action/commit/3e807ec379b815f9623b7ceca6c7f1f8585e9ead) fix: handle null comment/review author from deleted accounts ([#1490](https://redirect.github.com/anthropics/claude-code-action/issues/1490))
* Additional commits viewable in [compare view](https://github.com/anthropics/claude-code-action/compare/1298632ce7736903d02a1435002705aa2a594a6c...be7b93b1907a4abad570368f3c74b6fe3807510b)
Updates `github/codeql-action/init` from 4.37.0 to 4.37.3
Release notes
*Sourced from [github/codeql-action/init's releases](https://github.com/github/codeql-action/releases).*
> v4.37.3
> -------
>
> No user facing changes.
>
> v4.37.2
> -------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> v4.37.1
> -------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
Changelog
*Sourced from [github/codeql-action/init's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*
> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)
>
> 4.36.1 - 02 Jun 2026
> --------------------
>
> No user facing changes.
>
> 4.36.0 - 22 May 2026
> --------------------
>
> * *Breaking change*: Bump the minimum required CodeQL bundle version to 2.19.4. [#3894](https://redirect.github.com/github/codeql-action/pull/3894)
> * Add support for SHA-256 Git object IDs. [#3893](https://redirect.github.com/github/codeql-action/pull/3893)
> * Update default CodeQL bundle version to [2.25.5](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5). [#3926](https://redirect.github.com/github/codeql-action/pull/3926)
>
> 4.35.5 - 15 May 2026
> --------------------
>
> * We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. [#3899](https://redirect.github.com/github/codeql-action/pull/3899)
... (truncated)
Commits
* [`e4fba86`](https://github.com/github/codeql-action/commit/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81) Merge pull request [#4031](https://redirect.github.com/github/codeql-action/issues/4031) from github/update-v4.37.3-72f6a9da0
* [`fb50ab5`](https://github.com/github/codeql-action/commit/fb50ab5d62a274adf3ef3e22cfe750ae87a0ede7) Update changelog for v4.37.3
* [`72f6a9d`](https://github.com/github/codeql-action/commit/72f6a9da0def52d9193d6a758f0378b65091f8d1) Merge pull request [#4030](https://redirect.github.com/github/codeql-action/issues/4030) from github/mbg/fix/no-proxy
* [`3b5ee58`](https://github.com/github/codeql-action/commit/3b5ee58597653d9cc6785f3f1277f796d81f3646) Use default `request` options instead of `undefined`
* [`bfb6be4`](https://github.com/github/codeql-action/commit/bfb6be4b5ecd3650f02f530571453e8c64ef0778) Merge pull request [#4028](https://redirect.github.com/github/codeql-action/issues/4028) from github/mergeback/v4.37.2-to-main-e0647621
* [`526ab84`](https://github.com/github/codeql-action/commit/526ab84f9858816d9cf5f7b9df4dd5e2235f0eba) Rebuild
* [`d6217b9`](https://github.com/github/codeql-action/commit/d6217b9b8c14166e4851db94c11155d03bd13c07) Update changelog and version after v4.37.2
* [`e064762`](https://github.com/github/codeql-action/commit/e0647621c2984b5ed2f768cb892365bf2a616ad1) Merge pull request [#4027](https://redirect.github.com/github/codeql-action/issues/4027) from github/update-v4.37.2-385bcdc5a
* [`e0faed8`](https://github.com/github/codeql-action/commit/e0faed839190caa67a5cd42f1cc16246028ca3df) Add a couple of change notes
* [`73aad0e`](https://github.com/github/codeql-action/commit/73aad0eaa9df172668665a150d17b8bc5a650c20) Update changelog for v4.37.2
* Additional commits viewable in [compare view](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81)
Updates `github/codeql-action/analyze` from 4.37.0 to 4.37.3
Release notes
*Sourced from [github/codeql-action/analyze's releases](https://github.com/github/codeql-action/releases).*
> v4.37.3
> -------
>
> No user facing changes.
>
> v4.37.2
> -------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> v4.37.1
> -------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
Changelog
*Sourced from [github/codeql-action/analyze's changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md).*
> CodeQL Action Changelog
> =======================
>
> See the [releases page](https://github.com/github/codeql-action/releases) for the relevant changes to the CodeQL CLI and language packs.
>
> [UNRELEASED]
> ------------
>
> * This version of the CodeQL Action adds support for the `tools` input for the `codeql-action/init` step to be specified using a `github-codeql-tools` [repository property](https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). This feature will gradually be rolled out following the release of this version. Once rolled out, this allows for the CodeQL CLI version that is used in GitHub-managed workflows, such as Default Setup, to be set to a custom value. For example, customers who run into issues with rate limits when a new CodeQL CLI version is released can set the value to `toolcache` to always use the CodeQL CLI version that is available in the runner toolcache. For Advanced Setup workflows, the value provided for `tools` in the workflow definition always takes precedence unless the value of the repository property starts with `!`. [#4037](https://redirect.github.com/github/codeql-action/pull/4037)
>
> 4.37.3 - 22 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.37.2 - 21 Jul 2026
> --------------------
>
> * The new address format for the `config-file` input that was introduced in CodeQL Action 4.37.0 is now enabled by default. In addition to the format described there, the `remote=` prefix can now be used to explicitly indicate that the input refers to a remote file. All previous input formats continue to be accepted as well. [#4023](https://redirect.github.com/github/codeql-action/pull/4023)
> * The CodeQL Action can now make use of [configured private registries](https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries) in Default Setup to retrieve CodeQL configuration files from remote repositories that require authentication. This will allow customers to store their CodeQL configuration in a single repository that can then be referenced by Default Setup workflows in other repositories. We expect to roll this and other, related changes out to everyone in July. [#4007](https://redirect.github.com/github/codeql-action/pull/4007)
>
> 4.37.1 - 16 Jul 2026
> --------------------
>
> * *Upcoming breaking change*: Add a deprecation warning for customers using CodeQL version 2.20.6 and earlier. These versions of CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise Server 3.16, and will be unsupported by the next minor release of the CodeQL Action. [#3956](https://redirect.github.com/github/codeql-action/pull/3956)
> * Update default CodeQL bundle version to [2.26.1](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1). [#4019](https://redirect.github.com/github/codeql-action/pull/4019)
>
> 4.37.0 - 08 Jul 2026
> --------------------
>
> * Update default CodeQL bundle version to [2.26.0](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0). [#3995](https://redirect.github.com/github/codeql-action/pull/3995)
> * In addition to the existing input format, the `config-file` input for the `codeql-action/init` step will soon support a new `[owner/]repo[@ref][:path]` format. All components except the repository name are optional. If omitted, `owner` defaults to the same owner as the repository the analysis is running for, `ref` to `main`, and `path` to `.github/codeql-action.yaml`. Support for this format ships in this version of the CodeQL Action, but will only be enabled over the coming weeks. [#3973](https://redirect.github.com/github/codeql-action/pull/3973)
>
> 4.36.3 - 01 Jul 2026
> --------------------
>
> No user facing changes.
>
> 4.36.2 - 04 Jun 2026
> --------------------
>
> * Cache CodeQL CLI version information across Actions steps. [#3943](https://redirect.github.com/github/codeql-action/pull/3943)
> * Reduce requests while waiting for analysis processing by using exponential backoff when polling SARIF processing status. [#3937](https://redirect.github.com/github/codeql-action/pull/3937)
> * Update default CodeQL bundle version to [2.25.6](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6). [#3948](https://redirect.github.com/github/codeql-action/pull/3948)
>
> 4.36.1 - 02 Jun 2026
> --------------------
>
> No user facing changes.
>
> 4.36.0 - 22 May 2026
> --------------------
>
> * *Breaking change*: Bump the minimum required CodeQL bundle version to 2.19.4. [#3894](https://redirect.github.com/github/codeql-action/pull/3894)
> * Add support for SHA-256 Git object IDs. [#3893](https://redirect.github.com/github/codeql-action/pull/3893)
> * Update default CodeQL bundle version to [2.25.5](https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5). [#3926](https://redirect.github.com/github/codeql-action/pull/3926)
>
> 4.35.5 - 15 May 2026
> --------------------
>
> * We have improved how the JavaScript bundles for the CodeQL Action are generated to avoid duplication across bundles and reduce the size of the repository by around 70%. This should have no effect on the runtime behaviour of the CodeQL Action. [#3899](https://redirect.github.com/github/codeql-action/pull/3899)
... (truncated)
Commits
* [`e4fba86`](https://github.com/github/codeql-action/commit/e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81) Merge pull request [#4031](https://redirect.github.com/github/codeql-action/issues/4031) from github/update-v4.37.3-72f6a9da0
* [`fb50ab5`](https://github.com/github/codeql-action/commit/fb50ab5d62a274adf3ef3e22cfe750ae87a0ede7) Update changelog for v4.37.3
* [`72f6a9d`](https://github.com/github/codeql-action/commit/72f6a9da0def52d9193d6a758f0378b65091f8d1) Merge pull request [#4030](https://redirect.github.com/github/codeql-action/issues/4030) from github/mbg/fix/no-proxy
* [`3b5ee58`](https://github.com/github/codeql-action/commit/3b5ee58597653d9cc6785f3f1277f796d81f3646) Use default `request` options instead of `undefined`
* [`bfb6be4`](https://github.com/github/codeql-action/commit/bfb6be4b5ecd3650f02f530571453e8c64ef0778) Merge pull request [#4028](https://redirect.github.com/github/codeql-action/issues/4028) from github/mergeback/v4.37.2-to-main-e0647621
* [`526ab84`](https://github.com/github/codeql-action/commit/526ab84f9858816d9cf5f7b9df4dd5e2235f0eba) Rebuild
* [`d6217b9`](https://github.com/github/codeql-action/commit/d6217b9b8c14166e4851db94c11155d03bd13c07) Update changelog and version after v4.37.2
* [`e064762`](https://github.com/github/codeql-action/commit/e0647621c2984b5ed2f768cb892365bf2a616ad1) Merge pull request [#4027](https://redirect.github.com/github/codeql-action/issues/4027) from github/update-v4.37.2-385bcdc5a
* [`e0faed8`](https://github.com/github/codeql-action/commit/e0faed839190caa67a5cd42f1cc16246028ca3df) Add a couple of change notes
* [`73aad0e`](https://github.com/github/codeql-action/commit/73aad0eaa9df172668665a150d17b8bc5a650c20) Update changelog for v4.37.2
* Additional commits vi...
\_Description has been truncated\_
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Aug 10, 2026
Bumps [actions/cache](https://github.com/actions/cache) from 4.3.0 to 6.1.0. Release notes *Sourced from [actions/cache's releases](https://github.com/actions/cache/releases).* > v6.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v6.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1768](https://redirect.github.com/actions/cache/pull/1768) > > **Full Changelog**: <actions/cache@v6...v6.1.0> > > v6.0.0 > ------ > > What's Changed > -------------- > > * Update packages, migrate to ESM by [`@Samirat`](https://github.com/Samirat) in [actions/cache#1760](https://redirect.github.com/actions/cache/pull/1760) > > **Full Changelog**: <actions/cache@v5...v6.0.0> > > v5.1.0 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v5.1.0 - handle read-only cache access by [`@jasongin`](https://github.com/jasongin) in [actions/cache#1775](https://redirect.github.com/actions/cache/pull/1775) > > **Full Changelog**: <actions/cache@v5...v5.1.0> > > v5.0.5 > ------ > > What's Changed > -------------- > > * Update ts-http-runtime dependency by [`@yacaovsnc`](https://github.com/yacaovsnc) in [actions/cache#1747](https://redirect.github.com/actions/cache/pull/1747) > > **Full Changelog**: <actions/cache@v5...v5.0.5> > > v5.0.4 > ------ > > What's Changed > -------------- > > * Add release instructions and update maintainer docs by [`@Link`](https://github.com/Link)- in [actions/cache#1696](https://redirect.github.com/actions/cache/pull/1696) > * Potential fix for code scanning alert no. 52: Workflow does not contain permissions by [`@Link`](https://github.com/Link)- in [actions/cache#1697](https://redirect.github.com/actions/cache/pull/1697) > * Fix workflow permissions and cleanup workflow names / formatting by [`@Link`](https://github.com/Link)- in [actions/cache#1699](https://redirect.github.com/actions/cache/pull/1699) > * docs: Update examples to use the latest version by [`@XZTDean`](https://github.com/XZTDean) in [actions/cache#1690](https://redirect.github.com/actions/cache/pull/1690) > * Fix proxy integration tests by [`@Link`](https://github.com/Link)- in [actions/cache#1701](https://redirect.github.com/actions/cache/pull/1701) > * Fix cache key in examples.md for bun.lock by [`@RyPeck`](https://github.com/RyPeck) in [actions/cache#1722](https://redirect.github.com/actions/cache/pull/1722) > * Update dependencies & patch security vulnerabilities by [`@Link`](https://github.com/Link)- in [actions/cache#1738](https://redirect.github.com/actions/cache/pull/1738) > > New Contributors > ---------------- > > * [`@XZTDean`](https://github.com/XZTDean) made their first contribution in [actions/cache#1690](https://redirect.github.com/actions/cache/pull/1690) > * [`@RyPeck`](https://github.com/RyPeck) made their first contribution in [actions/cache#1722](https://redirect.github.com/actions/cache/pull/1722) > > **Full Changelog**: <actions/cache@v5...v5.0.4> > > v5.0.3 > ------ > > What's Changed > -------------- > > * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) > * Bump `@actions/core` to v2.0.3 ... (truncated) Changelog *Sourced from [actions/cache's changelog](https://github.com/actions/cache/blob/main/RELEASES.md).* > Releases > ======== > > How to prepare a release > ------------------------ > > > [!NOTE] > > Relevant for maintainers with write access only. > > 1. Switch to a new branch from `main`. > 2. Run `npm test` to ensure all tests are passing. > 3. Update the version in [`https://github.com/actions/cache/blob/main/package.json`](https://github.com/actions/cache/blob/main/package.json). > 4. Run `npm run build` to update the compiled files. > 5. Update this [`https://github.com/actions/cache/blob/main/RELEASES.md`](https://github.com/actions/cache/blob/main/RELEASES.md) with the new version and changes in the `## Changelog` section. > 6. Run `licensed cache` to update the license report. > 7. Run `licensed status` and resolve any warnings by updating the [`https://github.com/actions/cache/blob/main/.licensed.yml`](https://github.com/actions/cache/blob/main/.licensed.yml) file with the exceptions. > 8. Commit your changes and push your branch upstream. > 9. Open a pull request against `main` and get it reviewed and merged. > 10. Draft a new release <https://github.com/actions/cache/releases> use the same version number used in `package.json` > 1. Create a new tag with the version number. > 2. Auto generate release notes and update them to match the changes you made in `RELEASES.md`. > 3. Toggle the set as the latest release option. > 4. Publish the release. > 11. Navigate to <https://github.com/actions/cache/actions/workflows/release-new-action-version.yml> > 1. There should be a workflow run queued with the same version number. > 2. Approve the run to publish the new version and update the major tags for this action. > > Changelog > --------- > > ### 6.1.0 > > * Bump `@actions/cache` to v6.1.0 to pick up [actions/toolkit#2435 Handle cache write error due to read-only token](https://redirect.github.com/actions/toolkit/pull/2435) > * Switch redundant "Cache save failed" warning to debug log in save-only > > ### 6.0.0 > > * Updated `@actions/cache` to ^6.0.1, `@actions/core` to ^3.0.1, `@actions/exec` to ^3.0.0, `@actions/io` to ^3.0.2 > * Migrated to ESM module system > * Upgraded Jest to v30 and test infrastructure to be ESM compatible > > ### 5.0.4 > > * Bump `minimatch` to v3.1.5 (fixes ReDoS via globstar patterns) > * Bump `undici` to v6.24.1 (WebSocket decompression bomb protection, header validation fixes) > * Bump `fast-xml-parser` to v5.5.6 > > ### 5.0.3 > > * Bump `@actions/cache` to v5.0.5 (Resolves: <https://github.com/actions/cache/security/dependabot/33>) > * Bump `@actions/core` to v2.0.3 > > ### 5.0.2 ... (truncated) Commits * [`55cc834`](actions/cache@55cc834) Merge pull request [#1768](https://redirect.github.com/actions/cache/issues/1768) from jasongin/readonly-cache * [`d8cd72f`](actions/cache@d8cd72f) Bump `@actions/cache` to v6.1.0 - handle cache write error due to RO token * [`2c8a9bd`](actions/cache@2c8a9bd) Merge pull request [#1760](https://redirect.github.com/actions/cache/issues/1760) from actions/samirat/esm\_migration\_and\_package\_update * [`e9b91fd`](actions/cache@e9b91fd) Prettier fixes * [`e4884b8`](actions/cache@e4884b8) Rebuild dist * [`10baf01`](actions/cache@10baf01) Fixed licenses * [`e39b386`](actions/cache@e39b386) Fix test mock return order * [`b692820`](actions/cache@b692820) PR feedback * [`6074912`](actions/cache@6074912) Rebuild dist bundles as ESM to match type:module * [`5a912e8`](actions/cache@5a912e8) Fix lint and jest issues * Additional commits viewable in [compare view](actions/cache@v4.3.0...55cc834) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
@actions/cacheto v6.1.0 to pick up actions/toolkit#2435 Handle cache write error due to read-only tokenREADME.mdabout read-only cache accessdistMotivation and Context
The Actions service will soon issue tokens with read-only cache access to certain lower-trust worfklows such as
pull_request_target. (Until now, read-write cache access was always granted.) Without this fix, the cache actions do not propagate errors from the service when attempting to write to the cache, resulting in a misleading warning message emitted to the workflow log: "Unable to reserve cache with key ${key}, another job may be creating this cache." After this change, the correct "cache write denied" warning will be emitted instead when that happens.How Has This Been Tested?
@actions/cachechange in the toolkit repo included updated unit tests.Types of changes
Checklist: