dependabot[bot] and GitHub
46b3a80e9a
chore(deps): bump undici from 6.24.1 to 6.28.0 in /packages/core
...
Bumps [undici](https://github.com/nodejs/undici ) from 6.24.1 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v6.24.1...v6.28.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-08-05 14:16:07 +00:00
193fa46c20
chore(deps): bump minimatch from 9.0.5 to 9.0.9 in /packages/attest ( #2330 )
...
Bumps [minimatch](https://github.com/isaacs/minimatch ) from 9.0.5 to 9.0.9.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md )
- [Commits](https://github.com/isaacs/minimatch/compare/v9.0.5...v9.0.9 )
---
updated-dependencies:
- dependency-name: minimatch
dependency-version: 9.0.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 12:04:33 -04:00
50389e5712
chore(deps-dev): bump undici from 6.23.0 to 6.28.0 in /packages/attest ( #2463 )
...
Bumps [undici](https://github.com/nodejs/undici ) from 6.23.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v6.23.0...v6.28.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 12:04:29 -04:00
4811eeb947
chore(deps): bump brace-expansion in /packages/attest ( #2467 )
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 2.1.0 to 2.1.4.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v2.1.0...v2.1.4 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.1.4
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 12:04:25 -04:00
Salman Chishti and GitHub
50ee743cee
Merge pull request #2458 from actions/dependabot/npm_and_yarn/packages/artifact/linkify-it-5.0.2
...
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
2026-07-28 12:22:40 +01:00
Salman Chishti and GitHub
ecc1f60406
Merge pull request #2459 from actions/dependabot/npm_and_yarn/packages/attest/tar-7.5.22
...
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
2026-07-28 12:20:16 +01:00
Salman Chishti and GitHub
b86ae641a8
Merge pull request #2399 from actions/dependabot/npm_and_yarn/packages/artifact/fast-xml-builder-1.2.0
...
chore(deps): bump fast-xml-builder from 1.1.5 to 1.2.0 in /packages/artifact
2026-07-28 12:17:48 +01:00
dependabot[bot] and GitHub
8717b92d8d
chore(deps): bump linkify-it from 5.0.1 to 5.0.2 in /packages/artifact
...
Bumps [linkify-it](https://github.com/markdown-it/linkify-it ) from 5.0.1 to 5.0.2.
- [Changelog](https://github.com/markdown-it/linkify-it/blob/master/CHANGELOG.md )
- [Commits](https://github.com/markdown-it/linkify-it/compare/5.0.1...5.0.2 )
---
updated-dependencies:
- dependency-name: linkify-it
dependency-version: 5.0.2
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-28 11:14:49 +00:00
Salman Chishti and GitHub
91eae7fba2
Merge pull request #2432 from actions/dependabot/npm_and_yarn/packages/artifact/markdown-it-14.2.0
...
chore(deps): bump markdown-it from 14.1.1 to 14.2.0 in /packages/artifact
2026-07-28 12:12:36 +01:00
Salman Chishti and GitHub
5128684139
Merge pull request #2462 from actions/dependabot/npm_and_yarn/packages/artifact/undici-6.28.0
...
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
2026-07-28 12:08:41 +01:00
Salman Chishti and GitHub
1c3c009874
Merge pull request #2461 from actions/dependabot/npm_and_yarn/packages/github/undici-6.28.0
...
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
2026-07-28 12:08:23 +01:00
Salman Chishti and GitHub
f6915ab3cf
Merge pull request #2456 from actions/dependabot/npm_and_yarn/packages/glob/brace-expansion-5.0.7
...
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
2026-07-28 12:08:12 +01:00
dependabot[bot] and GitHub
29a6dcb5a5
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/artifact
...
Bumps [undici](https://github.com/nodejs/undici ) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v6.24.0...v6.28.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-27 00:42:16 +00:00
dependabot[bot] and GitHub
183caa7bb0
chore(deps): bump undici from 6.24.0 to 6.28.0 in /packages/github
...
Bumps [undici](https://github.com/nodejs/undici ) from 6.24.0 to 6.28.0.
- [Release notes](https://github.com/nodejs/undici/releases )
- [Commits](https://github.com/nodejs/undici/compare/v6.24.0...v6.28.0 )
---
updated-dependencies:
- dependency-name: undici
dependency-version: 6.28.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-26 16:14:19 +00:00
dependabot[bot] and GitHub
9c98fa55b2
chore(deps): bump tar from 7.5.10 to 7.5.22 in /packages/attest
...
Bumps [tar](https://github.com/isaacs/node-tar ) from 7.5.10 to 7.5.22.
- [Release notes](https://github.com/isaacs/node-tar/releases )
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md )
- [Commits](https://github.com/isaacs/node-tar/compare/v7.5.10...v7.5.22 )
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.22
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-26 15:27:39 +00:00
dependabot[bot] and GitHub
5f3f5aa073
chore(deps): bump brace-expansion from 5.0.6 to 5.0.7 in /packages/glob
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 5.0.6 to 5.0.7.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v5.0.6...v5.0.7 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 5.0.7
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-07-21 11:08:05 +00:00
Priya Gupta and GitHub
e7728b1bcd
@actions/glob: extend hashFiles options ( #2357 )
...
* @actions/glob: extend hashFiles options
* improve hashFiles symlink handling
* Improve error handling and messaging in hashFiles function
* apply relative exclude patterns across all roots and use named minimatch import
* format error message
2026-07-14 08:57:04 -04:00
ffdc20ef92
feat(cache): add cache-mode client behavior (read-denied warning + ACTIONS_CACHE_MODE skip) ( #2447 )
...
* feat(cache): surface cache read-denied as a distinct restore warning
Mirror the existing cache write-denied handling on the restore path. When
the receiver refuses a download URL because the run's token has no readable
cache scopes, it returns a twirp PermissionDenied (HTTP 403). The twirp
client wraps that 403 in a generic Error, so the stable 'cache read denied:'
prefix is embedded in the message rather than at the start.
- Add CACHE_READ_DENIED_PREFIX and CacheReadDeniedError
- Dispatch on the prefix in the restoreCacheV2 catch block (V2 only), log a
policy-specific warning, and report a cache miss so the run continues
- Add a test mirroring the write-denied coverage
* chore(cache): trim comments, bump to 6.2.0, add RELEASES entry
* refactor(cache): dispatch read-denied by error name to mirror write path
Re-throw CacheReadDeniedError from an inner try/catch around
GetCacheEntryDownloadURL and dispatch on typedError.name in the outer catch,
matching how saveCacheV2 handles CacheWriteDeniedError.
* feat(cache): handle read-denied on the v1 restore path
Extend the read-denied handling to Cache Service v1 so GHES (which forces v1
via _apis/artifactcache) is covered when read-scope enforcement ships there.
- Surface the receiver's error body message from getCacheEntry instead of a
generic status-code error, so the cache read denied: prefix reaches callers
- Re-throw CacheReadDeniedError from restoreCacheV1 and dispatch on it in the
outer catch, mirroring restoreCacheV2 and the write-denied v1 handling
- Add a v1 read-denied test
* refactor(cache): only surface receiver body for read-denied on v1
* test(cache): assert getCacheEntry only surfaces body for read-denied
* test(cache): cover non-read-denied getCacheEntry passthrough on v1
* refactor(cache): share read-denied prefix via constants to avoid drift
* feat(cache): skip restore/save per ACTIONS_CACHE_MODE
* test(cache): expand ACTIONS_CACHE_MODE skip coverage across v1/v2 and unknown modes
* fix copilot pr feedback
Co-authored-by: Copilot Autofix powered by AI <[email protected] >
* docs(cache): remove internal reference from cache-mode comment
* test(cache): merge redundant cache-mode skip tests and simplify read-denied handling
Address PR review feedback:
- Merge the duplicate restore/save skip test.each blocks into single blocks parametrized over ACTIONS_CACHE_SERVICE_V2.
- Drop the redundant CacheReadDeniedError catch arms; the typed error is not an HttpClientError so it already falls through to a non-fatal warning.
- Clarify why read-denied classification happens both in getCacheEntry and cache.ts (dependency-free internal module cannot import the typed error).
* refactor(cache): drop redundant CacheWriteDeniedError catch arms
Mirror the read-denied simplification on the save path. CacheWriteDeniedError
is not an HttpClientError and its name does not match the ReserveCacheError
arm, so it falls through to the same non-fatal warning. Logging behavior is
unchanged (warns, never fails the run) and the exported type is still thrown
internally for consumers and tests. Also refresh stale doc wording.
* test(cache): collapse redundant restore getCacheEntry-failure tests
The two restoreCache tests exercised the identical warning + cache-miss path
now that read-denied is no longer reclassified in the catch, so merge them into
one. The read-denied prefix detection that actually branches on the message is
covered by getCacheEntry tests in cacheHttpClient.test.ts.
---------
Co-authored-by: Copilot Autofix powered by AI <[email protected] >
2026-07-13 10:03:16 -05:00
Jason Ginchereau and GitHub
0786132e6a
Bump cache package to v6.1.0, update RELEASES.md ( #2436 )
2026-06-17 11:25:12 -10:00
dependabot[bot] and GitHub
1f777de31c
chore(deps): bump markdown-it in /packages/artifact
...
Bumps [markdown-it](https://github.com/markdown-it/markdown-it ) from 14.1.1 to 14.2.0.
- [Changelog](https://github.com/markdown-it/markdown-it/blob/master/CHANGELOG.md )
- [Commits](https://github.com/markdown-it/markdown-it/compare/14.1.1...14.2.0 )
---
updated-dependencies:
- dependency-name: markdown-it
dependency-version: 14.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-06-16 18:14:03 +00:00
Jason Ginchereau and GitHub
1746c55cc7
Handle cache write error due to read-only token
2026-06-16 08:03:28 -10:00
Jason Ginchereau
5fb375f061
Audit fix packages/cache
2026-06-11 17:24:11 -07:00
Jason Ginchereau
4d255d08df
Audit fix packages
2026-06-11 17:22:31 -07:00
Jason Ginchereau
26e77e9341
Adit fix, address copilot comments
2026-06-11 17:17:55 -07:00
Jason Ginchereau
78e3d71e19
Handle cache write error due to read-only token
2026-06-11 17:02:12 -07:00
Meredith Lancaster and GitHub
4b9afa4c89
Merge pull request #2368 from actions/dependabot/npm_and_yarn/packages/attest/brace-expansion-2.0.3
...
chore(deps): bump brace-expansion from 2.0.2 to 2.0.3 in /packages/attest
2026-06-08 15:21:00 -07:00
Meredith Lancaster and GitHub
4073a41e46
Merge pull request #2395 from actions/dependabot/npm_and_yarn/packages/attest/ip-address-10.2.0
...
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
2026-06-08 15:19:07 -07:00
dependabot[bot] and GitHub
f07f2238d5
chore(deps): bump fast-xml-builder in /packages/artifact
...
Bumps [fast-xml-builder](https://github.com/NaturalIntelligence/fast-xml-builder ) from 1.1.5 to 1.2.0.
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-builder/blob/main/CHANGELOG.md )
- [Commits](https://github.com/NaturalIntelligence/fast-xml-builder/compare/v1.1.5...v1.2.0 )
---
updated-dependencies:
- dependency-name: fast-xml-builder
dependency-version: 1.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-05-08 16:48:02 +00:00
Joshua Brooks and GitHub
8066c81322
Merge pull request #2393 from actions/samirat/update_minor_dependency_versions
...
Update minor versions of cache and artifact dependencies
2026-05-07 15:59:39 -04:00
dependabot[bot] and GitHub
5dc5ba43d0
chore(deps): bump ip-address from 10.0.1 to 10.2.0 in /packages/attest
...
Bumps [ip-address](https://github.com/beaugunderson/ip-address ) from 10.0.1 to 10.2.0.
- [Commits](https://github.com/beaugunderson/ip-address/commits )
---
updated-dependencies:
- dependency-name: ip-address
dependency-version: 10.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-05-06 23:08:09 +00:00
Joshua Brooks
ad7d6fb853
Bump toolkit version, add release notes
2026-05-01 17:38:16 +00:00
Joshua Brooks
f6e2bb745a
Move @protobuf-ts/plugin to devDependencies
2026-05-01 16:38:16 +00:00
Joshua Brooks
785fffe22d
Audit tool-cache
2026-05-01 16:36:55 +00:00
Joshua Brooks
2f08a036a6
Audit npm packages
2026-05-01 16:33:28 +00:00
Joshua Brooks
17e04b5199
Update minor versions of cache and artifact dependencies
2026-05-01 16:27:55 +00:00
Aiqiao Yan and GitHub
cf80afb392
Merge pull request #2383 from actions/aiqiaoy/release-new-versions
...
release new versions for a few packages
2026-04-21 15:52:32 -04:00
Aiqiao Yan
0607d7a54b
release new versions for a few packages
2026-04-21 17:15:02 +00:00
Aiqiao Yan and GitHub
36d90eb54c
Merge pull request #2356 from actions/dependabot/npm_and_yarn/flatted-3.4.2
...
chore(deps-dev): bump flatted from 3.3.3 to 3.4.2
2026-04-21 12:59:58 -04:00
Aiqiao Yan and GitHub
4ee32849b4
Merge pull request #2346 from actions/dependabot/npm_and_yarn/packages/github/undici-6.24.0
...
chore(deps): bump undici from 6.23.0 to 6.24.0 in /packages/github
2026-04-21 12:55:26 -04:00
Aiqiao Yan and GitHub
d76f9fe99a
Merge pull request #2348 from actions/dependabot/npm_and_yarn/packages/core/undici-6.24.1
...
chore(deps): bump undici from 6.23.0 to 6.24.1 in /packages/core
2026-04-21 12:54:48 -04:00
Aiqiao Yan and GitHub
7e08d73d76
Merge pull request #2345 from actions/dependabot/npm_and_yarn/packages/glob/undici-6.24.0
...
chore(deps): bump undici from 6.23.0 to 6.24.0 in /packages/glob
2026-04-21 12:42:56 -04:00
Aiqiao Yan and GitHub
8b842d839b
Merge pull request #2355 from shogo82148/bump-minimatch-v10
...
@actions/glob: bump minimatch from v3.0.4 to v10.2.5
2026-04-21 12:38:52 -04:00
ICHINOSE Shogo
16cd46c365
Merge branch 'main' into bump-minimatch-v10
2026-04-21 21:43:27 +09:00
dependabot[bot] and GitHub
b3818383be
chore(deps): bump brace-expansion in /packages/attest
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 2.0.2 to 2.0.3.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/v2.0.2...v2.0.3 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 2.0.3
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-20 21:46:32 +00:00
Aiqiao Yan and GitHub
75b8dd1009
Merge pull request #2369 from actions/dependabot/npm_and_yarn/packages/glob/brace-expansion-1.1.13
...
chore(deps): bump brace-expansion from 1.1.12 to 1.1.13 in /packages/glob
2026-04-20 17:44:57 -04:00
Aiqiao Yan and GitHub
a7c6618070
Merge pull request #2381 from actions/dependabot/npm_and_yarn/axios-1.15.1
...
chore(deps-dev): bump axios from 1.12.2 to 1.15.1
2026-04-20 17:44:12 -04:00
Aiqiao Yan and GitHub
54ad3ca9ba
Merge pull request #2347 from actions/dependabot/npm_and_yarn/packages/http-client/undici-6.24.0
...
chore(deps): bump undici from 6.23.0 to 6.24.0 in /packages/http-client
2026-04-20 17:34:56 -04:00
dependabot[bot] and GitHub
3c424f0d63
chore(deps-dev): bump axios from 1.12.2 to 1.15.1
...
Bumps [axios](https://github.com/axios/axios ) from 1.12.2 to 1.15.1.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.12.2...v1.15.1 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-20 21:34:33 +00:00
Aiqiao Yan and GitHub
d9346d8d93
Merge pull request #2378 from actions/dependabot/npm_and_yarn/follow-redirects-1.16.0
...
chore(deps-dev): bump follow-redirects from 1.15.11 to 1.16.0
2026-04-20 17:33:08 -04:00
dependabot[bot] and GitHub
1f375f130a
chore(deps-dev): bump follow-redirects from 1.15.11 to 1.16.0
...
Bumps [follow-redirects](https://github.com/follow-redirects/follow-redirects ) from 1.15.11 to 1.16.0.
- [Release notes](https://github.com/follow-redirects/follow-redirects/releases )
- [Commits](https://github.com/follow-redirects/follow-redirects/compare/v1.15.11...v1.16.0 )
---
updated-dependencies:
- dependency-name: follow-redirects
dependency-version: 1.16.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <[email protected] >
2026-04-15 18:58:03 +00:00