1.0.2 #5
brianvarskonst
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Workflows 1.0.2
Patch release for repository health and security maintenance on the stable
v1line.This release does not change callable workflow behavior, inputs, permissions, security defaults, or consumer runtime behavior.
Security
markdown-itto14.2.0via npm overrides to resolve the Dependabot advisory for quadratic smartquotes parsing in vulnerablemarkdown-itreleases.js-yamlto4.2.0so the repository audit remains clean whilemarkdownlint-cli2keeps exact transitive dependency pins.package-lock.jsonwith the patched dependency graph.Changes
Compatibility
No migration is required.
Consumers using the stable major alias can continue to use:
Consumers pinned to
1.0.1do not need to update for workflow behavior, but can move to1.0.2to track the latest repository security and documentation maintenance snapshot.Maintainer Notes
The
v1tag is updated to point to1.0.2so consumers using the stable major release line receive the latest patch release.Validation completed before release:
main.main.npm audit --audit-level=moderatereports zero vulnerabilities.This discussion was created from the release 1.0.2.
Beta Was this translation helpful? Give feedback.
All reactions