Skip to content

Bump goreleaser/goreleaser-action from 3 to 4 - #279

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/goreleaser/goreleaser-action-4
Closed

Bump goreleaser/goreleaser-action from 3 to 4#279
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/goreleaser/goreleaser-action-4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Dec 18, 2022

Copy link
Copy Markdown
Contributor

Bumps goreleaser/goreleaser-action from 3 to 4.

Release notes

Sourced from goreleaser/goreleaser-action's releases.

v4.0.0

What's Changed

Full Changelog: goreleaser/goreleaser-action@v3...v4.0.0

v3.2.0

What's Changed

  • chore: remove workaround for setOutput by @​crazy-max (#374)
  • chore(deps): bump @​actions/core from 1.9.1 to 1.10.0 (#372)
  • chore(deps): bump yargs from 17.5.1 to 17.6.0 (#373)

Full Changelog: goreleaser/goreleaser-action@v3.1.0...v3.2.0

v3.1.0

What's Changed

  • fix: dist resolution from config file by @​crazy-max (#369)
  • ci: fix workflow by @​crazy-max (#357)
  • docs: bump actions to latest major by @​crazy-max (#356)
  • chore(deps): bump crazy-max/ghaction-import-gpg from 4 to 5 (#360)
  • chore(deps): bump ghaction-import-gpg to v5 (#359)
  • chore(deps): bump @​actions/core from 1.6.0 to 1.8.2 (#358)
  • chore(deps): bump @​actions/core from 1.8.2 to 1.9.1 (#367)

Full Changelog: goreleaser/goreleaser-action@v3.0.0...v3.1.0

Commits
  • 8f67e59 chore: regenerate
  • 78df308 chore(deps): bump minimatch from 3.0.4 to 3.1.2 (#383)
  • 66134d9 Merge remote-tracking branch 'origin/master' into flarco/master
  • 3c08cfd chore(deps): bump yargs from 17.6.0 to 17.6.2
  • 5dc579b docs: add example when using workdir along with upload-artifact (#366)
  • 3b7d1ba feat!: remove auto-snapshot on dirty tag (#382)
  • 23e0ed5 fix: do not override GORELEASER_CURRENT_TAG (#370)
  • 1315dab update build
  • b60ea88 improve install
  • 4d25ab4 Update goreleaser.ts
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 3 to 4.
- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)
- [Commits](goreleaser/goreleaser-action@v3...v4)

---
updated-dependencies:
- dependency-name: goreleaser/goreleaser-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested review from a team as code owners December 18, 2022 00:13
@dependabot @github

dependabot Bot commented on behalf of github Dec 18, 2022

Copy link
Copy Markdown
Contributor Author

The following labels could not be found: github-actions.

@dependabot dependabot Bot added dependencies patch A minor, backward compatible change labels Dec 18, 2022
@dependabot @github

dependabot Bot commented on behalf of github Dec 19, 2022

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@aknysh
Andriy Knysh (aknysh) deleted the dependabot/github_actions/goreleaser/goreleaser-action-4 branch December 19, 2022 16:47
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 2, 2026
…st, postcss-selector-parser)

Minor-version bumps only, compliant with dependabot.yml's major-bump
ignore policy:
- google.golang.org/grpc v1.82.1 -> v1.83.1 (GHSA-vp52-pcj8-j9qc,
  alert #279): HTTP/2 DATA frame fragmentation memory exhaustion.
- browserslist -> ^4.28.7 via pnpm override (GHSA-c83g-rgw3-j3cx /
  GHSA-73wf-gq98-2v4g, alerts #281/#282): unbounded cache growth and a
  crash via untrusted browserslist-stats.json.
- postcss-selector-parser@^6 -> ^6.1.3 via pnpm override
  (GHSA-w9m9-85wc-3x92, alert #280): uncontrolled AST recursion DoS.
  This is a separate transitive 6.x line from the 7.x one already
  pinned; both now carry overrides.

Regenerated NOTICE (go-licenses) and website/pnpm-lock.yaml
(pnpm install --lockfile-only) for the version bumps; verified
`pnpm run build` still succeeds.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 2, 2026
- google.golang.org/grpc: bump v1.82.1 -> v1.83.2, fixing GHSA-vp52-pcj8-j9qc
  (heap memory exhaustion via HTTP/2 DATA frame fragmentation, <= 1.83.0).
- browserslist: pin transitive dependency to ^4.28.7 via pnpm.overrides,
  fixing GHSA-c83g-rgw3-j3cx (unbounded memory growth) and
  GHSA-73wf-gq98-2v4g (uncaught crash via untrusted stats file), both
  affecting <= 4.28.6.

Alert #280 (postcss-selector-parser) was already fixed on this branch by
an earlier commit; it stays "open" on GitHub only because it's scoped to
the default branch's dependency graph and will auto-close once this
branch merges.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Erik Osterman (Cloud Posse) (osterman) added a commit that referenced this pull request Sep 4, 2026
…st, postcss-selector-parser)

Minor-version bumps only, compliant with dependabot.yml's major-bump
ignore policy:
- google.golang.org/grpc v1.82.1 -> v1.83.1 (GHSA-vp52-pcj8-j9qc,
  alert #279): HTTP/2 DATA frame fragmentation memory exhaustion.
- browserslist -> ^4.28.7 via pnpm override (GHSA-c83g-rgw3-j3cx /
  GHSA-73wf-gq98-2v4g, alerts #281/#282): unbounded cache growth and a
  crash via untrusted browserslist-stats.json.
- postcss-selector-parser@^6 -> ^6.1.3 via pnpm override
  (GHSA-w9m9-85wc-3x92, alert #280): uncontrolled AST recursion DoS.
  This is a separate transitive 6.x line from the 7.x one already
  pinned; both now carry overrides.

Regenerated NOTICE (go-licenses) and website/pnpm-lock.yaml
(pnpm install --lockfile-only) for the version bumps; verified
`pnpm run build` still succeeds.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

patch A minor, backward compatible change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant