Repository navigation
v0.118.2
What's new
Skipped runs now explain themselves in the Actions UI: routing skips emit a notice and include the reason in the job summary, with an additional hint for unauthorized authors. Untrusted values in those messages are escaped, and notice or summary failures remain non-fatal; skipped runs still post no comment or reaction. The troubleshooting guide also explains which review-request events can use the requesting sender’s repository permission, and the limits of that path. #1731
Static file serving receives a security fix for paths that could be decoded twice and routed around middleware on a static prefix. The upgraded server rejects paths that still contain encoded percent signs after decoding; applications that serve filenames containing a literal % can explicitly allow them. #1714