Skip to content

v0.118.2

Choose a tag to compare

@fro-bot fro-bot released this 07 Oct 04:27
· 50 commits to release since this release

What's new

Skipped runs now explain themselves in the Actions UI: routing skips emit a notice and include the reason in the job summary, with an additional hint for unauthorized authors. Untrusted values in those messages are escaped, and notice or summary failures remain non-fatal; skipped runs still post no comment or reaction. The troubleshooting guide also explains which review-request events can use the requesting sender’s repository permission, and the limits of that path. #1731

Static file serving receives a security fix for paths that could be decoded twice and routed around middleware on a static prefix. The upgraded server rejects paths that still contain encoded percent signs after decoding; applications that serve filenames containing a literal % can explicitly allow them. #1714

Full changelog

0.118.2 (2026-10-07)

Build System

  • deps: update dependency anomalyco/opencode to v1.18.34 (#1732) (900b7eb)

Bug Fixes

  • deps: update dependency @hono/node-server to v2.1.3 (#1714) (5b5a9ab)
  • harness: surface skip reasons and document the review-request path (#1731) (a649745)