Skip to content

chore(deps): bump github-community-projects/contributors from 1.7.8 to 2.0.4#437

Merged
jmeridth merged 1 commit intomainfrom
dependabot/github_actions/github-community-projects/contributors-2.0.4
Mar 23, 2026
Merged

chore(deps): bump github-community-projects/contributors from 1.7.8 to 2.0.4#437
jmeridth merged 1 commit intomainfrom
dependabot/github_actions/github-community-projects/contributors-2.0.4

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 23, 2026

Bumps github-community-projects/contributors from 1.7.8 to 2.0.4.

Release notes

Sourced from github-community-projects/contributors's releases.

v2.0.4

Changelog

🐛 Bug Fixes

🧰 Maintenance

  • ci: add mark-ready-when-ready workflow @​zkoppert (#428)
  • chore(deps): bump github/codeql-action from 4.32.4 to 4.32.6 in the dependencies group @dependabot[bot] (#427)
  • chore(deps): switch dependabot package ecosystem from pip to uv @​jmeridth (#426)
  • chore(deps-dev): bump black from 26.1.0 to 26.3.1 in the uv group across 1 directory @dependabot[bot] (#425)
  • build: harden CI with frozen installs and octo-sts token federation @​jmeridth (#418)
  • chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 @dependabot[bot] (#421)
  • chore(deps): bump astral-sh/setup-uv from 5.4.1 to 7.3.1 @dependabot[bot] (#420)
  • chore(deps): bump python-dotenv from 1.2.1 to 1.2.2 in the dependencies group @dependabot[bot] (#419)

See details of all code changes since previous release

v2.0.3

Changelog

🐛 Bug Fixes

🧰 Maintenance

See details of all code changes since previous release

v2.0.2

Changelog

🐛 Bug Fixes

  • fix: convert app_id to string before login_as_app_installation call @​jmeridth (#413)
  • fix: use commits-first approach to avoid rate limiting and missing contributors @​zkoppert (#409)
  • fix: resolve pylint config errors breaking super-linter @​jmeridth (#408)
  • fix: Update action.yml to use v2 image @​jmeridth (#404)

🧰 Maintenance

  • chore(deps): bump github/codeql-action from 4.31.9 to 4.32.4 in the dependencies group @dependabot[bot] (#412)
  • chore(deps): bump pylint from 4.0.4 to 4.0.5 in the dependencies group @dependabot[bot] (#411)

See details of all code changes since previous release

... (truncated)

Commits
  • 08ba119 fix: add --project flag to uv entrypoint for GitHub Actions compatibility (#429)
  • 782e22b ci: add mark-ready-when-ready workflow (#428)
  • c3c60eb chore(deps): bump github/codeql-action in the dependencies group (#427)
  • c0db0d4 chore(deps): switch dependabot package ecosystem from pip to uv (#426)
  • e69cd55 fix: pin uv version and add caching to CI workflows (#424)
  • 340afa2 chore(deps-dev): bump black in the uv group across 1 directory (#425)
  • e2065bc Merge pull request #407 from github-community-projects/fix-new-contributor-init
  • f8d2b7c fix: add default for new_contributor and regression test
  • 2f41f3b Merge branch 'main' into fix-new-contributor-init
  • a92b6e0 chore: update ospo-reusable-workflows to new GitHub org (#422)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github-community-projects/contributors](https://github.com/github-community-projects/contributors) from 1.7.8 to 2.0.4.
- [Release notes](https://github.com/github-community-projects/contributors/releases)
- [Commits](0d5adc3...08ba119)

---
updated-dependencies:
- dependency-name: github-community-projects/contributors
  dependency-version: 2.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 23, 2026
@dependabot dependabot bot requested review from jmeridth and zkoppert as code owners March 23, 2026 00:11
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Mar 23, 2026
@jmeridth jmeridth merged commit 21d639f into main Mar 23, 2026
39 checks passed
@jmeridth jmeridth deleted the dependabot/github_actions/github-community-projects/contributors-2.0.4 branch March 23, 2026 00:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant