chore(deps): bump pnpm/action-setup from 5.0.0 to 6.0.8#439
chore(deps): bump pnpm/action-setup from 5.0.0 to 6.0.8#439dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 5.0.0 to 6.0.8. - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@fc06bc1...0e279bb) --- updated-dependencies: - dependency-name: pnpm/action-setup dependency-version: 6.0.5 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
2c454fd to
c54f7d2
Compare
|
Automated low-risk assessment This PR was evaluated against the repository's Low-Risk Pull Requests procedure and does not qualify as low risk.
This PR requires a manual review before merging. |
|
Retracted: this comment described a workflow file and step that do not match this PR's actual diff. I am re-verifying #439 properly and will repost accurate findings. Apologies for the noise. |
Advisory review (automated, advisory only — a human makes the final call)TL;DR: safe to merge. Impact / which code pathsThe PR updates the pinned
I resolved the new SHA Risk: low (verified compatible)The v4→v6 jump's one behavioral change is pnpm-version resolution: v5+ require the version to come from a Note: What I tested
RecommendationSafe to merge. Every workflow pins its pnpm version explicitly, so v6.0.8 behaves identically to the prior pins; the version pins themselves are untouched. |
Bumps pnpm/action-setup from 5.0.0 to 6.0.8.
Release notes
Sourced from pnpm/action-setup's releases.
... (truncated)
Commits
0e279bbfix: update pnpm to 11.1.1 (#248)3e83581fix: drop patchPnpmEnv so standalone+self-update works on Windows (#258)551b42edocs(README): fixcache_dependency_pathtype (#257)739bfe4fix: self-update bootstrap to packageManager-pinned version (#233) (#256)f61705dchore: add CODEOWNERS7a5507bfix: restore inputs from state in post (#255)1155470fix: honor devEngines.packageManager.onFail=error (#252) (#254)91ab88efix: bin_dest output points to self-updated pnpm, not bootstrap (#249)e578e19fix: update pnpm to 11.0.48912a91fix: append (not prepend) action node dir to PATH for npm bootstrap (#241)