Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump actions/setup-python from 4.5.0 to 4.6.0 #2579

Closed

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 20, 2023

Bumps actions/setup-python from 4.5.0 to 4.6.0.

Release notes

Sourced from actions/setup-python's releases.

Add allow-prereleases input

In scope of this release we added a new input (allow-prereleases) to allow falling back to pre-release versions of Python when a matching GA version of Python is not available

steps:
  - uses: actions/checkout@v3
  - uses: actions/setup-python@v4
    with:
      python-version: 3.12
      allow-prereleases: true

Besides, we added such changes as:

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested a review from nvuillam as a code owner April 20, 2023 16:00
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Apr 20, 2023
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/setup-python-4.6.0 branch from 669e432 to 54923c9 Compare April 22, 2023 08:47
@echoix
Copy link
Collaborator

echoix commented May 1, 2023

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/setup-python-4.6.0 branch from 54923c9 to 157b748 Compare May 1, 2023 21:34
@bdovaz
Copy link
Collaborator

bdovaz commented May 14, 2023

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/setup-python-4.6.0 branch from 157b748 to a832650 Compare May 14, 2023 15:38
@echoix
Copy link
Collaborator

echoix commented May 14, 2023

LGTM

@bdovaz
Copy link
Collaborator

bdovaz commented May 14, 2023

cc @nvuillam

@echoix
Copy link
Collaborator

echoix commented May 14, 2023

Its only the fact that the build cannot be tested because we log in to dockerhub to build...

@nvuillam
Copy link
Member

@echoix I would like to avoid Docker hub credentials to be accessed except from main branch, so probably the workflow should be updated , and without docker login, no more dependabot PR crashes ^^

@echoix
Copy link
Collaborator

echoix commented May 14, 2023

It's more what I was thinking, ie, we are still stuck needing to push to a registry in order to test/build...

@nvuillam
Copy link
Member

It's more what I was thinking, ie, we are still stuck needing to push to a registry in order to test/build...

I used to build it like that so I could test docker images before merging them... but I think it's simpler and safer if there is no docker upload during dev PRs

What we could eventually do is allow some builds from specific and protected branches, just for us

@nvuillam
Copy link
Member

@echoix @bdovaz it's on the way :)

#2639

@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/setup-python-4.6.0 branch from a832650 to d8cc17f Compare May 17, 2023 20:04
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 4.5.0 to 4.6.0.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v4.5.0...v4.6.0)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/setup-python-4.6.0 branch from d8cc17f to 85d61a1 Compare May 17, 2023 21:10
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github May 24, 2023

Superseded by #2685.

@dependabot dependabot bot closed this May 24, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/actions/setup-python-4.6.0 branch May 24, 2023 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants