chore(deps): bump actions/cache from 4 to 5 - #2
Closed
dependabot[bot] wants to merge 1 commit into
Closed
Conversation
Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v5) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
punkouter26
added a commit
that referenced
this pull request
Jun 15, 2026
#2 appservice.bicep wiring - Add hostingMode param to main.bicep ('appservice' | 'containerapp'). When set to 'appservice' (default for the production target), provision via the previously-orphaned appservice.bicep module. When 'containerapp', the existing Container Apps path is taken. Both branches can coexist via azd provision; the CI deploy.yml already targets App Service, so the appservice path is now the default. #3 OIDC env credential (already merged as bc090aa) - The environment: production block was dropped in bc090aa. The matching federated credential (subject: repo:punkouter26/PoSeeReview:environment:production) is now registered on the PoSeeReview app registration (id bc93e09a-...). This commit re-introduces the environment block so a future approval gate / secret scoping in GitHub Settings → Environments works out of the box. #4 dotnet format out of critical path - Remove 'dotnet format --verify-no-changes' from build-and-test. - Add a format-check job that only runs on PRs (if: github.event_name == 'pull_request'). Edits on master deploy without a 30s format-check overhead; PRs still surface style issues before merge. #5 base image pin + Dependabot + deploy-cleanup - Dockerfile: pin sdk:10.0.301-noble (was :10.0 which drifts) and aspnet:10.0.6-noble-chiseled (was :10.0 which drifts). - .github/dependabot.yml: weekly Monday 06:00 UTC for github-actions, nuget, and docker ecosystems with grouped updates. - deploy-cleanup job: runs after successful deploy, queries the Kudu REST API to list active deployments and surface a count. Full purge via Kudu /api/deployments DELETE is left as a follow-up since Kudu auth on Free tier can be flaky.
punkouter26
added a commit
that referenced
this pull request
Jun 30, 2026
- #2 all 6 controllers -> feature-slice endpoint extensions via MapGroup (Comics/Restaurants/Leaderboard/DevSession/Takedowns/Diagnostics); removed AddControllers/MapControllers; API-key action filter -> endpoint filter; rate limiting via RequireRateLimiting; ProblemDetails via Results.Problem - #9 diagnostics moved to UI-less top-level /diag (+ /diag/mock-status); client diag page route -> /diagnostics; client+http callers updated - Leaderboard empty ?region= now defaults to US (matches integration test intent) - Unit test retargeted to slice endpoint; InternalsVisibleTo for UnitTests Verified per-class: Unit 137/137, WebTests 3/3, Comics/Leaderboard/DevSession/ Restaurants endpoint classes green (remaining suite failures are pre-existing cross-class isolation + env: Google Maps key, Azurite blob). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
punkouter26
added a commit
that referenced
this pull request
Jun 30, 2026
9 of 11 audited items: controllers->Minimal API slices, CORS removed, Po.SeeReview.*->PoSeeReview.* rename, four test projects (E2EAPI + C# Playwright E2EUI), Shared/Core decoupled, /diag route, trimming + source-gen JSON, Azurite container rename, telemetry role-name + source-gen logging, plus DataAnnotations->FluentValidation. #4/#5 BFF cookie auth deferred. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/cache from 4 to 5.
Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
27d5ce7Merge pull request #1747 from actions/yacaovsnc/update-dependencyf280785licensed changes619aeb1npm run build generated dist filesbcf16c2Update ts-http-runtime to 0.3.56682284Merge pull request #1738 from actions/prepare-v5.0.4e340396Update RELEASES8a67110Add licenses1865903Update dependencies & patch security vulnerabilities5656298Merge pull request #1722 from RyPeck/patch-14e380d1Fix cache key in examples.md for bun.lockDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)