chore: Cherry-picked changes from upstream - #110
Conversation
|
🚀 PR Updated! The PR has been updated with the latest cherry-picked commits. @step-security/maintained-actions-dev Please review and approve the changes. ❌ Build script failed. No files were committed. 📦 Target Release Version: ❗ Missing Files:
🛑 Workflow Files (Cannot be auto-applied by GitHub Actions):
❌ Conflicting Files:
|
chore: update known checksums for 0.11.32
chore: update known checksums for 0.12.0
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
1818359 to
f104964
Compare
chore: update known checksums for 0.12.1
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
chore: update known checksums for 0.12.2
chore: update known checksums for 0.12.3
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
## Summary - disable `enable-cache: auto` for `pull_request_target`, `workflow_run`, and `release` events - disable automatic caching for tag pushes while leaving branch pushes unchanged - preserve explicit `enable-cache: true` as an override - run a `workflow_run` integration fixture with `act` in pull request CI and verify caching is disabled - document the behavior and update the published bundles ## Testing - `npm run all` - `actionlint .github/workflows/test.yml __tests__/workflows/workflow-run.yml` - `uvx zizmor __tests__/workflows/workflow-run.yml` Closes #984 Refs: pi-session 019fec42-9b26-714e-a359-830ac4401ecd
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary - add `latest-known` as an explicit version selector - resolve it locally to the newest version in the bundled checksum table - preserve existing default and `latest` behavior - document custom-manifest checksum semantics and update published bundles ## Testing - `npm ci --ignore-scripts` - `npm run all` (99 tests passed) Closes #919 Refs: pi-session 019fed0e-6019-7504-911b-bd9955cbbd49
## Summary Roll up the remaining net changes from the open Dependabot updates: - release-drafter/release-drafter 7.7.0 (#990) - github/codeql-action 4.37.4 (#987, #988, #989) - zizmorcore/zizmor-action 0.6.1 (#986) - @actions/cache 6.2.0 (#975) - @biomejs/biome 2.5.4 (#974) - undici 8.7.0 (#973) The Jest 30.4.2 (#905) and @renovatebot/pep440 5.0.0 (#907) updates are already present on main and require no additional changes. This also updates the Biome schema, applies the formatter changes from Biome 2.5.4, and regenerates the published bundles. ## Testing - `npm run all` - `actionlint` - `git diff --check` Refs: pi-session 019ff01b-f917-73c1-950e-2966956f263c
## Summary Roll up the remaining net changes from the open Dependabot updates: - release-drafter/release-drafter 7.7.0 (#990) - github/codeql-action 4.37.4 (#987, #988, #989) - zizmorcore/zizmor-action 0.6.1 (#986) - @actions/cache 6.2.0 (#975) - @biomejs/biome 2.5.4 (#974) - undici 8.7.0 (#973) The Jest 30.4.2 (#905) and @renovatebot/pep440 5.0.0 (#907) updates are already present on main and require no additional changes. This also updates the Biome schema, applies the formatter changes from Biome 2.5.4, and regenerates the published bundles. ## Testing - `npm run all` - `actionlint` - `git diff --check` Refs: pi-session 019ff01b-f917-73c1-950e-2966956f263c
## Summary Roll up the remaining net changes from the open Dependabot updates: - release-drafter/release-drafter 7.7.0 (#990) - github/codeql-action 4.37.4 (#987, #988, #989) - zizmorcore/zizmor-action 0.6.1 (#986) - @actions/cache 6.2.0 (#975) - @biomejs/biome 2.5.4 (#974) - undici 8.7.0 (#973) The Jest 30.4.2 (#905) and @renovatebot/pep440 5.0.0 (#907) updates are already present on main and require no additional changes. This also updates the Biome schema, applies the formatter changes from Biome 2.5.4, and regenerates the published bundles. ## Testing - `npm run all` - `actionlint` - `git diff --check` Refs: pi-session 019ff01b-f917-73c1-950e-2966956f263c
## Summary Roll up the remaining net changes from the open Dependabot updates: - release-drafter/release-drafter 7.7.0 (#990) - github/codeql-action 4.37.4 (#987, #988, #989) - zizmorcore/zizmor-action 0.6.1 (#986) - @actions/cache 6.2.0 (#975) - @biomejs/biome 2.5.4 (#974) - undici 8.7.0 (#973) The Jest 30.4.2 (#905) and @renovatebot/pep440 5.0.0 (#907) updates are already present on main and require no additional changes. This also updates the Biome schema, applies the formatter changes from Biome 2.5.4, and regenerates the published bundles. ## Testing - `npm run all` - `actionlint` - `git diff --check` Refs: pi-session 019ff01b-f917-73c1-950e-2966956f263c
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary - read the Python version from an explicitly selected `.tool-versions` file - preserve `python-version` and existing `UV_PYTHON` precedence - add parser, input, and workflow coverage and update documentation and bundled action artifacts ## Validation - `npm run all` - `actionlint .github/workflows/test.yml` - `uvx zizmor .github/workflows/test.yml` Closes #983 Refs: pi-session 019ff01a-544c-79f3-8f73-a00132af39f5
## Summary Roll up the remaining dependency changes from Dependabot PRs #997, #998, #999, #1000, #1001, #1002, and #1003: - update `github/codeql-action` to 4.37.6 - update `zizmorcore/zizmor-action` to 0.6.2 - update `undici` to 8.10.0 - update `smol-toml` to 1.7.1 - update `@biomejs/biome` and its schema to 2.5.6 - regenerate the published bundles PRs #905 and #907 were excluded because their requested Jest and pep440 versions are already present on `main`. ## Validation - `npm run all` - `actionlint .github/workflows/codeql-analysis.yml .github/workflows/test.yml` - `uvx zizmor .github/workflows/codeql-analysis.yml .github/workflows/test.yml` - `git diff --check` Refs: pi-session 019ff0c9-8e00-72d3-99ad-d4383a4c57d4
## Summary - reject path-like uv versions from `.tool-versions` - reject path-like Python versions from `.tool-versions` - document the restriction and cover Unix and Windows paths in tests ## Testing - `npm ci --ignore-scripts` - `npm run all` Refs: pi-session 019ff4bb-8b7c-7c4b-8bdf-7c188dfa2e3f
## Summary - reject path-like uv versions from `.tool-versions` - reject path-like Python versions from `.tool-versions` - document the restriction and cover Unix and Windows paths in tests ## Testing - `npm ci --ignore-scripts` - `npm run all` Refs: pi-session 019ff4bb-8b7c-7c4b-8bdf-7c188dfa2e3f
## Summary - reject path-like uv versions from `.tool-versions` - reject path-like Python versions from `.tool-versions` - document the restriction and cover Unix and Windows paths in tests ## Testing - `npm ci --ignore-scripts` - `npm run all` Refs: pi-session 019ff4bb-8b7c-7c4b-8bdf-7c188dfa2e3f
## Summary Roll up the remaining dependency changes from: - #1008 (`@actions/glob` 0.7.0) - #1009 (`@types/node` 26.1.2) - #1010 (`js-yaml` 5.2.3) - #1011 (`@biomejs/biome` 2.5.7) - #1012 (`@types/semver` 7.8.0) The Biome schema URL and committed action bundles are updated accordingly. ## Validation - `npm run all` Refs: pi-session 019ff5b2-b439-7431-9595-b965f7fe6119
f104964 to
e99aac5
Compare
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
|
|
||
| ```yaml | ||
| - name: Install the latest version of uv known to setup-uv | ||
| uses: step-security/setup-uv@v9 |
🔍 Cherry-Pick Verification Report📦 Upstream Changes: 📋 File-by-File Analysis:
|
Cherry-picked changes from upstream.