Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

⬆ Bump pypa/gh-action-pypi-publish from 1.12.0 to 1.12.2#12788

Merged
alejsdev merged 1 commit intomasterfrom
dependabot/github_actions/pypa/gh-action-pypi-publish-1.12.2
Nov 7, 2024
Merged

⬆ Bump pypa/gh-action-pypi-publish from 1.12.0 to 1.12.2#12788
alejsdev merged 1 commit intomasterfrom
dependabot/github_actions/pypa/gh-action-pypi-publish-1.12.2

Conversation

@dependabot
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubNov 7, 2024

Bumpspypa/gh-action-pypi-publish from 1.12.0 to 1.12.2.

Release notes

Sourced frompypa/gh-action-pypi-publish's releases.

v1.12.2

🐛 What's Fixed

The fix for signing legacy zip sdists turned out to be incomplete, so@​woodruffw💰 promptly produced another follow-up that updatedpypi-attestations from v0.0.13 to v0.0.15 in#297. This is the only change since the previous release.

🪞 Full Diff:pypa/gh-action-pypi-publish@v1.12.1...v1.12.2

🧔‍♂️ Release Manager:@​webknjaz🇺🇦

v1.12.1

🐛 What's Fixed

Version v1.12.0 hit several rare corner cases we never considered fully supported, and this release fixes a few of those.In#294,@​webknjaz💰 improved the self-hosted runner experience by pre-installing Python if it's not there, and with#293 the ability to use the action on GitHub Enterprise instances has been restored. The latter should've also fixed the ability to invokepypi-publish from nested in-repo composite actions — another exotic use-case that was never tested in our CI.@​woodruffw💰 also managed to squeeze in a last-minute fix for detecting legacy.zip sdists while producing attestations via#295.

🪞 Full Diff:pypa/gh-action-pypi-publish@v1.12.0...v1.12.1

🧔‍♂️ Release Manager:@​webknjaz🇺🇦

🙏 Huge Thanks to all the bug reporters for posting the logs, helping inspect the problems and verify the regression fixes!

Commits
  • 15c56db Merge pull request#297 from trail-of-forks/ww/bump-pypi-attestations
  • fe8d148 requirements: bump pypi-attestations to 0.0.15
  • 1f5d4ec Merge pull request#295 from trail-of-forks/ww/fix-sdist-collection
  • fec2f0c attestations: collect *.zip sdists as well
  • a8b73a6 Merge pull request#294 from webknjaz/bugfixes/optional-python
  • 9b4dfb0 ✨ Pre-install Python if there's none
  • 0a87186 Merge pull request#293 from webknjaz/bugfixes/uncheckout-intermediate-action
  • dfcfeca 🧪 Use prefetched action to make trampoline
  • 0d02f37 📝💅 Update the CI/CD badge in README
  • See full diff incompare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.12.0 to 1.12.2.- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)- [Commits](pypa/gh-action-pypi-publish@v1.12.0...v1.12.2)---updated-dependencies:- dependency-name: pypa/gh-action-pypi-publish  dependency-type: direct:production  update-type: version-update:semver-patch...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added dependenciesPull requests that update a dependency file github_actionsPull requests that update GitHub Actions code labelsNov 7, 2024
@alejsdevalejsdev merged commit731c85a intomasterNov 7, 2024
@alejsdevalejsdev deleted the dependabot/github_actions/pypa/gh-action-pypi-publish-1.12.2 branchNovember 7, 2024 20:32
s-rigaud pushed a commit to s-rigaud/fastapi that referenced this pull requestJan 23, 2025
Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.12.0 to 1.12.2.- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)- [Commits](pypa/gh-action-pypi-publish@v1.12.0...v1.12.2)---updated-dependencies:- dependency-name: pypa/gh-action-pypi-publish  dependency-type: direct:production  update-type: version-update:semver-patch...Signed-off-by: dependabot[bot] <support@github.com>Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

dependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions codeinternal

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant

@alejsdev

Comments


[8]ページ先頭

©2009-2026 Movatter.jp