Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Bump the actions group across 1 directory with 2 updates#29274

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged

Conversation

@dependabot
Copy link
Contributor

@dependabotdependabotbot commented on behalf ofgithubDec 9, 2024

Bumps the actions group with 2 updates in the / directory:actions/attest-build-provenance andpypa/gh-action-pypi-publish.

Updatesactions/attest-build-provenance from 1.4.4 to 2.1.0

Release notes

Sourced fromactions/attest-build-provenance's releases.

v2.1.0

What's Changed

Full Changelog:actions/attest-build-provenance@v2.0.1...v2.1.0

v2.0.1

What's Changed

Full Changelog:actions/attest-build-provenance@v2.0.0...v2.0.1

v2.0.0

Theattest-build-provenance action now supports attesting multiple subjects simultaneously. When identifying multiple subjects with thesubject-path input a single attestation is created with references to each of the supplied subjects, rather than generating separate attestations for each artifact. This reduces the number of attestations that you need to create and manage.

What's Changed

Full Changelog:actions/attest-build-provenance@v1.4.4...v2.0.0

Commits
  • 7668571 add attestation-id and attestation-url outputs (#415)
  • 9ad33ff add note about gh plans supporting attestations (#414)
  • f2f0851 Bump the npm-development group with 2 updates (#412)
  • c4fbc64 bump actions/attest from 2.0.0 to 2.0.1 (#406)
  • 619dbb2 bump actions/attest to v2.0.0 (#321)
  • 90d4930 Bump the npm-development group with 3 updates (#329)
  • fb315c1 Bump the npm-development group with 5 updates (#323)
  • a379071 Bump cross-spawn from 7.0.3 to 7.0.6 (#319)
  • dada0c3 Bump the npm-development group across 1 directory with 5 updates (#317)
  • See full diff incompare view

Updatespypa/gh-action-pypi-publish from 1.12.2 to 1.12.3

Release notes

Sourced frompypa/gh-action-pypi-publish's releases.

v1.12.3

✨ What's Improved

With the updates by@​woodruffw💰 and@​webknjaz💰 via#309 and#313, it is now possible to publishdistribution packages that includecore metadata v2.4, like those built usingmaturin. This is done by bumpingTwine to v6.0.1 andpkginfo to v1.12.0.

📝 Docs

We've made an attempt to clarify the runtime and workflow shape that are expected to be supported for calling this action in:https://github.com/marketplace/actions/pypi-publish#Non-goals.

[!TIP]Please, let us know in therelease discussion if anything still remains unclear.TL;DR always callpypi-publish once per job; don't invoke it in reusable workflows; physically move building the dists into separate jobs having restricted permissions and storing the dists as GitHub Actions artifacts; when using self-hosted runners, make sure to still usepypi-publish on a GitHub-provided infra withruns-on: ubuntu-latest, while building and testing may remain self-hosted; don't perform any other actions in the publishing job; don't callpypi-publish from composite actions.

🛠️ Internal Updates

@​br3ndonland💰 improved the container image generation automation to include Git SHA in#301. And@​woodruffw💰 added theworkflow_ref context to Trusted Publishing debug logging in#305, helping us diagnose misconfigurations faster.#313 also extends the smoke test in the CI to check against thematurin-made dists. Additionally,jeepney andsecretstorage transitive deps have been added to the pip constraint-based lock file, as Dependabot seems to have missed those earlier.

🪞 Full Diff:pypa/gh-action-pypi-publish@v1.12.2...v1.12.3

🧔‍♂️ Release Manager:@​webknjaz🇺🇦

🙏 Special Thanks to@​samuelcolvin💰 for nudging me to cut this release sooner and forsponsoring me via@​pydantic💰!

🔌 Shameless Plug: The other day I've made this🦋 Bluesky 🇺🇦 FOSS Maintainers Starter Pack subscribe to read news from people like me :)

💬 Discusson Bluesky 🦋,on Mastodon 🐘 andon GitHub.

Commits
  • 67339c7 📦 Only keep lower bounds @ input requirements
  • cbd6d01 📝Fix a typo in "privileges" @ README
  • 7252a9a 📝 Outline unsupported scenarios in README
  • a536fa9 📌📦 Include jeepney & secretstorage pins
  • 43caae4 💅📦 Split transitive dep constraints
  • f371c3d Merge pull request#313 from webknjaz/maintenance/metadata-2.4
  • 138a121 📌📦 Pinpkginfo to v1.12 @ runtime deps
  • ff2b051 🧪 Add a Maturin-based package to CI
  • 0a0a6ae 🧪 Allow CI to register multiple distributions
  • e7723a4 Merge pull request#309 from trail-of-forks/ww/bumptwine
  • Additional commits viewable incompare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting@dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 2 updates in the / directory: [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) and [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish).Updates `actions/attest-build-provenance` from 1.4.4 to 2.1.0- [Release notes](https://github.com/actions/attest-build-provenance/releases)- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)- [Commits](actions/attest-build-provenance@ef24412...7668571)Updates `pypa/gh-action-pypi-publish` from 1.12.2 to 1.12.3- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)- [Commits](pypa/gh-action-pypi-publish@15c56db...67339c7)---updated-dependencies:- dependency-name: actions/attest-build-provenance  dependency-type: direct:production  update-type: version-update:semver-major  dependency-group: actions- dependency-name: pypa/gh-action-pypi-publish  dependency-type: direct:production  update-type: version-update:semver-patch  dependency-group: actions...Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotbot added the PR: dependenciesPull requests that update a dependency file labelDec 9, 2024
@github-actionsgithub-actionsbot added the CI: Run cibuildwheelRun wheel building tests on a PR labelDec 9, 2024
@greglucasgreglucas added this to thev3.10.0 milestoneDec 9, 2024
@QuLogicQuLogic added CI: Run cibuildwheelRun wheel building tests on a PR and removed CI: Run cibuildwheelRun wheel building tests on a PR labelsDec 10, 2024
@scottshambaughscottshambaugh merged commit8d8751d intomainDec 11, 2024
57 checks passed
@scottshambaughscottshambaugh deleted the dependabot/github_actions/actions-ee75fb60f1 branchDecember 11, 2024 20:14
meeseeksmachine pushed a commit to meeseeksmachine/matplotlib that referenced this pull requestDec 11, 2024
QuLogic added a commit that referenced this pull requestDec 12, 2024
…274-on-v3.10.xBackport PR#29274 on branch v3.10.x (Bump the actions group across 1 directory with 2 updates)
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@QuLogicQuLogicQuLogic approved these changes

@scottshambaughscottshambaughscottshambaugh approved these changes

Assignees

No one assigned

Labels

CI: Run cibuildwheelRun wheel building tests on a PRPR: dependenciesPull requests that update a dependency file

Projects

None yet

Milestone

v3.10.0

Development

Successfully merging this pull request may close these issues.

4 participants

@QuLogic@scottshambaugh@greglucas

[8]ページ先頭

©2009-2025 Movatter.jp