Update dependencies - #44
Merged
Merged
Conversation
mingxwa
approved these changes
Jun 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
注册 for free
to join this conversation on GitHub.
Already have an account?
登录 to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4→v5v4→v6v2→v3v4→v6v0.15.15→v0.15.179.1.0→9.1.11.8.2→1.9.015→168.2.1→8.5.1==1.10.1→==1.11.1==1.5.1→==1.5.3==10.21.2→==10.21.33.13→3.14v1.7.8→v1.7.120.2.18→0.2.19v2→v3Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
actions/cache (actions/cache)
v5.0.5比较 Source
What's Changed
Full Changelog: actions/cache@v5...v5.0.5
v5.0.4比较 Source
What's Changed
新建 贡献者
Full Changelog: actions/cache@v5...v5.0.4
v5.0.3比较 Source
What's Changed
@actions/cacheto v5.0.5 (Resolves: https://github.com/actions/cache/security/dependabot/33)@actions/coreto v2.0.3Full Changelog: actions/cache@v5...v5.0.3
v5.0.2: v.5.0.2比较 Source
v5.0.2
What's Changed
When creating cache entries, 429s returned from the cache service will not be retried.
v5.0.1比较 Source
v5.0.1
What's Changed
v5.0.0
What's Changed
Full Changelog: actions/cache@v5...v5.0.1
v5.0.0比较 Source
What's Changed
Full Changelog: actions/cache@v4.3.0...v5.0.0
v5比较 Source
actions/checkout (actions/checkout)
v6.0.3比较 Source
v6.0.2比较 Source
v6.0.1比较 Source
v6.0.0比较 Source
v6比较 Source
v5.0.1比较 Source
v5.0.0比较 Source
v5比较 Source
actions/create-github-app-token (actions/create-github-app-token)
v3.2.0比较 Source
Features
repositoriesinput (#372) (85eb8dd)Bug Fixes
v3.1.1比较 Source
Bug Fixes
v3.1.0比较 Source
Bug Fixes
Features
client-idinput and deprecateapp-id(#353) (e6bd4e6)v3.0.0比较 Source
NODE_USE_ENV_PROXYfor proxy support (#342) (4451bcb)Bug Fixes
BREAKING CHANGES
v3比较 Source
actions/setup-node (actions/setup-node)
v6.4.0比较 Source
What's Changed
Dependency updates:
新建 贡献者
Full Changelog: actions/setup-node@v6...v6.4.0
v6.3.0比较 Source
What's Changed
Enhancements:
devEnginesfield by @susnux in #1283Dependency updates:
Bug fixes:
新建 贡献者
Full Changelog: actions/setup-node@v6...v6.3.0
v6.2.0比较 Source
What's Changed
Documentation
Dependency updates:
新建 贡献者
Full Changelog: actions/setup-node@v6...v6.2.0
v6.1.0比较 Source
What's Changed
Enhancement:
Dependency updates:
Documentation update:
Full Changelog: actions/setup-node@v6...v6.1.0
v6.0.0比较 Source
What's Changed
Breaking Changes
Dependency Upgrades
Full Changelog: actions/setup-node@v5...v6.0.0
v6比较 Source
v5.0.0比较 Source
What's Changed
Breaking Changes
This update, introduces automatic caching when a valid
packageManagerfield is present in yourpackage.json. This aims to improve workflow performance and make dependency management more seamless.To disable this automatic caching, set
package-manager-cache: falseMake sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes
Dependency Upgrades
新建 贡献者
Full Changelog: actions/setup-node@v4...v5.0.0
v5比较 Source
astral-sh/ruff-pre-commit (astral-sh/ruff-pre-commit)
v0.15.17比较 Source
See: https://github.com/astral-sh/ruff/releases/tag/0.15.17
v0.15.16比较 Source
See: https://github.com/astral-sh/ruff/releases/tag/0.15.16
bazelbuild/bazel (bazel)
v9.1.1比较 Source
bazelbuild/bazel-skylib (bazel_skylib)
v1.9.0比较 Source
What's Changed
copy_fileand setallow_symlinkby default toTrueifis_executableisFalse(#565)rules/private:is_windowsan emptyapplicable_license(#600)rules_godependency for compatibility with Bazel 9 (#601)贡献者:
@fdinoff, @fmeum, @fweikert, @susinmotion
Full Changelog: bazelbuild/bazel-skylib@1.8.2...1.9.0
keith/pre-commit-buildifier (keith/pre-commit-buildifier)
v8.5.1比较 Source
What's Changed
新建 贡献者
Full Changelog: keith/pre-commit-buildifier@8.2.1.1...8.5.1
mesonbuild/meson (meson)
v1.11.1比较 Source
v1.11.0比较 Source
v1.10.2比较 Source
timvink/mkdocs-git-revision-date-localized-plugin (mkdocs-git-revision-date-localized-plugin)
v1.5.3比较 Source
What's Changed
新建 贡献者
Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.2...v1.5.3
v1.5.2比较 Source
What's Changed
Bug fixes
page is Nonein mkdocs theme override Jinja2 templates by @Copilot in #202Dependency updates (security)
Full Changelog: timvink/mkdocs-git-revision-date-localized-plugin@v1.5.1...v1.5.2
facelessuser/pymdown-extensions (pymdown-extensions)
v10.21.3比较 Source
10.21.3
restrict_base_pathis enabled (the default). Found by @gistrec.actions/python-versions (python)
v3.14.6: 3.14.6比较 Source
Python 3.14.6
v3.14.5: 3.14.5比较 Source
Python 3.14.5
v3.14.4: 3.14.4比较 Source
Python 3.14.4
v3.14.3: 3.14.3比较 Source
Python 3.14.3
v3.14.2: 3.14.2比较 Source
Python 3.14.2
v3.14.1: 3.14.1比较 Source
Python 3.14.1
v3.14.0: 3.14.0比较 Source
Python 3.14.0
rhysd/actionlint (rhysd/actionlint)
v1.7.12比较 Source
timezoneconfiguration inon.schedulewith checks for IANA timezone string. See the documentation for more details. Note that actionlint starts to embed the timezone database in the executables from this version so the binary sizes slightly increase. (#641, thanks @martincostello)jobs.<job_name>.environment.deploymentconfiguration. (#639, thanks @springmeyer)macos-26-intelrunner label. (#629, thanks @hugovk)[Changes][v1.7.12]
v1.7.11比较 Source
case()function in${{ }}expressions which was recently added to GitHub 操作. (#612, #614, thanks @heppu)macos-26-largeandwindows-2025-vs2026runner labels. See the GitHub's announce for more details. (#615, thanks @hugovk and @muzimuzhi)ghcommand can verify the integrity of the downloaded binaries as follows. The verification is highly recommended in terms of supply chain security. (#608, thanks @takaram)./as error because they never match anything. (#521)[Changes][v1.7.11]
v1.7.10比较 Source
&anchorand*anchor) in workflow files. In addition to parsing YAML anchors correctly, actionlint checks unused and undefined anchors. See the document for more details. (#133, thanks @srz-zumix for the initial implementation at #568 and @alexaandru for trying another approach at #557)*-xlmacOS runner labels because they were dropped. (#592, thanks @muzimuzhi)macos-13macos-13-largemacos-13-xlargeworkflow_dispatchevent from 10 to 25 because the limitation was recently relaxed. (#598, thanks @Haegi)artifact-metadatapermission for workflow permissions. (#602, thanks @martincostello)if:conditions as error. See the rule document for more details.{and}characters in format string offormat()function call. For example v1.7.9 didn't parse"{{0} {1} {2}}"correctly.typein workflow call inputs as error.<<as error because GitHub 操作 doesn't support the syntax.jobs.<job_id>.snapshot.if.misein the installation document. (#591, thanks @risu729)[Changes][v1.7.10]
v1.7.9比较 Source
ubuntu-slimrunner label. (#585, thanks @cestorer)deprecationMessageproperty. Using a deprecated input is reported as error if it is not marked asrequired. See the document for more details. (#580)image_versionworkflow trigger.jobs.<job_id>.snapshotsyntax. To make actionlint recognize your own image generation runner, useself-hosted-runner.labelsconfig.if:likeif: trueas error. Only very simple expressions liketrueorfalseare detected for now. See the document for more details.id-tokenandmodelsscopes. (#582, thanks @holtkampjs)argsandentrypointinputs are not recognized atuses:when it's not a Docker action. (#550)credentialscannot be configured with${{ }}. (#590)run:anduses:). Available keys suggestion is now more accurate and unexpected keys are detected more accurately.actionlint.AllContextsmap constant in Go API that contains the information about all context availability.anthropics/claude-code-actionopenai/codex-actiongoogle-github-actions/run-gemini-climake covtask to easily generate a code coverage report.actionlintpacakge from tap of this repository with Homebrew a hard error. Install the cask version instead following the instruction in the error message.[Changes][v1.7.9]
bazelbuild/rules_cc (rules_cc)
v0.2.19比较 Source
Using bzlmod with Bazel 6 or later:
[Bazel 6] Add
common --enable_bzlmodto.bazelrc.Add to your
MODULE.bazelfile:Using WORKSPACE:
Full Changelog: bazelbuild/rules_cc@0.2.18...0.2.19
softprops/action-gh-release (softprops/action-gh-release)
v3.0.0比较 Source
3.0.0is a major release that moves the action runtime from Node 20 to Node 24.Use
v3on GitHub-hosted runners and self-hosted fleets that already support theNode 24 操作 runtime. If you still need the last Node 20-compatible line, stay on
v2.6.2.What's Changed
Other Changes 🔄
@types/nodeto the Node 24 line and allow future Dependabot updatesv3;v2remains pinned to the latest2.xreleasev3比较 Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.