Sourced from actions/checkout's releases.
v7.0.1
What's Changed
- skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1
Sourced from actions/checkout's changelog.
Changelog
v7.0.1
- Skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- Trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- Escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
v7.0.0
- Block checking out fork PR for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Various dependency updates
v6.0.3
- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414v6.0.2
- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356v6.0.1
- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327v6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248v5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301v5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226v4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305v4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924
... (truncated)
3d3c42e
prep v7.0.1 release (#2531)2880268
escape values passed to --unset (#2530)12cd223
trim only ascii whitespace for branch (#2521)62661c4
skip running unsafe pr check if input is default (#2518)e8d4307
Bump the minor-actions-dependencies group with 2 updates (#2499)631c942
eslint 9 (#2474)4f1f4ae
Bump actions/upload-artifact from 4 to 7 (#2476)ba09753
Bump actions/checkout from 6 to 7 (#2488)b9e0990
Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398
Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Sourced from docker/login-action's releases.
v4.6.0
- Harden buildx scoped config path handling by
@crazy-maxin docker/login-action#1059- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1095.0 in docker/login-action#1051- Bump js-yaml from 5.2.1 to 5.2.2 in docker/login-action#1057
- Bump postcss from 8.5.10 to 8.5.22 in docker/login-action#1056
Full Changelog: https://github.com/docker/login-action/compare/v4.5.2...v4.6.0
v4.5.2
- Surface Docker Hub OIDC error responses by
@crazy-maxin docker/login-action#1058Full Changelog: https://github.com/docker/login-action/compare/v4.5.1...v4.5.2
v4.5.1
- Support
dhi.ioas Docker Hub OIDC registry by@crazy-maxin docker/login-action#1054Full Changelog: https://github.com/docker/login-action/compare/v4.5.0...v4.5.1
v4.5.0
- Docker Hub OIDC login support by
@crazy-maxin docker/login-action#1048- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1091.0 in docker/login-action#1037- Bump
@docker/actions-toolkitfrom 0.92.0 to 0.94.0 in docker/login-action#1044 docker/login-action#1050- Bump brace-expansion from 1.1.13 to 1.1.16 in docker/login-action#1046
- Bump js-yaml from 5.2.0 to 5.2.1 in docker/login-action#1038
Full Changelog: https://github.com/docker/login-action/compare/v4.4.0...v4.5.0
v4.4.0
- Skip empty
registry-authsecret mask by@crazy-maxin docker/login-action#1035- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1077.0 docker/login-action#1034Full Changelog: https://github.com/docker/login-action/compare/v4.3.0...v4.4.0
v4.3.0
- Preserve names in esbuild bundle by
@crazy-maxin docker/login-action#1022- Bump
@aws-sdk/client-ecrand@aws-sdk/client-ecr-publicto 3.1076.0 docker/login-action#999 docker/login-action#1030- Bump
@docker/actions-toolkitfrom 0.90.0 to 0.92.0 in docker/login-action#1004 docker/login-action#1027- Bump
@sigstore/corefrom 3.1.0 to 3.2.1 in docker/login-action#1023- Bump
@sigstore/verifyfrom 3.1.0 to 3.1.1 in docker/login-action#1029- Bump http-proxy-agent and https-proxy-agent to 9.1.0 in docker/login-action#1017
- Bump js-yaml from 4.1.1 to 5.2.0 in docker/login-action#1028
- Bump sigstore from 4.1.0 to 4.1.1 in docker/login-action#1031
- Bump tmp from 0.2.5 to 0.2.7 in docker/login-action#1002
- Bump undici from 6.24.1 to 6.27.0 in docker/login-action#1020
- Bump vite from 7.3.3 to 7.3.6 in docker/login-action#1019
Full Changelog: https://github.com/docker/login-action/compare/v4.2.0...v4.3.0
dbcb813
Merge pull request #1051
from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015
[dependabot skip] chore: update generated contentb30b2f2
build(deps): bump the aws-sdk-dependencies group across 1 directory with
2 up...9087f1e
Merge pull request #1057
from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830
[dependabot skip] chore: update generated content2325523
build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4a
Merge pull request #1056
from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99ba
Merge pull request #1053
from docker/dependabot/github_actions/aws-actions/co...e512bd5
Merge pull request #1052
from docker/dependabot/github_actions/codeql-actions...a146c91
Merge pull request #1059
from crazy-max/harden-buildx-scope-pathsSourced from pypa/gh-action-pypi-publish's releases.
v1.14.2
🛠️ Urgh… Another release!? Again? Explain yourself!
Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.
[!tip] So what most people will find useful is
@takluyver💰's update of Twine to v7 that we use internally (#416). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.🧐 Tell me why..
TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like aio-libs/aiohttp#13226 around July 23. On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.
I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.
Over the course of investigation,
@facutuesca💰 found and fixed a related underlying cache invalidation bug in sigstore/sigstore-python#1838, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: https://publishing-five-minute-timeout.tiiny.site.
🫶 New Contributors
@davidbrochartmade their first contribution in #415@takluyvermade their first contribution in #416🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2
🧔♂️ Release Manager:
@webknjaz🇺🇦🙏 Special Thanks to
@davidbrochart💰 and@Dreamsorcerer💰 for turning my attention (in #415 and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware.@bdraco💰 came up with a DIY sharding workaround for aiohttp that served as a demo for other projects.@miketheman💰 confirmed the Warehouse-side details. Also,@jku💰 and@woodruffw💰 helped work through, review and release the Sigstore ecosystem upstream libs.💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and [on GitHub][release discussion].
[![GH Sponsors badge]][GH Sponsors URL]
... (truncated)
dc37677
Merge pull request #417
from trail-of-forks/ft/bump-deps8b2f234
Bump pypi-attestations and sigstore78b72db
Merge pull request #416
from takluyver/twine-v792f4d2a
Update twine to v7ba38be9
Merge pull request #408
from adisivaprasad/bump-setup-python-v6a6c5088
Bump actions/setup-python from v5.6.0 to v6.2.0Sourced from dorny/paths-filter's releases.
v4.0.2
What's Changed
- fix warning message by
@cgundyin dorny/paths-filter#282- chore: fix GitHub spelling in logs by
@squatin dorny/paths-filter#278- fix: use rev-parse instead of branch --show-current for older git compat by
@saschabrattonin dorny/paths-filter#303- fix: work around git dubious ownership errors in container jobs by
@saschabrattonin dorny/paths-filter#317- docs: update changelog for v4.0.2 by
@saschabrattonin dorny/paths-filter#318New Contributors
@cgundymade their first contribution in dorny/paths-filter#282@squatmade their first contribution in dorny/paths-filter#278Full Changelog: https://github.com/dorny/paths-filter/compare/v4.0.1...v4.0.2
Sourced from dorny/paths-filter's changelog.
Changelog
v4.0.2
- Work around git dubious ownership errors in container jobs
- Use rev-parse instead of branch --show-current for older git compat
- Fix warning message
v4.0.1
v4.0.0
v3.0.3
v3.0.2
v3.0.1
v3.0.0
v2.11.1
- Update @actions/core to v1.10.0 - Fixes warning about deprecated set-output
- Document need for pull-requests: read permission
- Updating to actions/checkout@v3
v2.11.0
- Set list-files input parameter as not required
- Update Node.js
- Fix incorrect handling of Unicode characters in exec()
- Use Octokit pagination
- Updates real world links
v2.10.2
v2.10.1
v2.10.0
v2.9.3
... (truncated)
7b450ff
docs: update changelog for v4.0.2 (#318)9280377
fix: work around git dubious ownership errors in container jobs (#317)f3ceefd
fix: use rev-parse instead of branch --show-current for older git compat
(#303)61f87a1
chore: fix GitHub spelling in logs (#278)b82ff81
fix warning message (#282)