Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update all non-major dependencies #9

Merged
merged 2 commits into from
Oct 9, 2023

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 9, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
actions/cache action patch v3.3.1 -> v3.3.2 age adoption passing confidence
actions/dependency-review-action action minor v3.0.8 -> v3.1.0 age adoption passing confidence
actions/first-interaction action minor v1.1.1 -> v1.2.0 age adoption passing confidence
actions/upload-artifact action patch v3.1.2 -> v3.1.3 age adoption passing confidence
amannn/action-semantic-pull-request action minor v5.2.0 -> v5.3.0 age adoption passing confidence
dawidd6/action-download-artifact action minor v2.27.0 -> v2.28.0 age adoption passing confidence
github/codeql-action action minor v2.21.5 -> v2.22.1 age adoption passing confidence
node minor 20.6.1 -> 20.8.0 age adoption passing confidence
ossf/scorecard-action action minor v2.2.0 -> v2.3.0 age adoption passing confidence
pnpm (source) packageManager minor 8.8.0 -> 8.9.0 age adoption passing confidence
step-security/harden-runner action minor v2.5.1 -> v2.6.0 age adoption passing confidence

Release Notes

actions/cache (actions/cache)

v3.3.2

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v3...v3.3.2

actions/dependency-review-action (actions/dependency-review-action)

v3.1.0: 3.1.0

Compare Source

What's New

Added support for dependencies submitted through the dependency submission API. This includes two new configuration parameters: retry-on-snapshot-warnings and retry-on-snapshot-warnings-timeout.

What's Changed

New Contributors

Full Changelog: actions/dependency-review-action@v3...v3.1.0

actions/first-interaction (actions/first-interaction)

v1.2.0

Compare Source

Upgrade our codeql actions from v1 -> v2

Updates github/codeql-action/init, github/codeql-action/autobuild, and github/codeql-action/analyze to v2.

👉 See the PR for details: https://github.com/actions/first-interaction/pull/275

actions/upload-artifact (actions/upload-artifact)

v3.1.3

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v3...v3.1.3

amannn/action-semantic-pull-request (amannn/action-semantic-pull-request)

v5.3.0

Compare Source

Features
dawidd6/action-download-artifact (dawidd6/action-download-artifact)

v2.28.0

Compare Source

github/codeql-action (github/codeql-action)

v2.22.1

Compare Source

v2.22.0

Compare Source

v2.21.9

Compare Source

v2.21.8

Compare Source

v2.21.7

Compare Source

v2.21.6

Compare Source

nodejs/node (node)

v20.8.0: 2023-09-28, Version 20.8.0 (Current), @​ruyadorno

Compare Source

Notable Changes
Stream performance improvements

Performance improvements to writable and readable streams, improving the creation and destruction by ±15% and reducing the memory overhead each stream takes in Node.js

Contributed by Benjamin Gruenbaum in #​49745 and Raz Luvaton in #​49834.

Performance improvements for readable webstream, improving readable stream async iterator consumption by ±140% and improving readable stream pipeTo consumption by ±60%

Contributed by Raz Luvaton in #​49662 and #​49690.

Rework of memory management in vm APIs with the importModuleDynamically option

This rework addressed a series of long-standing memory leaks and use-after-free issues in the following APIs that support importModuleDynamically:

  • vm.Script
  • vm.compileFunction
  • vm.SyntheticModule
  • vm.SourceTextModule

This should enable affected users (in particular Jest users) to upgrade from older versions of Node.js.

Contributed by Joyee Cheung in #​48510.

Other notable changes
Commits
ossf/scorecard-action (ossf/scorecard-action)

v2.3.0

Compare Source

What's Changed

Documentation

New Contributors

Full Changelog: ossf/scorecard-action@v2.2.0...v2.3.0

pnpm/pnpm (pnpm)

v8.9.0

Compare Source

step-security/harden-runner (step-security/harden-runner)

v2.6.0

Compare Source

What's Changed

Release v2.6.0 by @​varunsh-coder in https://github.com/step-security/harden-runner/pull/346

This release adds support for self-hosted Virtual Machine runners (e.g. on EC2).

Full Changelog: step-security/harden-runner@v2...v2.6.0


Configuration

📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from prisis as a code owner October 9, 2023 12:46
@renovate renovate bot added the c: dependencies Pull requests that adds/updates a dependency label Oct 9, 2023
@github-actions
Copy link
Contributor

github-actions bot commented Oct 9, 2023

Thank you for following the naming conventions! 🙏

Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great! Thank you for taking the time to create your first pull request! Please review the guidelines

@renovate renovate bot force-pushed the renovate/all-minor-patch branch from df88cee to 0f12c3f Compare October 9, 2023 13:26
@renovate
Copy link
Contributor Author

renovate bot commented Oct 9, 2023

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

@prisis prisis merged commit 233e102 into main Oct 9, 2023
35 checks passed
@prisis prisis deleted the renovate/all-minor-patch branch October 9, 2023 15:18
Copy link
Contributor

This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Please note this issue tracker is not a help forum. We recommend using our GitHub Discussions tab for questions.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators May 22, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
c: dependencies Pull requests that adds/updates a dependency
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant