Bugfix: Pass custom token as input argument to action by @mre in lycheeverse/lychee-action#222
Previously, the name of the token was incorrect, leading to no token being used if the user specified with: [token: ...].
Thanks to @tobon4 for pointing this out.
In scope of this release, we update node version runtime from node16 to node20 (actions/setup-python#772). Besides, we update dependencies to the latest versions.
The default values for author and committer have changed. See "What's new" below for details. If you are overriding the default values you will not be affected by this change.
On completion, the action now removes the temporary git remote configuration it adds when using push-to-fork. This should not affect you unless you were using the temporary configuration for some other purpose after the action completes.
What's new
Updated runtime to Node.js 20
The action now requires a minimum version of v2.308.0 for the Actions runner. Update self-hosted runners to v2.308.0 or later to ensure compatibility.
The default value for author has been changed to ${{ github.actor }} <${{ github.actor_id }}+${{ github.actor }}@users.noreply.github.com>. The change adds the ${{ github.actor_id }}+ prefix to the email address to align with GitHub's standard format for the author email address.
The default value for committer has been changed to github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>. This is to align with the default GitHub Actions bot user account.
Adds input git-token, the Personal Access Token (PAT) that the action will use for git operations. This input defaults to the value of token. Use this input if you would like the action to use a different token for git operations than the one used for the GitHub API.
push-to-fork now supports pushing to sibling repositories in the same network.
Previously, when using push-to-fork, the action did not remove temporary git remote configuration it adds during execution. This has been fixed and the configuration is now removed when the action completes.
If the pull request body is truncated due to exceeding the maximum length, the action will now suffix the body with the message "...[Pull request body truncated]" to indicate that the body has been truncated.
The action now uses --unshallow only when necessary, rather than as a default argument of git fetch. This should improve performance, particularly for large git repositories with extensive commit history.
The action can now be executed on one GitHub server and create pull requests on a different GitHub server. Server products include GitHub hosted (github.com), GitHub Enterprise Server (GHES), and GitHub Enterprise Cloud (GHEC). For example, the action can be executed on GitHub hosted and create pull requests on a GHES or GHEC instance.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the actions group in /.github/workflows with 6 updates:
1.0.1
1.0.2
3
4
1.9.0
1.10.0
4
5
2.0.0
3.0.1
5
6
Updates
actions/add-to-project
from 1.0.1 to 1.0.2Release notes
Sourced from actions/add-to-project's releases.
Commits
244f685
Merge pull request #591 from actions/dependabot/npm_and_yarn/eslint-plugin-je...2a5ef71
Build and package8c11461
Update license for json-schema.dep.yml66f6cff
Merge pull request #578 from actions/dependabot/npm_and_yarn/eslint-plugin-je...ddf5099
Merge pull request #590 from actions/dependabot/npm_and_yarn/typescript-eslin...da1ae5b
build(deps-dev): bump@typescript-eslint/eslint-plugin
ced87c7
Merge pull request #589 from actions/dependabot/npm_and_yarn/typescript-eslin...c78e6a1
Merge pull request #582 from actions/dependabot/npm_and_yarn/ts-jest-29.1.5267a19f
build(deps-dev): bump@typescript-eslint/parser
from 7.6.0 to 7.14.1e005a86
Merge pull request #588 from actions/dependabot/npm_and_yarn/types/node-16.18...Updates
actions/checkout
from 3 to 4Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
692973e
Prepare 4.1.7 release (#1775)6ccd57f
Pin actions/checkout's own workflows to a known, good, stable version. (#1776)b17fe1e
Handle hidden refs (#1774)b80ff79
Bump actions/checkout from 3 to 4 (#1697)b1ec302
Bump the minor-npm-dependencies group across 1 directory with 4 updates (#1739)a5ac7e5
Update for 4.1.6 release (#1733)24ed1a3
Check platform for extension (#1732)44c2b7a
README: Suggestuser.email
to be `41898282+github-actions[bot]@users
.norepl...8459bc0
Bump actions/upload-artifact from 2 to 4 (#1695)3f603f6
Bump actions/setup-node from 1 to 4 (#1696)Updates
lycheeverse/lychee-action
from 1.9.0 to 1.10.0Release notes
Sourced from lycheeverse/lychee-action's releases.
Commits
2b973e8
Bump lychee to 0.15.0 (#226)1e92115
Updateactions/checkout
to version4
(#224)c053181
Pass customtoken
as input argument to action (#222)eeb9cb6
Bump to lychee 0.14.20fa791a
Bump peter-evans/create-issue-from-file from 4 to 5 (#223)8c9a282
Bump actions/cache from 3 to 4 (#221)c3089c7
Bump to lychee 0.14.1fdea703
Update secure git hash for 1.9.0Updates
actions/setup-python
from 4 to 5Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
82c7e63
Documentation changes for avoiding rate limit issues on GHES (#835)10aa35a
feat: fallback to raw endpoint for manifest when rate limit is reached (#766)9a7ac94
Bump undici from 5.27.2 to 5.28.3 (#817)871daa9
Fix the "Specifying multiple Python/PyPy versions" link (#782)2f07895
Fix broken README.md link (#793)e9d6f99
Replace setup-python@v4 by setup-python@v5 in README (#776)0a5c615
Update action to node20 (#772)0ae5836
Add example of GraalPy to docs (#773)b64ffca
update actions/checkout to v4 (#761)8d28961
Examples now use checkout@v4 (#738)Updates
pre-commit/action
from 2.0.0 to 3.0.1Release notes
Sourced from pre-commit/action's releases.
Commits
2c7b380
v3.0.18e2deeb
Merge pull request #190 from SukiCZ/upgrade-action/cache-v40dbc303
Upgrade action/cache to v4. Fixes: #189c7d159c
Merge pull request #185 from pre-commit/asottile-patch-19dd4237
fix main badge37faf8a
Merge pull request #184 from pre-commit/pre-commit-ci-update-config049686e
[pre-commit.ci] pre-commit autoupdate5f528da
move back to maintenance-onlyefd3bcf
Merge pull request #170 from pre-commit/pre-commit-ci-update-configdf308c7
[pre-commit.ci] pre-commit autoupdateUpdates
peter-evans/create-pull-request
from 5 to 6Release notes
Sourced from peter-evans/create-pull-request's releases.
Commits
c5a7806
feat: add branch name output (#2995)4383ba9
build: update distribution (#2990)36f7648
build(deps): bump undici from 6.18.2 to 6.19.2 (#2977)5f7c158
build(deps-dev): bump@types/node
from 18.19.34 to 18.19.36 (#2976)db1713d
build(deps-dev): bump ts-jest from 29.1.4 to 29.1.5 (#2975)ca98a71
build(deps-dev): bump ws from 8.11.0 to 8.17.1 (#2970)ce00808
build(deps-dev): bump braces from 3.0.2 to 3.0.3 (#2962)7318c0b
build(deps-dev): bump prettier from 3.3.0 to 3.3.2 (#2959)e30bbbb
build: update distribution (#2947)bad19b8
build(deps-dev): bump@types/node
from 18.19.33 to 18.19.34 (#2935)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show