Closed dependabot[bot] closed 3 months ago
@nicoddemus FYI it'd be good to opt into using the attestations feature.
Ahh thanks, was not aware of the new feature.
@nicoddemus yeah, and it's experimental... I only merged it the other day :)
[!TIP]
Pro tip: Dependabot PRs contain release notes extracted from the projects. But they are collapsed. You can expand them. It's useful when trying to judge if the incoming bump might have any breaking behaviors...
The tip I like the best in your message is the implicit tip on tip formatting in github message :D very informative message: full of tips
Bumps the github-actions group with 1 update: pypa/gh-action-pypi-publish.
Updates
pypa/gh-action-pypi-publish
from 1.9.0 to 1.10.0Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
Commits
8a08d61
Expose PEP 740 attestations functionalityfb9fc6a
Merge pull request #245 from trail-of-forks/ww/bump-twine4d020ff
requirements: re-compile requirements with latest twineDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show