Skip to content

Releases: dependabot/dependabot-core

v0.390.0

Choose a tag to compare

@markhallen markhallen released this 03 Aug 15:09
3778744

What's Changed

New Contributors

Full Changelog: v0.389.0...v0.390.0

v0.389.0

Choose a tag to compare

@AbhishekBhaskar AbhishekBhaskar released this 27 Jul 18:25
7936a8a

What's Changed

  • Rescue errors in metadata_cascades_for_dep to prevent PR message loss by @yeikel in #14905
  • Bump sigstore from 4.1.0 to 4.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15484
  • Bump handlebars from 4.7.8 to 4.7.9 in /npm_and_yarn/helpers by @dependabot[bot] in #14547
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14605
  • fix: use canonical LOCKFILE_ENTRY_REGEX in replace-lockfile-declaration.ts by @thavaahariharangit with @Copilot in #15642
  • Prevent update job crash when a pinned GitHub Actions SHA is missing by @robaiken in #15628
  • feat(npm_and_yarn): enhance downgrade conflict messages with detailed blocking dependencies by @thavaahariharangit in #15656
  • Cargo: handle crates locked at multiple versions by @p-linnane in #15638
  • Revert "Cargo: handle crates locked at multiple versions" by @kbukum1 in #15667
  • Paginate Docker tag listing and classify registry error responses by @robaiken in #15651
  • fix: Import proxy CA certificate into Java truststore for Java package managers by @thavaahariharangit in #15670
  • Bump gradle from 4a253a2 to 2a6880c in /gradle by @dependabot[bot] in #15620
  • Fix security update jobs failing with dependency_file_not_found for single-directory manifests by @thavaahariharangit with @Copilot in #15658
  • Make Dependency strongly typed by @JamieMagee in #15647
  • v0.389.0 by @dependabot-core-action-automation[bot] in #15691

New Contributors

Full Changelog: v0.388.0...v0.389.0

v0.388.0

Choose a tag to compare

@kbukum1 kbukum1 released this 22 Jul 19:35
6c8bb8b

What's Changed

  • Type GitHub release metadata by @JamieMagee in #15597
  • Make GitCommitChecker strongly typed by @JamieMagee in #15598
  • Retry corepack prepare and install on signature metadata errors from private registries by @kbukum1 in #15606
  • Fix UV DependencyGrapher to detect nested uv.lock in monorepos by @thavaahariharangit with @Copilot in #15520
  • Bump library/rust from 1.95.0-bookworm to 1.97.0-bookworm in /cargo by @dependabot[bot] in #15560
  • Bump @sigstore/core from 3.1.0 to 3.2.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15455
  • Bump maven from 3.9.14 to 3.9.16 in /maven by @dependabot[bot] in #15127
  • Support Bundler source cooldown in Dependabot cooldown flow by @robaiken in #15517
  • Type shared release metadata by @JamieMagee in #15607
  • Make Job strongly typed by @JamieMagee in #15608
  • Type Job wire models by @JamieMagee in #15610
  • Type Service and ApiClient by @JamieMagee in #15614
  • Add support for calendar-based versions for Maven and Gradle by @yeikel in #14114
  • Type error reporting by @JamieMagee in #15615
  • Type updater dependency helpers by @JamieMagee in #15617
  • ensure proper formatting when patching element attributes by @brettfo in #15629
  • Bump ws from 8.18.3 to 8.21.1 in /npm_and_yarn/helpers/test/npm/fixtures/vulnerability-auditor/update-needed-across-two-versions by @dependabot[bot] in #15329
  • Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14608
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14609
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14610
  • Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #14694
  • Bump pip from 26.1.1 to 26.1.2 in /python/helpers in the pip group across 1 directory by @dependabot[bot] in #11830
  • Bump yaml from 2.3.1 to 2.9.0 in /bun/helpers by @dependabot[bot] in #14535
  • npm_and_yarn: group vulnerability auditor blocking-dependency messages by top-level ancestor by @thavaahariharangit in #15627
  • Bump ip-address and socks in /bun/helpers by @dependabot[bot] in #14924
  • Bump brace-expansion from 1.1.13 to 1.1.16 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15634
  • Bump brace-expansion from 1.1.13 to 1.1.16 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15633
  • Bump sigstore/cosign/cosign from v3.1.1 to v3.1.2 in /docker in the regclient group across 1 directory by @dependabot[bot] in #15621
  • Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14606
  • Bump @tootallnate/once from 2.0.0 to 2.0.1 in /bun/helpers by @dependabot[bot] in #15107
  • Bump the "uv-ecosystem" group with 1 update across multiple ecosystems by @dependabot[bot] in #14969
  • Bump ip-address and socks in /npm_and_yarn/helpers by @dependabot[bot] in #14923
  • Bump yaml from 2.3.1 to 2.9.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14533
  • Bump golang.org/x/mod from 0.37.0 to 0.38.0 in /go_modules/helpers by @dependabot[bot] in #15559
  • Bump @sigstore/verify from 3.1.0 to 3.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15477
  • julia: don't propose compat updates for workspace packages or synthesize member compat entries by @IanButterworth in #15643
  • fix: guard against unparseable versions in cooldown fallback by @currantw in #15632
  • Type dependency requirement readers by @JamieMagee in #15646
  • v0.388.0 by @dependabot-core-action-automation[bot] in #15623

New Contributors

Full Changelog: v0.387.0...v0.388.0

v0.387.0

Choose a tag to compare

@AbhishekBhaskar AbhishekBhaskar released this 16 Jul 20:27
79a21ea

What's Changed

New Contributors

Full Changelog: v0.386.0...v0.387.0

v0.386.0

Choose a tag to compare

@robaiken robaiken released this 13 Jul 16:30
e9c2e95

What's Changed

  • Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
  • Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
  • [Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
  • Handle global.json with no SDK version in dotnet_sdk parser by @brettfo in #15510
  • Type the cargo ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15492
  • Type the conda ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15493
  • Type the docker ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15495
  • Use shared git-tag cooldown in terraform by @robaiken in #15472
  • Retry corepack once on signature metadata error by @thavaahariharangit with @Copilot in #15466
  • Type the deno, elm, devcontainers, bazel, and helm ecosystems by @JamieMagee in #15527
  • Add word-separator and lowercase formatting for branch name by @AbhishekBhaskar in #15478
  • Fix Docker cooldown not respected for multi-arch images missing Last-Modified by @robaiken with @Copilot in #15486
  • Reduce redundant git-source probes during npm metadata resolution by @thavaahariharangit with @Copilot in #15480
  • Type the maven ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15531
  • Add branch name config template format support with validation by @AbhishekBhaskar in #15535
  • fix(gradle): prefer local gradlew for lockfile updates by @thavaahariharangit in #15546
  • helm: support versioning-strategy (range-preserving updates) by @casey-robertson-paypal in #15218
  • Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by @dependabot[bot] in #15498
  • [Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by @brrygrdn in #15521
  • Allow periods in Helm values file names for Docker ecosystem by @telnet23 in #15557
  • Match existing group PRs covering a subset of job directories by @IanButterworth in #15548
  • Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by @dependabot[bot] in #15562
  • Fix npm security updates for transitive dependencies in workspace monorepos by @Swampen in #15514
  • Add helm to the smoke-test matrix by @casey-robertson-paypal in #15554
  • v0.386.0 by @dependabot-core-action-automation[bot] in #15564

New Contributors

Full Changelog: v0.385.0...v0.386.0

v0.385.0

Choose a tag to compare

@thavaahariharangit thavaahariharangit released this 06 Jul 18:31
00e8493

What's Changed

  • Support package-scoped NuGet release notes by @Cjewett in #15211
  • Filter null entries from job directories by @brettfo in #15457
  • devcontainers: preserve major-only Feature pins when precision-matching tags are absent by @thavaahariharangit with @Copilot in #15445
  • Type opaque hashes in common with T.anything by @JamieMagee in #15458
  • Type the options passthrough in base classes with T.anything by @JamieMagee in #15459
  • Apply git-tag cooldown across ecosystems by @robaiken in #15369
  • Type requirement helpers in the update-checker base class by @JamieMagee in #15461
  • Select group update handler for multi-ecosystem NuGet jobs by @brettfo in #15460
  • Type error-detail payloads across common and the updater by @JamieMagee in #15462
  • Type package release details with T.anything by @JamieMagee in #15463
  • Type message builder commit options and vulnerabilities-fixed by @JamieMagee in #15465
  • Fix multiple --default-index args when multiple replaces-base credentials exist by @thavaahariharangit with @Copilot in #15481
  • Fetch gradle.properties and making available lock file generation with in dependabot by @thavaahariharangit with @Copilot in #15467
  • Detect cargo registries across hierarchical .cargo/config.toml files by @brettfo in #15474
  • fix(bundler): only re-vendor platform gems for updated dependencies by @jurre in #15451
  • Fix Sorbet runtime signature violations by @JamieMagee in #15476
  • Use shared git-tag cooldown in python by @robaiken in #15470
  • Fix multiline HTML version parsing for Python/UV private registries by @thavaahariharangit with @Copilot in #15469
  • v0.385.0 by @dependabot-core-action-automation[bot] in #15502

New Contributors

Full Changelog: v0.384.0...v0.385.0

v0.384.0

Choose a tag to compare

@sachin-sandhu sachin-sandhu released this 30 Jun 16:05
434965e

What's Changed

New Contributors

Full Changelog: v0.383.0...v0.384.0

v0.383.0

Choose a tag to compare

@v-HaripriyaC v-HaripriyaC released this 24 Jun 02:35
5b941ee

What's Changed

  • Bump bundled npm from 11.8.0 to 11.17.0 by @kbukum1 in #15335
  • Fix composer specs failure due to block-insecure feature by @AbhishekBhaskar in #15334
  • Add blocked_versions.ignored metric for Security-blocked update checks by @kbukum1 in #15333
  • Preserve original bundler checksum on Bundler 4.0.11+ lockfile updates by @lucasmazza in #15249
  • Generate .npmrc from scope property when lockfile inference fails by @AbhishekBhaskar in #15264
  • Revert disabling block insecure flag in composer by @AbhishekBhaskar in #15339
  • Fix no method error during fetching credentials properties by @AbhishekBhaskar in #15340
  • Use only uv.lock for uv dependency graphing by @Nishnha in #15217
  • Add transitive blocked-version enforcement to updater by @robaiken in #15295
  • fix(npm_and_yarn): strip trailing slash from registry URL in Corepack env vars by @ajha-cs in #15324
  • Fix pre-commit cooldown bypass and incorrect PR metadata issues with grouped updates by @AbhishekBhaskar in #15346
  • Surface blocking parent dependency in npm fix-unavailable message by @thavaahariharangit in #15337
  • Skip Gradle cooldown metadata fetch when cooldown is not configured by @yeikel in #15136
  • Bundler: surface invalid registry gem metadata as a private source error by @kbukum1 in #15351
  • Set default max branch name length to 100 characters by @kbukum1 in #15282
  • set temporary token for cargo auth that the proxy will then replace by @brettfo in #15298
  • Reject updates for private registries without proper dependabot configuration by @AbhishekBhaskar in #15347
  • gradle: bump updater image to 9.4.1 by @thavaahariharangit in #15356
  • Bundler: tolerate empty registry checksum metadata in v4 helper by @kbukum1 in #15359
  • Preserve custom gradle-wrapper.properties values during wrapper updates by @kbukum1 in #15336
  • fix(pre-commit, github-actions): use tag creation date for cooldown instead of commit date by @robaiken in #15350
  • Update Sorbet toolchain and regenerate gem RBIs by @JamieMagee in #15304
  • Enable six zero-offense Sorbet guardrail cops by @JamieMagee in #15305
  • Replace to_hash with to_h and enable ImplicitConversionMethod by @JamieMagee in #15306
  • Enforce method signatures via Sorbet/EnforceSignatures by @JamieMagee in #15307
  • Image content validation for manifest lists for container image updates by @jpinz in #15352
  • Type Version and Requirement internals across ecosystems by @JamieMagee in #15379
  • Type RequirementsUpdater base and gradle/maven/sbt with DependencyRequirement by @JamieMagee in #15380
  • Type standalone RequirementsUpdaters with DependencyRequirement by @JamieMagee in #15381
  • Drop Python 3.9 support by @kbukum1 in #15391
  • Stub docker manifest request in helm update_checker spec by @JamieMagee in #15398
  • Parse DependencyGroup rules into typed readers by @JamieMagee in #15395
  • Type provider_metadata as integer-keyed by @JamieMagee in #15396
  • Fix Swift native requirement parser when there are additional arguments in .package() by @kkebo in #15311
  • v0.383.0 by @dependabot-core-action-automation[bot] in #15365

New Contributors

Full Changelog: v0.382.0...v0.383.0

v0.382.0

Choose a tag to compare

@AbhishekBhaskar AbhishekBhaskar released this 15 Jun 22:12
6b62d68

What's Changed

New Contributors

Full Changelog: v0.381.0...v0.382.0

v0.381.0

Choose a tag to compare

@kbukum1 kbukum1 released this 09 Jun 18:01
ed54286

What's Changed

  • Disable npmMinimalAgeGate for Yarn Berry security updates by @yeikel in #15191
  • Add Bundler 4 support by @JamieMagee in #15180
  • Bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /maven/lib/dependabot/maven by @dependabot[bot] in #15190
  • Add GONOPROXY/GONOSUMDB env vars to go_modules FileParser by @Nishnha in #15159
  • fix(go_modules): include advisory pseudo-version boundaries for security fix resolution by @thavaahariharangit in #15213
  • Retry Gradle metadata fetch on EOF by @thavaahariharangit in #15204
  • Handle npm registry EOFError in latest version finder by @thavaahariharangit in #15205
  • fix(python): honor .pip-tools.toml unsafe-package in pip-compile updates by @thavaahariharangit in #15202
  • Swift: add missing rescue-path test for trailing slash in normalize_name by @Copilot in #15220
  • Fix TypeError: String does not have #dig method in PipenvRunner by @Copilot in #14821
  • fix(go_modules): run strict go mod tidy and surface real errors by @kbukum1 in #15094
  • Gate YARN_NPM_MINIMAL_AGE_GATE on Yarn 4.10+ by @yeikel in #15226
  • opentofu: handle OCI source type in MetadataFinder by @diofeher in #14990
  • Respect cooldown rules when generating Poetry lockfiles by @thavaahariharangit in #15232
  • Fix nuget exception on call to single() by @sebasgomez238 in #15233
  • Fix Maven property update previous version metadata by @kbukum1 in #15224
  • Detect ICU package error indicating EOL SDK by @brettfo in #15234
  • Fix docker_compose parser crash on YAML symbols in lock files by @kbukum1 in #15036
  • Handle Berry lockfiles without explicit Yarn config by @Copilot in #14820
  • Fix behavioral gap in prerelease detection found with Python and generalized to common by @v-HaripriyaC in #15179
  • Fix incorrect cooldown filtering for sha pinned dependencies in pre-commit by @AbhishekBhaskar in #15225
  • Harden Helm helper CLI argument handling and fix helm search flag ordering by @Copilot in #15247
  • Add an experimental GitHub Action summary for graph jobs by @brrygrdn in #15223
  • Add RBI shims for API client wrappers, remove ~110 T.unsafe calls by @JamieMagee in #14615
  • Bump library/rust from 1.94.0-bookworm to 1.95.0-bookworm in /cargo by @dependabot[bot] in #15188
  • Replace Job's untyped hashes with T::ImmutableStruct by @JamieMagee in #14616
  • Fix Gradle/Maven prerelease detection gaps by @v-HaripriyaC in #15222
  • Fix OCI Helm chart metadata finder to strip oci:// prefix by @Copilot in #13634
  • Fix workflow summary experiment name by @brrygrdn in #15250
  • Validate dependency versions in GlobalJsonDiscovery by @brettfo in #15255
  • Enable two Sorbet cops, ignore bazel/nix specs by @JamieMagee in #15257
  • Enable Sorbet/ForbidTUntyped with a todo backlog by @JamieMagee in #15258
  • v0.381.0 by @dependabot-core-action-automation[bot] in #15246

Full Changelog: v0.380.0...v0.381.0