Try our Chrome extension
Easily add the current web-page from your browser directly into your changedetection.io tool, more great features coming soon!Changedetection.io needs your support!
You can help us by supporting changedetection.io on these platforms;
- Rate us at AlternativeTo.net
- Star us on GitHub
- Follow us at Twitter/X
- G2 Software reviews
- Check us out on LinkedIn
- And tell your friends and colleagues :)
The more popular changedetection.io is, the more time we can dedicate to adding amazing features!
Many thanks :)
changedetection.io team
Noch nicht vor Sekunden.
False
Noch nicht vor Sekunden
vor 8 StundenGehe zu einem einzelnen snapshot
Skip to content
Navigation Menu
Sign in Appearance settings
* Platform
+ AI CODE CREATION
o GitHub Copilot Write better code with AI
o GitHub Copilot app Direct agents from issue to merge
o MCP Registry Integrate external tools
+ DEVELOPER WORKFLOWS
o Actions Automate any workflow
o Codespaces Instant dev environments
o Issues Plan and track work
o Code Review Manage code changes
o Code Quality Enforce quality at merge
+ APPLICATION SECURITY
o GitHub Advanced Security Find and fix vulnerabilities
o Code security Secure your code as you build
o Secret protection Stop leaks before they start
+ EXPLORE
o Why GitHub
o Documentation
o Blog
o Changelog
o Marketplace
View all features
* Solutions
+ BY COMPANY SIZE
o Enterprises
o Small and medium teams
o Startups
o Nonprofits
+ BY USE CASE
o App Modernization
o DevSecOps
o DevOps
o CI/CD
o View all use cases
+ BY INDUSTRY
o Healthcare
o Financial services
o Manufacturing
o Government
o View all industries
View all solutions
* Resources
+ EXPLORE BY TOPIC
o AI
o Software Development
o DevOps
o Security
o View all topics
+ EXPLORE BY TYPE
o Customer stories
o Events & webinars
o Ebooks & reports
o Business insights
o GitHub Skills
+ SUPPORT & SERVICES
o Documentation
o Customer support
o Community forum
o Trust center
o Partners
View all resources
* Open Source
+ COMMUNITY
o GitHub Sponsors Fund open source developers
+ PROGRAMS
o Security Lab
o Maintainer Community
o Accelerator
o GitHub Stars
o Archive Program
+ REPOSITORIES
o Topics
o Trending
o Collections
* Enterprise
+ ENTERPRISE SOLUTIONS
o Enterprise platform AI-powered developer platform
+ AVAILABLE ADD-ONS
o GitHub Advanced Security Enterprise-grade security features
o Copilot for Business Enterprise-grade AI features
o Premium Support Enterprise-grade 24/7 support
* Pricing
Type / to search
Sign in
Sign up Appearance settings
You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
Uh oh!
There was an error while loading. Please reload this page.
dependabot / dependabot-core Public
* Notifications You must be signed in to change notification settings
* Fork 1.5k
* Star 5.7k
* Code
* Issues 1.2k
* Pull requests 307
* Pull requests 308
* Discussions
* Actions
* Projects
* Security and quality 1
* Insights
Additional navigation options
* Code
* Issues
* Pull requests
* Discussions
* Actions
* Projects
* Security and quality
* Insights
Releases: dependabot/dependabot-core
Releases Tags
Releases · dependabot/dependabot-core
Release list
* v0.390.0
* v0.389.0
* v0.388.0
* v0.387.0
* v0.386.0
* v0.385.0
* v0.384.0
* v0.383.0
* v0.382.0
* v0.381.0
Previous Next
Jump to release
* v0.390.0
* v0.389.0
* v0.388.0
* v0.387.0
* v0.386.0
* v0.385.0
* v0.384.0
* v0.383.0
* v0.382.0
* v0.381.0
Previous Next
v0.390.0
v0.390.0 Latest
Latest
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
markhallen released this 03 Aug 15:09
v0.390.0
3778744
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Add typed requirement source API by @JamieMagee in #15705
* Reland "Cargo: handle crates locked at multiple versions" (#15638) by @p-linnane in #15668
* Preserve original absence of the bundler self-checksum on lockfile updates by @p-linnane in #15669
* Support security updates for vcpkg ports by @JamieMagee in #15676
* Beta support of PNPM 11 by @v-robaiken in #15710
* Remove enable_cooldown_default_days feature flag; make 3-day cooldown default unconditional by @v-robaiken with @Copilot in #15711
* github_actions: integrate gh-actions-lock lockfile relocking by @nodeselector in #15267
* Fix npm ignoring scoped registry issue by @AbhishekBhaskar in #15692
* Fix Gradle lockfile updates for repos with in-repo convention plugins by @thavaahariharangit in #15677
* Bump pytest from 9.0.3 to 9.1.1 in /python/helpers by @dependabot[bot] in #15687
* Feature flag clean up by @v-robaiken in #15724
* Bump pip-tools from 7.5.3 to 7.6.0 in /python/helpers in the pip-tools group across 1 directory by @dependabot[bot] in #15686
* Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError by @kbukum1 in #15701
* Revert "Respect resolutions/overrides and pin Berry wildcard updates to fix spurious NoChangeError" by @kbukum1 in #15730
* Type npm_and_yarn requirement access by @JamieMagee in #15706
* Compare full path, not file name, when excluding fetched files by @timdawborn in #15703
* Type bun requirement access by @JamieMagee in #15707
* Type bundler requirement access by @JamieMagee in #15708
* Stop retrying client errors when recording cooldown telemetry by @JamieMagee in #15737
* Bump cython from 3.2.4 to 3.2.9 in /python/helpers in the common group across 1 directory by @dependabot[bot] in #15685
* Stop pinning the resolved js-yaml version in sub-dependency specs by @JamieMagee in #15744
* Preserve .NET SDK prerelease version strings by @theinfosecguy in #15746
* Bump library/rust from 1.97.0-bookworm to 1.97.1-bookworm in /cargo by @dependabot[bot] in #15682
* Bump the prod-dependencies group across 2 directories with 22 updates by @dependabot[bot] in #15605
* v0.390.0 by @dependabot-core-action-automation[bot] in #15752
New Contributors
* @v-robaiken made their first contribution in #15710
* @nodeselector made their first contribution in #15267
* @timdawborn made their first contribution in #15703
* @theinfosecguy made their first contribution in #15746
Full Changelog: v0.389.0...v0.390.0
Contributors
*
*
*
*
*
*
*
*
*
*
timdawborn, JamieMagee, and 8 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
🎉 1 Frulfump reacted with hooray emoji
All reactions
* 🎉 1 reaction
1 person reacted
v0.389.0
v0.389.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
AbhishekBhaskar released this 27 Jul 18:25
v0.389.0
7936a8a
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Rescue errors in metadata_cascades_for_dep to prevent PR message loss by @yeikel in #14905
* Bump sigstore from 4.1.0 to 4.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15484
* Bump handlebars from 4.7.8 to 4.7.9 in /npm_and_yarn/helpers by @dependabot[bot] in #14547
* Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14605
* fix: use canonical LOCKFILE_ENTRY_REGEX in replace-lockfile-declaration.ts by @thavaahariharangit with @Copilot in #15642
* Prevent update job crash when a pinned GitHub Actions SHA is missing by @robaiken in #15628
* feat(npm_and_yarn): enhance downgrade conflict messages with detailed blocking dependencies by @thavaahariharangit in #15656
* Cargo: handle crates locked at multiple versions by @p-linnane in #15638
* Revert "Cargo: handle crates locked at multiple versions" by @kbukum1 in #15667
* Paginate Docker tag listing and classify registry error responses by @robaiken in #15651
* fix: Import proxy CA certificate into Java truststore for Java package managers by @thavaahariharangit in #15670
* Bump gradle from 4a253a2 to 2a6880c in /gradle by @dependabot[bot] in #15620
* Fix security update jobs failing with dependency_file_not_found for single-directory manifests by @thavaahariharangit with @Copilot in #15658
* Make Dependency strongly typed by @JamieMagee in #15647
* v0.389.0 by @dependabot-core-action-automation[bot] in #15691
New Contributors
* @p-linnane made their first contribution in #15638
Full Changelog: v0.388.0...v0.389.0
Contributors
*
*
*
*
*
*
*
JamieMagee, robaiken, and 5 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.388.0
v0.388.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
kbukum1 released this 22 Jul 19:35
v0.388.0
6c8bb8b
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Type GitHub release metadata by @JamieMagee in #15597
* Make GitCommitChecker strongly typed by @JamieMagee in #15598
* Retry corepack prepare and install on signature metadata errors from private registries by @kbukum1 in #15606
* Fix UV DependencyGrapher to detect nested uv.lock in monorepos by @thavaahariharangit with @Copilot in #15520
* Bump library/rust from 1.95.0-bookworm to 1.97.0-bookworm in /cargo by @dependabot[bot] in #15560
* Bump @sigstore/core from 3.1.0 to 3.2.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15455
* Bump maven from 3.9.14 to 3.9.16 in /maven by @dependabot[bot] in #15127
* Support Bundler source cooldown in Dependabot cooldown flow by @robaiken in #15517
* Type shared release metadata by @JamieMagee in #15607
* Make Job strongly typed by @JamieMagee in #15608
* Type Job wire models by @JamieMagee in #15610
* Type Service and ApiClient by @JamieMagee in #15614
* Add support for calendar-based versions for Maven and Gradle by @yeikel in #14114
* Type error reporting by @JamieMagee in #15615
* Type updater dependency helpers by @JamieMagee in #15617
* ensure proper formatting when patching element attributes by @brettfo in #15629
* Bump ws from 8.18.3 to 8.21.1 in /npm_and_yarn/helpers/test/npm/fixtures/vulnerability-auditor/update-needed-across-two-versions by @dependabot[bot] in #15329
* Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14608
* Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14609
* Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14610
* Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #14694
* Bump pip from 26.1.1 to 26.1.2 in /python/helpers in the pip group across 1 directory by @dependabot[bot] in #11830
* Bump yaml from 2.3.1 to 2.9.0 in /bun/helpers by @dependabot[bot] in #14535
* npm_and_yarn: group vulnerability auditor blocking-dependency messages by top-level ancestor by @thavaahariharangit in #15627
* Bump ip-address and socks in /bun/helpers by @dependabot[bot] in #14924
* Bump brace-expansion from 1.1.13 to 1.1.16 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15634
* Bump brace-expansion from 1.1.13 to 1.1.16 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15633
* Bump sigstore/cosign/cosign from v3.1.1 to v3.1.2 in /docker in the regclient group across 1 directory by @dependabot[bot] in #15621
* Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14606
* Bump @tootallnate/once from 2.0.0 to 2.0.1 in /bun/helpers by @dependabot[bot] in #15107
* Bump the "uv-ecosystem" group with 1 update across multiple ecosystems by @dependabot[bot] in #14969
* Bump ip-address and socks in /npm_and_yarn/helpers by @dependabot[bot] in #14923
* Bump yaml from 2.3.1 to 2.9.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14533
* Bump golang.org/x/mod from 0.37.0 to 0.38.0 in /go_modules/helpers by @dependabot[bot] in #15559
* Bump @sigstore/verify from 3.1.0 to 3.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15477
* julia: don't propose compat updates for workspace packages or synthesize member compat entries by @IanButterworth in #15643
* fix: guard against unparseable versions in cooldown fallback by @currantw in #15632
* Type dependency requirement readers by @JamieMagee in #15646
* v0.388.0 by @dependabot-core-action-automation[bot] in #15623
New Contributors
* @currantw made their first contribution in #15632
Full Changelog: v0.387.0...v0.388.0
Contributors
*
*
*
*
*
*
*
*
*
brettfo, JamieMagee, and 7 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.387.0
v0.387.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
AbhishekBhaskar released this 16 Jul 20:27
v0.387.0
79a21ea
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Type the gradle, swift, and pre_commit ecosystems by @JamieMagee in #15534
* Default cooldown to 3 days when default-days is not specified (behind a feature flag) by @robaiken with @Copilot in #15344
* Use shared base cooldown in git_submodules by @robaiken in #15537
* [Update graph] Avoid PathDependenciesNotReachable killing the whole job by @brrygrdn in #15522
* [Update Graph] Ensure that txt/in pairs are included properly in layers when working out references by @brrygrdn in #15581
* build(deps): bump opentofu to 1.12.1 by @RinseV in #15231
* Type the Sentry before_send processors by @JamieMagee in #15569
* Clear T.untyped from four strong updater files by @JamieMagee in #15570
* feat(opentofu): use registry API for multi-platform lockfile hashes by @diofeher in #15296
* julia: various fixes by @IanButterworth in #15549
* Type git_metadata_fetcher's git responses by @JamieMagee in #15572
* pre-commit: add regression tests for prerelease version filtering by @v-HaripriyaC in #15542
* add test ensuring duplicate PRs aren't submitted in security jobs by @brettfo in #15584
* Clear T.untyped from already-strong ecosystem files by @JamieMagee in #15573
* Update branch name case values to align with schema accepted values by @AbhishekBhaskar in #15592
* julia: fix TypeError when a cooldown is configured by @IanButterworth in #15591
* Fix codespell typo in updater job spec by @thavaahariharangit with @Copilot in #15599
* Swift: SemVer-compliant version comparison and validation by @v-HaripriyaC in #15589
* Type git source details by @JamieMagee in #15593
* Expose typed git source details by @JamieMagee in #15594
* v0.387.0 by @dependabot-core-action-automation[bot] in #15604
New Contributors
* @RinseV made their first contribution in #15231
Full Changelog: v0.386.0...v0.387.0
Contributors
*
*
*
*
*
*
*
*
*
*
diofeher, brrygrdn, and 8 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.386.0
v0.386.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
robaiken released this 13 Jul 16:30
v0.386.0
e9c2e95
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Capture offending gem details on bundler registry metadata errors by @kbukum1 in #15512
* Bundler: apply empty-checksum metadata patch to the v2 helper by @kbukum1 in #15513
* [Update graph] Ensure bystander txt files are removed before parsing for Python by @brrygrdn in #15508
* Handle global.json with no SDK version in dotnet_sdk parser by @brettfo in #15510
* Type the cargo ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15492
* Type the conda ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15493
* Type the docker ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15495
* Use shared git-tag cooldown in terraform by @robaiken in #15472
* Retry corepack once on signature metadata error by @thavaahariharangit with @Copilot in #15466
* Type the deno, elm, devcontainers, bazel, and helm ecosystems by @JamieMagee in #15527
* Add word-separator and lowercase formatting for branch name by @AbhishekBhaskar in #15478
* Fix Docker cooldown not respected for multi-arch images missing Last-Modified by @robaiken with @Copilot in #15486
* Reduce redundant git-source probes during npm metadata resolution by @thavaahariharangit with @Copilot in #15480
* Type the maven ecosystem and remove it from the T.untyped burndown by @JamieMagee in #15531
* Add branch name config template format support with validation by @AbhishekBhaskar in #15535
* fix(gradle): prefer local gradlew for lockfile updates by @thavaahariharangit in #15546
* helm: support versioning-strategy (range-preserving updates) by @casey-robertson-paypal in #15218
* Bump gradle from 9.4.1-jdk21-ubi to 9.6.1-jdk21-ubi in /gradle by @dependabot[bot] in #15498
* [Update graph] Add support for requirements.txt 'layering' instead of compressing to a single file by @brrygrdn in #15521
* Allow periods in Helm values file names for Docker ecosystem by @telnet23 in #15557
* Match existing group PRs covering a subset of job directories by @IanButterworth in #15548
* Bump library/golang from 1.26.1-bookworm to 1.26.5-bookworm in /go_modules by @dependabot[bot] in #15562
* Fix npm security updates for transitive dependencies in workspace monorepos by @Swampen in #15514
* Add helm to the smoke-test matrix by @casey-robertson-paypal in #15554
* v0.386.0 by @dependabot-core-action-automation[bot] in #15564
New Contributors
* @telnet23 made their first contribution in #15557
* @Swampen made their first contribution in #15514
Full Changelog: v0.385.0...v0.386.0
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
brrygrdn, brettfo, and 10 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.385.0
v0.385.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
thavaahariharangit released this 06 Jul 18:31
v0.385.0
00e8493
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Support package-scoped NuGet release notes by @Cjewett in #15211
* Filter null entries from job directories by @brettfo in #15457
* devcontainers: preserve major-only Feature pins when precision-matching tags are absent by @thavaahariharangit with @Copilot in #15445
* Type opaque hashes in common with T.anything by @JamieMagee in #15458
* Type the options passthrough in base classes with T.anything by @JamieMagee in #15459
* Apply git-tag cooldown across ecosystems by @robaiken in #15369
* Type requirement helpers in the update-checker base class by @JamieMagee in #15461
* Select group update handler for multi-ecosystem NuGet jobs by @brettfo in #15460
* Type error-detail payloads across common and the updater by @JamieMagee in #15462
* Type package release details with T.anything by @JamieMagee in #15463
* Type message builder commit options and vulnerabilities-fixed by @JamieMagee in #15465
* Fix multiple --default-index args when multiple replaces-base credentials exist by @thavaahariharangit with @Copilot in #15481
* Fetch gradle.properties and making available lock file generation with in dependabot by @thavaahariharangit with @Copilot in #15467
* Detect cargo registries across hierarchical .cargo/config.toml files by @brettfo in #15474
* fix(bundler): only re-vendor platform gems for updated dependencies by @jurre in #15451
* Fix Sorbet runtime signature violations by @JamieMagee in #15476
* Use shared git-tag cooldown in python by @robaiken in #15470
* Fix multiline HTML version parsing for Python/UV private registries by @thavaahariharangit with @Copilot in #15469
* v0.385.0 by @dependabot-core-action-automation[bot] in #15502
New Contributors
* @Cjewett made their first contribution in #15211
Full Changelog: v0.384.0...v0.385.0
Contributors
*
*
*
*
*
*
jurre, brettfo, and 4 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.384.0
v0.384.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
sachin-sandhu released this 30 Jun 16:05
v0.384.0
434965e
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Bazel: Fix prerelease filtering with same-release-line scoping by @v-HaripriyaC in #15332
* Respect cooldown for Docker digest updates and suppress multi-arch no-ops by @robaiken in #15354
* Bypass npmrc min-release-age for transitive npm security updates by @robaiken in #15386
* Ratchet the Sorbet T.untyped burndown by @JamieMagee in #15399
* feat(docker): implement single-platform image detection and optimize manifest fetching logic by @jpinz in #15390
* Fix private registry config not found error not being raised issue in npm_and_yarn by @AbhishekBhaskar in #15394
* don't fail if nuget cred is missing url by @brettfo in #15378
* Type commit_message_options with a value object by @JamieMagee in #15400
* Type the Dependabot config file parser by @JamieMagee in #15401
* Fix Terraform registry replacement typing and credential semantics by @thavaahariharangit with @Copilot in #15406
* fix: avoid path collisions for SHA-pinned GitHub Actions by @markhallen in #14806
* Nix: skip flake inputs pinned to a bare commit SHA by @JamieMagee in #15412
* Type the vulnerability version-range renderer by @JamieMagee in #15402
* Add JobCommand enum and Command property to NuGet Job model by @brettfo in #15277
* Upgrade Ruby to 4.0.5 by @Bo98 in #14830
* Bump updater-core image to RubyGems/Bundler 4.0.13 by @JamieMagee in #15256
* Fix issue with PrivateRegistryConfigNotFound error incorrectly firing when scope is configured by @AbhishekBhaskar in #15416
* Fake MSBuild SolutionDir during NuGet discovery (#13756) by @brettfo in #15392
* NuGet: Filter all editable files not present prior to discovery by @brettfo in #15358
* Support Central Package Versions updates in XmlFileWriter by @brettfo in #15409
* [Update Graph] Report empty manifests as present but empty instead of omitting them by @brrygrdn in #15427
* Fix vcpkg empty PRs for up-to-date baselines by @JamieMagee in #15420
* Nix: update NixOS channel tarball inputs by @JamieMagee in #15413
* fix(opentofu): accept terraform_registry credentials for OCI registry tags by @thavaahariharangit in #15422
* Commit changes to workspace member TOML files by @crabbit-git in #15142
* Fix COREPACK_NPM_REGISTRY trailing slash causing pnpm HTTP 404 on private registries by @thavaahariharangit with @Copilot in #15444
* Map additional NuGet feed errors to private_source_bad_response by @brettfo in #15426
* Support version and security NuGet job commands by @brettfo in #15430
* Show the vcpkg release tag instead of master in PR titles by @JamieMagee in #15433
* Register MSBuild before running the job so early NuGet errors are reported by @brettfo in #15431
* Add a baseline to vcpkg projects missing one by @JamieMagee in #15432
* Fix file updater failed to update for all support files sentry error by @AbhishekBhaskar in #15421
* Skip disabled Maven repositories by @adoroszlai in #15443
* v0.384.0 by @dependabot-core-action-automation[bot] in #15438
New Contributors
* @crabbit-git made their first contribution in #15142
* @adoroszlai made their first contribution in #15443
Full Changelog: v0.383.0...v0.384.0
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
markhallen, brrygrdn, and 10 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.383.0
v0.383.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
v-HaripriyaC released this 24 Jun 02:35
v0.383.0
5b941ee
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Bump bundled npm from 11.8.0 to 11.17.0 by @kbukum1 in #15335
* Fix composer specs failure due to block-insecure feature by @AbhishekBhaskar in #15334
* Add blocked_versions.ignored metric for Security-blocked update checks by @kbukum1 in #15333
* Preserve original bundler checksum on Bundler 4.0.11+ lockfile updates by @lucasmazza in #15249
* Generate .npmrc from scope property when lockfile inference fails by @AbhishekBhaskar in #15264
* Revert disabling block insecure flag in composer by @AbhishekBhaskar in #15339
* Fix no method error during fetching credentials properties by @AbhishekBhaskar in #15340
* Use only uv.lock for uv dependency graphing by @Nishnha in #15217
* Add transitive blocked-version enforcement to updater by @robaiken in #15295
* fix(npm_and_yarn): strip trailing slash from registry URL in Corepack env vars by @ajha-cs in #15324
* Fix pre-commit cooldown bypass and incorrect PR metadata issues with grouped updates by @AbhishekBhaskar in #15346
* Surface blocking parent dependency in npm fix-unavailable message by @thavaahariharangit in #15337
* Skip Gradle cooldown metadata fetch when cooldown is not configured by @yeikel in #15136
* Bundler: surface invalid registry gem metadata as a private source error by @kbukum1 in #15351
* Set default max branch name length to 100 characters by @kbukum1 in #15282
* set temporary token for cargo auth that the proxy will then replace by @brettfo in #15298
* Reject updates for private registries without proper dependabot configuration by @AbhishekBhaskar in #15347
* gradle: bump updater image to 9.4.1 by @thavaahariharangit in #15356
* Bundler: tolerate empty registry checksum metadata in v4 helper by @kbukum1 in #15359
* Preserve custom gradle-wrapper.properties values during wrapper updates by @kbukum1 in #15336
* fix(pre-commit, github-actions): use tag creation date for cooldown instead of commit date by @robaiken in #15350
* Update Sorbet toolchain and regenerate gem RBIs by @JamieMagee in #15304
* Enable six zero-offense Sorbet guardrail cops by @JamieMagee in #15305
* Replace to_hash with to_h and enable ImplicitConversionMethod by @JamieMagee in #15306
* Enforce method signatures via Sorbet/EnforceSignatures by @JamieMagee in #15307
* Image content validation for manifest lists for container image updates by @jpinz in #15352
* Type Version and Requirement internals across ecosystems by @JamieMagee in #15379
* Type RequirementsUpdater base and gradle/maven/sbt with DependencyRequirement by @JamieMagee in #15380
* Type standalone RequirementsUpdaters with DependencyRequirement by @JamieMagee in #15381
* Drop Python 3.9 support by @kbukum1 in #15391
* Stub docker manifest request in helm update_checker spec by @JamieMagee in #15398
* Parse DependencyGroup rules into typed readers by @JamieMagee in #15395
* Type provider_metadata as integer-keyed by @JamieMagee in #15396
* Fix Swift native requirement parser when there are additional arguments in .package() by @kkebo in #15311
* v0.383.0 by @dependabot-core-action-automation[bot] in #15365
New Contributors
* @lucasmazza made their first contribution in #15249
* @ajha-cs made their first contribution in #15324
* @kkebo made their first contribution in #15311
Full Changelog: v0.382.0...v0.383.0
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
lucasmazza, kkebo, and 10 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.382.0
v0.382.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
AbhishekBhaskar released this 15 Jun 22:12
v0.382.0
6b62d68
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Add support for scope property in npm_registry credentials by @AbhishekBhaskar in #15219
* uv: Remove dead add_auth_env_vars code and add credential matching diagnostics by @kbukum1 in #15209
* Fix npm registry credential leak to sibling paths on the same host by @Copilot in #15248
* Fix pnpm lockfileVersion 9.0 parsing error with optional chaining by @markhallen in #13959
* Parse remaining Job collections into typed structs by @JamieMagee in #15262
* Add a typed Hash subclass for requirement entries by @JamieMagee in #15263
* Fix Gradle wrapper jar encoding by @kbukum1 in #15235
* fix(maven): handle .target updates in file updater by @thavaahariharangit in #15270
* Default all Cargo crates to increase-if-necessary by @JamieMagee in #14306
* Improve handling of Python failures when insecure-external-code-execution: deny is set, Tidier summary output by @brrygrdn in #15269
* Type updated_requirements as DependencyRequirement across all ecosystems by @JamieMagee in #15272
* Remove T.untyped from four common files by @JamieMagee in #15278
* Type create_dependency_file with keyword arguments by @JamieMagee in #15279
* Remove T.untyped from three updater files by @JamieMagee in #15281
* fix(npm_and_yarn): prefer replaces-base registry over lockfile source for metadata fetches by @thavaahariharangit in #15273
* Type DependencyFile#to_h and Notice#to_hash serialization hashes by @JamieMagee in #15283
* Type parse_dep_string return in bundler and npm_and_yarn by @JamieMagee in #15284
* Type registry_parser, git_pin_replacer, and drop stale pnpm entry by @JamieMagee in #15286
* Type python requirement_parser and pip_compile_files by @JamieMagee in #15287
* Type parse_dep_string return in cargo and pub by @JamieMagee in #15288
* Remove stale ForbidTUntyped entries for eight update checkers by @JamieMagee in #15297
* Type Prism AST node parameters in bundler finders by @JamieMagee in #15299
* Introduce typed GitTagDetails for GitCommitChecker local-tag shape by @JamieMagee in #15300
* Type requirements parameters as DependencyRequirement in gradle and cargo by @JamieMagee in #15302
* Type go_modules requirement parsing and version comparison by @JamieMagee in #15303
* Clarify npm security update failure messages by @thavaahariharangit in #15294
* Bump the regclient group across 1 directory with 2 updates by @dependabot[bot] in #14769
* Fix CHECKSUMS header being stripped when removing bundler 4.0.x entry (#15193) by @jmgarnier in #15229
* Bump bundled Deno to 2.8.3 for lockfile v5 support by @markhallen in #15319
* Add Deno workspace support by @markhallen in #15322
* Bump golang.org/x/mod from 0.33.0 to 0.37.0 in /go_modules/helpers by @dependabot[bot] in #15314
* v0.382.0 by @dependabot-core-action-automation[bot] in #15317
New Contributors
* @jmgarnier made their first contribution in #15229
Full Changelog: v0.381.0...v0.382.0
Contributors
*
*
*
*
*
*
*
*
jmgarnier, markhallen, and 6 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
v0.381.0
v0.381.0
Compare
Choose a tag to compare
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
No results found
View all tags
kbukum1 released this 09 Jun 18:01
v0.381.0
ed54286
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPG key ID: B5690EEEBB952194
Verified
Learn about vigilant mode.
What's Changed
* Disable npmMinimalAgeGate for Yarn Berry security updates by @yeikel in #15191
* Add Bundler 4 support by @JamieMagee in #15180
* Bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0 in /maven/lib/dependabot/maven by @dependabot[bot] in #15190
* Add GONOPROXY/GONOSUMDB env vars to go_modules FileParser by @Nishnha in #15159
* fix(go_modules): include advisory pseudo-version boundaries for security fix resolution by @thavaahariharangit in #15213
* Retry Gradle metadata fetch on EOF by @thavaahariharangit in #15204
* Handle npm registry EOFError in latest version finder by @thavaahariharangit in #15205
* fix(python): honor .pip-tools.toml unsafe-package in pip-compile updates by @thavaahariharangit in #15202
* Swift: add missing rescue-path test for trailing slash in normalize_name by @Copilot in #15220
* Fix TypeError: String does not have #dig method in PipenvRunner by @Copilot in #14821
* fix(go_modules): run strict go mod tidy and surface real errors by @kbukum1 in #15094
* Gate YARN_NPM_MINIMAL_AGE_GATE on Yarn 4.10+ by @yeikel in #15226
* opentofu: handle OCI source type in MetadataFinder by @diofeher in #14990
* Respect cooldown rules when generating Poetry lockfiles by @thavaahariharangit in #15232
* Fix nuget exception on call to single() by @sebasgomez238 in #15233
* Fix Maven property update previous version metadata by @kbukum1 in #15224
* Detect ICU package error indicating EOL SDK by @brettfo in #15234
* Fix docker_compose parser crash on YAML symbols in lock files by @kbukum1 in #15036
* Handle Berry lockfiles without explicit Yarn config by @Copilot in #14820
* Fix behavioral gap in prerelease detection found with Python and generalized to common by @v-HaripriyaC in #15179
* Fix incorrect cooldown filtering for sha pinned dependencies in pre-commit by @AbhishekBhaskar in #15225
* Harden Helm helper CLI argument handling and fix helm search flag ordering by @Copilot in #15247
* Add an experimental GitHub Action summary for graph jobs by @brrygrdn in #15223
* Add RBI shims for API client wrappers, remove ~110 T.unsafe calls by @JamieMagee in #14615
* Bump library/rust from 1.94.0-bookworm to 1.95.0-bookworm in /cargo by @dependabot[bot] in #15188
* Replace Job's untyped hashes with T::ImmutableStruct by @JamieMagee in #14616
* Fix Gradle/Maven prerelease detection gaps by @v-HaripriyaC in #15222
* Fix OCI Helm chart metadata finder to strip oci:// prefix by @Copilot in #13634
* Fix workflow summary experiment name by @brrygrdn in #15250
* Validate dependency versions in GlobalJsonDiscovery by @brettfo in #15255
* Enable two Sorbet cops, ignore bazel/nix specs by @JamieMagee in #15257
* Enable Sorbet/ForbidTUntyped with a todo backlog by @JamieMagee in #15258
* v0.381.0 by @dependabot-core-action-automation[bot] in #15246
Full Changelog: v0.380.0...v0.381.0
Contributors
*
*
*
*
*
*
*
*
*
*
*
*
diofeher, brrygrdn, and 10 other contributors
Assets 2
Loading
Uh oh!
There was an error while loading. Please reload this page.
All reactions
Previous 1 2 3 4 5 … 19 20 Next
Previous Next
Footer
© 2026 GitHub, Inc.
Footer navigation
* Terms
* Privacy
* Security
* Status
* Community
* Docs
* Contact
* Manage cookies
* Do not share my personal information
You can’t perform that action at this time.
Tipp: Markieren Sie Text zum Teilen oder zum Hinzufügen zu Ignorierlisten.
— Download difference patch
Derzeit werden Unterschiede nur textuell und nicht grafisch dargestellt, es ist nur der letzte Screenshot verfügbar.
Für den Screenshot ist die Aktivierung von Playwright/WebDriver erforderlich