豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

Releases: dependabot/dependabot-core

v0.339.0

09 Oct 10:25
7e41ea6

Choose a tag to compare

What's Changed

  • v0.339.0 by @dependabot-core-action-automation[bot] in #13260

Full Changelog: v0.338.2...v0.339.0

v0.337.0

07 Oct 02:30
7e43177

Choose a tag to compare

What's Changed

  • Fixes a Passed 'nil' into T.must error in the Cargo file fetcher when workspace paths are exactly "*" by @thavaahariharangit in #13221
  • Fix Python version defaulting to 3.9 (lowest available) instead of latest when no explicit version specified by @thavaahariharangit in #13215
  • Enforce a stricter interface between serializer and dependency data gathering by @brrygrdn in #13209
  • Add explicit dependency for maven on rexml by @pavera in #13229
  • v0.337.0 by @dependabot-core-action-automation[bot] in #13239

Full Changelog: v0.336.0...v0.337.0

v0.336.0

02 Oct 17:14
b87220d

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.335.0...v0.336.0

v0.335.0

25 Sep 15:59
edc8196

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.334.0...v0.335.0

v0.334.0

18 Sep 22:09
3c952c1

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.333.0...v0.334.0

v0.333.0

18 Sep 16:25
6654762

Choose a tag to compare

What's Changed

Full Changelog: v0.332.0...v0.333.0

v0.332.0

11 Sep 12:41
13929b9

Choose a tag to compare

What's Changed

  • [Experiment] Simplify the building of Dependency Submission payloads to align with static parsers by @brrygrdn in #12990
  • improve tag name extractor by @brettfo in #13018
  • [Experiment][Cleanup] Remove per-file dependency list logic from Bundler, Go and NPM by @brrygrdn in #12997
  • Do not run Scorecard analysis from forks by @yeikel in #13006
  • Only run group updates when running multi ecosystem updates by @robaiken in #13005
  • Removing exclude_paths from dry-run by @robaiken in #13028
  • Bump Sorbet from 0.5.11952 to 0.5.12414 by @JamieMagee in #12862
  • Prefer Azure mirror for Ubuntu by @yeikel in #13023
  • Upgrade git and git-lfs by @yeikel in #13022
  • Conda security update delegation logic fix to address security update failures by @theztefan in #13026
  • v0.332.0 by @dependabot-core-action-automation[bot] in #13060

Full Changelog: v0.331.0...v0.332.0

v0.331.0

04 Sep 09:08
bbdcb2b

Choose a tag to compare

What's Changed

  • Do not run the gems-bump-version workflow from forks by @yeikel in #12935
  • More descriptive error message for tag <tag> does not exist by @Nishnha in #12984
  • Clarify error message by @jeffwidman in #12985
  • Add support for vcpkg dependency constraints by @JamieMagee in #12872
  • Add ecosystem metadata metrics support to Conda FileParser by @Copilot in #12978
  • removing timestamp which makes it harder to smoke test by @jakecoffman in #13004
  • Match release stability for dated Rust toolchain releases by @JamieMagee in #12986
  • Update exclude-paths feature implementation approach by @AbhishekBhaskar in #12966
  • always restore packages.config before attempting update by @brettfo in #13010
  • v0.331.0 by @dependabot-core-action-automation[bot] in #13015

Full Changelog: v0.330.0...v0.331.0

v0.330.0

29 Aug 20:38
b923bb5

Choose a tag to compare

What's Changed

  • add missing test case by @brettfo in #12776
  • add end-to-end test for updating json files by @brettfo in #12963
  • Fix git rewrite rules: configure SSH-to-HTTPS rewriting when credentials handled by proxy by @kbukum1 in #12971
  • Bump brace-expansion in /bun/helpers by @dependabot[bot] in #12964
  • Bump regclient to 0.9.1 by @yeikel in #12937
  • Read maven-dependency-plugin version dynamically+ enable dependabot for maven helpers by @yeikel in #12717
  • Fix KeyError in git credential configuration when host is missing by @kbukum1 in #12973
  • Add early branch validation with helpful error messages for target-branch configurations by @Copilot in #12924
  • Add GroupDependencySelector integration to CreateGroupUpdatePullRequest by @robaiken in #12968
  • Adding GroupDependencySelector filter to refresh group pull request by @robaiken in #12969
  • Add support for goproxy_server and go.env files by @jurre in #12747
  • Consider the title of the issue while labeling by @yeikel in #12954
  • Do not run the stalebot from forks by @yeikel in #12936
  • Fix multi-directory processing to skip directories without required files by @Copilot in #12922
  • v0.329.0 by @dependabot-core-action-automation[bot] in #12980
  • v0.330.0 by @dependabot-core-action-automation[bot] in #12983

Full Changelog: v0.328.0...v0.330.0

v0.328.0

28 Aug 16:12
0aef364

Choose a tag to compare

What's Changed

  • Enable GitHub Copilot coding agent with instructions and environment setup by @markhallen in #12949
  • Removes feature flag from cooldown metadata collection by @sachin-sandhu in #12955
  • [Experiment] First pass of npm support for the dependency submission workflow by @brrygrdn in #12893
  • Fix issues with multi-version dependency changes when refreshing security update PRs by @jasonpaulos in #12897
  • Include old version number whenever possible by @brettfo in #12962
  • Add type safety in UV ecosystem FileFetcher by @Copilot in #12952
  • Updating registry finder priority by @thavaahariharangit in #12958
  • Reset smoke test branch by @brettfo in #12967
  • Add GroupDependencySelector from per-directory merge logic by @markhallen in #12911
  • v0.328.0 by @dependabot-core-action-automation[bot] in #12965

New Contributors

  • @Copilot made their first contribution in #12952

Full Changelog: v0.327.0...v0.328.0