Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update minor/patch updates #253

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 1, 2024

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
anchore/sbom-action action patch v0.17.5 -> v0.17.7 age adoption passing confidence
github.com/pulumi/pulumi-terraform-bridge/v3 require minor v3.93.1 -> v3.95.0 age adoption passing confidence
github.com/pulumi/pulumi/sdk/v3 require minor v3.137.0 -> v3.138.0 age adoption passing confidence
go (source) toolchain patch 1.23.2 -> 1.23.3 age adoption passing confidence
golang.org/x/text require minor v0.19.0 -> v0.20.0 age adoption passing confidence
goreleaser/goreleaser-action action minor v6.0.0 -> v6.1.0 age adoption passing confidence
jaxxstorm/action-install-gh-release action minor v1.12.0 -> v1.13.0 age adoption passing confidence
pypa/gh-action-pypi-publish action minor v1.10.3 -> v1.12.2 age adoption passing confidence

Release Notes

anchore/sbom-action (anchore/sbom-action)

v0.17.7

Compare Source

Changes in v0.17.7

v0.17.6

Compare Source

Changes in v0.17.6

pulumi/pulumi-terraform-bridge (github.com/pulumi/pulumi-terraform-bridge/v3)

v3.95.0

Compare Source

What's Changed

Full Changelog: pulumi/pulumi-terraform-bridge@v3.94.0...v3.95.0

v3.94.0

Compare Source

What's Changed

Full Changelog: pulumi/pulumi-terraform-bridge@v3.93.1...v3.94.0

pulumi/pulumi (github.com/pulumi/pulumi/sdk/v3)

v3.138.0

Compare Source

3.138.0 (2024-11-06)

Features
  • [backend/diy] Keep computer awake while an update is running
    #​17699

  • [backend/service] Keep computer awake while an update is running
    #​17699
    #​17675

  • [cli] Add interactive account selection to pulumi login command
    #​17618

  • [cli/display] Colorize selected stack when listing
    #​17606

  • [engine] Persist metadata about snapshot integrity errors
    #​17291

  • [programgen] Implement package descriptor blocks in PCL to load parameterized packages
    #​17589

  • [sdk/nodejs] Support Node.js 23
    #​17639

Bug Fixes
  • [docs] Fix spacing and formatting of stack init command's long doc
    #​17534

  • [engine] Spot skipped-create dependencies even when inputs don't change
    #​17633

  • [engine] Normalize URNs in DeletedWith references
    #​17666

  • [engine] Disable the enviromental GITHUB_TOKEN on 403 responses
    #​17671

  • [sdk/go] Overwrite directories in workspace.CopyTemplateFiles when called with force=true
    #​17695

  • [sdk/python] Add additional debug information to ValueError and AssertionError
    #​17577

Miscellaneous
  • [docs] Update function comments to remove outdated DIY backend note
    #​17563

  • [yaml] Update YAML to 1.11.2
    #​17637

golang/go (go)

v1.23.3

goreleaser/goreleaser-action (goreleaser/goreleaser-action)

v6.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: goreleaser/goreleaser-action@v6.0.0...v6.1.0

jaxxstorm/action-install-gh-release (jaxxstorm/action-install-gh-release)

v1.13.0

Compare Source

What's Changed
New Contributors

Full Changelog: jaxxstorm/action-install-gh-release@v1...v1.13.0

pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)

v1.12.2

Compare Source

🐛 What's Fixed

The fix for signing legacy zip sdists turned out to be incomplete, so @​woodruffw💰 promptly produced another follow-up that updated pypi-attestations from v0.0.13 to v0.0.15 in #​297. This is the only change since the previous release.

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.12.1...v1.12.2

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

v1.12.1

Compare Source

🐛 What's Fixed

Version v1.12.0 hit several rare corner cases we never considered fully supported, and this release fixes a few of those.
In #​294, @​webknjaz💰 improved the self-hosted runner experience by pre-installing Python if it's not there, and with #​293 the ability to use the action on GitHub Enterprise instances has been restored. The latter should've also fixed the ability to invoke [pypi-publish][pypi-publish] from nested in-repo composite actions — another exotic use-case that was never tested in our CI.
@​woodruffw💰 also managed to squeeze in a last-minute fix for detecting legacy .zip sdists while producing attestations via #​295.

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.12.0...v1.12.1

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Huge Thanks to all the bug reporters for posting the logs, helping inspect the problems and verify the regression fixes!

v1.12.0

Compare Source

⚡️ Why Should You Update?

This is a minor version bump, but it does not add any new user-facing interfaces. Still, I felt like it should not be a patch-release: this update brings significant changes to the action invocation and internal release process.

Previously, each invocation of [pypi-publish][pypi-publish] required building a container image in the invoking CI job. This was inefficient and added about 30 seconds to the publishing jobs at their startup just to build the container.

I wanted to improve this for over three years (#​58) and a little over half a year ago @​br3ndonland💰 stepped up and offered a very comprehensive solution to the limitation I was hoping to overcome: #​230.

Going forward, I'm going to pre-build per-version containers prior to cutting each release. And the action invocations will just pull the image from GitHub Container registry.

[!CAUTION]
Known quirks:

  • This seems to not work on self-hosted runners without a python executable: #​289. The workaround could be installing it prior to running the action.
  • ~Pinning to commit hashes does not work: #​290. Workaround: postpone updating until it's fixed or switch to Git tags for now. Subscribe to that issue to follow the progress.~ UPD: This was an issue during the first 12 hours post release and it has been addressed upstream by publishing a commit SHA-tagged image for the release on Nov 12, 2024 at 10:27 UTC+1.
  • Calling pypi-publish from another nested repo-local composite action might be breaking file paths: #​291. Workaround: postpone updating until it's fixed. Subscribe to that issue to follow the progress.
  • Running within GitHub Enterprise fails on the action repo clone: #​292. Workaround: postpone updating until it's fixed. Subscribe to that issue to follow the progress.

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.11.0...v1.12.0

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

v1.11.0

Compare Source

🔏 Helping you become a trusted supply chain link 🔗

Two months ago, in v1.10.0, @​woodruffw💰 integrated support for generating and uploading PEP 740 digital attestations that can be used as provenance objects when analyzing dependency chains for the integrity.

To make sure it works well, it was implemented as an opt-in, so a relatively small subset of projects was able to try it out, and a few issues have been determined and fixed during this time.

That changes today! This version changes the feature toggle to “on by default”. This means that from now on, every project making use of Trusted Publishing will start producing and publishing digital attestations without having to do any modifications to how they use this action.

@​woodruffw💰 flipped the respective toggle in #​277 with the possibility to opt-out.

🛠️ Internal Dependencies

@​woodruffw💰 bumped sigstore to v3.5.1 and pypi-attestations to v0.0.13 in lock files via #​276.

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.10.3...v1.11.0

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to William for working on improving the supply chain provenance in the ecosystem! The overall effort is tracked @&#https://github.com/pypi/warehouse/issues/15871/15871.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/minorpatch-updates branch from f452218 to 1b9b1e1 Compare November 2, 2024 01:46
@renovate renovate bot changed the title chore(deps): update anchore/sbom-action action to v0.17.6 chore(deps): update minor/patch updates Nov 2, 2024
@renovate renovate bot force-pushed the renovate/minorpatch-updates branch from 1b9b1e1 to d1ef9fb Compare November 3, 2024 10:08
Copy link
Contributor Author

renovate bot commented Nov 3, 2024

ℹ Artifact update notice

File name: provider/go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 3 additional dependencies were updated

Details:

Package Change
github.com/pulumi/pulumi-yaml v1.10.3 -> v1.11.1
github.com/pulumi/pulumi/pkg/v3 v3.136.1 -> v3.137.0
golang.org/x/sync v0.8.0 -> v0.9.0

@renovate renovate bot force-pushed the renovate/minorpatch-updates branch 8 times, most recently from 4739363 to 30ec42b Compare November 12, 2024 00:41
@renovate renovate bot force-pushed the renovate/minorpatch-updates branch from 30ec42b to 71c57ac Compare November 13, 2024 18:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants