chore(deps): bump the github-actions group across 1 directory with 9 updates by dependabot[bot] · Pull Request #2636 · modelcontextprotocol/python-sdk
Bumps the github-actions group with 9 updates in the / directory:
| Package | From | To |
|---|---|---|
| actions/checkout | 4.3.1 |
6.0.3 |
| anthropics/claude-code-action | 1.0.53 |
1.0.148 |
| actions/github-script | 8.0.0 |
9.0.0 |
| astral-sh/setup-uv | 7.2.1 |
8.2.0 |
| actions/setup-node | 6.2.0 |
6.4.0 |
| actions/upload-artifact | 6.0.0 |
7.0.1 |
| actions/download-artifact | 7.0.0 |
8.0.1 |
| pypa/gh-action-pypi-publish | 1.13.0 |
1.14.0 |
| peter-evans/create-pull-request | 8.1.0 |
8.1.1 |
Updates actions/checkout from 4.3.1 to 6.0.3
Release notes
Sourced from actions/checkout's releases.
v6.0.3
What's Changed
- Update changelog by
@ericsciplein actions/checkout#2357- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- Update changelog for v6.0.3 by
@yaananthin actions/checkout#2446New Contributors
@yaananthmade their first contribution in actions/checkout#2414Full Changelog: actions/checkout@v6...v6.0.3
v6.0.2
What's Changed
- Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by
@TingluoHuangin actions/checkout#2355- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356Full Changelog: actions/checkout@v6.0.1...v6.0.2
v6.0.1
What's Changed
- Update all references from v5 and v4 to v6 by
@ericsciplein actions/checkout#2314- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327- Clarify v6 README by
@ericsciplein actions/checkout#2328Full Changelog: actions/checkout@v6...v6.0.1
v6.0.0
What's Changed
- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- v6-beta by
@ericsciplein actions/checkout#2298- update readme/changelog for v6 by
@ericsciplein actions/checkout#2311Full Changelog: actions/checkout@v5.0.0...v6.0.0
v6-beta
What's Changed
Updated persist-credentials to store the credentials under
$RUNNER_TEMPinstead of directly in the local git config.This requires a minimum Actions Runner version of v2.329.0 to access the persisted credentials for Docker container action scenarios.
v5.0.1
What's Changed
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
Changelog
v6.0.3
- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414v6.0.2
- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356v6.0.1
- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327v6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248v5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301v5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226v4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305v4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924v4.2.0
- Add Ref and Commit outputs by
@lucacomein actions/checkout#1180- Dependency updates by
@dependabot- actions/checkout#1777, actions/checkout#1872v4.1.7
- Bump the minor-npm-dependencies group across 1 directory with 4 updates by
@dependabotin actions/checkout#1739- Bump actions/checkout from 3 to 4 by
@dependabotin actions/checkout#1697- Check out other refs/* by commit by
@orhantoyin actions/checkout#1774
... (truncated)
Commits
df4cb1cUpdate changelog for v6.0.3 (#2446)1cce339Fix checkout init for SHA-256 repositories (#2439)900f221fix: expand merge commit SHA regex and add SHA-256 test cases (#2414)0c366fdUpdate changelog (#2357)de0fac2Fix tag handling: preserve annotations and explicit fetch-tags (#2356)064fe7fAdd orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set (...8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)- Additional commits viewable in compare view
Updates anthropics/claude-code-action from 1.0.53 to 1.0.148
Release notes
Sourced from anthropics/claude-code-action's releases.
v1.0.148
Full Changelog: anthropics/claude-code-action@v1...v1.0.148
v1.0.147
What's Changed
- Add pr-stamp-sweep review workflow by
@ashwin-antin anthropics/claude-code-action#1409Full Changelog: anthropics/claude-code-action@v1...v1.0.147
v1.0.146
What's Changed
- test: add unit tests for parseGitHubContext and context type guards by
@mateuscmtropicalin anthropics/claude-code-action#1404- docs(faq): correct rebase FAQ to match actual behavior by
@bymlein anthropics/claude-code-action#1370- fix: fall back to inherited env for auth when inputs are empty by
@kirsaniumin anthropics/claude-code-action#1342- fix: break SDK iterator after result message to prevent hang in pull_request runs by
@scobbein anthropics/claude-code-action#1339- Pin setup-bun binary for post-steps by
@kiwigitopsin anthropics/claude-code-action#1365- fix: clear stale claude-prompts dir before each write by
@kyungilparkin anthropics/claude-code-action#1288- Include labels in formatContext() output for issues and PRs by
@joshpayne-jobyin anthropics/claude-code-action#1298- fix(sanitizer): match attribute quotes by type to avoid mangling content by
@bymlein anthropics/claude-code-action#1371- docs: fix execution file parsing example by
@looooown2006in anthropics/claude-code-action#1297- fix(image-downloader): detect image type from magic bytes, not URL extension by
@pmespressoin anthropics/claude-code-action#1396New Contributors
@mateuscmtropicalmade their first contribution in anthropics/claude-code-action#1404@bymlemade their first contribution in anthropics/claude-code-action#1370@kirsaniummade their first contribution in anthropics/claude-code-action#1342@scobbemade their first contribution in anthropics/claude-code-action#1339@kiwigitopsmade their first contribution in anthropics/claude-code-action#1365@kyungilparkmade their first contribution in anthropics/claude-code-action#1288@joshpayne-jobymade their first contribution in anthropics/claude-code-action#1298@looooown2006made their first contribution in anthropics/claude-code-action#1297@pmespressomade their first contribution in anthropics/claude-code-action#1396Full Changelog: anthropics/claude-code-action@v1...v1.0.146
v1.0.145
Full Changelog: anthropics/claude-code-action@v1...v1.0.145
v1.0.144
Full Changelog: anthropics/claude-code-action@v1...v1.0.144
v1.0.143
What's Changed
- Drop --tsconfig-override from Bun invocations to avoid runtime crash by
@chsmc-antin anthropics/claude-code-action#1315New Contributors
@chsmc-antmade their first contribution in anthropics/claude-code-action#1315Full Changelog: anthropics/claude-code-action@v1...v1.0.143
... (truncated)
Commits
d5726dechore: bump Claude Code to 2.1.177 and Agent SDK to 0.3.17756fa348chore: bump Claude Code to 2.1.176 and Agent SDK to 0.3.17682d95d4Add pr-stamp-sweep review workflow (#1409)0cb4f3echore: bump Claude Code to 2.1.175 and Agent SDK to 0.3.1758551f4bfix(image-downloader): detect image type from magic bytes (#1396)eba921fdocs: fix execution file parsing example (#1297)36617bdfix(sanitizer): match attribute quotes by type to avoid mangling content (#1371)24b9156Include labels in formatContext() output for issues and PRs (#1298)9441a7ffix: clear stale claude-prompts dir before each write (#1288)b371255pin setup-bun path for post steps (#1365)- Additional commits viewable in compare view
Updates actions/github-script from 8.0.0 to 9.0.0
Release notes
Sourced from actions/github-script's releases.
v9.0.0
New features:
getOctokitfactory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients withgetOctokitfor details and examples.- Orchestration ID in user-agent — The
ACTIONS_ORCHESTRATION_IDenvironment variable is automatically appended to the user-agent string for request tracing.Breaking changes:
require('@actions/github')no longer works in scripts. The upgrade to@actions/githubv9 (ESM-only) meansrequire('@actions/github')will fail at runtime. If you previously used patterns likeconst { getOctokit } = require('@actions/github')to create secondary clients, use the new injectedgetOctokitfunction instead — it's available directly in the script context with no imports needed.getOctokitis now an injected function parameter. Scripts that declareconst getOctokit = ...orlet getOctokit = ...will get aSyntaxErrorbecause JavaScript does not allowconst/letredeclaration of function parameters. Use the injectedgetOctokitdirectly, or usevar getOctokit = ...if you need to redeclare it.- If your script accesses other
@actions/githubinternals beyond the standardgithub/octokitclient, you may need to update those references for v9 compatibility.What's Changed
- Add ACTIONS_ORCHESTRATION_ID to user-agent string by
@Copilotin actions/github-script#695- ci: use deployment: false for integration test environments by
@salmanmkcin actions/github-script#712- feat!: add getOctokit to script context, upgrade
@actions/githubv9,@octokit/corev7, and related packages by@salmanmkcin actions/github-script#700New Contributors
@Copilotmade their first contribution in actions/github-script#695Full Changelog: actions/github-script@v8.0.0...v9.0.0
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunction- Additional commits viewable in compare view
Updates astral-sh/setup-uv from 7.2.1 to 8.2.0
Release notes
Sourced from astral-sh/setup-uv's releases.
v8.2.0 🌈 New inputs
quietanddownload-from-astral-mirrorChanges
This release brings two new inputs and a few bug fixes.
New inputs
Lets talk about the new inputs first.
quiet
Pretty simple. It turns of all
infologgings. Useful if you use this in a composite action and are not interested in all the details. In the upcoming releases we will add log groups to fully implement support for "less noise"[!NOTE]
Warnings and errors are always logged.download-from-astral-mirror
In some cases you may want to directly use the fallback of checking for available versions and downloading releases from GitHub instead of using the astral.sh mirror. Setting
download-from-astral-mirror: falseallows you to do that.Bugfixes
When using the astral.sh mirror to query available versions and download releases (done by default) we now stop sending the GitHub token in the header. The mirror never looked at it but we shouldn't be handing out that data even if it is just a short lived token. All other bugfixes try to limit the impact of failed GitHub queries due to retries and other faults.
We couldn't pinpoint all rootcauses yet but added more logging for error cases to track them down.
🐛 Bug fixes
- fix: report unexpected cache save failures
@eifinger(#896)- fix: report unexpected setup failures
@eifinger(#895)- fix: add timeout to fetch to prevent silent hangs
@eifinger-bot(#883)- Limit GitHub tokens to github.com download URLs
@zsol(#878)- increase libuv-workaround timeout to 100ms
@eifinger(#880)🚀 Enhancements
- Add quiet input to suppress info-level log output
@eifinger(#898)- feat: add
download-from-astral-mirrorinput@eifinger(#897)🧰 Maintenance
- docs: update dependabot rollup biome guidance
@eifinger(#902)- chore: update known checksums for 0.11.18 @github-actions[bot] (#899)
- chore: update known checksums for 0.11.17 @github-actions[bot] (#892)
- chore: update known checksums for 0.11.16 @github-actions[bot] (#889)
- chore: update known checksums for 0.11.15 @github-actions[bot] (#885)
- chore: update known checksums for 0.11.14 @github-actions[bot] (#879)
- chore: update known checksums for 0.11.13 @github-actions[bot] (#877)
... (truncated)
Commits
fac544cchore(deps): roll up dependabot updates (#903)7390f77docs: update dependabot rollup biome guidance (#902)363c64achore(deps): roll up dependabot updates (#901)c4fcbafchore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.3.1 (#900)8e642c5chore: update known checksums for 0.11.18 (#899)a92cb43Add quiet input to suppress info-level log output (#898)e07f2acchore(deps): bump eifinger/actionlint-action from 1.10.1 to 1.10.2 (#842)bc4034echore(deps): bump github/codeql-action from 4.35.4 to 4.36.0 (#893)df42d4fchore(deps): bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6 (#891)b9c8c4cfeat: adddownload-from-astral-mirrorinput (#897)- Additional commits viewable in compare view
Updates actions/setup-node from 6.2.0 to 6.4.0
Release notes
Sourced from actions/setup-node's releases.
v6.4.0
What's Changed
Dependency updates:
- Upgrade
@actionsdependencies by@Copilotin actions/setup-node#1525- Update Node.js versions in versions.yml and bump package to v6.4.0 by
@priya-kinthaliin actions/setup-node#1533New Contributors
@Copilotmade their first contribution in actions/setup-node#1525Full Changelog: actions/setup-node@v6...v6.4.0
v6.3.0
What's Changed
Enhancements:
- Support parsing
devEnginesfield by@susnuxin actions/setup-node#1283When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.
Dependency updates:
- Fix npm audit issues by
@gowridurgadin actions/setup-node#1491- Replace uuid with crypto.randomUUID() by
@trivikrin actions/setup-node#1378- Upgrade minimatch from 3.1.2 to 3.1.5 by
@dependabotin actions/setup-node#1498Bug fixes:
- Remove hardcoded bearer for mirror-url
@marco-ippolitoin actions/setup-node#1467- Scope test lockfiles by package manager and update cache tests by
@gowridurgadin actions/setup-node#1495New Contributors
@susnuxmade their first contribution in actions/setup-node#1283Full Changelog: actions/setup-node@v6...v6.3.0
Commits
48b55a0Update Node.js versions in versions.yml and bump package to v6.4.0 (#1533)ab72c7eUpgrade@actionsdependencies (#1525)53b8394Bump minimatch from 3.1.2 to 3.1.5 (#1498)54045abScope test lockfiles by package manager and update cache tests (#1495)c882bffReplace uuid with crypto.randomUUID() (#1378)774c1d6feat(node-version-file): support parsingdevEnginesfield (#1283)efcb663fix: remove hardcoded bearer (#1467)d02c89dFix npm audit issues (#1491)- See full diff in compare view
Updates actions/upload-artifact from 6.0.0 to 7.0.1
Release notes
Sourced from actions/upload-artifact's releases.
v7.0.1
What's Changed
- Update the readme with direct upload details by
@danwkennedyin actions/upload-artifact#795- Readme: bump all the example versions to v7 by
@danwkennedyin actions/upload-artifact#796- Include changes in typespec/ts-http-runtime 0.3.5 by
@yacaovsncin actions/upload-artifact#797Full Changelog: actions/upload-artifact@v7...v7.0.1
v7.0.0
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new
archiveparameter tofalseto skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. Thenameparameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.ESM
To support new versions of the
@actions/*packages, we've upgraded the package to ESM.What's Changed
- Add proxy integration test by
@Link- in actions/upload-artifact#754- Upgrade the module to ESM and bump dependencies by
@danwkennedyin actions/upload-artifact#762- Support direct file uploads by
@danwkennedyin actions/upload-artifact#764New Contributors
@Link- made their first contribution in actions/upload-artifact#754Full Changelog: actions/upload-artifact@v6...v7.0.0
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration test- See full diff in compare view
Updates actions/download-artifact from 7.0.0 to 8.0.1
Release notes
Sourced from actions/download-artifact's releases.
v8.0.1
What's Changed
- Support for CJK characters in the artifact name by
@danwkennedyin actions/download-artifact#471- Add a regression test for artifact name + content-type mismatches by
@danwkennedyin actions/download-artifact#472Full Changelog: actions/download-artifact@v8...v8.0.1
v8.0.0
v8 - What's new
[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.
[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).
Direct downloads
To support direct uploads in
actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks theContent-Typeheader ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the newskip-decompressparameter totrue.Enforced checks (breaking)
A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the
digest-mismatchparameter. To be secure by default, we are now defaulting the behavior toerrorwhich will fail the workflow run.ESM
To support new versions of the @actions/* packages, we've upgraded the package to ESM.
What's Changed
- Don't attempt to un-zip non-zipped downloads by
@danwkennedyin actions/download-artifact#460- Add a setting to specify what to do on hash mismatch and default it to
errorby@danwkennedyin actions/download-artifact#461Full Changelog: actions/download-artifact@v7...v8.0.0
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they do- Additional commits viewable in compare view
Updates pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0
Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
v1.14.0
✨ What's Changed
The main change in this release is that
verboseandprint-hashinputs are now on by default. This was contributed by@whitequark💰 in #397.📝 Docs
@woodruffw💰 updated the mentions of PEP 740 to stop implying that it might be experimental (it hasn't been for quite a while!) in #388 and@him2him2💰 brushed up some grammar in the README and SECURITY docs via #395.🛠️ Internal Updates
@woodruffw💰 bumpedsigstoreandpypi-attestationsin the lock file (#391) and@webknjaz💰 added infra for using type annotations in the project (#381).💪 New Contributors
@him2him2made their first contribution in #395@whitequarkmade their first contribution in #397🪞 Full Diff: pypa/gh-action-pypi-publish@v1.13.0...v1.14.0
🧔♂️ Release Manager:
@webknjaz🇺🇦🙏 Special Thanks to
@facutuesca💰 and@woodruffw💰 for helping maintain this project when I can't!💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
Commits
cef2210Merge pull request #397 from whitequark/patch-1b4595e2Enableverboseandprint-hashby default.e2bab26Merge pull request #395 from him2him2/docs/fix-typos-and-grammar7495c38docs: fix typos and grammar in README and SECURITY03f86feMerge pull request #388 from woodruffw-forks/ww/rm-experimental4c78f1cMerge branch 'unstable/v1' into ww/rm-experimentalb5a6e8bdeps: bump sigstore and pypi-attestationsa48a03eremove another experimental mention8087a88action: remove a lingering mention of PEP 740 being experimental3317ede🧪 Integrate actionlint via pre-commit framework- Additional commits viewable in compare view
Updates peter-evans/create-pull-request from 8.1.0 to 8.1.1
Release notes
Sourced from peter-evans/create-pull-request's releases.
Create Pull Request v8.1.1
What's Changed
- build(deps-dev): bump the npm group with 2 updates by
@dependabot[bot] in peter-evans/create-pull-request#4305- build(deps): bump minimatch by
@dependabot[bot] in peter-evans/create-pull-request#4311- build(deps): bump the github-actions group with 2 updates by
@dependabot[bot] in peter-evans/create-pull-request#4316- build(deps): bump
@tootallnate/onceand jest-environment-jsdom by@dependabot[bot] in peter-evans/create-pull-request#4323- build(deps-dev): bump undici from 6.23.0 to 6.24.0 by
@dependabot[bot] in peter-evans/create-pull-request#4328- build(deps-dev): bump flatted from 3.3.1 to 3.4.2 by
@dependabot[bot] in peter-evans/create-pull-request#4334- build(deps): bump picomatch by
@dependabot[bot] in peter-evans/create-pull-request#4339- build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 by
@dependabot[bot] in peter-evans/create-pull-request#4344- build(deps-dev): bump the npm group with 3 updates by
@dependabot[bot] in peter-evans/create-pull-request#4349- fix: retry post-creation API calls on 422 eventual consistency errors by
@peter-evansin peter-evans/create-pull-request#4356Full Changelog: peter-evans/create-pull-request@v8.1.0...v8.1.1
Commits
5f6978ffix: retry post-creation API calls on 422 eventual consistency errors (#4356)d32e88dbuild(deps-dev): bump the npm group with 3 updates (#4349)8170bccbuild(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#4344)0041819build(deps): bump picomatch (#4339)b993918build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (#4334)36d7c84build(deps-dev): bump undici from 6.23.0 to 6.24.0 (#4328)a45d1fbbuild(deps): bump@toot...Description has been truncated