Skip to content

chore(deps): update github actions updates#288

Merged
renovate[bot] merged 1 commit intomasterfrom
renovate/github-actions
Jan 8, 2025
Merged

chore(deps): update github actions updates#288
renovate[bot] merged 1 commit intomasterfrom
renovate/github-actions

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Dec 9, 2024

This PR contains the following updates:

Package Type Update Change
SonarSource/gh-action_releasability action patch 2.1.0 -> 2.1.2
pypa/gh-action-pypi-publish action patch v1.12.2 -> v1.12.3

Release Notes

SonarSource/gh-action_releasability (SonarSource/gh-action_releasability)

v2.1.2

Compare Source

What's Changed

Full Changelog: SonarSource/gh-action_releasability@2.1.1...2.1.2

v2.1.1

Compare Source

What's Changed

Full Changelog: SonarSource/gh-action_releasability@2.1.0...2.1.1

pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)

v1.12.3

Compare Source

✨ What's Improved

With the updates by @​woodruffw💰 and @​webknjaz💰 via #​309 and #​313, it is now possible to publish distribution packages that include core metadata v2.4, like those built using maturin. This is done by bumping Twine to v6.0.1 and pkginfo to v1.12.0.

📝 Docs

We've made an attempt to clarify the runtime and workflow shape that are expected to be supported for calling this action in: https://github.com/marketplace/actions/pypi-publish#Non-goals.

[!TIP]
Please, let us know in the release discussion if anything still remains unclear.
TL;DR always call [pypi-publish][pypi-publish] once per job; don't invoke it in reusable workflows; physically move building the dists into separate jobs having restricted permissions and storing the dists as GitHub Actions artifacts; when using self-hosted runners, make sure to still use [pypi-publish][pypi-publish] on a GitHub-provided infra with runs-on: ubuntu-latest, while building and testing may remain self-hosted; don't perform any other actions in the publishing job; don't call [pypi-publish][pypi-publish] from composite actions.

🛠️ Internal Updates

@​br3ndonland💰 improved the container image generation automation to include Git SHA in #​301. And @​woodruffw💰 added the workflow_ref context to Trusted Publishing debug logging in #​305, helping us diagnose misconfigurations faster. #​313 also extends the smoke test in the CI to check against the maturin-made dists. Additionally, jeepney and secretstorage transitive deps have been added to the pip constraint-based lock file, as Dependabot seems to have missed those earlier.

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.12.2...v1.12.3

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​samuelcolvin💰 for nudging me to cut this release sooner and for sponsoring me via @​pydantic💰!

🔌 Shameless Plug: The other day I've made this 🦋 Bluesky 🇺🇦 FOSS Maintainers Starter Pack subscribe to read news from people like me :)

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.


Configuration

📅 Schedule: Branch creation - "after 7am every weekday,before 8pm every weekday" in timezone Europe/Paris, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Dec 9, 2024
@renovate renovate bot requested a review from a team as a code owner December 9, 2024 16:49
@renovate renovate bot enabled auto-merge (squash) December 9, 2024 16:49
@renovate renovate bot force-pushed the renovate/github-actions branch from d85bb38 to d01181c Compare December 18, 2024 15:43
@renovate renovate bot changed the title chore(deps): update pypa/gh-action-pypi-publish action to v1.12.3 chore(deps): update github actions updates Dec 18, 2024
@renovate renovate bot force-pushed the renovate/github-actions branch from d01181c to 97d1869 Compare December 19, 2024 11:59
@renovate renovate bot force-pushed the renovate/github-actions branch from 97d1869 to 2a1bfeb Compare January 3, 2025 10:16
@renovate renovate bot force-pushed the renovate/github-actions branch from 2a1bfeb to c472242 Compare January 6, 2025 13:30
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Jan 6, 2025

@renovate renovate bot merged commit a727de2 into master Jan 8, 2025
@renovate renovate bot deleted the renovate/github-actions branch January 8, 2025 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants