Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: astral-sh/setup-uv
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 1e862df
Choose a base ref
...
head repository: astral-sh/setup-uv
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: ed21f2f
Choose a head ref
  • 14 commits
  • 19 files changed
  • 5 contributors

Commits on Nov 21, 2025

  1. chore: update known checksums for 0.9.11 (#688)

    chore: update known checksums for 0.9.11
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Nov 21, 2025
    Configuration menu
    Copy the full SHA
    be7fc19 View commit details
    Browse the repository at this point in the history

Commits on Nov 25, 2025

  1. chore: update known checksums for 0.9.12 (#693)

    chore: update known checksums for 0.9.12
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Nov 25, 2025
    Configuration menu
    Copy the full SHA
    1e64fb1 View commit details
    Browse the repository at this point in the history

Commits on Nov 26, 2025

  1. chore: update known checksums for 0.9.13 (#694)

    chore: update known checksums for 0.9.13
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Nov 26, 2025
    Configuration menu
    Copy the full SHA
    d500d41 View commit details
    Browse the repository at this point in the history
  2. Bump eifinger/actionlint-action from 1.9.2 to 1.9.3 (#690)

    Bumps
    [eifinger/actionlint-action](https://github.com/eifinger/actionlint-action)
    from 1.9.2 to 1.9.3.
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/eifinger/actionlint-action/commit/213860089b7cf97d640aa67567898fabeb132746"><code>2138600</code></a>
    set default actionlint version to 1.7.9 (<a
    href="https://redirect.github.com/eifinger/actionlint-action/issues/29">#29</a>)</li>
    <li><a
    href="https://github.com/eifinger/actionlint-action/commit/9eac110dcad8d93d091a2c04fcd168439221ef2a"><code>9eac110</code></a>
    build(deps): bump actions/checkout from 5.0.0 to 6.0.0 (<a
    href="https://redirect.github.com/eifinger/actionlint-action/issues/28">#28</a>)</li>
    <li>See full diff in <a
    href="https://github.com/eifinger/actionlint-action/compare/03ff1f78c0670b71017616a37170f327df932030...213860089b7cf97d640aa67567898fabeb132746">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=eifinger/actionlint-action&package-manager=github_actions&previous-version=1.9.2&new-version=1.9.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Nov 26, 2025
    Configuration menu
    Copy the full SHA
    8f1d388 View commit details
    Browse the repository at this point in the history

Commits on Nov 27, 2025

  1. Bump zizmorcore/zizmor-action from 0.2.0 to 0.3.0 (#696)

    Bumps
    [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action)
    from 0.2.0 to 0.3.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/zizmorcore/zizmor-action/releases">zizmorcore/zizmor-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v0.3.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>README: fix troubleshooting link by <a
    href="https://github.com/woodruffw"><code>@​woodruffw</code></a> in <a
    href="https://redirect.github.com/zizmorcore/zizmor-action/pull/50">zizmorcore/zizmor-action#50</a></li>
    <li>README: add a troubleshooting section about Advanced Security by <a
    href="https://github.com/woodruffw"><code>@​woodruffw</code></a> in <a
    href="https://redirect.github.com/zizmorcore/zizmor-action/pull/51">zizmorcore/zizmor-action#51</a></li>
    <li>feat: Support a config option by <a
    href="https://github.com/naokihaba"><code>@​naokihaba</code></a> in <a
    href="https://redirect.github.com/zizmorcore/zizmor-action/pull/56">zizmorcore/zizmor-action#56</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/naokihaba"><code>@​naokihaba</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/zizmorcore/zizmor-action/pull/56">zizmorcore/zizmor-action#56</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/zizmorcore/zizmor-action/compare/v0.2.0...v0.3.0">https://github.com/zizmorcore/zizmor-action/compare/v0.2.0...v0.3.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/e639db99335bc9038abc0e066dfcd72e23d26fb4"><code>e639db9</code></a>
    remove mise.toml (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/57">#57</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/f4409e30393d9c364fd5536e128179c68b5a813f"><code>f4409e3</code></a>
    feat: Support a config option (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/56">#56</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/1aba86d8e1245be7a9ca003d46fcc85a76e6aa61"><code>1aba86d</code></a>
    chore(deps): bump github/codeql-action in the github-actions group (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/54">#54</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/da5ac40c5419dcf7f21630fb2f95e725ae8fb9d5"><code>da5ac40</code></a>
    README: add a troubleshooting section about Advanced Security (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/51">#51</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/cc28a584f0663c198a7788dbab0f86d75b341140"><code>cc28a58</code></a>
    README: fix troubleshooting link (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/50">#50</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/c323c83e3ab58baf4acbc7b6b39eef0e0cb14e4d"><code>c323c83</code></a>
    chore(deps): bump zizmorcore/zizmor-action from 0.1.2 to 0.2.0 in the
    github-...</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/0696496a48b64e0568faa46ddaf5f6fe48b83b04"><code>0696496</code></a>
    chore(deps): bump github/codeql-action in the github-actions group (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/48">#48</a>)</li>
    <li><a
    href="https://github.com/zizmorcore/zizmor-action/commit/873539476a7f9b0da7504d0d9e9a6a5275094d98"><code>8735394</code></a>
    docs: bump action pins (<a
    href="https://redirect.github.com/zizmorcore/zizmor-action/issues/46">#46</a>)</li>
    <li>See full diff in <a
    href="https://github.com/zizmorcore/zizmor-action/compare/e673c3917a1aef3c65c972347ed84ccd013ecda4...e639db99335bc9038abc0e066dfcd72e23d26fb4">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=zizmorcore/zizmor-action&package-manager=github_actions&previous-version=0.2.0&new-version=0.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Nov 27, 2025
    Configuration menu
    Copy the full SHA
    06e4edb View commit details
    Browse the repository at this point in the history

Commits on Dec 2, 2025

  1. chore: update known checksums for 0.9.14 (#700)

    chore: update known checksums for 0.9.14
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Dec 2, 2025
    Configuration menu
    Copy the full SHA
    5ae467f View commit details
    Browse the repository at this point in the history
  2. chore: use npm ci --ignore-scripts everywhere (#699)

    Like astral-sh/ruff-action#276 🙂 
    
    This also adds cooldown stanzas to the Dependabot updater rules: this
    ensures that we only receive dependency bumps once they're at least a
    week old, which should reduce the window of opportunity for an attacker
    who temporarily compromises popular packages (like with "Shai-Hulud"
    last week).
    
    Signed-off-by: William Woodruff <[email protected]>
    woodruffw authored Dec 2, 2025
    Configuration menu
    Copy the full SHA
    64f7f4e View commit details
    Browse the repository at this point in the history

Commits on Dec 3, 2025

  1. chore: update known checksums for 0.9.15 (#704)

    chore: update known checksums for 0.9.15
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Dec 3, 2025
    Configuration menu
    Copy the full SHA
    9c12bae View commit details
    Browse the repository at this point in the history

Commits on Dec 7, 2025

  1. chore: update known checksums for 0.9.16 (#706)

    chore: update known checksums for 0.9.16
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Dec 7, 2025
    Configuration menu
    Copy the full SHA
    7dd56c1 View commit details
    Browse the repository at this point in the history
  2. Bump github/codeql-action from 4.30.9 to 4.31.6 (#698)

    Bumps [github/codeql-action](https://github.com/github/codeql-action)
    from 4.30.9 to 4.31.6.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/releases">github/codeql-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.31.6</h2>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>4.31.6 - 01 Dec 2025</h2>
    <p>No user facing changes.</p>
    <p>See the full <a
    href="https://github.com/github/codeql-action/blob/v4.31.6/CHANGELOG.md">CHANGELOG.md</a>
    for more information.</p>
    <h2>v4.31.5</h2>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>4.31.5 - 24 Nov 2025</h2>
    <ul>
    <li>Update default CodeQL bundle version to 2.23.6. <a
    href="https://redirect.github.com/github/codeql-action/pull/3321">#3321</a></li>
    </ul>
    <p>See the full <a
    href="https://github.com/github/codeql-action/blob/v4.31.5/CHANGELOG.md">CHANGELOG.md</a>
    for more information.</p>
    <h2>v4.31.4</h2>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>4.31.4 - 18 Nov 2025</h2>
    <p>No user facing changes.</p>
    <p>See the full <a
    href="https://github.com/github/codeql-action/blob/v4.31.4/CHANGELOG.md">CHANGELOG.md</a>
    for more information.</p>
    <h2>v4.31.3</h2>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>4.31.3 - 13 Nov 2025</h2>
    <ul>
    <li>CodeQL Action v3 will be deprecated in December 2026. The Action now
    logs a warning for customers who are running v3 but could be running v4.
    For more information, see <a
    href="https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/">Upcoming
    deprecation of CodeQL Action v3</a>.</li>
    <li>Update default CodeQL bundle version to 2.23.5. <a
    href="https://redirect.github.com/github/codeql-action/pull/3288">#3288</a></li>
    </ul>
    <p>See the full <a
    href="https://github.com/github/codeql-action/blob/v4.31.3/CHANGELOG.md">CHANGELOG.md</a>
    for more information.</p>
    <h2>v4.31.2</h2>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's
    changelog</a>.</em></p>
    <blockquote>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>[UNRELEASED]</h2>
    <p>No user facing changes.</p>
    <h2>4.31.6 - 01 Dec 2025</h2>
    <p>No user facing changes.</p>
    <h2>4.31.5 - 24 Nov 2025</h2>
    <ul>
    <li>Update default CodeQL bundle version to 2.23.6. <a
    href="https://redirect.github.com/github/codeql-action/pull/3321">#3321</a></li>
    </ul>
    <h2>4.31.4 - 18 Nov 2025</h2>
    <p>No user facing changes.</p>
    <h2>4.31.3 - 13 Nov 2025</h2>
    <ul>
    <li>CodeQL Action v3 will be deprecated in December 2026. The Action now
    logs a warning for customers who are running v3 but could be running v4.
    For more information, see <a
    href="https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/">Upcoming
    deprecation of CodeQL Action v3</a>.</li>
    <li>Update default CodeQL bundle version to 2.23.5. <a
    href="https://redirect.github.com/github/codeql-action/pull/3288">#3288</a></li>
    </ul>
    <h2>4.31.2 - 30 Oct 2025</h2>
    <p>No user facing changes.</p>
    <h2>4.31.1 - 30 Oct 2025</h2>
    <ul>
    <li>The <code>add-snippets</code> input has been removed from the
    <code>analyze</code> action. This input has been deprecated since CodeQL
    Action 3.26.4 in August 2024 when this removal was announced.</li>
    </ul>
    <h2>4.31.0 - 24 Oct 2025</h2>
    <ul>
    <li>Bump minimum CodeQL bundle version to 2.17.6. <a
    href="https://redirect.github.com/github/codeql-action/pull/3223">#3223</a></li>
    <li>When SARIF files are uploaded by the <code>analyze</code> or
    <code>upload-sarif</code> actions, the CodeQL Action automatically
    performs post-processing steps to prepare the data for the upload.
    Previously, these post-processing steps were only performed before an
    upload took place. We are now changing this so that the post-processing
    steps will always be performed, even when the SARIF files are not
    uploaded. This does not change anything for the
    <code>upload-sarif</code> action. For <code>analyze</code>, this may
    affect Advanced Setup for CodeQL users who specify a value other than
    <code>always</code> for the <code>upload</code> input. <a
    href="https://redirect.github.com/github/codeql-action/pull/3222">#3222</a></li>
    </ul>
    <h2>4.30.9 - 17 Oct 2025</h2>
    <ul>
    <li>Update default CodeQL bundle version to 2.23.3. <a
    href="https://redirect.github.com/github/codeql-action/pull/3205">#3205</a></li>
    <li>Experimental: A new <code>setup-codeql</code> action has been added
    which is similar to <code>init</code>, except it only installs the
    CodeQL CLI and does not initialize a database. Do not use this in
    production as it is part of an internal experiment and subject to change
    at any time. <a
    href="https://redirect.github.com/github/codeql-action/pull/3204">#3204</a></li>
    </ul>
    <h2>4.30.8 - 10 Oct 2025</h2>
    <p>No user facing changes.</p>
    <h2>4.30.7 - 06 Oct 2025</h2>
    <ul>
    <li>[v4+ only] The CodeQL Action now runs on Node.js v24. <a
    href="https://redirect.github.com/github/codeql-action/pull/3169">#3169</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/github/codeql-action/commit/fe4161a26a8629af62121b670040955b330f9af2"><code>fe4161a</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3336">#3336</a>
    from github/update-v4.31.6-ecec1f887</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/88c2ab5eee3b475eef2f7aabf89bd9f052153d91"><code>88c2ab5</code></a>
    Update changelog for v4.31.6</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/ecec1f88769052ebc45aa0affc53ea30d474cffa"><code>ecec1f8</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3335">#3335</a>
    from github/mbg/ci/run-codeql-on-all-prs</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/23da73277866951560f258278028b48f68958a0a"><code>23da732</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3334">#3334</a>
    from github/kaspersv/overlay-minor-comments</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/f7abc748a3da068e17cfd0e1086e8d72e51f17b6"><code>f7abc74</code></a>
    Remove branch filter for PR event in CodeQL workflow</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/32ada5e061c0433b9e40f11632c2412a55b745f9"><code>32ada5e</code></a>
    Merge branch 'main' into kaspersv/overlay-minor-comments</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/75b2f49aeaf4e8a9eab338ddc5d628eea7366eeb"><code>75b2f49</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3333">#3333</a>
    from github/kaspersv/overlay-no-resource-checks-option</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/f036b1cb781fa664100fee1f7c56a0088663dd26"><code>f036b1c</code></a>
    Merge branch 'main' into kaspersv/overlay-no-resource-checks-option</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/58c5954801c246a3975b658372285b37c45de271"><code>58c5954</code></a>
    Add comment to runnerSupportsOverlayAnalysis</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/b02fa13292ce189c02cbb1ba5488f7dbbc8c6b14"><code>b02fa13</code></a>
    Order feature flags alphabetically</li>
    <li>Additional commits viewable in <a
    href="https://github.com/github/codeql-action/compare/16140ae1a102900babc80a33c44059580f687047...fe4161a26a8629af62121b670040955b330f9af2">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=4.30.9&new-version=4.31.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 7, 2025
    Configuration menu
    Copy the full SHA
    0439606 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    4180991 View commit details
    Browse the repository at this point in the history
  4. set biome files.maxSize to 2MiB (#708)

    Account for large known checksums
    eifinger authored Dec 7, 2025
    Configuration menu
    Copy the full SHA
    5ce0900 View commit details
    Browse the repository at this point in the history
  5. bump dependencies (#709)

    eifinger authored Dec 7, 2025
    Configuration menu
    Copy the full SHA
    93202d8 View commit details
    Browse the repository at this point in the history
  6. Bump peter-evans/create-pull-request from 7.0.8 to 7.0.9 (#695)

    Bumps
    [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request)
    from 7.0.8 to 7.0.9.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/peter-evans/create-pull-request/releases">peter-evans/create-pull-request's
    releases</a>.</em></p>
    <blockquote>
    <h2>Create Pull Request v7.0.9</h2>
    <p>⚙️ Fixes an <a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4228">incompatibility</a>
    with the recently released <code>actions/checkout@v6</code>.</p>
    <h2>What's Changed</h2>
    <ul>
    <li>~70 dependency updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a></li>
    <li>docs: fix workaround description about <code>ready_for_review</code>
    by <a href="https://github.com/ybiquitous"><code>@​ybiquitous</code></a>
    in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3939">peter-evans/create-pull-request#3939</a></li>
    <li>Docs: <code>add-paths</code> default behavior by <a
    href="https://github.com/joeflack4"><code>@​joeflack4</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3928">peter-evans/create-pull-request#3928</a></li>
    <li>docs: update to create-github-app-token v2 by <a
    href="https://github.com/Goooler"><code>@​Goooler</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4063">peter-evans/create-pull-request#4063</a></li>
    <li>Fix compatibility with actions/checkout@v6 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4230">peter-evans/create-pull-request#4230</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/joeflack4"><code>@​joeflack4</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3928">peter-evans/create-pull-request#3928</a></li>
    <li><a href="https://github.com/Goooler"><code>@​Goooler</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4063">peter-evans/create-pull-request#4063</a></li>
    <li><a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4230">peter-evans/create-pull-request#4230</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/peter-evans/create-pull-request/compare/v7.0.8...v7.0.9">https://github.com/peter-evans/create-pull-request/compare/v7.0.8...v7.0.9</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/84ae59a2cdc2258d6fa0732dd66352dddae2a412"><code>84ae59a</code></a>
    fix: compatibility with actions/checkout@v6 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4230">#4230</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/b4733b9419fd47bbfa1807b15627e17cd70b5b22"><code>b4733b9</code></a>
    build(deps-dev): bump js-yaml from 4.1.0 to 4.1.1 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4222">#4222</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/0edc001d28a2959cd7a6b505629f1d82f0a6e67d"><code>0edc001</code></a>
    build(deps-dev): bump the npm group with 2 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4201">#4201</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/430aea0fb112656c3ac187e7a22b3604508ba3a7"><code>430aea0</code></a>
    build(deps): bump the github-actions group with 3 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4200">#4200</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/46cdba753c74545733b821043d64bd6925fc4da9"><code>46cdba7</code></a>
    build(deps-dev): bump the npm group with 3 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4185">#4185</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/b937339b17ca3e45ec14ebcafb879873b1ee8564"><code>b937339</code></a>
    build(deps): bump the github-actions group with 2 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4184">#4184</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/e9af275c3778a67411fcac2d613e8d4e9be452fd"><code>e9af275</code></a>
    ci: update dependabot config</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/d3e081a03ae8d69301ed924bae10d70ea4af94d9"><code>d3e081a</code></a>
    build(deps-dev): bump <code>@​types/node</code> from 18.19.127 to
    18.19.128 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4178">#4178</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/9ec683ee07f9121fdf529b923931dd78d977a5c9"><code>9ec683e</code></a>
    build(deps-dev): bump <code>@​types/node</code> from 18.19.125 to
    18.19.127 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4165">#4165</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/65d8d10bf76513796c0f69457c2567b5da3b9626"><code>65d8d10</code></a>
    build(deps-dev): bump ts-jest from 29.4.2 to 29.4.4 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4163">#4163</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/peter-evans/create-pull-request/compare/271a8d0340265f705b14b6d32b9829c1cb33d45e...84ae59a2cdc2258d6fa0732dd66352dddae2a412">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=peter-evans/create-pull-request&package-manager=github_actions&previous-version=7.0.8&new-version=7.0.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Dec 7, 2025
    Configuration menu
    Copy the full SHA
    ed21f2f View commit details
    Browse the repository at this point in the history
Loading