Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: getsentry/sentry-cli
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 3.6.0
Choose a base ref
...
head repository: getsentry/sentry-cli
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 3.6.1
Choose a head ref
  • 14 commits
  • 77 files changed
  • 4 contributors

Commits on Jun 26, 2026

  1. Configuration menu
    Copy the full SHA
    903b388 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    33e0b91 View commit details
    Browse the repository at this point in the history

Commits on Jun 29, 2026

  1. Configuration menu
    Copy the full SHA
    fb79c59 View commit details
    Browse the repository at this point in the history

Commits on Jul 6, 2026

  1. ci(workflow): Update runner images (#3357)

    Bump pinned GitHub-hosted runner labels to the newest GA images from
    actions/runner-images.
    
    This updates Windows jobs to windows-2025 and macOS jobs to macos-26
    while keeping Ubuntu on 24.04, which is still the newest GA Ubuntu
    label.
    
    Ref #3356
    szokeasaurusrex authored Jul 6, 2026
    Configuration menu
    Copy the full SHA
    14ba8c3 View commit details
    Browse the repository at this point in the history

Commits on Jul 7, 2026

  1. chore(deps): bump getsentry/github-workflows from 3.3.0 to 3.4.0 (#3333)

    Bumps
    [getsentry/github-workflows](https://github.com/getsentry/github-workflows)
    from 3.3.0 to 3.4.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/getsentry/github-workflows/releases">getsentry/github-workflows's
    releases</a>.</em></p>
    <blockquote>
    <h2>3.4.0</h2>
    <h3>Features</h3>
    <ul>
    <li>Validate PR - Action is advisory: it posts a single friendly comment
    on community PRs that don't reference an issue with maintainer
    discussion. PRs are not closed and no labels are applied. Recommended
    trigger is <code>types: [opened]</code>.</li>
    <li>Validate PR - Skip validation for PRs with fewer than 100 lines
    changed, excluding common lock files (<code>Cargo.lock</code>,
    <code>yarn.lock</code>, <code>package-lock.json</code>,
    <code>Pipfile.lock</code>, etc.). Tiny PRs no longer go through the
    issue-discussion loop.</li>
    <li>Add validate-pr composite action for validating non-maintainer PRs
    against contribution guidelines (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/153">#153</a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li>Complete script injection hardening across all actions: move
    remaining step outputs to env vars, validate Danger version against
    semver (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/152">#152</a>)</li>
    <li>Updater - Trigger CI for new PRs without changelog updates (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/166">#166</a>)</li>
    <li>Updater - Select the first branch when multiple branches point at
    <code>HEAD</code> (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/165">#165</a>)</li>
    </ul>
    <h3>Dependencies</h3>
    <ul>
    <li>Bump Danger JS from v13.0.4 to v13.0.5 (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/160">#160</a>)
    <ul>
    <li><a
    href="https://github.com/danger/danger-js/blob/main/CHANGELOG.md#1305">changelog</a></li>
    <li><a
    href="https://github.com/danger/danger-js/compare/13.0.4...13.0.5">diff</a></li>
    </ul>
    </li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/getsentry/github-workflows/blob/main/CHANGELOG.md">getsentry/github-workflows's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>Unreleased</h2>
    <h3>Fixes</h3>
    <ul>
    <li>Danger - Harden <code>extra-install-packages</code> handling: pass
    the package list into the container via env var instead of host-shell
    string interpolation (defense in depth) (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/169">#169</a>)</li>
    </ul>
    <h2>3.4.0</h2>
    <h3>Features</h3>
    <ul>
    <li>Validate PR - Action is advisory: it posts a single friendly comment
    on community PRs that don't reference an issue with maintainer
    discussion. PRs are not closed and no labels are applied. Recommended
    trigger is <code>types: [opened]</code>.</li>
    <li>Validate PR - Skip validation for PRs with fewer than 100 lines
    changed, excluding common lock files (<code>Cargo.lock</code>,
    <code>yarn.lock</code>, <code>package-lock.json</code>,
    <code>Pipfile.lock</code>, etc.). Tiny PRs no longer go through the
    issue-discussion loop.</li>
    <li>Add validate-pr composite action for validating non-maintainer PRs
    against contribution guidelines (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/153">#153</a>)</li>
    </ul>
    <h3>Fixes</h3>
    <ul>
    <li>Complete script injection hardening across all actions: move
    remaining step outputs to env vars, validate Danger version against
    semver (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/152">#152</a>)</li>
    <li>Updater - Trigger CI for new PRs without changelog updates (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/166">#166</a>)</li>
    <li>Updater - Select the first branch when multiple branches point at
    <code>HEAD</code> (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/165">#165</a>)</li>
    </ul>
    <h3>Dependencies</h3>
    <ul>
    <li>Bump Danger JS from v13.0.4 to v13.0.5 (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/160">#160</a>)
    <ul>
    <li><a
    href="https://github.com/danger/danger-js/blob/main/CHANGELOG.md#1305">changelog</a></li>
    <li><a
    href="https://github.com/danger/danger-js/compare/13.0.4...13.0.5">diff</a></li>
    </ul>
    </li>
    </ul>
    <h2>3.3.0</h2>
    <h3>Features</h3>
    <ul>
    <li>Updater - Support CMake <code>GIT_TAG</code> with variable
    references like <code>${FOO_REF}</code>, resolving and updating the
    corresponding <code>set()</code> definition (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/149">#149</a>)</li>
    </ul>
    <h2>3.2.1</h2>
    <h3>Fixes</h3>
    <ul>
    <li>Sentry-CLI integration test action - Accept chunked ProGuard uploads
    for compatibility with Sentry CLI 3.x (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/140">#140</a>)</li>
    </ul>
    <h2>3.2.0</h2>
    <h3>Features</h3>
    <ul>
    <li>Danger - Add support for repository-specific dangerfiles (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/129">#129</a>)
    <ul>
    <li>Add <code>extra-dangerfile</code> input parameter to run custom
    Danger checks alongside shared workflow checks</li>
    <li>Add <code>extra-install-packages</code> input to install additional
    apt packages required by custom dangerfiles</li>
    <li>Custom dangerfiles receive full Danger API access
    (<code>fail</code>, <code>warn</code>, <code>message</code>,
    <code>markdown</code>, <code>danger</code>)</li>
    <li>Enables repositories to extend Danger checks without overwriting
    shared workflow comments</li>
    </ul>
    </li>
    <li>Sentry-CLI integration test action - Add
    <code>InvokeSentryResult::Events()</code> method to extract events from
    envelopes (<a
    href="https://redirect.github.com/getsentry/github-workflows/pull/137">#137</a>)</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/607fed74f812e69201531a5185b6c3c57caa4e89"><code>607fed7</code></a>
    release: 3.4.0</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/82866c1a3c6e52bc3122efc4c0f804d9954947a7"><code>82866c1</code></a>
    chore: update getsentry/craft to 2.26.3 (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/168">#168</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/24be69680c3a46c03edfbeb05268ec312f77e1e7"><code>24be696</code></a>
    fix: complete script injection hardening across all actions (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/152">#152</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/a940f77968911ab853d344aad6bd3453935ebb6c"><code>a940f77</code></a>
    fix(updater): Trigger CI for new PRs without changelog updates (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/166">#166</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/98c1e36a10138a6a2d579714dda6b65d6a85acba"><code>98c1e36</code></a>
    test(updater): Accept either main or master as sentry-cli main branch
    (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/167">#167</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/d81d7469a37abff4600d45c612f6c1b16241e9ef"><code>d81d746</code></a>
    chore: update danger/danger.properties to 13.0.5 (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/160">#160</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/80476a95b1c643ab5900b451932043d9ff26cdbf"><code>80476a9</code></a>
    fix(updater): Select first matching main branch (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/165">#165</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/43bf14b190c12080cfbedf2d2c82337bc559a0e1"><code>43bf14b</code></a>
    feat(validate-pr): Make advisory; drop close + labels (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/163">#163</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/71588ddf95134f804e82c5970a8098588e2eaecd"><code>71588dd</code></a>
    feat(validate-pr): Skip checks for users with write access (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/162">#162</a>)</li>
    <li><a
    href="https://github.com/getsentry/github-workflows/commit/02fd7a28bcd99b2e2ab71a7fa6e4d92d824c2c19"><code>02fd7a2</code></a>
    feat(validate-pr): Skip all checks when a maintainer reopens a PR (<a
    href="https://redirect.github.com/getsentry/github-workflows/issues/161">#161</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/getsentry/github-workflows/compare/26f565c05d0dd49f703d238706b775883037d76b...607fed74f812e69201531a5185b6c3c57caa4e89">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=getsentry/github-workflows&package-manager=github_actions&previous-version=3.3.0&new-version=3.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 7, 2026
    Configuration menu
    Copy the full SHA
    ee8a2dd View commit details
    Browse the repository at this point in the history
  2. chore(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0 (#3332)

    Bumps
    [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action)
    from 4.0.0 to 4.1.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/docker/setup-buildx-action/releases">docker/setup-buildx-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.1.0</h2>
    <ul>
    <li>Bump <code>@​docker/actions-toolkit</code> from 0.79.0 to 0.90.0 in
    <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/489">docker/setup-buildx-action#489</a></li>
    <li>Bump brace-expansion from 1.1.12 to 5.0.6 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/547">docker/setup-buildx-action#547</a>
    <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/508">docker/setup-buildx-action#508</a></li>
    <li>Bump fast-xml-builder from 1.0.0 to 1.2.0 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/540">docker/setup-buildx-action#540</a></li>
    <li>Bump fast-xml-parser from 5.4.2 to 5.8.0 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/496">docker/setup-buildx-action#496</a></li>
    <li>Bump flatted from 3.3.3 to 3.4.2 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/499">docker/setup-buildx-action#499</a></li>
    <li>Bump glob from 10.3.12 to 13.0.6 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/495">docker/setup-buildx-action#495</a></li>
    <li>Bump handlebars from 4.7.8 to 4.7.9 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/504">docker/setup-buildx-action#504</a></li>
    <li>Bump lodash from 4.17.23 to 4.18.1 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/523">docker/setup-buildx-action#523</a></li>
    <li>Bump picomatch from 4.0.3 to 4.0.4 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/503">docker/setup-buildx-action#503</a></li>
    <li>Bump postcss from 8.5.6 to 8.5.10 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/537">docker/setup-buildx-action#537</a></li>
    <li>Bump tar from 6.2.1 to 7.5.15 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/545">docker/setup-buildx-action#545</a></li>
    <li>Bump undici from 6.23.0 to 6.25.0 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/492">docker/setup-buildx-action#492</a></li>
    <li>Bump vite from 7.3.1 to 7.3.2 in <a
    href="https://redirect.github.com/docker/setup-buildx-action/pull/520">docker/setup-buildx-action#520</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/docker/setup-buildx-action/compare/v4.0.0...v4.1.0">https://github.com/docker/setup-buildx-action/compare/v4.0.0...v4.1.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5"><code>d7f5e7f</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/setup-buildx-action/issues/489">#489</a>
    from docker/dependabot/npm_and_yarn/docker/actions-to...</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/92bc5c9777806d0a73d9d668ba2114fa1177f164"><code>92bc5c9</code></a>
    chore: update generated content</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/da11e35abee0f20cb4f1c1b7c461d37c29be52f5"><code>da11e35</code></a>
    build(deps): bump <code>@​docker/actions-toolkit</code> from 0.79.0 to
    0.90.0</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/f021e162ef95b6fba51af1c6674f537f25bce851"><code>f021e16</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/setup-buildx-action/issues/492">#492</a>
    from docker/dependabot/npm_and_yarn/undici-6.24.1</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/b5af94fab700aee0c64d6077e0e34ae987815b67"><code>b5af94f</code></a>
    chore: update generated content</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/16ad9776a801d0c47f0a05f007b88a3789aa8ab6"><code>16ad977</code></a>
    build(deps): bump undici from 6.23.0 to 6.25.0</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/d7a12d7df895b33bd02a9b4bf62a12f2b9a24458"><code>d7a12d7</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/setup-buildx-action/issues/495">#495</a>
    from docker/dependabot/npm_and_yarn/glob-10.5.0</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/28ff27de4eed7518d361591f2cd1dfb69c34a7cb"><code>28ff27d</code></a>
    build(deps): bump glob from 10.3.12 to 13.0.6</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/daf436b50e13d9053b9730cbc16516891878b019"><code>daf436b</code></a>
    Merge pull request <a
    href="https://redirect.github.com/docker/setup-buildx-action/issues/496">#496</a>
    from docker/dependabot/npm_and_yarn/fast-xml-parser-5...</li>
    <li><a
    href="https://github.com/docker/setup-buildx-action/commit/9725348367859764880f2f2e688a6b0c353e3f35"><code>9725348</code></a>
    chore: update generated content</li>
    <li>Additional commits viewable in <a
    href="https://github.com/docker/setup-buildx-action/compare/4d04d5d9486b7bd6fa91e7baf45bbb4f8b9deedd...d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=docker/setup-buildx-action&package-manager=github_actions&previous-version=4.0.0&new-version=4.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 7, 2026
    Configuration menu
    Copy the full SHA
    f19f288 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    1bf4117 View commit details
    Browse the repository at this point in the history

Commits on Jul 9, 2026

  1. ref(organizations): Use control silo endpoint for org listing (#3352)

    ### Description
    The organization listing endpoint (GET /organizations/) is now served
    from the control silo and returns every organization the authenticated
    user belongs to across all regions in a single paginated response. This
    replaces the previous per-region fan-out (which called
    /users/me/regions/ and then queried each region) with one call.
    
    Also aligns the Organization model with the current API response: drops
    requireEmailVerification (removed in getsentry/sentry#115003) and makes
    features optional (removed from the listing endpoint in #115007), so no
    longer fails to deserialize the live response.
    
    ### Issues
    * resolves: INFRENG-199
    
    ### Legal Boilerplate
    Look, I get it. The entity doing business as "Sentry" was incorporated
    in the State of Delaware in 2015 as Functional Software, Inc. and is
    gonna need some rights from me in order to utilize my contributions in
    this here PR. So here's the deal: I retain all rights, title and
    interest in and to my contributions, and by keeping this boilerplate
    intact I confirm that Sentry can use, modify, copy, and redistribute my
    contributions, under Sentry's choice of terms.
    ldelvoye authored Jul 9, 2026
    Configuration menu
    Copy the full SHA
    0f55bf4 View commit details
    Browse the repository at this point in the history

Commits on Jul 17, 2026

  1. fix(sourcemaps): Prevent Debug ID collisions (#3356)

    Generate Debug IDs from both the generated JS bytes and the sourcemap
    bytes when a sourcemap is available. This keeps distinct JS files from
    sharing a Debug ID when their maps are byte-identical, while preserving
    existing IDs already present in JS or sourcemaps.
    
    Add a regression test for identical empty maps with distinct JS inputs.
    Update the sourcemaps inject snapshots because the injected Debug IDs
    and embedded source map payloads now change for every affected case.
    
    Fixes #3350
    Fixes
    [CLI-341](https://linear.app/getsentry/issue/CLI-341/sentry-cli-mapping-identical-empty-source-maps-to-same-debug-id)
    szokeasaurusrex authored Jul 17, 2026
    Configuration menu
    Copy the full SHA
    ecb5dd0 View commit details
    Browse the repository at this point in the history
  2. build(deps): bump swatinem/rust-cache from 2.8.2 to 2.9.1 (#3233)

    Bumps [swatinem/rust-cache](https://github.com/swatinem/rust-cache) from
    2.8.2 to 2.9.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/swatinem/rust-cache/releases">swatinem/rust-cache's
    releases</a>.</em></p>
    <blockquote>
    <h2>v2.9.1</h2>
    <p>Fix regression in hash calculation</p>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/Swatinem/rust-cache/compare/v2.9.0...v2.9.1">https://github.com/Swatinem/rust-cache/compare/v2.9.0...v2.9.1</a></p>
    <h2>v2.9.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Add support for running rust-cache commands from within a Nix shell
    by <a href="https://github.com/marc0246"><code>@​marc0246</code></a> in
    <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/290">Swatinem/rust-cache#290</a></li>
    <li>Bump taiki-e/install-action from 2.62.57 to 2.62.60 in the actions
    group by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/291">Swatinem/rust-cache#291</a></li>
    <li>Bump the actions group across 1 directory with 5 updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/296">Swatinem/rust-cache#296</a></li>
    <li>Bump the prd-major group with 3 updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/294">Swatinem/rust-cache#294</a></li>
    <li>Bump <code>@​types/node</code> from 24.10.1 to 25.0.2 in the
    dev-major group by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/295">Swatinem/rust-cache#295</a></li>
    <li>Consider all installed toolchains in cache key by <a
    href="https://github.com/tamird"><code>@​tamird</code></a> in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/293">Swatinem/rust-cache#293</a></li>
    <li>Compare case-insenitively for full cache key match by <a
    href="https://github.com/kbriggs"><code>@​kbriggs</code></a> in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/303">Swatinem/rust-cache#303</a></li>
    <li>Migrate to <code>node24</code> runner by <a
    href="https://github.com/rhysd"><code>@​rhysd</code></a> in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/314">Swatinem/rust-cache#314</a></li>
    <li>Bump the actions group across 1 directory with 7 updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/312">Swatinem/rust-cache#312</a></li>
    <li>Bump the prd-minor group across 1 directory with 2 updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/307">Swatinem/rust-cache#307</a></li>
    <li>Bump <code>@​types/node</code> from 25.0.2 to 25.2.2 in the
    dev-minor group by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/309">Swatinem/rust-cache#309</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/marc0246"><code>@​marc0246</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/290">Swatinem/rust-cache#290</a></li>
    <li><a href="https://github.com/tamird"><code>@​tamird</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/293">Swatinem/rust-cache#293</a></li>
    <li><a href="https://github.com/kbriggs"><code>@​kbriggs</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/Swatinem/rust-cache/pull/303">Swatinem/rust-cache#303</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/Swatinem/rust-cache/compare/v2.8.2...v2.9.0">https://github.com/Swatinem/rust-cache/compare/v2.8.2...v2.9.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md">swatinem/rust-cache's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>2.9.1</h2>
    <ul>
    <li>Fix regression in hash calculation</li>
    </ul>
    <h2>2.9.0</h2>
    <ul>
    <li>Update to <code>node24</code></li>
    <li>Support running from within a <code>nix</code> shell</li>
    <li>Consider all installed toolchains for cache key</li>
    <li>Use case-insensitive comparison to determine exact cache hit</li>
    </ul>
    <h2>2.8.2</h2>
    <ul>
    <li>Don't overwrite env for cargo-metadata call</li>
    </ul>
    <h2>2.8.1</h2>
    <ul>
    <li>Set empty <code>CARGO_ENCODED_RUSTFLAGS</code> when retrieving
    metadata</li>
    <li>Various dependency updates</li>
    </ul>
    <h2>2.8.0</h2>
    <ul>
    <li>Add support for <code>warpbuild</code> cache provider</li>
    <li>Add new <code>cache-workspace-crates</code> feature</li>
    </ul>
    <h2>2.7.8</h2>
    <ul>
    <li>Include CPU arch in the cache key</li>
    </ul>
    <h2>2.7.7</h2>
    <ul>
    <li>Also cache <code>cargo install</code> metadata</li>
    </ul>
    <h2>2.7.6</h2>
    <ul>
    <li>Allow opting out of caching $CARGO_HOME/bin</li>
    <li>Add runner OS in cache key</li>
    <li>Adds an option to do lookup-only of the cache</li>
    </ul>
    <h2>2.7.5</h2>
    <ul>
    <li>Support Cargo.lock format cargo-lock v4</li>
    <li>Only run macOsWorkaround() on macOS</li>
    </ul>
    <h2>2.7.3</h2>
    <ul>
    <li>Work around upstream problem that causes cache saving to hang for
    minutes.</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/c19371144df3bb44fab255c43d04cbc2ab54d1c4"><code>c193711</code></a>
    2.9.1</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/781e8d91ab29deb65464798965e49853f963b561"><code>781e8d9</code></a>
    try reverting pipeline change</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/3d1fa4654a5786f5537b1d31acd0f35e56de9924"><code>3d1fa46</code></a>
    add changelog</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/c676846f29d98ff6b0106d3608c7ffd4048af17b"><code>c676846</code></a>
    2.9.0</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/bf71d02c11df9d5253618f39943e9dd59f7fd5a9"><code>bf71d02</code></a>
    bump dependencies and rebuild</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/8a02ed5e290d8afc7e587930243f3016b3223f50"><code>8a02ed5</code></a>
    Bump <code>@​types/node</code> from 25.0.2 to 25.2.2 in the dev-minor
    group (<a
    href="https://redirect.github.com/swatinem/rust-cache/issues/309">#309</a>)</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/390157d4874246aff722dd7f77e641fcae197678"><code>390157d</code></a>
    Bump the prd-minor group across 1 directory with 2 updates (<a
    href="https://redirect.github.com/swatinem/rust-cache/issues/307">#307</a>)</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/68500c182e89a3f56d9b1de095d7e62f0ea5b8bf"><code>68500c1</code></a>
    Bump the actions group across 1 directory with 7 updates (<a
    href="https://redirect.github.com/swatinem/rust-cache/issues/312">#312</a>)</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/1a8384176d7ed15c323a201c65073983cdb5a5be"><code>1a83841</code></a>
    Migrate to <code>node24</code> runner (<a
    href="https://redirect.github.com/swatinem/rust-cache/issues/314">#314</a>)</li>
    <li><a
    href="https://github.com/Swatinem/rust-cache/commit/11da8522bc3856a8fbc565f1d1530989c793d67d"><code>11da852</code></a>
    Compare case-insenitively for full cache key match (<a
    href="https://redirect.github.com/swatinem/rust-cache/issues/303">#303</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/swatinem/rust-cache/compare/779680da715d629ac1d338a641029a2f4372abb5...c19371144df3bb44fab255c43d04cbc2ab54d1c4">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=swatinem/rust-cache&package-manager=github_actions&previous-version=2.8.2&new-version=2.9.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    You can trigger a rebase of this PR by commenting `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    > **Note**
    > Automatic rebases have been disabled on this pull request as it has
    been open for over 30 days.
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 17, 2026
    Configuration menu
    Copy the full SHA
    ec650c1 View commit details
    Browse the repository at this point in the history
  3. chore(deps): bump github/codeql-action from 4.35.4 to 4.36.2 (#3331)

    Bumps [github/codeql-action](https://github.com/github/codeql-action)
    from 4.35.4 to 4.36.2.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/releases">github/codeql-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.36.2</h2>
    <ul>
    <li>Cache CodeQL CLI version information across Actions steps. <a
    href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li>
    <li>Reduce requests while waiting for analysis processing by using
    exponential backoff when polling SARIF processing status. <a
    href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li>
    </ul>
    <h2>v4.36.1</h2>
    <p>No user facing changes.</p>
    <h2>v4.36.0</h2>
    <ul>
    <li><em>Breaking change</em>: Bump the minimum required CodeQL bundle
    version to 2.19.4. <a
    href="https://redirect.github.com/github/codeql-action/pull/3894">#3894</a></li>
    <li>Add support for SHA-256 Git object IDs. <a
    href="https://redirect.github.com/github/codeql-action/pull/3893">#3893</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5">2.25.5</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3926">#3926</a></li>
    </ul>
    <h2>v4.35.5</h2>
    <ul>
    <li>We have improved how the JavaScript bundles for the CodeQL Action
    are generated to avoid duplication across bundles and reduce the size of
    the repository by around 70%. This should have no effect on the runtime
    behaviour of the CodeQL Action. <a
    href="https://redirect.github.com/github/codeql-action/pull/3899">#3899</a></li>
    <li>For performance and accuracy reasons, <a
    href="https://redirect.github.com/github/roadmap/issues/1158">improved
    incremental analysis</a> will now only be enabled on a pull request when
    diff-informed analysis is also enabled for that run. If diff-informed
    analysis is unavailable (for example, because the PR diff ranges could
    not be computed), the action will fall back to a full analysis. <a
    href="https://redirect.github.com/github/codeql-action/pull/3791">#3791</a></li>
    <li>If multiple inputs are provided for the GitHub-internal
    <code>analysis-kinds</code> input, only <code>code-scanning</code> will
    be enabled. The <code>analysis-kinds</code> input is experimental, for
    GitHub-internal use only, and may change without notice at any time. <a
    href="https://redirect.github.com/github/codeql-action/pull/3892">#3892</a></li>
    <li>Added an experimental change which, when running a Code Scanning
    analysis for a PR with <a
    href="https://redirect.github.com/github/roadmap/issues/1158">improved
    incremental analysis</a> enabled, prefers CodeQL CLI versions that have
    a cached overlay-base database for the configured languages. This speeds
    up analysis for a repository when there is not yet a cached overlay-base
    database for the latest CLI version. We expect to roll this change out
    to everyone in May. <a
    href="https://redirect.github.com/github/codeql-action/pull/3880">#3880</a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's
    changelog</a>.</em></p>
    <blockquote>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>[UNRELEASED]</h2>
    <p>No user facing changes.</p>
    <h2>4.36.2 - 04 Jun 2026</h2>
    <ul>
    <li>Cache CodeQL CLI version information across Actions steps. <a
    href="https://redirect.github.com/github/codeql-action/pull/3943">#3943</a></li>
    <li>Reduce requests while waiting for analysis processing by using
    exponential backoff when polling SARIF processing status. <a
    href="https://redirect.github.com/github/codeql-action/pull/3937">#3937</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.6">2.25.6</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3948">#3948</a></li>
    </ul>
    <h2>4.36.1 - 02 Jun 2026</h2>
    <p>No user facing changes.</p>
    <h2>4.36.0 - 22 May 2026</h2>
    <ul>
    <li><em>Breaking change</em>: Bump the minimum required CodeQL bundle
    version to 2.19.4. <a
    href="https://redirect.github.com/github/codeql-action/pull/3894">#3894</a></li>
    <li>Add support for SHA-256 Git object IDs. <a
    href="https://redirect.github.com/github/codeql-action/pull/3893">#3893</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.5">2.25.5</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3926">#3926</a></li>
    </ul>
    <h2>4.35.5 - 15 May 2026</h2>
    <ul>
    <li>We have improved how the JavaScript bundles for the CodeQL Action
    are generated to avoid duplication across bundles and reduce the size of
    the repository by around 70%. This should have no effect on the runtime
    behaviour of the CodeQL Action. <a
    href="https://redirect.github.com/github/codeql-action/pull/3899">#3899</a></li>
    <li>For performance and accuracy reasons, <a
    href="https://redirect.github.com/github/roadmap/issues/1158">improved
    incremental analysis</a> will now only be enabled on a pull request when
    diff-informed analysis is also enabled for that run. If diff-informed
    analysis is unavailable (for example, because the PR diff ranges could
    not be computed), the action will fall back to a full analysis. <a
    href="https://redirect.github.com/github/codeql-action/pull/3791">#3791</a></li>
    <li>If multiple inputs are provided for the GitHub-internal
    <code>analysis-kinds</code> input, only <code>code-scanning</code> will
    be enabled. The <code>analysis-kinds</code> input is experimental, for
    GitHub-internal use only, and may change without notice at any time. <a
    href="https://redirect.github.com/github/codeql-action/pull/3892">#3892</a></li>
    <li>Added an experimental change which, when running a Code Scanning
    analysis for a PR with <a
    href="https://redirect.github.com/github/roadmap/issues/1158">improved
    incremental analysis</a> enabled, prefers CodeQL CLI versions that have
    a cached overlay-base database for the configured languages. This speeds
    up analysis for a repository when there is not yet a cached overlay-base
    database for the latest CLI version. We expect to roll this change out
    to everyone in May. <a
    href="https://redirect.github.com/github/codeql-action/pull/3880">#3880</a></li>
    </ul>
    <h2>4.35.4 - 07 May 2026</h2>
    <ul>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.4">2.25.4</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3881">#3881</a></li>
    </ul>
    <h2>4.35.3 - 01 May 2026</h2>
    <ul>
    <li><em>Upcoming breaking change</em>: Add a deprecation warning for
    customers using CodeQL version 2.19.3 and earlier. These versions of
    CodeQL were discontinued on 9 April 2026 alongside GitHub Enterprise
    Server 3.15, and will be unsupported by the next minor release of the
    CodeQL Action. <a
    href="https://redirect.github.com/github/codeql-action/pull/3837">#3837</a></li>
    <li>Configurations for private registries that use Cloudsmith or GCP
    OIDC are now accepted. <a
    href="https://redirect.github.com/github/codeql-action/pull/3850">#3850</a></li>
    <li>Best-effort connection tests for private registries now use
    <code>GET</code> requests instead of <code>HEAD</code> for better
    compatibility with various registry implementations. For NuGet feeds,
    the test is now always performed against the service index. <a
    href="https://redirect.github.com/github/codeql-action/pull/3853">#3853</a></li>
    <li>Fixed a bug where two diagnostics produced within the same
    millisecond could overwrite each other on disk, causing one of them to
    be lost. <a
    href="https://redirect.github.com/github/codeql-action/pull/3852">#3852</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.3">2.25.3</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3865">#3865</a></li>
    </ul>
    <h2>4.35.2 - 15 Apr 2026</h2>
    <ul>
    <li>The undocumented TRAP cache cleanup feature that could be enabled
    using the <code>CODEQL_ACTION_CLEANUP_TRAP_CACHES</code> environment
    variable is deprecated and will be removed in May 2026. If you are
    affected by this, we recommend disabling TRAP caching by passing the
    <code>trap-caching: false</code> input to the <code>init</code> Action.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3795">#3795</a></li>
    <li>The Git version 2.36.0 requirement for improved incremental analysis
    now only applies to repositories that contain submodules. <a
    href="https://redirect.github.com/github/codeql-action/pull/3789">#3789</a></li>
    <li>Python analysis on GHES no longer extracts the standard library,
    relying instead on models of the standard library. This should result in
    significantly faster extraction and analysis times, while the effect on
    alerts should be minimal. <a
    href="https://redirect.github.com/github/codeql-action/pull/3794">#3794</a></li>
    <li>Fixed a bug in the validation of OIDC configurations for private
    registries that was added in CodeQL Action 4.33.0 / 3.33.0. <a
    href="https://redirect.github.com/github/codeql-action/pull/3807">#3807</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.25.2">2.25.2</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3823">#3823</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/github/codeql-action/commit/8aad20d150bbac5944a9f9d289da16a4b0d87c1e"><code>8aad20d</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3949">#3949</a>
    from github/update-v4.36.2-dcb947ce1</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/f521b08cd8f468ab193ea950a589cb2e9c869c6a"><code>f521b08</code></a>
    Add additional changelog notes</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/8aeff0ffb7b78582ee0d0e6eebb8140684400d08"><code>8aeff0f</code></a>
    Update changelog for v4.36.2</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/dcb947ce15976d40ea82935510b2db4872ec124c"><code>dcb947c</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3948">#3948</a>
    from github/update-bundle/codeql-bundle-v2.25.6</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/c251bcefa178f7780f62f150002acffe3d07fde9"><code>c251bce</code></a>
    Add changelog note</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/62953c18b35f59e28351d2f1e806925aef8b1e3c"><code>62953c1</code></a>
    Update default bundle to codeql-bundle-v2.25.6</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/423b570baf1976cd7a3daeba5d6e9f9b76432f37"><code>423b570</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3946">#3946</a>
    from github/dependabot/npm_and_yarn/npm-minor-5d507a...</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/c35d1b164463ee62a100735382aaaa525c5d3496"><code>c35d1b1</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3947">#3947</a>
    from github/dependabot/github_actions/dot-github/wor...</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/cb1a588b02755b176e7b9d033ed4b69312f0e1bd"><code>cb1a588</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3937">#3937</a>
    from github/robertbrignull/waitForProcessing_backoff</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/ba47406412c54532b5b4fcfbaf877c9e2382b206"><code>ba47406</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/3943">#3943</a>
    from github/henrymercer/cache-cli-version-info</li>
    <li>Additional commits viewable in <a
    href="https://github.com/github/codeql-action/compare/68bde559dea0fdcac2102bfdf6230c5f70eb485e...8aad20d150bbac5944a9f9d289da16a4b0d87c1e">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=4.35.4&new-version=4.36.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 17, 2026
    Configuration menu
    Copy the full SHA
    0718e61 View commit details
    Browse the repository at this point in the history
  4. chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#3367)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2
    to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    <h2>v6.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update changelog by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>Update changelog for v6.0.3 by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
    update error wording (<a
    href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
    getting ready for checkout v7 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
    Bump the minor-npm-dependencies group across 1 directory with 3 updates
    (<a
    href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
    upgrade module to esm and update dependencies (<a
    href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
    Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
    and Remove uuid (<a
    href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
    Bump js-yaml from 4.1.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
    Bump flatted from 3.3.1 to 3.4.2 (<a
    href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
    Bump actions/publish-immutable-action (<a
    href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
    block checking out fork pr for pull_request_target and workflow_run (<a
    href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/df4cb1c069e1874edd31b4311f1884172cec0e10"><code>df4cb1c</code></a>
    Update changelog for v6.0.3 (<a
    href="https://redirect.github.com/actions/checkout/issues/2446">#2446</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/checkout&package-manager=github_actions&previous-version=6.0.2&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 17, 2026
    Configuration menu
    Copy the full SHA
    28f7c1f View commit details
    Browse the repository at this point in the history
  5. chore(deps): bump actions/create-github-app-token from 3.1.1 to 3.2.0 (

    …#3366)
    
    Bumps
    [actions/create-github-app-token](https://github.com/actions/create-github-app-token)
    from 3.1.1 to 3.2.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/create-github-app-token/releases">actions/create-github-app-token's
    releases</a>.</em></p>
    <blockquote>
    <h2>v3.2.0</h2>
    <h2><a
    href="https://github.com/actions/create-github-app-token/compare/v3.1.1...v3.2.0">3.2.0</a>
    (2026-05-12)</h2>
    <h3>Features</h3>
    <ul>
    <li>add support for enterprise-level GitHub Apps (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/263">#263</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/952a2a7073df6bfa5f49bc469ec895b6ec1acea4">952a2a7</a>)</li>
    <li>support full repository names in <code>repositories</code> input (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/372">#372</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/85eb8dd41472213aed25d1a126460e0069138ab6">85eb8dd</a>)</li>
    </ul>
    <h3>Bug Fixes</h3>
    <ul>
    <li><strong>deps:</strong> bump <code>@​actions/core</code> from 3.0.0
    to 3.0.1 in the production-dependencies group (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/364">#364</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/43e5c345bfd4d4f3ecea019ad0042001a09dd857">43e5c34</a>)</li>
    <li>validate private-key input (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/376">#376</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/f24bbd89643991c0de27ae823c01791b2c6bafdd">f24bbd8</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md">actions/create-github-app-token's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2><a
    href="https://github.com/actions/create-github-app-token/compare/v3.1.1...v3.2.0">3.2.0</a>
    (2026-05-12)</h2>
    <h3>Features</h3>
    <ul>
    <li>add support for enterprise-level GitHub Apps (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/263">#263</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/952a2a7073df6bfa5f49bc469ec895b6ec1acea4">952a2a7</a>)</li>
    <li>support full repository names in <code>repositories</code> input (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/372">#372</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/85eb8dd41472213aed25d1a126460e0069138ab6">85eb8dd</a>)</li>
    </ul>
    <h3>Bug Fixes</h3>
    <ul>
    <li><strong>deps:</strong> bump <code>@​actions/core</code> from 3.0.0
    to 3.0.1 in the production-dependencies group (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/364">#364</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/43e5c345bfd4d4f3ecea019ad0042001a09dd857">43e5c34</a>)</li>
    <li>validate private-key input (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/376">#376</a>)
    (<a
    href="https://github.com/actions/create-github-app-token/commit/f24bbd89643991c0de27ae823c01791b2c6bafdd">f24bbd8</a>)</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/bcd2ba49218906704ab6c1aa796996da409d3eb1"><code>bcd2ba4</code></a>
    chore(main): release 3.2.0 (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/370">#370</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/f24bbd89643991c0de27ae823c01791b2c6bafdd"><code>f24bbd8</code></a>
    fix: validate private-key input (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/376">#376</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/363531b6d972a60a00b3f1e6bb139e5e6c764cd9"><code>363531b</code></a>
    docs: capitalize Git as a proper noun in README (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/374">#374</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/fd2801133e469d2950f2c5af5e591d6b2ad833c8"><code>fd28011</code></a>
    docs: update procedure to configure Git (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/287">#287</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/85eb8dd41472213aed25d1a126460e0069138ab6"><code>85eb8dd</code></a>
    feat: support full repository names in <code>repositories</code> input
    (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/372">#372</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/c9aabb83728c3bd519212fa657ebc07e1f2a5dec"><code>c9aabb8</code></a>
    build(deps-dev): bump yaml from 2.8.3 to 2.8.4 in the
    development-dependencie...</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/e02e816e5591415258a53bf735aff57977dcd5e2"><code>e02e816</code></a>
    build(deps-dev): bump undici from 7.24.6 to 8.2.0 (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/366">#366</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/8d835bfd37aa48fcb8e709925115857568d98bc4"><code>8d835bf</code></a>
    build(deps-dev): bump esbuild from 0.27.4 to 0.28.0 in the
    development-depend...</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/952a2a7073df6bfa5f49bc469ec895b6ec1acea4"><code>952a2a7</code></a>
    feat: add support for enterprise-level GitHub Apps (<a
    href="https://redirect.github.com/actions/create-github-app-token/issues/263">#263</a>)</li>
    <li><a
    href="https://github.com/actions/create-github-app-token/commit/43e5c345bfd4d4f3ecea019ad0042001a09dd857"><code>43e5c34</code></a>
    fix(deps): bump <code>@​actions/core</code> from 3.0.0 to 3.0.1 in the
    production-dependenc...</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/create-github-app-token/compare/1b10c78c7865c340bc4f6099eb2f838309f1e8c3...bcd2ba49218906704ab6c1aa796996da409d3eb1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/create-github-app-token&package-manager=github_actions&previous-version=3.1.1&new-version=3.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 17, 2026
    Configuration menu
    Copy the full SHA
    308c9ad View commit details
    Browse the repository at this point in the history

Commits on Jul 20, 2026

  1. release: 3.6.1

    szokeasaurusrex committed Jul 20, 2026
    Configuration menu
    Copy the full SHA
    b2d322a View commit details
    Browse the repository at this point in the history
Loading