Skip to content

contractual next version - #15

Open
omermorad wants to merge 34 commits into
masterfrom
next
Open

omermorad wants to merge 34 commits into
masterfrom
next

Conversation

@omermorad

Copy link
Copy Markdown
Contributor

No description provided.

@omermorad omermorad self-assigned this Mar 12, 2026
@omermorad omermorad added the next label Mar 12, 2026
Change `npx contractual` to `npx @contractual/cli` to ensure
the correct package is used from the Verdaccio registry instead
of an unrelated `contractual` package from npm.
Changed JSON output from { results: [...] } to { contracts: { name: {...} } }
to match expected format in e2e tests and provide better ergonomics for
scripting (e.g., parsed.contracts.order.changes).
omermorad and others added 2 commits March 27, 2026 16:38
 - @contractual/changesets@0.1.0-dev.0
 - @contractual/cli@0.1.0-dev.0
 - @contractual/differs.json-schema@0.1.0-dev.0
 - @contractual/governance@0.1.0-dev.0
 - @contractual/types@0.1.0-dev.0
- Change openapi-diff from ^0.24.1 to ^0.23.7
- Version 0.24.x doesn't exist on npm, latest is 0.23.7
- Fixes npm install errors when using published packages
omermorad and others added 18 commits April 2, 2026 20:00
Update tests to use new contracts object format instead of results array:
- Old format: { results: [...] }
- New format: { contracts: { contractName: {...} } }

Fixes:
- --format json test: check for contracts object instead of results array
- --severity breaking test: iterate over contracts object
- --severity non-breaking test: iterate over contracts object

All 17 tests now passing.
 - @contractual/cli@0.1.0-dev.1
 - @contractual/governance@0.1.0-dev.1
Replace the `openapi-diff` npm package (3.0 only) with a custom OpenAPI
differ built on @redocly/openapi-core, supporting both 3.0 and 3.1 specs.

Extract shared schema diffing primitives (walker, classifiers, ref-resolver)
into @contractual/differs.core so they can be reused across differs.

New packages:
- @contractual/differs.core — shared walker, classifiers, ref-resolver
- @contractual/differs.openapi — OpenAPI 3.0/3.1 differ via Redocly

Changes:
- @contractual/differs.json-schema now wraps differs.core (backward compat)
- @contractual/governance drops openapi-diff dep, registers new differ
- @contractual/types extended with 15 OpenAPI structural change types
- Add e2e tests for OpenAPI 3.1 (type arrays, type narrowing/widening)

Spec version sync:
- New utility `updateSpecVersion()` in @contractual/changesets that updates
  the version field inside spec files (info.version for OpenAPI/AsyncAPI,
  top-level version for ODCS, skipped for JSON Schema)
- Preserves YAML comments/formatting via parseDocument(), detects JSON indent
- Creates missing version fields (e.g., missing info object) automatically
- Called before bump/setVersion so snapshot copies include the updated version
- Per-contract opt-out via `syncVersion: false` in contractual.config.json
- CLI flag `--no-sync-version` to skip for all contracts in a run
- Integrated into `contract add` command for initial version sync
- 22 e2e tests covering all spec types, bump types, missing fields,
  pre-release, multi-contract, config opt-out, and CLI flag

# Conflicts:
#	pnpm-lock.yaml
 - @contractual/changesets@0.1.0-dev.1
 - @contractual/cli@0.1.0-dev.2
 - @contractual/differs.core@0.1.0-dev.1
 - @contractual/differs.json-schema@0.1.0-dev.1
 - @contractual/differs.openapi@0.1.0-dev.1
 - @contractual/governance@0.1.0-dev.2
 - @contractual/types@0.1.0-dev.1
…flow

Redocly's bundle with dereference:true creates JS object cycles for
circular schemas (e.g. Category referencing itself). Our deepEqual
recurses infinitely on these cycles.

Fix: use Redocly for bundling only (resolves external refs), then use
our own ref-resolver from differs.core which has circular detection
and replaces cycles with $circularRef placeholders.

Also:
- Move @redocly/openapi-core from optional peer dep to regular dep
  in differs.openapi so users don't need to install it separately
- Remove peer dep from governance (gets it transitively)
- Add e2e tests for circular ref schemas
- Add timeout option to e2e test helper
 - @contractual/cli@0.1.0-dev.3
 - @contractual/differs.openapi@0.1.0-dev.2
 - @contractual/governance@0.1.0-dev.3
 - @contractual/changesets@0.1.0-dev.4
 - @contractual/cli@0.1.0-dev.4
 - @contractual/differs.core@0.1.0-dev.4
 - @contractual/differs.json-schema@0.1.0-dev.4
 - @contractual/differs.openapi@0.1.0-dev.4
 - @contractual/governance@0.1.0-dev.4
 - @contractual/types@0.1.0-dev.4
… changes

- Adding optional parameter is now non-breaking (was incorrectly breaking)
- Adding required parameter uses new parameter-required-added type (breaking)
- Detect operation-level metadata changes: description, summary, deprecated
- Detect top-level info.description and info.title changes
- All metadata changes classified as patch (creates changesets, not breaking)
…nter paths

formatChangeMessage() had no cases for OpenAPI structural types
(path-added, operation-added, parameter-*, response-*, etc.) so
they were falling through to "Unknown change at /paths/~1v2~1media".

Now shows "New path added: /v2/media" instead.

- Add cases for all 16 OpenAPI structural change types
- Decode JSON Pointer paths for display (~1 → /, ~0 → ~)
- Add e2e tests for message formatting
 - @contractual/changesets@0.1.0-dev.5
 - @contractual/cli@0.1.0-dev.5
 - @contractual/differs.core@0.1.0-dev.5
 - @contractual/differs.json-schema@0.1.0-dev.5
 - @contractual/differs.openapi@0.1.0-dev.5
 - @contractual/governance@0.1.0-dev.5
 - @contractual/types@0.1.0-dev.5
anyOf/oneOf/allOf and conditional schema changes were falling through
to the default case, producing "Unknown change" messages in PR comments.
 - @contractual/cli@0.1.0-next.0
 - @contractual/differs.core@0.1.0-next.0
 - @contractual/differs.json-schema@0.1.0-next.0
 - @contractual/differs.openapi@0.1.0-next.0
 - @contractual/governance@0.1.0-next.0
 - @contractual/cli@0.1.0-dev.6
 - @contractual/differs.core@0.1.0-dev.6
 - @contractual/differs.json-schema@0.1.0-dev.6
 - @contractual/differs.openapi@0.1.0-dev.6
 - @contractual/governance@0.1.0-dev.6
… double slashes

OpenAPI path keys like /v1/extract were producing //v1/extract in
changeset output. Decode per-segment and bracket keys containing slashes.
 - @contractual/cli@0.1.0-dev.7
 - @contractual/differs.core@0.1.0-dev.7
 - @contractual/differs.json-schema@0.1.0-dev.7
 - @contractual/differs.openapi@0.1.0-dev.7
 - @contractual/governance@0.1.0-dev.7
updateYamlSpec parsed leniently with parseDocument() then called
doc.toString() unconditionally, which throws 'Document with errors
cannot be stringified' whenever the spec has any recoverable parse
error (e.g. an under-indented multi-line scalar deep in the file).
A cosmetic version sync would then take down the entire release.

Now: clean docs use the structured setIn + toString path; docs with
parse errors fall back to a surgical in-place splice of just the
version field's source range, leaving malformed regions untouched;
if the field cannot be located we warn and continue instead of
throwing. Numeric-looking versions are kept as strings.

Adds a co-located unit test (vitest devDep + lockfile entry) and
excludes *.test.ts / *.spec.ts from tsconfig.build.json so tests are
never compiled into the published dist.
 - @contractual/changesets@0.1.0-dev.6
 - @contractual/cli@0.1.0-dev.8
@qballer

qballer commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Small PR :)

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread .github/workflows/release-preview.yml Fixed
Comment thread .github/workflows/release-preview.yml Fixed
Comment thread packages/governance/linters/json-schema-ajv.ts Fixed
omermorad and others added 8 commits September 29, 2026 09:12
Bumps the actions group with 4 updates:
[actions/checkout](https://github.com/actions/checkout),
[pnpm/action-setup](https://github.com/pnpm/action-setup),
[actions/setup-node](https://github.com/actions/setup-node) and
[codecov/codecov-action](https://github.com/codecov/codecov-action).

Updates `actions/checkout` from 4 to 7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>block checking out fork pr for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
<li>getting ready for checkout v7 release by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
<li>update error wording by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
<h2>v6.1.0</h2>
<h2>What's Changed</h2>
<ul>
<li><strong>[BREAKING]</strong> backport
<code>allow-unsafe-pr-checkout</code> to v6 by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2500">actions/checkout#2500</a></li>
<li>backport fixes to releases-v6 by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2527">actions/checkout#2527</a></li>
</ul>
<p><a
href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a>
for more details about this breaking change</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v6.1.0">https://github.com/actions/checkout/compare/v6.0.3...v6.1.0</a></p>
<h2>v6.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Update changelog by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>Update changelog for v6.0.3 by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
<h2>v6.0.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID
is set by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p>
<h2>v6.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Update all references from v5 and v4 to v6 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
<li>Clarify v6 README by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.1</h2>
<ul>
<li>Skip running unsafe pr check if input is default by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
<li>Trim only ascii whitespace for branch by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
<li>Escape values passed to --unset by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Various dependency updates</li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
prep v7.0.1 release (<a
href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
escape values passed to --unset (<a
href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
trim only ascii whitespace for branch (<a
href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
skip running unsafe pr check if input is default (<a
href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
Bump the minor-actions-dependencies group with 2 updates (<a
href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
eslint 9 (<a
href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
Bump actions/upload-artifact from 4 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
Bump actions/checkout from 6 to 7 (<a
href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
Bump docker/login-action from 3.3.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/checkout/compare/v4...v7">compare
view</a></li>
</ul>
</details>
<br />

Updates `pnpm/action-setup` from 4 to 6
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pnpm/action-setup/releases">pnpm/action-setup's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<p>Added support for pnpm <a
href="https://github.com/pnpm/pnpm/releases/tag/v11.0.0-rc.0">v11</a>.</p>
<h2>v5.0.0</h2>
<p>Updated the action to use Node.js 24.</p>
<h2>v4.4.0</h2>
<p>Updated the action to use Node.js 24.</p>
<h2>v4.3.0</h2>
<h2>What's Changed</h2>
<ul>
<li>docs: fix the run_install example in the Readme by <a
href="https://github.com/dreyks"><code>@​dreyks</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/175">pnpm/action-setup#175</a></li>
<li>chore: remove unused <code>@types/node-fetch</code> dependency by <a
href="https://github.com/silverwind"><code>@​silverwind</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/186">pnpm/action-setup#186</a></li>
<li>Clarify that package_json_file is relative to GITHUB_WORKSPACE by <a
href="https://github.com/chris-martin"><code>@​chris-martin</code></a>
in <a
href="https://redirect.github.com/pnpm/action-setup/pull/184">pnpm/action-setup#184</a></li>
<li>feat: store caching by <a
href="https://github.com/jrmajor"><code>@​jrmajor</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/188">pnpm/action-setup#188</a></li>
<li>refactor: remove star imports by <a
href="https://github.com/KSXGitHub"><code>@​KSXGitHub</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/196">pnpm/action-setup#196</a></li>
<li>fix(ci): exclude macos by <a
href="https://github.com/KSXGitHub"><code>@​KSXGitHub</code></a> in <a
href="https://redirect.github.com/pnpm/action-setup/pull/197">pnpm/action-setup#197</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/dreyks"><code>@​dreyks</code></a> made
their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/175">pnpm/action-setup#175</a></li>
<li><a
href="https://github.com/silverwind"><code>@​silverwind</code></a> made
their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/186">pnpm/action-setup#186</a></li>
<li><a
href="https://github.com/chris-martin"><code>@​chris-martin</code></a>
made their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/184">pnpm/action-setup#184</a></li>
<li><a href="https://github.com/jrmajor"><code>@​jrmajor</code></a> made
their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/188">pnpm/action-setup#188</a></li>
<li><a
href="https://github.com/Boosted-Bonobo"><code>@​Boosted-Bonobo</code></a>
made their first contribution in <a
href="https://redirect.github.com/pnpm/action-setup/pull/199">pnpm/action-setup#199</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pnpm/action-setup/compare/v4.2.0...v4.3.0">https://github.com/pnpm/action-setup/compare/v4.2.0...v4.3.0</a></p>
<h2>v4.2.0</h2>
<p>When there's a <code>.npmrc</code> file at the root of the
repository, pnpm will be fetched from the registry that is specified in
that <code>.npmrc</code> file <a
href="https://redirect.github.com/pnpm/action-setup/pull/179">#179</a></p>
<h2>v4.1.0</h2>
<p>Add support for <code>package.yaml</code> <a
href="https://redirect.github.com/pnpm/action-setup/pull/156">#156</a>.</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pnpm/action-setup/commit/0977fd99725f1db4007ccb2928dbb4e90d06cc86"><code>0977fd9</code></a>
docs: Update README to include devEngines.packageManager (<a
href="https://redirect.github.com/pnpm/action-setup/issues/273">#273</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/48261aca053e825d84804e8ce05524d558249ac9"><code>48261ac</code></a>
fix: update pnpm to v11.19.0 (<a
href="https://redirect.github.com/pnpm/action-setup/issues/283">#283</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/75677f717d48404e86ae8ee4891543f40de175aa"><code>75677f7</code></a>
ci: use pnpm 11 for <code>pr-check</code> (<a
href="https://redirect.github.com/pnpm/action-setup/issues/284">#284</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/769ae71fb33e6e448a5dc92ad5da997c268eecec"><code>769ae71</code></a>
refactor: introduce restore keys for cache (<a
href="https://redirect.github.com/pnpm/action-setup/issues/280">#280</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/6fed91f804570c1144bfe1911c348642cb986bd4"><code>6fed91f</code></a>
docs(README): point users to the successor pnpm/setup action (<a
href="https://redirect.github.com/pnpm/action-setup/issues/282">#282</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/0ebf47130e4866e96fce0953f49152a61190b271"><code>0ebf471</code></a>
fix: update pnpm to v11.7.0 (<a
href="https://redirect.github.com/pnpm/action-setup/issues/267">#267</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/0e279bb959325dab635dd2c09392533439d90093"><code>0e279bb</code></a>
fix: update pnpm to 11.1.1 (<a
href="https://redirect.github.com/pnpm/action-setup/issues/248">#248</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/3e835812ef01165f4f8ae08ade56da44427ed4e0"><code>3e83581</code></a>
fix: drop patchPnpmEnv so standalone+self-update works on Windows (<a
href="https://redirect.github.com/pnpm/action-setup/issues/258">#258</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/551b42e879e37e74d986effdd2a1647d2b02d464"><code>551b42e</code></a>
docs(README): fix <code>cache_dependency_path</code> type (<a
href="https://redirect.github.com/pnpm/action-setup/issues/257">#257</a>)</li>
<li><a
href="https://github.com/pnpm/action-setup/commit/739bfe42ca9233c5e6aca07c1a25a9d34aca49b0"><code>739bfe4</code></a>
fix: self-update bootstrap to packageManager-pinned version (<a
href="https://redirect.github.com/pnpm/action-setup/issues/233">#233</a>)
(<a
href="https://redirect.github.com/pnpm/action-setup/issues/256">#256</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/pnpm/action-setup/compare/v4...v6">compare
view</a></li>
</ul>
</details>
<br />

Updates `actions/setup-node` from 4 to 7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/setup-node/releases">actions/setup-node's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements:</h3>
<ul>
<li>Add cache-primary-key and cache-matched-key as outputs by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1577">actions/setup-node#1577</a></li>
<li>Migrate to ESM and upgrade dependencies by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1574">actions/setup-node#1574</a></li>
</ul>
<h3>Bug fixes:</h3>
<ul>
<li>Remove dummy NODE_AUTH_TOKEN export by <a
href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
<a
href="https://redirect.github.com/actions/setup-node/pull/1558">actions/setup-node#1558</a></li>
<li>Only use <code>mirrorToken</code> in <code>getManifest</code> if
it's provided by <a
href="https://github.com/deiga"><code>@​deiga</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
</ul>
<h3>Documentation updates:</h3>
<ul>
<li>Add documentation for publishing to npm with Trusted Publisher
(OIDC) by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li>docs: Update restore-only cache documentation by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1550">actions/setup-node#1550</a></li>
<li>docs: Update caching recommendations to mitigate cache poisoning
risks by <a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1567">actions/setup-node#1567</a></li>
</ul>
<h3>Dependency update:</h3>
<ul>
<li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
denied by <a
href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
<li><a href="https://github.com/deiga"><code>@​deiga</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
<li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6...v7.0.0">https://github.com/actions/setup-node/compare/v6...v7.0.0</a></p>
<h2>v6.5.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update <code>@​actions/cache</code> to 5.1.0 and add security
overrides for undici and fast-xml-parser by <a
href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1579">actions/setup-node#1579</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0">https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0</a></p>
<h2>v6.4.0</h2>
<h2>What's Changed</h2>
<h3>Dependency updates:</h3>
<ul>
<li>Upgrade <a
href="https://github.com/actions"><code>@​actions</code></a>
dependencies by <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1525">actions/setup-node#1525</a></li>
<li>Update Node.js versions in versions.yml and bump package to v6.4.0
by <a
href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
in <a
href="https://redirect.github.com/actions/setup-node/pull/1533">actions/setup-node#1533</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/setup-node/pull/1525">actions/setup-node#1525</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/setup-node/compare/v6...v6.4.0">https://github.com/actions/setup-node/compare/v6...v6.4.0</a></p>
<h2>v6.3.0</h2>
<h2>What's Changed</h2>
<h3>Enhancements:</h3>
<ul>
<li>Support parsing <code>devEngines</code> field by <a
href="https://github.com/susnux"><code>@​susnux</code></a> in <a
href="https://redirect.github.com/actions/setup-node/pull/1283">actions/setup-node#1283</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020"><code>8207627</code></a>
Migrate to ESM and upgrade dependencies (<a
href="https://redirect.github.com/actions/setup-node/issues/1574">#1574</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4"><code>04be95c</code></a>
Add cache-primary-key and cache-matched-key as outputs (<a
href="https://redirect.github.com/actions/setup-node/issues/1577">#1577</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140"><code>7c2c68d</code></a>
docs: Update caching recommendations to mitigate cache poisoning risks
(<a
href="https://redirect.github.com/actions/setup-node/issues/1567">#1567</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d"><code>6a61c03</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/setup-node/issues/1569">#1569</a>
from jasongin/update-actions-cache-5.1.0</li>
<li><a
href="https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f"><code>30eb73b</code></a>
Resolve high-severity audit issues</li>
<li><a
href="https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f"><code>4e1a87a</code></a>
Update dist</li>
<li><a
href="https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574"><code>360237f</code></a>
Strict equality</li>
<li><a
href="https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3"><code>4f8aac5</code></a>
Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
<li><a
href="https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980"><code>f4a67bb</code></a>
Only use <code>mirrorToken</code> in <code>getManifest</code> if it's
provided (<a
href="https://redirect.github.com/actions/setup-node/issues/1548">#1548</a>)</li>
<li><a
href="https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75"><code>0355742</code></a>
Remove dummy NODE_AUTH_TOKEN export (<a
href="https://redirect.github.com/actions/setup-node/issues/1558">#1558</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/setup-node/compare/v4...v7">compare
view</a></li>
</ul>
</details>
<br />

Updates `codecov/codecov-action` from 4 to 7
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/codecov/codecov-action/releases">codecov/codecov-action's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<p>⚠️ Due to migration issues with keybase, we are unable to update our
keys under the <code>codecovsecurity</code> account. We have deleted the
account and are using <code>codecovsecops</code> with the original gpg
key</p>
<h2>What's Changed</h2>
<ul>
<li>ci: remove Enforce License Compliance workflow by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1950">codecov/codecov-action#1950</a></li>
<li>chore(release): 7.0.0 by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1957">codecov/codecov-action#1957</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v6.0.1...v7.0.0">https://github.com/codecov/codecov-action/compare/v6.0.1...v7.0.0</a></p>
<h2>v6.0.2</h2>
<p>This is a copy of the <code>v7.0.0</code> release to make updates
easier</p>
<h2>What's Changed</h2>
<ul>
<li>ci: remove Enforce License Compliance workflow by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1950">codecov/codecov-action#1950</a></li>
<li>chore(release): 7.0.0 by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1957">codecov/codecov-action#1957</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v6.0.1...v6.0.2">https://github.com/codecov/codecov-action/compare/v6.0.1...v6.0.2</a></p>
<h2>v6.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: prevent template injection in run: steps (VULN-1652) by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1947">codecov/codecov-action#1947</a></li>
<li>chore(release): 6.0.1 by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1949">codecov/codecov-action#1949</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v6.0.0...v6.0.1">https://github.com/codecov/codecov-action/compare/v6.0.0...v6.0.1</a></p>
<h2>v6.0.0</h2>
<h2>⚠️ This version introduces support for node24 which make cause
breaking changes for systems that do not currently support node24.
⚠️</h2>
<h2>What's Changed</h2>
<ul>
<li>Revert &quot;Revert &quot;build(deps): bump actions/github-script
from 7.0.1 to 8.0.0&quot;&quot; by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1929">codecov/codecov-action#1929</a></li>
<li>Th/6.0.0 by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1928">codecov/codecov-action#1928</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.5.4...v6.0.0">https://github.com/codecov/codecov-action/compare/v5.5.4...v6.0.0</a></p>
<h2>v5.5.5</h2>
<p>This release only contains the keybase.io change as described <a
href="https://redirect.github.com/codecov/codecov-action/issues/1956">here</a>.</p>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.5.4...v5.5.5">https://github.com/codecov/codecov-action/compare/v5.5.4...v5.5.5</a></p>
<h2>v5.5.4</h2>
<p>This is a mirror of <code>v5.5.2</code>. <code>v6</code> will be
released which requires <code>node24</code></p>
<h2>What's Changed</h2>
<ul>
<li>Revert &quot;build(deps): bump actions/github-script from 7.0.1 to
8.0.0&quot; by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1926">codecov/codecov-action#1926</a></li>
<li>chore(release): 5.5.4 by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1927">codecov/codecov-action#1927</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md">codecov/codecov-action's
changelog</a>.</em></p>
<blockquote>
<h2>v5.5.2</h2>
<h3>What's Changed</h3>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2">https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2</a></p>
<h2>v5.5.1</h2>
<h3>What's Changed</h3>
<ul>
<li>fix: overwrite pr number on fork by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1871">codecov/codecov-action#1871</a></li>
<li>build(deps): bump actions/checkout from 4.2.2 to 5.0.0 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1868">codecov/codecov-action#1868</a></li>
<li>build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1867">codecov/codecov-action#1867</a></li>
<li>fix: update to use local app/ dir by <a
href="https://github.com/thomasrockhu-codecov"><code>@​thomasrockhu-codecov</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1872">codecov/codecov-action#1872</a></li>
<li>docs: fix typo in README by <a
href="https://github.com/datalater"><code>@​datalater</code></a> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1866">codecov/codecov-action#1866</a></li>
<li>Document a <code>codecov-cli</code> version reference example by <a
href="https://github.com/webknjaz"><code>@​webknjaz</code></a> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1774">codecov/codecov-action#1774</a></li>
<li>build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1861">codecov/codecov-action#1861</a></li>
<li>build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1833">codecov/codecov-action#1833</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.5.0..v5.5.1">https://github.com/codecov/codecov-action/compare/v5.5.0..v5.5.1</a></p>
<h2>v5.5.0</h2>
<h3>What's Changed</h3>
<ul>
<li>feat: upgrade wrapper to 0.2.4 by <a
href="https://github.com/jviall"><code>@​jviall</code></a> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1864">codecov/codecov-action#1864</a></li>
<li>Pin actions/github-script by Git SHA by <a
href="https://github.com/martincostello"><code>@​martincostello</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1859">codecov/codecov-action#1859</a></li>
<li>fix: check reqs exist by <a
href="https://github.com/joseph-sentry"><code>@​joseph-sentry</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1835">codecov/codecov-action#1835</a></li>
<li>fix: Typo in README by <a
href="https://github.com/spalmurray"><code>@​spalmurray</code></a> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1838">codecov/codecov-action#1838</a></li>
<li>docs: Refine OIDC docs by <a
href="https://github.com/spalmurray"><code>@​spalmurray</code></a> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1837">codecov/codecov-action#1837</a></li>
<li>build(deps): bump github/codeql-action from 3.28.17 to 3.28.18 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1829">codecov/codecov-action#1829</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.4.3..v5.5.0">https://github.com/codecov/codecov-action/compare/v5.4.3..v5.5.0</a></p>
<h2>v5.4.3</h2>
<h3>What's Changed</h3>
<ul>
<li>build(deps): bump github/codeql-action from 3.28.13 to 3.28.17 by
<code>@​app/dependabot</code> in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1822">codecov/codecov-action#1822</a></li>
<li>fix: OIDC on forks by <a
href="https://github.com/joseph-sentry"><code>@​joseph-sentry</code></a>
in <a
href="https://redirect.github.com/codecov/codecov-action/pull/1823">codecov/codecov-action#1823</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/codecov/codecov-action/compare/v5.4.2..v5.4.3">https://github.com/codecov/codecov-action/compare/v5.4.2..v5.4.3</a></p>
<h2>v5.4.2</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/codecov/codecov-action/commit/303a32d7a59b442fa8d48b6a1cc6825c09c847a5"><code>303a32d</code></a>
chore(release): 7.1.1 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1973">#1973</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/0b35c9ecc4f0529d0eb674914510c22f85b196b4"><code>0b35c9e</code></a>
chore(release): 7.1.0 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1971">#1971</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/fb8b3582c8e4def4969c97caa2f19720cb33a72f"><code>fb8b358</code></a>
chore(release): 7.0.0 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1957">#1957</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/ca0a928a4cb3911011e868128a5cd90437c12db1"><code>ca0a928</code></a>
ci: remove Enforce License Compliance workflow (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1950">#1950</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/e79a6962e0d4c0c17b229090214935d2e33f8354"><code>e79a696</code></a>
chore(release): 6.0.1 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1949">#1949</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/51e64229ac331acb0d7f7b17c67423995f991c79"><code>51e6422</code></a>
fix: prevent template injection in run: steps (VULN-1652) (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1947">#1947</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/57e3a136b779b570ffcdbf80b3bdc90e7fab3de2"><code>57e3a13</code></a>
Th/6.0.0 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1928">#1928</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/f67d33dda8a42b51c42a8318a1f66468119e898b"><code>f67d33d</code></a>
Revert &quot;Revert &quot;build(deps): bump actions/github-script from
7.0.1 to 8.0.0&quot;&quot;...</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/75cd11691c0faa626561e295848008c8a7dddffe"><code>75cd116</code></a>
chore(release): 5.5.4 (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1927">#1927</a>)</li>
<li><a
href="https://github.com/codecov/codecov-action/commit/87d39f4a2cec2673cf9505764fb20a38792ea722"><code>87d39f4</code></a>
Revert &quot;build(deps): bump actions/github-script from 7.0.1 to
8.0.0&quot; (<a
href="https://redirect.github.com/codecov/codecov-action/issues/1926">#1926</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/codecov/codecov-action/compare/v4...v7">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [@inquirer/prompts](https://github.com/SBoudrias/Inquirer.js) from
8.5.2 to 8.7.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/SBoudrias/Inquirer.js/releases">@​inquirer/prompts's
releases</a>.</em></p>
<blockquote>
<h2><code>@​inquirer/prompts</code><a
href="https://github.com/8"><code>@​8</code></a>.7.2</h2>
<h3>What's new</h3>
<ul>
<li>Fixed a race where keystrokes batched in the same tick as the key
that settled a prompt could still reach keypress handlers after the
prompt was done, cancelled, or aborted (<code>@inquirer/core</code>, <a
href="https://redirect.github.com/SBoudrias/Inquirer.js/pull/2255">#2255</a>,
closes <a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/1816">#1816</a>).</li>
<li><code>confirm()</code> now trims surrounding whitespace from answers
before matching yes/no keywords (<code>@inquirer/confirm</code>, <a
href="https://redirect.github.com/SBoudrias/Inquirer.js/pull/2254">#2254</a>).</li>
</ul>
<h3>Included</h3>
<ul>
<li><code>@inquirer/checkbox@^5.2.5</code></li>
<li><code>@inquirer/confirm@^6.3.2</code></li>
<li><code>@inquirer/editor@^5.3.3</code></li>
<li><code>@inquirer/expand@^5.1.5</code></li>
<li><code>@inquirer/input@^5.1.6</code></li>
<li><code>@inquirer/number@^4.2.3</code></li>
<li><code>@inquirer/password@^5.2.2</code></li>
<li><code>@inquirer/rawlist@^5.3.5</code></li>
<li><code>@inquirer/search@^4.3.3</code></li>
<li><code>@inquirer/select@^5.2.5</code></li>
</ul>
<h2><code>@​inquirer/prompts</code><a
href="https://github.com/8"><code>@​8</code></a>.7.1</h2>
<h3>What's new</h3>
<ul>
<li>All bundled prompts now pin <code>@inquirer/type</code> to an exact
version in their published manifests. Since these type definitions leak
into consumers' <code>tsc</code> runs, a semver range on the types-only
dependency could break downstream TypeScript builds without any change
to Inquirer.js itself (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/pull/2247">#2247</a>,
fixes <a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2244">#2244</a>).</li>
</ul>
<h3>Included</h3>
<ul>
<li><code>@inquirer/checkbox@^5.2.4</code></li>
<li><code>@inquirer/confirm@^6.3.1</code></li>
<li><code>@inquirer/editor@^5.3.2</code></li>
<li><code>@inquirer/expand@^5.1.4</code></li>
<li><code>@inquirer/input@^5.1.5</code></li>
<li><code>@inquirer/number@^4.2.2</code></li>
<li><code>@inquirer/password@^5.2.1</code></li>
<li><code>@inquirer/rawlist@^5.3.4</code></li>
<li><code>@inquirer/search@^4.3.2</code></li>
<li><code>@inquirer/select@^5.2.4</code></li>
</ul>
<h2><code>@​inquirer/prompts</code><a
href="https://github.com/8"><code>@​8</code></a>.7.0</h2>
<h3>What's new</h3>
<ul>
<li><code>password</code> gains the <code>toggleMask</code> option
(ctrl+t to reveal the typed value).</li>
<li><code>confirm</code> now matches localized yes/no answers
per-locale.</li>
<li>Prettified prompt and theme types for better IDE display.</li>
<li>Added <code>inquirer-grouped-checkbox</code> to the community
prompts list (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/pull/2236">#2236</a>).</li>
</ul>
<h3>Included</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/cbdb34bfc6c245941d80ef88493c50b3d6dbfce6"><code>cbdb34b</code></a>
chore: Publish new release</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/8340d2dd764d4b11d4e200412b614f9964ae0691"><code>8340d2d</code></a>
fix(<code>@​inquirer/core</code>): clear hook effects before settling
prompts</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/2475e07186d824d52504095c71c2272d9e7338fe"><code>2475e07</code></a>
test(<code>@​inquirer/core</code>): cover hook cleanup error
semantics</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/15cd8d3b53bfc270633072073c24d6be6ce3d83b"><code>15cd8d3</code></a>
fix(confirm): ignore surrounding whitespace in answers</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/9cb0da6c187346c955ab0b788fa1a88c897f16da"><code>9cb0da6</code></a>
chore(deps): Bump github/codeql-action/analyze from 4.37.7 to
4.37.9</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/1c750bc55ab4fac310d70db84a7a6ada76c0e854"><code>1c750bc</code></a>
chore(deps-dev): Bump the build group with 3 updates (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2251">#2251</a>)</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/81f1525110990603e9796d48eecde0f8c2d2fc98"><code>81f1525</code></a>
chore(deps-dev): Bump <code>@​types/node</code> in the types group (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2252">#2252</a>)</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/7c27f26606a16b6e8f55b51e4431c72658c674c5"><code>7c27f26</code></a>
chore(deps-dev): Bump oxfmt in the formatting group (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2249">#2249</a>)</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/6119088a4e07ec59460c3cd44d06817de97bfdac"><code>6119088</code></a>
chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2250">#2250</a>)</li>
<li><a
href="https://github.com/SBoudrias/Inquirer.js/commit/0d167c0aface3f5cf95132ada9bfec7946dd5b74"><code>0d167c0</code></a>
chore(deps-dev): Bump the linting group with 4 updates (<a
href="https://redirect.github.com/SBoudrias/Inquirer.js/issues/2248">#2248</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.5.2...@inquirer/prompts@8.7.2">compare
view</a></li>
</ul>
</details>
<details>
<summary>Maintainer changes</summary>
<p>This version was pushed to npm by <a
href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new
releaser for <code>@​inquirer/prompts</code> since your current
version.</p>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@inquirer/prompts&package-manager=npm_and_yarn&previous-version=8.5.2&new-version=8.7.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chalk](https://github.com/chalk/chalk) from 5.6.2 to 6.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/chalk/chalk/releases">chalk's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<h3>Breaking</h3>
<ul>
<li>Require Node.js 22  8a94e0e</li>
</ul>
<h3>Improvements</h3>
<ul>
<li>Add underline styles and underline colors (<a
href="https://redirect.github.com/chalk/chalk/issues/689">#689</a>)
4c304dd</li>
<li>Improve performance  5729845 fa5cff2</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Treat a numeric <code>FORCE_COLOR</code> as an exact level (<a
href="https://redirect.github.com/chalk/chalk/issues/688">#688</a>)
e912931</li>
<li>Downsample <code>ansi256()</code> and <code>bgAnsi256()</code> to 16
colors at level 1 (<a
href="https://redirect.github.com/chalk/chalk/issues/687">#687</a>)
ff549c5</li>
</ul>
<hr />
<p><a
href="https://github.com/chalk/chalk/compare/v5.6.2...v6.0.0">https://github.com/chalk/chalk/compare/v5.6.2...v6.0.0</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/chalk/chalk/commit/661317e6f91fe7c90306c2c48ea9354562ee9146"><code>661317e</code></a>
6.0.0</li>
<li><a
href="https://github.com/chalk/chalk/commit/5729845f33d357e0c21b29b2b16849b72fb8cec4"><code>5729845</code></a>
Improve performance</li>
<li><a
href="https://github.com/chalk/chalk/commit/4c304dd72cce5a036c02e5dd8af52996ae98501f"><code>4c304dd</code></a>
Add extended underline styles and underline colors (<a
href="https://redirect.github.com/chalk/chalk/issues/689">#689</a>)</li>
<li><a
href="https://github.com/chalk/chalk/commit/e91293130c7d642c7b91152c3c942743a3b910a7"><code>e912931</code></a>
Fix: Treat a numeric <code>FORCE_COLOR</code> as an exact level (<a
href="https://redirect.github.com/chalk/chalk/issues/688">#688</a>)</li>
<li><a
href="https://github.com/chalk/chalk/commit/8a94e0ebfc495dda27f7090fb1a012790b15a76d"><code>8a94e0e</code></a>
Require Node.js 22</li>
<li><a
href="https://github.com/chalk/chalk/commit/fa5cff280e821c928dab716a03beff06529ffaf3"><code>fa5cff2</code></a>
Optimize 2-argument calls (<a
href="https://redirect.github.com/chalk/chalk/issues/670">#670</a>)</li>
<li><a
href="https://github.com/chalk/chalk/commit/ff549c534c413a9225322c1ff4e5fc0d97ae5610"><code>ff549c5</code></a>
Fix: Downsample <code>ansi256()</code> and <code>bgAnsi256()</code> to
16 colors at level 1 (<a
href="https://redirect.github.com/chalk/chalk/issues/687">#687</a>)</li>
<li><a
href="https://github.com/chalk/chalk/commit/678e5505458d0cf40134e205aed4454e0eeac45c"><code>678e550</code></a>
Tweaks</li>
<li><a
href="https://github.com/chalk/chalk/commit/aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef"><code>aa06bb5</code></a>
Fix typos (<a
href="https://redirect.github.com/chalk/chalk/issues/664">#664</a>)</li>
<li>See full diff in <a
href="https://github.com/chalk/chalk/compare/v5.6.2...v6.0.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=chalk&package-manager=npm_and_yarn&previous-version=5.6.2&new-version=6.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [rimraf](https://github.com/isaacs/rimraf) from 5.0.10 to 6.1.3.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/isaacs/rimraf/blob/main/CHANGELOG.md">rimraf's
changelog</a>.</em></p>
<blockquote>
<h1>6.1</h1>
<ul>
<li>Move to native <code>fs/promises</code> usage instead of
promisifying
manually.</li>
</ul>
<h1>6.0</h1>
<ul>
<li>Drop support for nodes before v20</li>
<li>Add <code>--version</code> to CLI</li>
</ul>
<h1>5.0</h1>
<ul>
<li>No default export, only named exports</li>
</ul>
<h1>4.4</h1>
<ul>
<li>Provide Dirent or Stats object as second argument to filter</li>
</ul>
<h1>4.3</h1>
<ul>
<li>Return boolean indicating whether the path was fully removed</li>
<li>Add filter option</li>
<li>bin: add --verbose, -v to print files as they are deleted</li>
<li>bin: add --no-verbose, -V to not print files as they are
deleted</li>
<li>bin: add -i --interactive to be prompted on each deletion</li>
<li>bin: add -I --no-interactive to not be prompted on each
deletion</li>
<li><strong>4.3.1</strong> Fixed inappropriately following symbolic
links to
directories</li>
</ul>
<h1>v4.2</h1>
<ul>
<li>Brought back <code>glob</code> support, using the new and improved
glob v9</li>
</ul>
<h1>v4.1</h1>
<ul>
<li>Improved hybrid module with no need to look at the
<code>.default</code>
dangly bit. <code>.default</code> preserved as a reference to
<code>rimraf</code>
for compatibility with anyone who came to rely on it in v4.0.</li>
<li>Accept and ignore <code>-rf</code> and <code>-fr</code> arguments to
the bin.</li>
</ul>
<h1>v4.0</h1>
<ul>
<li>Remove <code>glob</code> dependency entirely. This library now only
accepts actual file and folder names to delete.</li>
<li>Accept array of paths or single path.</li>
<li>Windows performance and reliability improved.</li>
<li>All strategies separated into explicitly exported methods.</li>
<li>Drop support for Node.js below version 14</li>
<li>rewrite in TypeScript</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/isaacs/rimraf/commit/f738c781d14fa7bc06f8e39e062d78f701fde3f1"><code>f738c78</code></a>
6.1.3</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/a164a85093f78e40d8f995b0d8ff3a1856324768"><code>a164a85</code></a>
update deps</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/4635ba7498849cade724bd34c1ec9feae4b56236"><code>4635ba7</code></a>
update deps</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/509c53f8b0298508c3a536dc121bbc0652d3e56f"><code>509c53f</code></a>
limit ci workflow permissions</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/68ce04f9bfb436e66356428e2970c78fa2a76d02"><code>68ce04f</code></a>
formatting</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/37680c5d7f0104042ab8e8fae3e77484dc7687ca"><code>37680c5</code></a>
add warning to not pass untrusted input to this method ever</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/786563d3901763fa77090271d239233aa27e7a3a"><code>786563d</code></a>
remove contributing doc, already covered by .github repo</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/dbeef7399038d0cc467dbac5f91074cd0dc847dd"><code>dbeef73</code></a>
contributing</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/84d27afdbf7a211ecce6e9e73530aeb7278ea5d2"><code>84d27af</code></a>
update workflows and standard project junk</li>
<li><a
href="https://github.com/isaacs/rimraf/commit/cd45498f616f9265dfe1e30640d6424348f75f04"><code>cd45498</code></a>
6.1.2</li>
<li>Additional commits viewable in <a
href="https://github.com/isaacs/rimraf/compare/v5.0.10...v6.1.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=rimraf&package-manager=npm_and_yarn&previous-version=5.0.10&new-version=6.1.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [ora](https://github.com/sindresorhus/ora) from 8.2.0 to 9.4.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/sindresorhus/ora/releases">ora's
releases</a>.</em></p>
<blockquote>
<h2>v9.4.1</h2>
<ul>
<li>Fix type definitions (<a
href="https://redirect.github.com/sindresorhus/ora/issues/257">#257</a>)
431ebc4</li>
<li>Fix <code>failText</code> type to accept <code>unknown</code>
instead of <code>Error</code>, matching the actual promise rejection
value bc3a283</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/ora/compare/v9.4.0...v9.4.1">https://github.com/sindresorhus/ora/compare/v9.4.0...v9.4.1</a></p>
<h2>v9.4.0</h2>
<ul>
<li>Add <code>successSymbol</code> and <code>failSymbol</code> options
to <code>oraPromise</code> 3d2e0a9</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/ora/compare/v9.3.0...v9.4.0">https://github.com/sindresorhus/ora/compare/v9.3.0...v9.4.0</a></p>
<h2>v9.3.0</h2>
<ul>
<li>Reduce flicker in rendering  2ab4f76</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/ora/compare/v9.2.0...v9.3.0">https://github.com/sindresorhus/ora/compare/v9.2.0...v9.3.0</a></p>
<h2>v9.2.0</h2>
<ul>
<li>Update <code>stdin-discarder</code> dependency (<a
href="https://redirect.github.com/sindresorhus/ora/issues/251">#251</a>)
020eaba</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/ora/compare/v9.1.0...v9.2.0">https://github.com/sindresorhus/ora/compare/v9.1.0...v9.2.0</a></p>
<h2>v9.1.0</h2>
<ul>
<li>Support external writes to stream (<code>console.log</code>) while
spinning d2b543a</li>
<li>Replace <code>strip-ansi</code> dependency with native
<code>stripVTControlCharacters</code> (<a
href="https://redirect.github.com/sindresorhus/ora/issues/249">#249</a>)
68d50e5</li>
</ul>
<hr />
<p><a
href="https://github.com/sindresorhus/ora/compare/v9.0.0...v9.1.0">https://github.com/sindresorhus/ora/compare/v9.0.0...v9.1.0</a></p>
<h2>v9.0.0</h2>
<h3>Breaking</h3>
<ul>
<li>Require Node.js 20  7aca06d</li>
</ul>
<h3>Fixes</h3>
<ul>
<li>Fix clearing in some cases  aa51538</li>
<li>Fix <code>frame()</code> not displaying dynamic
<code>prefixText</code>/<code>suffixText</code> from functions
0f19f57</li>
<li>Fix multiline text exceeding console height leaving garbage when
scrolling 45d30ad</li>
</ul>
<hr />
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/sindresorhus/ora/commit/79cd8c15ac34572cffb3ab53e3d4b6bab6d59ea8"><code>79cd8c1</code></a>
9.4.1</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/bc3a28363a9873304ffb56420cb55fe83a7f41e8"><code>bc3a283</code></a>
Minor tweaks</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/431ebc40dceb1f700f3b60821f139541dbd7c93d"><code>431ebc4</code></a>
Fix type definitions (<a
href="https://redirect.github.com/sindresorhus/ora/issues/257">#257</a>)</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/46a670390249718af7c66452afdc5d78ceb579e9"><code>46a6703</code></a>
9.4.0</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/3d2e0a907e1141a121e5ed3348d9ea0981ca8a9c"><code>3d2e0a9</code></a>
Add <code>successSymbol</code> and <code>failSymbol</code> options to
<code>oraPromise</code></li>
<li><a
href="https://github.com/sindresorhus/ora/commit/f70f613d72f0afb0f4cb0a7fe56268f8abd1a170"><code>f70f613</code></a>
Test tweaks</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/7cf29a75e64409205a6606dada9780ccf5acf6a8"><code>7cf29a7</code></a>
Validate some options better</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/4496362714e1edd414e5347e8d4b337f103f0e15"><code>4496362</code></a>
9.3.0</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/2ab4f7613879515e29039888115831422f49e1af"><code>2ab4f76</code></a>
Reduce flicker in rendering</li>
<li><a
href="https://github.com/sindresorhus/ora/commit/8d17b13a8b3330af16cfa24c6e3b8a99f678c5c4"><code>8d17b13</code></a>
Add FAQ item</li>
<li>Additional commits viewable in <a
href="https://github.com/sindresorhus/ora/compare/v8.2.0...v9.4.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ora&package-manager=npm_and_yarn&previous-version=8.2.0&new-version=9.4.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants