mirror of
https://github.com/max-sixty/worktrunk.git
synced 2026-09-14 20:00:38 +08:00
codex/remove-codex-cloud-specific-tests
171 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9c13f6e7d4 |
chore: bump taiki-e/install-action from 2.85.11 to 2.85.13 (#3828)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.11 to 2.85.13. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>2.85.12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.13] - 2026-08-13</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.3.3.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.5.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.113.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.4.</p> </li> <li> <p>Update <code>bpf-linker@latest</code> to 0.11.0.</p> </li> </ul> <h2>[2.85.12] - 2026-08-12</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.3.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.256.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.10.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.51.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.13.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.4.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.8.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/82cd3e7658a6f96c86c0234aeeda1748937cb0a1"><code>82cd3e7</code></a> Release 2.85.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/4dd6c67d0ecd1fab76c6cecc5931e1239cc16add"><code>4dd6c67</code></a> Update <code>tombi@latest</code> to 1.3.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/91cb1bb28383045bb69f87d336ede6db3c61927b"><code>91cb1bb</code></a> Update <code>mise@latest</code> to 2026.8.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/83d968e89df664219ce13abb14808207a131cc64"><code>83d968e</code></a> Update <code>kingfisher@latest</code> to 1.113.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f7ab7f5d0a3e5a8120f10f39cfc442b2f40642b0"><code>f7ab7f5</code></a> Update cargo-xwin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3faddd9e3002e0d2922192f5808a78c4118eb58c"><code>3faddd9</code></a> Update <code>cargo-shear@latest</code> to 1.13.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/b4cb4b238691473c8bf1425b4d38120d5058dfc2"><code>b4cb4b2</code></a> Update <code>bpf-linker@latest</code> to 0.11.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/b20dedce73af6905cdc30d6611090c9b67557c8d"><code>b20dedc</code></a> Release 2.85.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/952d13c8bb10d7e37f96fa2c8131338550a62663"><code>952d13c</code></a> ci: Skip cargo-rdme on x86_64 macOS</li> <li><a href="https://github.com/taiki-e/install-action/commit/c8724e7258d0b8f8188a94aec0c00ae9da81edd7"><code>c8724e7</code></a> Update <code>zola@latest</code> to 0.23.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.11...v2.85.13">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1b278042de |
chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary Weekly CI renovation check found the following updates: - `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) — `ci.yaml` ×2, `nightly.yaml` - `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`, `coverage.yaml`, `actions/test-setup`, and `scripts/codex-cloud/Taskfile.yaml` - `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml` - `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and the root `Taskfile.yaml`'s `setup-web` task The Codex Cloud archive checksums were recomputed from the new upstream tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is copied into both README launcher commands. The `setup-web` PowerShell pin came in as a follow-up commit: the initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing tests the two PowerShell pins against each other, so that one drifts silently — worth a note for future renovation runs. The `powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch downloads is present in the v7.6.5 release. ## Already up to date - Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, `rust-toolchain.toml` need no change, and `flake.lock` is untouched. - `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7, `cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61, `lychee` 0.24.2 - Task 3.52.0 (mise, Codex Cloud) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Held back: zola 0.22.1 → 0.23.3 Not bumped. Zola 0.23.0 shipped [Tera2 + refactoring](https://github.com/getzola/zola/pull/3105), which is a templating-engine swap rather than a routine release. Building `docs/` with the 0.23.3 binary fails at the first line of `templates/base.html`: ``` ERROR error: Unknown tag --> base.html:1:4 | 1 | {% import "macros.html" as macros %} | ^^^^^^ ``` `templates/base.html` and `templates/macros.html` are the two files that use the `import`/`macro` pair, so the migration looks small, but it is template work with its own review rather than a pin bump — kept out of this PR so the rest can land. Raised separately. <details><summary>Verification</summary> - Every version above was read from the upstream source of truth: `crates.io` for the cargo tools, `nushell/nushell` and `PowerShell/PowerShell` releases, PyPI for pre-commit, and `static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable (1.97.1). - Checksums were computed from the downloaded archives and the extracted binaries were run (`nu --version` → `0.115.0`); the archive layouts (`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are unchanged, so the `install_binary` paths still resolve. - All six edited YAML files parse. - The nushell bump was exercised against the shell-integration suite: `cargo test --features shell-integration-tests --test integration -- nushell` with 0.115.0 on `PATH`. 13 of 14 pass; `test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it fails identically on the currently-pinned 0.114.1, and passes on *both* versions when run alone. It is a pre-existing shared-state race in the sandbox, not a regression from this bump: the test asserts against the real user `$nu.vendor-autoload-dirs` entry rather than one under its temp `HOME` (nu resolves the home dir from the passwd database, so the test's `HOME` override does not move it), and a sibling uninstall test in the same filter removes `wt.nu` from that shared directory. Noted rather than fixed here — it is unrelated to the pins. - The zola failure above was reproduced with the official 0.23.3 `x86_64-unknown-linux-gnu` release binary against this repo's `docs/`. </details> --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
ab76101b0b |
chore: bump taiki-e/install-action from 2.85.10 to 2.85.11 (#3801)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.10 to 2.85.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.11</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.11] - 2026-08-09</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.2.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.3.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.5.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.3.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.112.0.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7f4eb899022d8fe70b20c4f3de697aa85c309026"><code>7f4eb89</code></a> Release 2.85.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/c17da6245a7fe549cefa05b31e3614ce0b16c2af"><code>c17da62</code></a> Update <code>zola@latest</code> to 0.23.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/97e8291c2ba440a7119c03ebe3ed1e584a1f9b7f"><code>97e8291</code></a> Update <code>wasm-bindgen@latest</code> to 0.2.127</li> <li><a href="https://github.com/taiki-e/install-action/commit/91f9e5c61a2dc7936a8f404d01b7c1551b9c581a"><code>91f9e5c</code></a> Update <code>uv@latest</code> to 0.12.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/bd0cb00440414f36db2f79bca8e27971bb63b2a3"><code>bd0cb00</code></a> Update <code>osv-scanner@latest</code> to 2.5.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/4def957aa80c252e2d4c61387c6a429d377907d1"><code>4def957</code></a> Update <code>mise@latest</code> to 2026.8.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d149dc3890afe4774d158d353b5a3e55fe90f60"><code>3d149dc</code></a> Update <code>kingfisher@latest</code> to 1.112.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/20d4381a5cf6917520fde30f9ff52387410bfb6e"><code>20d4381</code></a> Update <code>editorconfig-checker@latest</code> to 3.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/583939ec0c8ee9c523cc60342d3d979ce6730f38"><code>583939e</code></a> codegen: Ignore clippy::assert_is_empty lint</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.10...v2.85.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec2aa4d154 |
chore: bump taiki-e/install-action from 2.85.8 to 2.85.10 (#3793)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.8 to 2.85.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.10</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>2.85.9</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.10] - 2026-08-07</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.2.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.7.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.3.</p> </li> <li> <p>Update <code>coreutils@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.3.</p> </li> </ul> <h2>[2.85.9] - 2026-08-06</h2> <ul> <li> <p>Update <code>zola@latest</code> to 0.23.1.</p> </li> <li> <p>Update <code>wild@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.2.</p> </li> <li> <p>Update <code>just@latest</code> to 1.58.0.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.1.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.2.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.7.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/6c6fd71fe4fb72c3697d269963d0e15df8adedad"><code>6c6fd71</code></a> Release 2.85.10</li> <li><a href="https://github.com/taiki-e/install-action/commit/37cec23487191ef9aef8b1315865bd6dc584bef4"><code>37cec23</code></a> Update zola manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/4914ea4fea5759852f8cda51753420130b883d65"><code>4914ea4</code></a> Update <code>uv@latest</code> to 0.12.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/0ce64163d455e35fedc5f5925221d4a71f05c990"><code>0ce6416</code></a> Update <code>tombi@latest</code> to 1.2.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/1f89e2fb52c482b53fcf083bf64b5abd5d6563ab"><code>1f89e2f</code></a> Update osv-scanner manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/65ef13f21e6dd200e402682be3b1bc896f6aa862"><code>65ef13f</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9f6a5a8ec701c59d62ac1013b92714e7410b2cae"><code>9f6a5a8</code></a> Update <code>cosign@latest</code> to 3.1.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/df08c38f9c0580a749efefc712ba563ff2107db5"><code>df08c38</code></a> Update <code>coreutils@latest</code> to 0.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dc7bb1f807a876bf372de55372b320860efe4019"><code>dc7bb1f</code></a> Update <code>cargo-rdme@latest</code> to 2.2.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9970698e35256036b84ecfb8a70b90fe068a934b"><code>9970698</code></a> Update <code>cargo-crap@latest</code> to 0.4.3</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.8...v2.85.10">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ec574b6c35 |
ci: bump pinned cargo-nextest 0.9.143 and worktrunk 0.72.0 (#3783)
## Summary Weekly CI pin check found the following drift (these inline `version:` strings are invisible to Dependabot — it follows `Cargo.toml` deps and `uses: foo@vN` refs, not pinned versions inside `with:` blocks): - `cargo-nextest`: 0.9.140 → 0.9.143 (MSRV 1.91, compatible with our 1.96) — pinned in `coverage.yaml`, `actions/test-setup`, and `actions/claude-setup`; all three moved together. - `worktrunk`: 0.71.0 → 0.72.0 (MSRV 1.96, compatible with our 1.96) — the CI-installed `wt` that runs `wt hook pre-merge`, bumped to the current release; pinned in `ci.yaml` (×2) and `nightly.yaml`. ## Already up to date - `cargo-affected`: 0.4.0, `cargo-insta`: 1.48.0, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `hustcer/setup-nu` (nushell): 0.114.1 — matches the current nushell release across all four call sites - Runner images: ubuntu-24.04, windows-2022 ## Notes - windows-2022 stays pinned ([actions/runner-images#12677](https://github.com/actions/runner-images/issues/12677) — windows-2025 lacks the D: drive). - **cargo-nextest 0.9.143 has nothing config-facing to adjust.** The 0.9.140 → 0.9.143 range is dynamic-library-search-path fixes (build-dir layout v2, `build.build-dir`, `[[example]]` targets), archive filterset fixes, an opt-in `junit.report-skipped` setting we don't set, and a listing progress bar. The one behavior change — ordering the Cargo artifact directory ahead of `deps` on the dylib search path, matching Cargo since 1.93 — doesn't affect this repo, which links no `dylib` dependency. - **worktrunk 0.72.0 is only exercised through `wt hook pre-merge`** in these three jobs, so the release's `wt merge` / `wt step push` two-tree changes and the `branch_outcome` JSON rename don't reach CI. The relevant one is the opposite direction: 0.72.0 fixes `wt` writing ANSI to a pipe and exiting 101 on `Broken pipe`, which is exactly the non-tty shape these jobs run in. - **`zola` is deliberately left at 0.22.1** — see below. ## Deferred: zola 0.22.1 → 0.23.2 `taiki-e/install-action`'s `tool: zola@0.22.1` in `check-docs` (and the matching pin in `publish-docs.yaml`) is behind, but 0.23.0 is not a routine bump. Upstream calls it "probably the most breaking version of Zola that will happen" ([CHANGELOG](https://github.com/getzola/zola/blob/master/CHANGELOG.md)): **shortcodes are removed entirely** and Tera is updated to v2 with its own [migration guide](https://github.com/Keats/tera/blob/master/MIGRATION.md). `docs/templates/shortcodes/` and `docs/templates/macros.html` both exist, so this needs a real docs-site migration rather than a version-string change, and it would land in the same PR as the live-site publish pin. Left for a separate change; flagging it here so it isn't silently skipped each week. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
02a8dc829c |
chore: bump taiki-e/install-action from 2.85.7 to 2.85.8 (#3758)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.7 to 2.85.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.8</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.8] - 2026-08-04</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.29.0.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.49.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.73.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.6.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.12.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.8.1.</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.1.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/cb33e69fad06166ca28a42b2575e4dadabf62ee8"><code>cb33e69</code></a> Release 2.85.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/205431a517a990dfa58a0f22a02abd8cbef31c11"><code>205431a</code></a> Update <code>zizmor@latest</code> to 1.29.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/e734f91b32f269a08deefc4ceb37d4aa4747a26b"><code>e734f91</code></a> Update wild manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/2596ecb10ea03dec655fc75e41a3b0f4dad7bc42"><code>2596ecb</code></a> Update <code>typos@latest</code> to 1.49.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/a44271eb2d867e7b1cf13602d4e4f0a93eec2f5e"><code>a44271e</code></a> Update <code>trivy@latest</code> to 0.73.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9b100e5f66ebcc3ef6c9e7380611a923118c93bd"><code>9b100e5</code></a> Update <code>tombi@latest</code> to 1.2.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/f28498427840d9dc2242c579fe43460aad78fb48"><code>f284984</code></a> Update <code>prek@latest</code> to 0.4.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/3b86746a2ded65050e00646b310ebba2a15bdaf6"><code>3b86746</code></a> Update <code>mise@latest</code> to 2026.8.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/9287d185066eec8a77c1f11905ac9727db063430"><code>9287d18</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/32702bef0f7f8c45b9b179686f51a0f2739378c3"><code>32702be</code></a> Update <code>convco@latest</code> to 0.7.1</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.7...v2.85.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5a5f5795c9 |
chore: bump taiki-e/install-action from 2.85.5 to 2.85.7 (#3739)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.5 to 2.85.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.7</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.75.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.110.0.</p> </li> </ul> <h2>2.85.6</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.255.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.18.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.3.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.7] - 2026-08-02</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.12.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.75.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.110.0.</p> </li> </ul> <h2>[2.85.6] - 2026-08-01</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.255.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.18.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.3.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.4.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/67729d5c413db75907f0ad1e39bb04b9c868ff60"><code>67729d5</code></a> Release 2.85.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/d247d7efe4dd236c2b4dee4c768ae8993e3df073"><code>d247d7e</code></a> Update wasmtime manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9197a82bb72ccea72eb87ca9bcf8dfeebceecb4a"><code>9197a82</code></a> Update zizmor manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/68f6cd570d5902077df155f8ef44867ad5f57fe7"><code>68f6cd5</code></a> Update <code>wasmtime@latest</code> to 47.0.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/377ee3f6a005506fab9f724afd7eae3134bc1154"><code>377ee3f</code></a> Update <code>uv@latest</code> to 0.12.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/8724fbfce1efccf3c603dcdece7882571347b0c7"><code>8724fbf</code></a> Update <code>rclone@latest</code> to 1.75.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/8d0062e663b7476d094ab4bc20c4436abdefb289"><code>8d0062e</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/28977a596b3205a34299d9607ece4eed2c6932eb"><code>28977a5</code></a> Update <code>kingfisher@latest</code> to 1.110.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/b951679bfc703a3cdad770a495203180e58aeb3d"><code>b951679</code></a> Update cargo-semver-checks manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/1beb33eee6d086258184383af9a538940be190ed"><code>1beb33e</code></a> Release 2.85.6</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.5...v2.85.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
ecde50eabe |
chore: bump taiki-e/install-action from 2.85.4 to 2.85.5 (#3716)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.4 to 2.85.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.5</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.17.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.16.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.5] - 2026-07-30</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.12.0.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.50.0.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.17.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.16.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/6a1bd70eaac3c8bdf093356838d7ee09fda951cf"><code>6a1bd70</code></a> Release 2.85.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/e55bdcf1dbf7a2b65f2a51365635e9b42fc25b1b"><code>e55bdcf</code></a> Update <code>uv@latest</code> to 0.12.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/360695b5ac7cbf7052eb841633b06cd5e5cf73cd"><code>360695b</code></a> Update <code>syft@latest</code> to 1.50.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9dfbbc2988d91169e4279461e8b23ade4a670b52"><code>9dfbbc2</code></a> Update <code>sccache@latest</code> to 0.17.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/acc58332f7353bf8d3e368d3838b46513a4a90cb"><code>acc5833</code></a> Update <code>mise@latest</code> to 2026.7.16</li> <li><a href="https://github.com/taiki-e/install-action/commit/deaa28d948b4684cf00f14feb5a9267ae3792577"><code>deaa28d</code></a> Update cargo-neat manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.4...v2.85.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1db305f32f |
ci: bump pinned cargo-affected 0.4.0 and worktrunk 0.71.0 (#3708)
## Summary Weekly CI pin check found the following drift (these `version:` strings are invisible to Dependabot — it follows `Cargo.toml` deps and `uses: foo@vN` refs, not inline pins): - `cargo-affected`: 0.3.2 → 0.4.0 (MSRV 1.94, compatible with our 1.96) — pinned twice in `affected.yaml` (`collect-affected` + `affected-tests`); both moved together. - `worktrunk`: 0.69.2 → 0.71.0 (MSRV 1.96, compatible with our 1.96) — the CI-installed `wt`, bumped to the current release; pinned in `ci.yaml` (×2) and `nightly.yaml`. ## Already up to date - `cargo-insta`: 1.48.0, `cargo-nextest`: 0.9.140, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `hustcer/setup-nu` (nushell): 0.114.1 - `zola`: 0.22.1 (taiki-e/install-action) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Notes - windows-2022 stays pinned (actions/runner-images#12677 — windows-2025 lacks the D: drive). - Both bumped tools' latest MSRVs are ≤ 1.96, so they stay compatible with the current toolchain. - **cargo-affected 0.4.0 DB compatibility:** the `cargo-affected-db-v1-*` cache marker in `affected.yaml` does **not** need bumping. The v0.3.2→v0.4.0 diff (`perf(collect): export each binary's coverage map once`, `Make status predict what run does`) touches `src/db.rs` only with `pub` → `pub(crate)` visibility changes — no SQLite schema change to the `fingerprint_components` / coverage tables — so an existing main DB deserializes unchanged. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
62cc0af7f8 |
chore: bump taiki-e/install-action from 2.85.3 to 2.85.4 (#3659)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.3 to 2.85.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.4</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.33.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.15.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.6.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.4] - 2026-07-29</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.33.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.15.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.6.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/065d6a08a14e61e89fb0a4c10eecdbdef39c7d8e"><code>065d6a0</code></a> Release 2.85.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/971197ad86f8f6f161d7a8d91f1d711c4c21f628"><code>971197a</code></a> Update <code>uv@latest</code> to 0.11.33</li> <li><a href="https://github.com/taiki-e/install-action/commit/3fc72354cdfd0f85327736793faab9b90a6282bb"><code>3fc7235</code></a> Update syft manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/7e230c19cf947f65a34e4e6f737c5f594c6779ba"><code>7e230c1</code></a> Update sccache manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/51f77e860854ede202e22ff29a94094601feca62"><code>51f77e8</code></a> Update <code>mise@latest</code> to 2026.7.15</li> <li><a href="https://github.com/taiki-e/install-action/commit/87ddca437422cbc964934ac7b2d8423c1838090a"><code>87ddca4</code></a> Update <code>biome@latest</code> to 2.5.6</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.3...v2.85.4">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f1923e9344 |
chore: bump taiki-e/install-action from 2.85.2 to 2.85.3 (#3649)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.2 to 2.85.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.3</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.2.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.14.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.13.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.3.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.3] - 2026-07-28</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.2.</p> </li> <li> <p>Update <code>ubi@latest</code> to 0.10.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.14.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.13.0.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.3.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/18b1216eba7f8039b0f8d131d5473787f0edce68"><code>18b1216</code></a> Release 2.85.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/3a7eb9d7de04335647f871d88d8831485be842be"><code>3a7eb9d</code></a> Update <code>xh@latest</code> to 0.26.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d4a0c1c709bc0f907c2a23b1a17cf6296b08298"><code>3d4a0c1</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/9e4a53cd83bbbd84b17bc14008d4b067b9e99edb"><code>9e4a53c</code></a> Update <code>ubi@latest</code> to 0.10.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/9f2f6a3c937466e1abfae58f471a04b8835bc6de"><code>9f2f6a3</code></a> Update <code>mise@latest</code> to 2026.7.14</li> <li><a href="https://github.com/taiki-e/install-action/commit/e026bd26eeb6a9542c62d43e1f98ced8d56ac346"><code>e026bd2</code></a> Update <code>martin@latest</code> to 1.13.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f72efa0e99d8d9c15bf7fa6f14f0d4eb369fd084"><code>f72efa0</code></a> Update <code>cargo-shear@latest</code> to 1.13.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/d19664f75e59dd9c49e306b357f78fcb72cd2711"><code>d19664f</code></a> Update <code>cargo-binstall@latest</code> to 1.21.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/4d9bbfb56af57e022493493eecb97d07bf4fddd5"><code>4d9bbfb</code></a> Update biome manifest</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.85.2...v2.85.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
8ef63150b6 |
chore: bump taiki-e/install-action from 2.85.0 to 2.85.2 (#3623)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.85.0 to 2.85.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.2</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.11.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.13.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.109.0.</p> </li> </ul> <h2>2.85.1</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.32.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.12.</p> </li> <li> <p>Update <code>cyclonedx@latest</code> to 0.33.1.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.2] - 2026-07-26</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.11.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.13.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.109.0.</p> </li> </ul> <h2>[2.85.1] - 2026-07-25</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.30.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.32.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.12.</p> </li> <li> <p>Update <code>cyclonedx@latest</code> to 0.33.1.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/41049aa56687c35e0afa74eed4f09cec4f9afabf"><code>41049aa</code></a> Release 2.85.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/dfcf36552b1b743e910b9b9b6b114a08e56a1e5e"><code>dfcf365</code></a> Update <code>prek@latest</code> to 0.4.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/eea03ccfa855b965a301aa52424915fddc32f855"><code>eea03cc</code></a> Update <code>mise@latest</code> to 2026.7.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/81ca2feb84748ed3fa514707ee1004f4f3ad715a"><code>81ca2fe</code></a> Update martin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/cc90ed04bc1a258ea90a83789f24b759a77c9671"><code>cc90ed0</code></a> Update <code>kingfisher@latest</code> to 1.109.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/55639a3362f508fda5154d3451072205f5c32ca6"><code>55639a3</code></a> Update cargo-shear manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d7d7cd5ac7f994c1892ae0c06165095b9139094"><code>3d7d7cd</code></a> Release 2.85.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/d09ccb4fe2105ac9ead6376f7a423ff88defeb57"><code>d09ccb4</code></a> Update <code>vacuum@latest</code> to 0.30.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/ac43dee1a92e482c0e244bdb0bb126908159e245"><code>ac43dee</code></a> Update <code>uv@latest</code> to 0.11.32</li> <li><a href="https://github.com/taiki-e/install-action/commit/49b16979f38f30e44b1f68af9115be9a6ffc5215"><code>49b1697</code></a> Update prek manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.85.0...v2.85.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
4202cffe61 |
fix(ci): split ci by cadence so coverage uploads on every main commit (#3608)
## What prompted this Getting #3605 green ran into codecov reporting a `base_commit` three commits older than the real merge-base. This audits whether our config causes that. ## The cause Codecov picks a PR's base by walking back to the newest ancestor that has a coverage report. It used the real merge-base for PRs #3480, #3532 and #3602, and a stale one for #3603 and #3605. The difference is whether the merge-base uploaded a report. **29 of the last 40 main commits did not.** `ci` had one concurrency group for main pushes, and GitHub cancels the *pending* run in a group whenever a newer one joins, even with `cancel-in-progress: false`. So the question is how long a run holds the group, and a run isn't done until its slowest job is: | job | duration on main | |-----|------------------| | `fast-checks` | 2 min | | `code-coverage` | 3-4 min | | `test (windows)` | 11 min | | `collect affected coverage (windows)` | 110-129 min | Each main run held the group for ~2 hours, so nearly every subsequent main push was cancelled while queued, taking the 4-minute coverage job with it. Every cancelled main run's `updated_at` lands within a second of the next push's `created_at`. The 2 hours is real work, not queue: 2-5s from `created_at` to `started_at`, then 108 minutes inside `cargo affected collect` — 4181 tests under `-C instrument-coverage` with a per-test LLVM profile, ~5 GB of profraw. ## The fix: one workflow per cadence The three groups of jobs have incompatible needs, and one group was serving all of them. | workflow | cadence on main | why | |----------|-----------------|-----| | `ci` | every commit, ~11 min | required gate + fast checks | | `coverage` | every commit, keyed per-sha | a skipped upload leaves later PRs on a stale base | | `affected` | sampled, ~2 h | a DB a few commits old still anchors a correct superset | `affected` keeps exactly the grouping it has today, so its sampling is unchanged and deliberate. It just no longer drags the other two along. ### Scope of the impact The posted `codecov/patch` check scopes to the PR's own GitHub diff, so a stale base did **not** score PRs against other people's lines. On #3605 the posted 91.66% is exactly `github.rs`'s 11/12, while the stale-base compare object reported 64/65 across 13 files. What a stale base costs: - `codecov/project` reports "compared to \<stale sha\>" - the patch `auto` target is the stale base's project coverage (0.02pp here) - the compare API object widens to `base..head`, which is what made the investigation look like silence Separately, `test`/`lint`/`fast-checks` also stopped completing on main. Nothing load-bearing rode on that (they already ran on the PR), but it left `tend-ci-fix` with nothing to watch, since it doesn't fire on cancelled runs. ## Two smaller fixes - `ignore: "**/tests/**"` compiles to `.*/tests/.*` (confirmed against codecov's validator), which needs a leading directory and so never matched `tests/` itself. Inert today since `cargo llvm-cov` reports only `src/` (verified against a downloaded `cobertura.xml`), but now correct if that changes. Now `tests/**`. - `fail_ci_if_error` gated on `github.repository_owner`, which is the *base* repo's owner on a fork PR too, so the soft-fail its comment describes never applied. It keys off the head repo now. ## Docs The API behaviour was ours to misuse, not codecov's to explain. Three traps, all confirmed against the live API: - `file_report/<path>/` 404s with `coverage info not found` because the route swallows the trailing slash into the path. Without it the endpoint returns `line_coverage`. - `?pullid=N` always compares the PR's **current** head. `?base=&head=` asks about an earlier commit. - the compare response has no `patch_totals` key, and `.name` is `{base, head}` rather than a string, so a filename lookup silently matches nothing. A working recipe already existed in `running-tend`, but that skill is scoped to CI. `tests/CLAUDE.md` owns coverage investigation, so the queries go there and `running-tend` points at them instead of keeping a second copy. Re-running the corrected query against #3605's failing commit reproduces the miss exactly: `src/git/remote_ref/github.rs:164`, the `gh repo set-default` hint, matching what the session eventually found by hand. ## This PR demonstrates it It changes no Rust at all, only YAML and markdown. Codecov still reported a **10-file, 111-line patch** on its first commit, because it based the comparison on `203603909` rather than the real merge-base `32f380a27`. Every main commit in between has no report: | commit | ci run | report | |--------|--------|--------| | `32f380a27` | queued | no | | `9645e3e13` | cancelled | no | | `bcd1ffdfd` | cancelled | no | | `8865f20ab` | cancelled | no | Every one of those 111 patch lines belongs to somebody else's merged commit. It passed at 100% only because those commits are well covered. > _This was written by Claude Code on behalf of @max-sixty_ --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
901b79ab52 |
ci: bump pinned worktrunk to 0.69.2 (#3612)
Weekly CI pin bump. Only `worktrunk` drifted since last week — every other `baptiste0928/cargo-install` pin (cargo-msrv `0.19.3`, cargo-llvm-cov `0.8.7`, cargo-insta `1.48.0`, cargo-nextest `0.9.140`, cargo-udeps `0.1.61`, lychee `0.24.2`), plus `setup-nu` `0.114.1` and `zola@0.22.1`, is already at the latest upstream release. - **worktrunk** `=0.68.0` → `=0.69.2` (3 sites: `ci.yaml` ×2, `nightly.yaml`) Compatibility: worktrunk `0.69.2` declares `rust-version = 1.96`, matching the pinned toolchain (`rust-toolchain.toml` channel `1.96.0`), so it builds under `baptiste0928/cargo-install`. MSRV/toolchain needed no bump this week: current stable is `1.97.1`, so latest−1 is `1.96`, which is already what `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` pin. Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
4ea2fe46a3 |
chore: bump taiki-e/install-action from 2.84.0 to 2.85.0 (#3570)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.84.0 to 2.85.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.85.0</h2> <ul> <li> <p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p> </li> <li> <p>Support <code>bpf-linker</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p> </li> <li> <p>Support <code>rafn</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>, thanks <a href="https://github.com/DarkWanderer"><code>@DarkWanderer</code></a>)</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.1.</p> </li> <li> <p>Update <code>zizmor@latest</code> to 1.28.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 47.0.2.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.31.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.49.0.</p> </li> </ul> <h2>2.84.1</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.254.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.30.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.11.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.5.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.85.0] - 2026-07-23</h2> <ul> <li> <p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p> </li> <li> <p>Support <code>bpf-linker</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p> </li> <li> <p>Support <code>rafn</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>, thanks <a href="https://github.com/DarkWanderer"><code>@DarkWanderer</code></a>)</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.1.</p> </li> <li> <p>Update <code>zizmor@latest</code> to 1.28.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 47.0.2.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.31.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.49.0.</p> </li> </ul> <h2>[2.84.1] - 2026-07-22</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 47.0.1.</p> </li> <li> <p>Update <code>wasm-tools@latest</code> to 1.254.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.30.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.11.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.5.0.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.5.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7572810d7dd469b651bb7793945692cf78da5dd7"><code>7572810</code></a> Release 2.85.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/d73fed906d8b5a8fbe1165c7635ef41dbf5e6ccd"><code>d73fed9</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/20d0440ac8346c2da5bfa9bc79b6d50c30ee7658"><code>20d0440</code></a> Support bpf-linker (<a href="https://redirect.github.com/taiki-e/install-action/issues/1950">#1950</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/05a01b63a23569d0bf6dde483954e312dce7d417"><code>05a01b6</code></a> Update vacuum manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/23a3cce147f42d0975d244f68a4af961ccd8fd53"><code>23a3cce</code></a> Update <code>cargo-neat@latest</code> to 0.5.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/54ede987e296f0fc0b43f3f75d496577fad36a9c"><code>54ede98</code></a> Support rafn (<a href="https://redirect.github.com/taiki-e/install-action/issues/1935">#1935</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/411aa4ba3c7fb6ad60a7421c46e881a3a1ceb8ad"><code>411aa4b</code></a> Support wild (<a href="https://redirect.github.com/taiki-e/install-action/issues/1949">#1949</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/4427ee328dd40578670ed6724b4a766207e21f0e"><code>4427ee3</code></a> Update <code>zizmor@latest</code> to 1.28.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/68a5a96ea71119471050840e296140c66135d7b8"><code>68a5a96</code></a> Update <code>wasmtime@latest</code> to 47.0.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/f276a80345c4641da04f6613887cc496c332c232"><code>f276a80</code></a> Update <code>uv@latest</code> to 0.11.31</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.84.0...v2.85.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
89b58e2522 |
chore: bump taiki-e/install-action from 2.83.3 to 2.84.0 (#3529)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.83.3 to 2.84.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.84.0</h2> <ul> <li> <p>Support <code>d2</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p> </li> <li> <p>Support <code>protoc-gen-connect-openapi</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>, thanks <a href="https://github.com/JasterV"><code>@JasterV</code></a>)</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.0. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>, thanks <a href="https://github.com/graelo"><code>@graelo</code></a>)</p> </li> <li> <p>Update <code>just@latest</code> to 1.57.0.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.4.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.2.</p> </li> </ul> <h2>2.83.4</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.10.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.29.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.10.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.7.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.84.0] - 2026-07-20</h2> <ul> <li> <p>Support <code>d2</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p> </li> <li> <p>Support <code>protoc-gen-connect-openapi</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>, thanks <a href="https://github.com/JasterV"><code>@JasterV</code></a>)</p> </li> <li> <p>Update <code>convco@latest</code> to 0.7.0. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>, thanks <a href="https://github.com/graelo"><code>@graelo</code></a>)</p> </li> <li> <p>Update <code>just@latest</code> to 1.57.0.</p> </li> <li> <p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.2.4.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.2.</p> </li> </ul> <h2>[2.83.4] - 2026-07-17</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.10.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.29.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.10.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.7.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/a6b2e2dcd845ddd7f509ce4f3ed3d922b80cc5d9"><code>a6b2e2d</code></a> Release 2.84.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/fbdd9c50c029b1f2d5667c090563e4a31cc3f43c"><code>fbdd9c5</code></a> Update cargo-neat manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/424c5f90440984601897d473b7936cc3fd52bda8"><code>424c5f9</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/a1fa02c1f9b8ef65d443ad6b3f0b99f5863b6f4f"><code>a1fa02c</code></a> Support <code>protoc-gen-connect-openapi</code> (<a href="https://redirect.github.com/taiki-e/install-action/issues/1922">#1922</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/9e22773f98774c41688b7cc39a5f7f7eaa4ca97d"><code>9e22773</code></a> Update DEVELOPMENT.md</li> <li><a href="https://github.com/taiki-e/install-action/commit/8d5009fee2da9de26fee96bb727c2df318ffce42"><code>8d5009f</code></a> Support d2</li> <li><a href="https://github.com/taiki-e/install-action/commit/5193316cc852ca0f37d4819875e939522c4f7c47"><code>5193316</code></a> Update <code>tombi@latest</code> to 1.2.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/4c740c71c8320819d812216022c3ff178e1a3394"><code>4c740c7</code></a> Update <code>tombi@latest</code> to 1.2.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/de240ff26f6e8b33bacd85a1a7c621c92d8d7c70"><code>de240ff</code></a> Update <code>just@latest</code> to 1.57.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dfca8548668aebabd66da598ea31d87a03819d43"><code>dfca854</code></a> Update <code>cargo-semver-checks@latest</code> to 0.49.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.83.3...v2.84.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
99704db62f |
chore: bump taiki-e/install-action from 2.83.2 to 2.83.3 (#3497)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.83.2 to 2.83.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.83.3</h2> <ul> <li> <p>Update <code>release-plz@latest</code> to 0.3.160.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.9.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.6.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.2.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.4.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.83.3] - 2026-07-16</h2> <ul> <li> <p>Update <code>release-plz@latest</code> to 0.3.160.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.9.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.6.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.2.</p> </li> <li> <p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.4.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/ed67fa35ac944f3a9b33f12c4dd43b6f31a47e20"><code>ed67fa3</code></a> Release 2.83.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/618fa5589cc587c869ec39ae0606a6cf6ef03c0b"><code>618fa55</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/47579092c792f14738b668ee240d199bcad0d8e2"><code>4757909</code></a> Update zizmor manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/f1fa00538cc2e7231cb60e4d47c24597e0c387b7"><code>f1fa005</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/aa8dc906017e56077bc125256c4d9301b1cde72a"><code>aa8dc90</code></a> Update <code>release-plz@latest</code> to 0.3.160</li> <li><a href="https://github.com/taiki-e/install-action/commit/b9654978ff643e657a453245addf012127caa2c5"><code>b965497</code></a> Update <code>prek@latest</code> to 0.4.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/7aab3a9c373d60a23a5b89c212174c0baa6a0fa0"><code>7aab3a9</code></a> Update <code>mise@latest</code> to 2026.7.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/bfee8d1ca4d6f82a5c3f7151f046e75e6c202ff5"><code>bfee8d1</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/b65771b2e228b44f33eb596fbf78979075cd8aa7"><code>b65771b</code></a> Update <code>dprint@latest</code> to 0.55.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/20468927b3c1d5f14e6c4c1379ced0c6cc1ed103"><code>2046892</code></a> Update <code>cargo-dinghy@latest</code> to 0.8.5</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.83.2...v2.83.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
5967df2dfc | chore(ci): weekly renovation 2026-07-19 (#3518) | ||
|
|
0a1cd19cc9 |
chore: drop the NEXTEST_NO_INPUT_HANDLER workaround (#3482)
nextest#2878 (the run suspending with SIGTTOU when a test spawns an interactive shell, as the `shell-integration-tests` feature does) was fixed in nextest 0.9.118, so the `NEXTEST_NO_INPUT_HANDLER=1` workaround threaded through the insta hook, CI, and the test docs is obsolete. Verified on nextest 0.9.132: the shell-wrapper tests run to completion under a real PTY without the variable. `.config/nextest.toml` now pins `nextest-version = "0.9.118"`, so an older nextest fails with a clear version error instead of suspending mid-run. > _This was written by Claude Code on behalf of max_ --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
334b9c6165 |
chore: bump taiki-e/install-action from 2.83.0 to 2.83.2 (#3444)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.83.0 to 2.83.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.83.2</h2> <ul> <li> <p>Update <code>parse-dockerfile@latest</code> to 0.1.8.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.5.</p> </li> <li> <p>Update <code>just@latest</code> to 1.56.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.4.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.4.1.</p> </li> </ul> <h2>2.83.1</h2> <ul> <li> <p>Update <code>rclone@latest</code> to 1.74.4.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.4.</p> </li> <li> <p>Update <code>cargo-deny@latest</code> to 0.20.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.83.2] - 2026-07-12</h2> <ul> <li> <p>Update <code>parse-dockerfile@latest</code> to 0.1.8.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.5.</p> </li> <li> <p>Update <code>just@latest</code> to 1.56.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.4.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.4.1.</p> </li> </ul> <h2>[2.83.1] - 2026-07-10</h2> <ul> <li> <p>Update <code>rclone@latest</code> to 1.74.4.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.4.</p> </li> <li> <p>Update <code>cargo-deny@latest</code> to 0.20.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/43aecc8d72668fbcfe75c31400bc4f890f1c5853"><code>43aecc8</code></a> Release 2.83.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/fca47892c74f4dffa1e86ad93eca31cf898c2541"><code>fca4789</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/b41cc1f9ab348b9db341d8597853df93b08652f0"><code>b41cc1f</code></a> Update <code>parse-dockerfile@latest</code> to 0.1.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/8d866f8ca86db77044d7d29639e24660d0b37b88"><code>8d866f8</code></a> Update <code>mise@latest</code> to 2026.7.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/7ebe462223a33af951eed3c3ab1f754ddf2992e2"><code>7ebe462</code></a> Update <code>just@latest</code> to 1.56.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/01ab5633b01b19988c158b5366d64947fd6cacce"><code>01ab563</code></a> Update <code>gungraun-runner@latest</code> to 0.19.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/f164a682e7e0033cf72f1d5722d079fe82275c1e"><code>f164a68</code></a> Update <code>cargo-neat@latest</code> to 0.4.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/2ca9b94c269419b7b0c711c09d0b21c4e1d51145"><code>2ca9b94</code></a> Release 2.83.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/8598f86981150fb7f6511798af658bbf80a8ea46"><code>8598f86</code></a> Update parse-dockerfile manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/76cfe4de2d710e12bae93580164f20dff9fd96e9"><code>76cfe4d</code></a> Update <code>rclone@latest</code> to 1.74.4</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.83.0...v2.83.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
d7e3aac9a0 | ci: bump pinned tool versions (cargo-nextest, worktrunk, nushell) (#3429) | ||
|
|
fbf380b447 |
chore: bump taiki-e/install-action from 2.82.11 to 2.83.0 (#3405)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.11 to 2.83.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.83.0</h2> <ul> <li> <p>Support <code>cargo-about</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1924">#1924</a>, thanks <a href="https://github.com/ruffsl"><code>@ruffsl</code></a>)</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.28.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.12.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.106.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.3.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.83.0] - 2026-07-09</h2> <ul> <li> <p>Support <code>cargo-about</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1924">#1924</a>, thanks <a href="https://github.com/ruffsl"><code>@ruffsl</code></a>)</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.28.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.12.0.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.106.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.3.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/c7eb1735f09259a5035e8e5d44b1406b1cddc0fb"><code>c7eb173</code></a> Release 2.83.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/84d4171800adc3ccfe039969324217bde4ca0f25"><code>84d4171</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/21e5d859bea44c4a9c990a48a63fed2203e01d68"><code>21e5d85</code></a> Support cargo-about (<a href="https://redirect.github.com/taiki-e/install-action/issues/1924">#1924</a>)</li> <li><a href="https://github.com/taiki-e/install-action/commit/786ded99bea7500a913f1f19b18bfcfdf782fb97"><code>786ded9</code></a> Update <code>uv@latest</code> to 0.11.28</li> <li><a href="https://github.com/taiki-e/install-action/commit/1c1bbcf779fa11c2ef8cf0bda69bba43465230e6"><code>1c1bbcf</code></a> Update rclone manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/4e5eb09101d68b0b5f52740d1abc011ae003ac6f"><code>4e5eb09</code></a> Update <code>martin@latest</code> to 1.12.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/dc84fc5f1a7ad878e27656eb3ed173e393c62867"><code>dc84fc5</code></a> Update <code>kingfisher@latest</code> to 1.106.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/cf10e546be4ee50afcfd94a851bcd9eb64cba30d"><code>cf10e54</code></a> Update <code>biome@latest</code> to 2.5.3</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.82.11...v2.83.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c8de0d872a |
ci: move lychee link check to the nightly workflow (#3402)
Moves the lychee link check out of PR CI into the `nightly` workflow. Link health depends on external sites (429s, bot-blocking, link rot), which made `lint` the flakiest PR check, and breakage isn't correlated with the PR that trips it: the most recent main run's lint job went red on the docs.anthropic.com restructure (fixed in #3399) with no code change involved. The hook stays defined once in `.pre-commit-config.yaml`, moved to the `manual` stage, so the PR `lint` job, local `pre-commit run --all-files`, and the `wt merge` gate all skip it (the wt.toml Windows conditional existed only to skip lychee and collapses). The new `link-check` nightly job runs that stage with the pinned lychee and is wired into `create-issue-on-nightly-failure`, so breakage lands in the nightly-failure issue for tend instead of blocking unrelated PRs. Running through pre-commit rather than `git ls-files | xargs lychee` keeps file selection at one definition: pre-commit's `types: [file]` filter excludes the 16 tracked `.md`/`.txt` symlinks, which would otherwise false-positive on relative links resolved against the symlink's directory. The trade: a PR that introduces a genuinely wrong URL now merges green and is caught up to a day later, asynchronously. Verified locally that the default stage no longer selects the hook and that `pre-commit run lychee-system --all-files --hook-stage manual` reproduces the CI lint run's selection exactly (same two flagged inputs). The nightly job itself first runs on the next cron or a `workflow_dispatch`. > _This was written by Claude Code on behalf of max_ Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
b4aba5c4a3 |
chore: bump taiki-e/install-action from 2.82.9 to 2.82.11 (#3387)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.9 to 2.82.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.11</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.253.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.27.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.2.</p> </li> <li> <p>Update <code>mdbook@latest</code> to 0.5.4.</p> </li> </ul> <h2>2.82.10</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.2.0.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.140.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.11] - 2026-07-08</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.253.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.27.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.2.</p> </li> <li> <p>Update <code>mdbook@latest</code> to 0.5.4.</p> </li> </ul> <h2>[2.82.10] - 2026-07-07</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.2.0.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.140.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/5ebac0d9522d786674368e47e92963ba13f2c376"><code>5ebac0d</code></a> Release 2.82.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/0ef1b06f246983bfc9b14d94cff7855d90529e46"><code>0ef1b06</code></a> Update <code>wasm-tools@latest</code> to 1.253.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/78ce37c0ce7da0b633b3ee9a800d18e6d4fb11e7"><code>78ce37c</code></a> Update <code>mise@latest</code> to 2026.7.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/080cc5c6de6a4709eb3c099c56ad225fa3db5492"><code>080cc5c</code></a> Update wasm-tools manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/c870c7a1dbaa5d99671937765392df21151c7808"><code>c870c7a</code></a> Update <code>uv@latest</code> to 0.11.27</li> <li><a href="https://github.com/taiki-e/install-action/commit/dcc765d42b0daa9842059edfb11fda14143027e2"><code>dcc765d</code></a> Update <code>mise@latest</code> to 2026.7.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/98fa0bac11003b6f1143fd1634b47d42624003b2"><code>98fa0ba</code></a> Update <code>mdbook@latest</code> to 0.5.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/544756b7938b454b9339922116f9f21301cc8169"><code>544756b</code></a> Update martin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/116765984988a711571bdb8292667a67de89b08e"><code>1167659</code></a> Update kingfisher manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/ca5e0a7228a263c12320511f1b10890972a12bbc"><code>ca5e0a7</code></a> Update biome manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.9...v2.82.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
c9044d01b5 |
chore: bump taiki-e/install-action from 2.82.7 to 2.82.9 (#3375)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.7 to 2.82.9. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.9</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.9.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.8.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.0.</p> </li> <li> <p>Update <code>cargo-leptos@latest</code> to 0.3.7.</p> </li> </ul> <h2>2.82.8</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.8.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.26.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.72.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.7.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.0.</p> </li> <li> <p>Update <code>just@latest</code> to 1.55.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.9] - 2026-07-05</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.9.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.8.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.37.0.</p> </li> <li> <p>Update <code>cargo-leptos@latest</code> to 0.3.7.</p> </li> </ul> <h2>[2.82.8] - 2026-07-03</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.8.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.26.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.72.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.7.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.7.0.</p> </li> <li> <p>Update <code>just@latest</code> to 1.55.1.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.2.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/4684b8405694ae9dd42c9f39ba901a70ae83f4a3"><code>4684b84</code></a> Release 2.82.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/29fb1dbe52c0247f03f90f9dd43b08d3c603510b"><code>29fb1db</code></a> Update <code>vacuum@latest</code> to 0.29.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/584230b16680bbb1ddef3c65a89568570fd36f69"><code>584230b</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/1872019a1c4268421e4c2d5f230285190a08b258"><code>1872019</code></a> Update <code>prek@latest</code> to 0.4.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/3e817d29dde43a866e242560569eb7f418035f1a"><code>3e817d2</code></a> Update <code>cargo-tarpaulin@latest</code> to 0.37.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/a71dd1a66df622ab4134f69df1b8c4b7a8889ddf"><code>a71dd1a</code></a> Update <code>cargo-leptos@latest</code> to 0.3.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/c93ccc03e00cd0e08e494f5fd058a6c55a6a1907"><code>c93ccc0</code></a> Release 2.82.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/5083f1886534d6d96c49df934ae7106b35fd488e"><code>5083f18</code></a> Update <code>vacuum@latest</code> to 0.29.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/fdd68a857612ac3f29f4abaa6be9f4d379946632"><code>fdd68a8</code></a> Update <code>uv@latest</code> to 0.11.26</li> <li><a href="https://github.com/taiki-e/install-action/commit/3b61d4b2086bc6aee10b8e58f1e6a25675e03da4"><code>3b61d4b</code></a> Update <code>typos@latest</code> to 1.48.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.7...v2.82.9">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
0beeb3b738 | chore(ci): weekly renovation 2026-07-05 (#3368) | ||
|
|
9478fc6675 |
chore: bump taiki-e/install-action from 2.82.6 to 2.82.7 (#3342)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.6 to 2.82.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.7</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.1.6.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.105.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.3.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.8.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.36.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.7] - 2026-06-30</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.1.6.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.105.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.3.</p> </li> <li> <p>Update <code>editorconfig-checker@latest</code> to 3.8.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.1.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.36.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/16b05812d776ae1dfaabc8277e421fb6d2506419"><code>16b0581</code></a> Release 2.82.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/68c845308d9b56d38e797c62e48eddfe1b4ba94f"><code>68c8453</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/8532697fda4ee37ccd65901e90d87a785c45d7bd"><code>8532697</code></a> Update trivy manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/2959f9e73b89d18f2d72d0aa55ed797e70062732"><code>2959f9e</code></a> Update <code>tombi@latest</code> to 1.1.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/9bfa119f6c347b458726d629758b16dd861727a4"><code>9bfa119</code></a> Update <code>kingfisher@latest</code> to 1.105.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f198b91ffb69aa6008cb3b0ea9cf6eb6b0af01f4"><code>f198b91</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/20feedd5827d6d189bca20753dbd5582948e7478"><code>20feedd</code></a> Update <code>gungraun-runner@latest</code> to 0.19.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/314197aa953241335b4a4c41c2d6e8066d6150da"><code>314197a</code></a> Update <code>editorconfig-checker@latest</code> to 3.8.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f8632ebbd28b43dce012ff3db91c959c7751db33"><code>f8632eb</code></a> Update <code>dprint@latest</code> to 0.55.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/4234dc0f7acb7e7774a1716b103fcaf2d9ed9b4d"><code>4234dc0</code></a> Update <code>cargo-tarpaulin@latest</code> to 0.36.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.6...v2.82.7">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
fb20a315a1 |
ci: split fast checks from the full suite; add nightly full-tests safety net (#3332)
Prep work toward making the advisory `cargo-affected` legs the PR test path, without flipping any merge gate yet. ## What changed - **`ci.yaml`** — the `test (linux/macos/windows)` job bundled five gates through one `wt hook pre-merge` call. Split the platform-independent ones — `Cargo.lock` freshness, doctests, and the rustdoc `-Dwarnings` build — into a new Linux-only `fast-checks` job. `test` now runs *only* the full nextest suite (`insta`), so it's a clean drop-in shape for the affected legs later. `fast-checks` stays required and unchanged across the eventual flip. - **`nightly.yaml`** — added a `full-tests` matrix job (linux/macos/windows, the full suite). This is the safety net for what cargo-affected can't cover: tests it under-selects, plus non-Rust/build inputs it can't trace (`include_str!`, templates, `build.rs`, toolchain, proc-macros). It also hosts the Linux `--unreferenced reject` orphan check. It runs on nightly cron, the `nightly` label, dispatch, and dep-pushes — deliberately **not** on the main-gating path, so a cargo-affected miss surfaces in nightly (non-blocking, Tend-fixable) rather than reddening main. Nothing is gated by the affected legs yet; `test (*)` stays the required PR gate during calibration. The flip (make affected required, delete the PR `test` job) is a later, separate change — documented in the `ci.yaml` comment block. ## ⚠️ Branch-protection follow-up Splitting `lockfile`/`doctest`/`doc` out of the required `test` job means **`fast-checks` must be added to the required status checks** (the "Merge access" ruleset). Until it is, those three gates don't block PRs. This is an admin action that should accompany the merge. ## Testing CI-config only; validated with `actionlint` and pre-commit (yaml/eof/whitespace/typos). The workflow behavior itself validates on this PR's run. > _This was written by Claude Code on behalf of max_ Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
16027a6a58 |
fix(ci): install zsh/fish via apt-get, drop cache-apt-pkgs-action (#3324)
## What this does Removes the third-party `awalsh128/cache-apt-pkgs-action` from CI entirely, installing zsh + fish with a plain `sudo apt-get update && sudo apt-get install -y zsh fish` at all four call sites: - `ci.yaml` — `code-coverage` - `nightly.yaml` — `feature-powerset` and `benchmarks` - `.github/actions/test-setup/action.yaml` — composite action used by the required `test` matrix It also drops the Dependabot `ignore` entry for the action (no longer needed once the action is gone). ## Why (and why this supersedes #3321) `awalsh128/cache-apt-pkgs-action@v1.6.2` (dependabot bump #3311) empties its own `packages: zsh fish` argument in the "Normalizing package list" step and aborts with `Packages argument is empty`, in ~20s, before any compilation — killing `code-coverage` on every PR, which in turn stopped `codecov/patch` from posting anywhere. Root cause is upstream PR #177 quoting `${packages}`, tracked at [awalsh128/cache-apt-pkgs-action#210](https://github.com/awalsh128/cache-apt-pkgs-action/issues/210). #3321 already fixed main by pinning back to `v1.6.1`. This PR takes the sturdier route — dropping the dependency — based on the upstream's health: - Issue #210 is open with **no maintainer engagement**; affected users call the action "basically non-functional," with a fresh repro confirmed on 2026-06-29. - **No open PR** reverts #177 or fixes the regression; v1.6.2 (broken) is still tagged `Latest`, and contributor PRs sit unmerged for months. - The action's mutable `v1`/`latest` tags are actively being retargeted upstream (open PR #211), which is how a `@v1.6.1` ref can resolve to drifted code — so even the pin isn't a stable anchor. `zsh` and `fish` are in the standard Ubuntu repos (no PPA), so the action only *cached* an install of two tiny packages — a negligible speed-up for a third-party dependency that is under-maintained, broke CI repo-wide, and can't be stably pinned. Dropping it removes the whole failure class and matches the existing `musl-tools` install already in `nightly.yaml`. Verified: the identical `apt-get` step already runs green in the required `test (linux)` job (installs zsh 5.9 + fish 3.7.0), and a full `code-coverage` run on this branch completed green end-to-end with `codecov/patch` posting again. ## Guard against recurrence #3311 merged while its own `code-coverage` was red because `code-coverage`/`codecov/patch` aren't *required* status checks (only `test (linux/macos/windows)` are), and `codecov/patch` was absent rather than red (the job died before uploading), so the mechanical-bump merge saw nothing blocking. Recommended guard: make the `code-coverage` job a required status check — it fails only on genuine breakage (the codecov upload already soft-fails on fork PRs), so it blocks this class without re-introducing the flake that keeps `codecov/patch` itself advisory. > _This was written by Claude Code on behalf of max_ Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
225b232b51 |
ci: gate rust caches to main and share one per OS to fit the 10 GB cap (#3323)
## What The Actions cache sat at **11.1 GB across 57 caches** against GitHub's hard **10 GB per-repo cap**, so every run was evicting older caches LRU-style — constant churn. ~57% of that was single-PR caches (`refs/pull/N/merge`) that no other PR can ever restore, depositing budget that evicted the reusable `main` caches. ## Changes - **`save-if` gated to `main` on every rust-cache call.** PRs restore `main`'s cache via the restore-key fallback and never deposit their own. This alone drops the footprint under the cap. - **One shared cache per OS for the test family.** `test-setup` now sets `shared-key`, with `test` as the sole saver (new `save-cache` input, default `true`); `affected-tests` / `collect-affected` / `release-target` pass `save-cache: "false"`. The PR-only `affected-tests` job needed this most — it never runs on `main`, so a per-job key had no baseline and cold-built every PR; it now rides `test`'s `main` cache. - **Nightly/release jobs stop saving.** Stable ones (`feature-powerset`, `benchmarks`, `crate-build`) restore the shared cache read-only; the nightly-toolchain ones (`check-unused`, `minimal-versions`) and the cross-target `release-target` just don't save — near-zero reuse against the cap. - **`cache-bin: false` applied to the v0 jobs too** (`lint`, `feature-check`, `msrv`, `code-coverage`), closing the latent rustup-proxy bug that `test-setup` already guarded against. ## Deliberate non-changes - `lint` / `feature-check` / `code-coverage` keep their own `main`-gated caches rather than joining the shared one. They build divergent artifacts (clippy-check, `--no-default-features`, coverage-instrumented), and we're no longer space-constrained after the above — a right-sized own cache beats a 1.3 GB restore for partial reuse. - Did **not** add PRQL's `Cargo.lock`-hash-in-prefix-key: rust-cache already keys on the lockfile, and `save-if: main` already prevents the PR-junk accumulation that trick fights (one mechanism per guarantee). - The `awalsh128/cache-apt-pkgs-action` stays pinned at `v1.6.1` (per #3321, merged into this branch) — not replaced. Only `Swatinem/rust-cache` config changes here. Projected active cache: **~3–5 GB**, all `main`-scoped. No `wt` behavior change, so no changelog entry. > _This was written by Claude Code on behalf of max_ --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|
|
7daa0763d7 |
fix(ci): pin cache-apt-pkgs-action back to v1.6.1 (#3321)
## Problem CI on `main` fails in the required `code-coverage` job ([failed run](https://github.com/max-sixty/worktrunk/actions/runs/28358354325)). The `Install shells (zsh, fish)` step aborts: ``` PACKAGES: zsh fish Normalizing package list... Validating action arguments (version='1', packages='')... exit status 100Packages argument is empty. ##[error]Process completed with exit code 3. ``` This is a deterministic regression in `awalsh128/cache-apt-pkgs-action@v1.6.2`, introduced by the bump in #3311. v1.6.2's new "Normalize package list" step turns the input `zsh fish` into an empty string before validation. Upstream root cause: PR #177 added quotes around `${packages}` in `get_normalized_package_list`, so `apt_query` treats the entire space-separated list as one package name and the normalization yields nothing — tracked at [awalsh128/cache-apt-pkgs-action#210](https://github.com/awalsh128/cache-apt-pkgs-action/issues/210). v1.6.2 is still the latest release with no fix. #3311 bumped three of the four call sites (`ci.yaml` `code-coverage`, two in `nightly.yaml`); `.github/actions/test-setup/action.yaml` was never bumped and stayed on v1.6.1 — which is why test-setup-based jobs passed while `code-coverage` failed. ## Solution Revert the three v1.6.2 references to v1.6.1, the known-good version the test-setup action already uses, so all four sites are consistent again. Also add a Dependabot `ignore` for v1.6.2 of this action so the daily github-actions update doesn't immediately re-create the same broken bump; the entry is scoped to that one version, so Dependabot can bump forward once a fixed release ships. This is the right level: the failure is entirely upstream, the fix matches the existing precedent (#2583 pinned this action), and pinning back is a clean revert rather than a workaround layered on a broken release. ## Testing The fix is a CI-config change; correctness is verified by CI itself re-running the `code-coverage` job with v1.6.1. The v1.6.1 path is already exercised by every existing run via `test-setup`, which never failed on this step. Note: the advisory (non-required) `collect affected coverage (windows)` leg in the failed run also failed, on an unrelated PTY flake (`test_switch_picker_create_validates_templates_before_worktree`) — a separate known-flaky Windows shell-integration test, not caused by this commit and not addressed here. --- Automated fix for [failed run](https://github.com/max-sixty/worktrunk/actions/runs/28358354325) Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
b7cf4f0cf0 |
chore: bump taiki-e/install-action from 2.82.4 to 2.82.6 (#3312)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.4 to 2.82.6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.6</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.7.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.25.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.46.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.0.</p> </li> <li> <p>Update <code>cargo-auditable@latest</code> to 0.7.5.</p> </li> </ul> <h2>2.82.5</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 46.0.1.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.126.</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.29.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.14.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.1.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.6] - 2026-06-29</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.7.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.25.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.46.0.</p> </li> <li> <p>Update <code>dprint@latest</code> to 0.55.0.</p> </li> <li> <p>Update <code>cargo-auditable@latest</code> to 0.7.5.</p> </li> </ul> <h2>[2.82.5] - 2026-06-26</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 46.0.1.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.126.</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.29.6.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.14.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.1.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/9bcaee1dcae34154180f412e2fa69355a7cda9f6"><code>9bcaee1</code></a> Release 2.82.6</li> <li><a href="https://github.com/taiki-e/install-action/commit/e43cd7ce2e2c5a6d08d652405a0ead8cda7bf2db"><code>e43cd7c</code></a> Update <code>vacuum@latest</code> to 0.29.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/3761407ad0b5e4e5b42ccb62e48ffa2712e94703"><code>3761407</code></a> Update <code>uv@latest</code> to 0.11.25</li> <li><a href="https://github.com/taiki-e/install-action/commit/cb6ad0dba1ff078e589e75ae88bb03120688feef"><code>cb6ad0d</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/6022671c93f20efad71663e3adc06d63e7f1ec8a"><code>6022671</code></a> Update <code>syft@latest</code> to 1.46.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/ab5aae8354703341b0939f4e6c1bb66372b446db"><code>ab5aae8</code></a> Update gungraun-runner manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/867613b49949fba1c8fe194d323c7c51b77b24d2"><code>867613b</code></a> Update editorconfig-checker manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/c5837ef63439ac9ebc0ecce97e23cca6a4a5aac4"><code>c5837ef</code></a> Update <code>dprint@latest</code> to 0.55.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/7d41d74582778d0345db89bc1054e86f3802b6d2"><code>7d41d74</code></a> Update <code>cargo-auditable@latest</code> to 0.7.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/bffeee26d4db9be238a4ea78d8826604ebcb594d"><code>bffeee2</code></a> Release 2.82.5</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.4...v2.82.6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
1c31672a62 |
chore: bump awalsh128/cache-apt-pkgs-action from 1.6.1 to 1.6.2 (#3311)
Bumps [awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action) from 1.6.1 to 1.6.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/awalsh128/cache-apt-pkgs-action/releases">awalsh128/cache-apt-pkgs-action's releases</a>.</em></p> <blockquote> <h2>v1.6.2</h2> <h2>What's Changed</h2> <ul> <li>Apply PR <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/193">#193</a> dependency pinning to <code>action.yml</code> (overwrite current action refs) by <a href="https://github.com/awalsh128"><code>@awalsh128</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/201">awalsh128/cache-apt-pkgs-action#201</a></li> <li>install_and_cache_pkgs.sh: Fix two issues saving preinst and postinst scripts. by <a href="https://github.com/gtjoseph"><code>@gtjoseph</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/195">awalsh128/cache-apt-pkgs-action#195</a></li> <li>[WIP] Fix test workflows for actions by <a href="https://github.com/awalsh128"><code>@awalsh128</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/184">awalsh128/cache-apt-pkgs-action#184</a></li> <li>Fix apt-cache package lookup failure in nektos/act environments by <a href="https://github.com/awalsh128"><code>@awalsh128</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/172">awalsh128/cache-apt-pkgs-action#172</a></li> <li>add shellcheck linting by <a href="https://github.com/mac-anysphere"><code>@mac-anysphere</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/177">awalsh128/cache-apt-pkgs-action#177</a></li> <li>Harden <code>apt_query</code> virtual package resolution against <code>apt-cache showpkg</code> warnings by <a href="https://github.com/awalsh128"><code>@awalsh128</code></a> with <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/202">awalsh128/cache-apt-pkgs-action#202</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/gtjoseph"><code>@gtjoseph</code></a> made their first contribution in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/195">awalsh128/cache-apt-pkgs-action#195</a></li> <li><a href="https://github.com/mac-anysphere"><code>@mac-anysphere</code></a> made their first contribution in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/177">awalsh128/cache-apt-pkgs-action#177</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2">https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/5513791f75b039e2a79653b1a92238d3fb8d99b4"><code>5513791</code></a> fix: handle apt showpkg warnings</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/fe5b289324486feb07d9025df8e9238a624f28d8"><code>fe5b289</code></a> test: add apt warning regression coverage</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/e58a49f1deb2c70b97469d56a30a7a344b7cdf25"><code>e58a49f</code></a> add shellcheck linting</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/599df6ec23f0ff55f24e458f4092a0264e02a1c9"><code>599df6e</code></a> Fix apt-cache package lookup failure in nektos/act environments (<a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/172">#172</a>)</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/cd5ee21d96e6e91cfd14e1b6437aa31ae6b1026d"><code>cd5ee21</code></a> [WIP] Fix test workflows for actions (<a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/184">#184</a>)</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/c0e0741be64938eb55bb4e1831c6eaab079ca3b6"><code>c0e0741</code></a> install_and_cache_pkgs.sh: Fix two issues saving preinst and postinst scripts...</li> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/497648d2e1b97f712a3941670092a4a578235fe2"><code>497648d</code></a> Apply PR <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/193">#193</a> dependency pinning to <code>action.yml</code> (overwrite current action re...</li> <li>See full diff in <a href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
93325018af | chore(ci): weekly renovation 2026-06-28 (#3284) | ||
|
|
0b0f10497d |
chore: bump taiki-e/install-action from 2.82.3 to 2.82.4 (#3255)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.3 to 2.82.4. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.4</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.24.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.13.</p> </li> <li> <p>Update <code>just@latest</code> to 1.54.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.4] - 2026-06-25</h2> <ul> <li> <p>Update <code>uv@latest</code> to 0.11.24.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.13.</p> </li> <li> <p>Update <code>just@latest</code> to 1.54.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/682e7d9e49c5e653d371fc6adbda67653461378a"><code>682e7d9</code></a> Release 2.82.4</li> <li><a href="https://github.com/taiki-e/install-action/commit/88e83503037db61d4f066a4d9cb32e6fc06b70c2"><code>88e8350</code></a> Update wasmtime manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/cf0e00b44cf05faddafcc8082c6c2366e2a02380"><code>cf0e00b</code></a> Update wasm-bindgen manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/a130ea674166df9065f363cbb53f1f2bc4a6298c"><code>a130ea6</code></a> Update vacuum manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/0bdcc65dc21d0ae46842dc5ad063d69ce8991365"><code>0bdcc65</code></a> Update <code>uv@latest</code> to 0.11.24</li> <li><a href="https://github.com/taiki-e/install-action/commit/3f52215559b820ee57b68e3fa9b38f6cd205e9c8"><code>3f52215</code></a> Update <code>mise@latest</code> to 2026.6.13</li> <li><a href="https://github.com/taiki-e/install-action/commit/294a073b0ebe66401c699c21b98e9ecb5a6da735"><code>294a073</code></a> Update <code>just@latest</code> to 1.54.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/f9bf24932b3cbfe7ae26b5addcd257989e14ec4d"><code>f9bf249</code></a> Update cargo-rdme manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/98288d38cbfc5fa065ff61c6971d50dc3ba7d408"><code>98288d3</code></a> Update <code>biome@latest</code> to 2.5.1</li> <li>See full diff in <a href="https://github.com/taiki-e/install-action/compare/v2.82.3...v2.82.4">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
daf432666c |
chore: bump taiki-e/install-action from 2.82.2 to 2.82.3 (#3190)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.2 to 2.82.3. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.3</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.26.1.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 46.0.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.12.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.104.0.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.35.5.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.138.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.0.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.20.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.0.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.3] - 2026-06-24</h2> <ul> <li> <p>Update <code>zizmor@latest</code> to 1.26.1.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 46.0.0.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.5.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.12.</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.104.0.</p> </li> <li> <p>Update <code>cargo-tarpaulin@latest</code> to 0.35.5.</p> </li> <li> <p>Update <code>cargo-nextest@latest</code> to 0.9.138.</p> </li> <li> <p>Update <code>cargo-crap@latest</code> to 0.3.0.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.20.1.</p> </li> <li> <p>Update <code>cargo-rdme@latest</code> to 2.0.1.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/ace6ebe54a6a0c86dfb5f7764b17f793b6925bc3"><code>ace6ebe</code></a> Release 2.82.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/9593d26a566b2dea5528756ce1b593cda56ddf7f"><code>9593d26</code></a> Update <code>zizmor@latest</code> to 1.26.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/0569c0141a12a1553b9c9a83491ff772d114a6e5"><code>0569c01</code></a> Update <code>wasmtime@latest</code> to 46.0.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/5ea9fc8c273a1ac2a9f4c160d34b2e37dd1cb9e7"><code>5ea9fc8</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/d9b6e0d11a25ad9f54aabdb65b4b4fe88d20f710"><code>d9b6e0d</code></a> Update <code>tombi@latest</code> to 1.1.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/d22450fe07f49b408f280b0c4e4ec6c581dd7154"><code>d22450f</code></a> Update <code>mise@latest</code> to 2026.6.12</li> <li><a href="https://github.com/taiki-e/install-action/commit/586c055e27e0fa5c61e72baabffb3c90a6ec9cda"><code>586c055</code></a> Update <code>kingfisher@latest</code> to 1.104.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/5e27d3091b1094b517876d28ce9933e444be309a"><code>5e27d30</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/eda88a4fdb0862974fa83c21b8ebec7d1ec53972"><code>eda88a4</code></a> Update <code>cargo-tarpaulin@latest</code> to 0.35.5</li> <li><a href="https://github.com/taiki-e/install-action/commit/30ff9da4b104d9918bd41562f2981303f48d3402"><code>30ff9da</code></a> Update <code>cargo-nextest@latest</code> to 0.9.138</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.2...v2.82.3">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e3664c6343 |
chore: bump actions/cache from 5 to 6 (#3191)
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/cache/releases">actions/cache's releases</a>.</em></p> <blockquote> <h2>v6.0.0</h2> <h2>What's Changed</h2> <ul> <li>Update packages, migrate to ESM by <a href="https://github.com/Samirat"><code>@Samirat</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p> <h2>v5.0.5</h2> <h2>What's Changed</h2> <ul> <li>Update ts-http-runtime dependency by <a href="https://github.com/yacaovsnc"><code>@yacaovsnc</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p> <h2>v5.0.4</h2> <h2>What's Changed</h2> <ul> <li>Add release instructions and update maintainer docs by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li> <li>Potential fix for code scanning alert no. 52: Workflow does not contain permissions by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li> <li>Fix workflow permissions and cleanup workflow names / formatting by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li> <li>docs: Update examples to use the latest version by <a href="https://github.com/XZTDean"><code>@XZTDean</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li> <li>Fix proxy integration tests by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li> <li>Fix cache key in examples.md for bun.lock by <a href="https://github.com/RyPeck"><code>@RyPeck</code></a> in <a href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li> <li>Update dependencies & patch security vulnerabilities by <a href="https://github.com/Link"><code>@Link</code></a>- in <a href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/XZTDean"><code>@XZTDean</code></a> made their first contribution in <a href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li> <li><a href="https://github.com/RyPeck"><code>@RyPeck</code></a> made their first contribution in <a href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p> <h2>v5.0.3</h2> <h2>What's Changed</h2> <ul> <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li> <li>Bump <code>@actions/core</code> to v2.0.3</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/cache/compare/v5...v5.0.3">https://github.com/actions/cache/compare/v5...v5.0.3</a></p> <h2>v.5.0.2</h2> <h1>v5.0.2</h1> <h2>What's Changed</h2> <p>When creating cache entries, 429s returned from the cache service will not be retried.</p> <h2>v5.0.1</h2> <blockquote> <p>[!IMPORTANT] <strong><code>actions/cache@v5</code> runs on the Node.js 24 runtime and requires a minimum Actions Runner version of <code>2.327.1</code>.</strong></p> </blockquote> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache's changelog</a>.</em></p> <blockquote> <h1>Releases</h1> <h2>How to prepare a release</h2> <blockquote> <p>[!NOTE] Relevant for maintainers with write access only.</p> </blockquote> <ol> <li>Switch to a new branch from <code>main</code>.</li> <li>Run <code>npm test</code> to ensure all tests are passing.</li> <li>Update the version in <a href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li> <li>Run <code>npm run build</code> to update the compiled files.</li> <li>Update this <a href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a> with the new version and changes in the <code>## Changelog</code> section.</li> <li>Run <code>licensed cache</code> to update the license report.</li> <li>Run <code>licensed status</code> and resolve any warnings by updating the <a href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a> file with the exceptions.</li> <li>Commit your changes and push your branch upstream.</li> <li>Open a pull request against <code>main</code> and get it reviewed and merged.</li> <li>Draft a new release <a href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a> use the same version number used in <code>package.json</code> <ol> <li>Create a new tag with the version number.</li> <li>Auto generate release notes and update them to match the changes you made in <code>RELEASES.md</code>.</li> <li>Toggle the set as the latest release option.</li> <li>Publish the release.</li> </ol> </li> <li>Navigate to <a href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a> <ol> <li>There should be a workflow run queued with the same version number.</li> <li>Approve the run to publish the new version and update the major tags for this action.</li> </ol> </li> </ol> <h2>Changelog</h2> <h3>6.1.0</h3> <ul> <li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435 Handle cache write error due to read-only token</a></li> <li>Switch redundant "Cache save failed" warning to debug log in save-only</li> </ul> <h3>6.0.0</h3> <ul> <li>Updated <code>@actions/cache</code> to ^6.0.1, <code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to ^3.0.0, <code>@actions/io</code> to ^3.0.2</li> <li>Migrated to ESM module system</li> <li>Upgraded Jest to v30 and test infrastructure to be ESM compatible</li> </ul> <h3>5.0.4</h3> <ul> <li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar patterns)</li> <li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)</li> <li>Bump <code>fast-xml-parser</code> to v5.5.6</li> </ul> <h3>5.0.3</h3> <ul> <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li> <li>Bump <code>@actions/core</code> to v2.0.3</li> </ul> <h3>5.0.2</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a> Merge pull request <a href="https://redirect.github.com/actions/cache/issues/1760">#1760</a> from actions/samirat/esm_migration_and_package_update</li> <li><a href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a> Prettier fixes</li> <li><a href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a> Rebuild dist</li> <li><a href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a> Fixed licenses</li> <li><a href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a> Fix test mock return order</li> <li><a href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a> PR feedback</li> <li><a href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a> Rebuild dist bundles as ESM to match type:module</li> <li><a href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a> Fix lint and jest issues</li> <li><a href="https://github.com/actions/cache/commit/b9bf592b98b6a5d0cad9929c76247de1cac78abe"><code>b9bf592</code></a> Update documentation for v6 release</li> <li><a href="https://github.com/actions/cache/commit/80f777761d0990932f64ed2740522d7226a49062"><code>80f7777</code></a> Update packages, migrate to ESM</li> <li>See full diff in <a href="https://github.com/actions/cache/compare/v5...v6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9e8d4612c8 |
chore: bump actions/checkout from 6 to 7 (#3131)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/releases">actions/checkout's releases</a>.</em></p> <blockquote> <h2>v7.0.0</h2> <h2>What's Changed</h2> <ul> <li>block checking out fork pr for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> <li>getting ready for checkout v7 release by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li> <li>update error wording by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p> <h2>v6.0.3</h2> <h2>What's Changed</h2> <ul> <li>Update changelog by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>Update changelog for v6.0.3 by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/yaananth"><code>@yaananth</code></a> made their first contribution in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p> <h2>v6.0.2</h2> <h2>What's Changed</h2> <ul> <li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p> <h2>v6.0.1</h2> <h2>What's Changed</h2> <ul> <li>Update all references from v5 and v4 to v6 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> <li>Clarify v6 README by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v7.0.0</h2> <ul> <li>Block checking out fork PR for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li> <li>Bump flatted from 3.3.1 to 3.4.2 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li> <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li> <li>Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li> <li>upgrade module to esm and update dependencies by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li> <li>Bump the minor-npm-dependencies group across 1 directory with 3 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li> </ul> <h2>v6.0.3</h2> <ul> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <h2>v6.0.2</h2> <ul> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <h2>v6.0.1</h2> <ul> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> </ul> <h2>v6.0.0</h2> <ul> <li>Persist creds to a separate file by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li> <li>Update README to include Node.js 24 support details and requirements by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li> </ul> <h2>v5.0.1</h2> <ul> <li>Port v6 cleanup to v5 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li> </ul> <h2>v5.0.0</h2> <ul> <li>Update actions checkout to use node 24 by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li> </ul> <h2>v4.3.1</h2> <ul> <li>Port v6 cleanup to v4 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li> </ul> <h2>v4.3.0</h2> <ul> <li>docs: update README.md by <a href="https://github.com/motss"><code>@motss</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li> <li>Add internal repos for checking out multiple repositories by <a href="https://github.com/mouismail"><code>@mouismail</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li> <li>Documentation update - add recommended permissions to Readme by <a href="https://github.com/benwells"><code>@benwells</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li> <li>Adjust positioning of user email note and permissions heading by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li> <li>Update README.md by <a href="https://github.com/nebuk89"><code>@nebuk89</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li> <li>Update CODEOWNERS for actions by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li> <li>Update package dependencies by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li> </ul> <h2>v4.2.2</h2> <ul> <li><code>url-helper.ts</code> now leverages well-known environment variables by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li> <li>Expand unit test coverage for <code>isGhes</code> by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li> </ul> <h2>v4.2.1</h2> <ul> <li>Check out other refs/* by commit if provided, fall back to ref by <a href="https://github.com/orhantoy"><code>@orhantoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a> update error wording (<a href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li> <li><a href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a> getting ready for checkout v7 release (<a href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a> Bump the minor-npm-dependencies group across 1 directory with 3 updates (<a href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li> <li><a href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a> upgrade module to esm and update dependencies (<a href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li> <li><a href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a> Bump <code>@actions/core</code> and <code>@actions/tool-cache</code> and Remove uuid (<a href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li> <li><a href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a> Bump js-yaml from 4.1.0 to 4.2.0 (<a href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li> <li><a href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a> Bump flatted from 3.3.1 to 3.4.2 (<a href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li> <li><a href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a> Bump actions/publish-immutable-action (<a href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li> <li><a href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a> block checking out fork pr for pull_request_target and workflow_run (<a href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li> <li>See full diff in <a href="https://github.com/actions/checkout/compare/v6...v7">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e0cfd884e9 |
chore(ci): weekly renovation 2026-06-21 (#3147)
## Summary
Weekly CI renovation check. One pinned-version drift found and bumped:
- `worktrunk`: `=0.58.0` → `=0.60.0` (MSRV 1.95, compatible with our
pinned 1.95.0 toolchain) — `ci.yaml` `test` job. Flagged by a workflow
annotation on the latest green `main` run ("New version for worktrunk
available: 0.60.0").
## Already up to date
- **Rust stable**: latest is 1.96.0, so latest−1 = 1.95 —
`rust-toolchain.toml` (1.95.0) and both `rust-version` pins (1.95)
already match. No MSRV/toolchain bump.
- **cargo-install pins**: cargo-insta 1.48.0, cargo-nextest 0.9.137,
lychee 0.24.2, cargo-msrv 0.19.3, cargo-llvm-cov 0.8.7, cargo-udeps
0.1.61 — all current against crates.io.
- **setup-nu**: 0.113.1 (latest nushell release).
- **zola**: 0.22.1 (latest getzola release).
- **Runner images**: ubuntu-24.04, macos-15, windows-2022 (windows-2022
stays pinned — actions/runner-images#12677).
## Notes
- worktrunk 0.59.0 and 0.60.0 both declare `rust-version = "1.95"`;
verified via crates.io API against the pinned toolchain.
- Only the `test` job pins a specific worktrunk version; the
`cargo-affected` install follows the default branch and is intentionally
unpinned.
---
🤖 Automated weekly renovation
Co-authored-by: worktrunk-bot <worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
|
||
|
|
56cc99c780 |
chore: bump taiki-e/install-action from 2.82.0 to 2.82.2 (#3155)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.82.0 to 2.82.2. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.2</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.1.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.23.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.71.2.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.16.0.</p> </li> </ul> <h2>2.82.1</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.4.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.22.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.4.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.11.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.11.0.</p> </li> <li> <p>Update <code>just@latest</code> to 1.53.0.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.2] - 2026-06-21</h2> <ul> <li> <p>Update <code>xh@latest</code> to 0.26.1.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.23.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.71.2.</p> </li> <li> <p>Update <code>sccache@latest</code> to 0.16.0.</p> </li> </ul> <h2>[2.82.1] - 2026-06-20</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.4.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.22.</p> </li> <li> <p>Update <code>osv-scanner@latest</code> to 2.4.0.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.11.</p> </li> <li> <p>Update <code>martin@latest</code> to 1.11.0.</p> </li> <li> <p>Update <code>just@latest</code> to 1.53.0.</p> </li> <li> <p>Update <code>cargo-zigbuild@latest</code> to 0.23.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/9e1e5806d4a4822de933115878265be9aaa786d9"><code>9e1e580</code></a> Release 2.82.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/788896b6163ee187bf02f51161e573dbc028dba0"><code>788896b</code></a> Update zizmor manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/7631577b669c94d73e58cb9f217d0f56abd33a48"><code>7631577</code></a> Update <code>xh@latest</code> to 0.26.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/e0f1a05cc9f43f4fd57d15fe7ee20ca5b78f65fc"><code>e0f1a05</code></a> Update <code>uv@latest</code> to 0.11.23</li> <li><a href="https://github.com/taiki-e/install-action/commit/3cda1e20d17fde3f9958653d219495e0591233ec"><code>3cda1e2</code></a> Update <code>trivy@latest</code> to 0.71.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/11ac3210af3c20497864c3d27d4499b6a7108098"><code>11ac321</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/b5f9e335d3eaba5117342d9d9fda485aea29c524"><code>b5f9e33</code></a> Update <code>sccache@latest</code> to 0.16.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/4e48cd5f5170589da6cad450be3e62ca61534cc1"><code>4e48cd5</code></a> Update cargo-tarpaulin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/e0a923573389b28b6cefdbe8309332b471f55583"><code>e0a9235</code></a> Update cargo-rdme manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/8b3c737da4b541bf0fb5a3e0488ff20535badac9"><code>8b3c737</code></a> Release 2.82.1</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.82.0...v2.82.2">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
e25a7a9bd7 |
chore: bump taiki-e/install-action from 2.81.11 to 2.82.0 (#3114)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.81.11 to 2.82.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.82.0</h2> <ul> <li> <p>Support <code>cargo-vet</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1908">#1908</a>, thanks <a href="https://github.com/jakewimmer"><code>@jakewimmer</code></a>)</p> </li> <li> <p>Support <code>cargo-crap</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1905">#1905</a>, thanks <a href="https://github.com/BartoszCiesla"><code>@BartoszCiesla</code></a>)</p> </li> <li> <p>Support <code>cargo-leptos</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1903">#1903</a>, thanks <a href="https://github.com/404Simon"><code>@404Simon</code></a>)</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.103.0.</p> </li> <li> <p>Update <code>cargo-xwin@latest</code> to 0.23.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 45.0.2.</p> </li> <li> <p>Update <code>cargo-deny@latest</code> to 0.19.9.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.5.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.71.1.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.10.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.82.0] - 2026-06-17</h2> <ul> <li> <p>Support <code>cargo-vet</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1908">#1908</a>, thanks <a href="https://github.com/jakewimmer"><code>@jakewimmer</code></a>)</p> </li> <li> <p>Support <code>cargo-crap</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1905">#1905</a>, thanks <a href="https://github.com/BartoszCiesla"><code>@BartoszCiesla</code></a>)</p> </li> <li> <p>Support <code>cargo-leptos</code>. (<a href="https://redirect.github.com/taiki-e/install-action/pull/1903">#1903</a>, thanks <a href="https://github.com/404Simon"><code>@404Simon</code></a>)</p> </li> <li> <p>Update <code>kingfisher@latest</code> to 1.103.0.</p> </li> <li> <p>Update <code>cargo-xwin@latest</code> to 0.23.0.</p> </li> <li> <p>Update <code>wasmtime@latest</code> to 45.0.2.</p> </li> <li> <p>Update <code>cargo-deny@latest</code> to 0.19.9.</p> </li> <li> <p>Update <code>prek@latest</code> to 0.4.5.</p> </li> <li> <p>Update <code>trivy@latest</code> to 0.71.1.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.10.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/b8cecb83565409bcc297b2df6e77f030b2a468d5"><code>b8cecb8</code></a> Release 2.82.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/981171473775d521e3ae1e0b14c569b51c48651e"><code>9811714</code></a> Update changelog</li> <li><a href="https://github.com/taiki-e/install-action/commit/e7005464717d3cca03b48509ba65ebbde552e10c"><code>e700546</code></a> Update wasmtime manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/fdfb4a4a7c8af40d72ebb849dac38e8718ea669c"><code>fdfb4a4</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/ef03904287f8419ca540ee664cc9227c6d501867"><code>ef03904</code></a> Update martin manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/b6d098313f0ccec3f73270982ba4474205dbd7fd"><code>b6d0983</code></a> Update <code>kingfisher@latest</code> to 1.103.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/ebeb9b1a53c2307773f018dca9868b795675e6c5"><code>ebeb9b1</code></a> Update just manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/119edcf29d9a2c67fad2ed58e04242daceb433e5"><code>119edcf</code></a> Update <code>cargo-xwin@latest</code> to 0.23.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/cd319da91ecc8685df284d89c5435723973a5668"><code>cd319da</code></a> Update <code>wasmtime@latest</code> to 45.0.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/4942894b57b5ad6fdcb38216eb1f7df561374b20"><code>4942894</code></a> Update cargo-xwin manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.81.11...v2.82.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
08b0fc8a0d |
chore: bump taiki-e/install-action from 2.81.10 to 2.81.11 (#3088)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.81.10 to 2.81.11. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.81.11</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.252.0.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.125.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.21.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.35.1.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.9.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.0.</p> </li> <li> <p>Update <code>cargo-insta@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.81.11] - 2026-06-15</h2> <ul> <li> <p>Update <code>wasm-tools@latest</code> to 1.252.0.</p> </li> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.125.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.21.</p> </li> <li> <p>Update <code>protoc@latest</code> to 3.35.1.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.9.</p> </li> <li> <p>Update <code>jaq@latest</code> to 3.1.0.</p> </li> <li> <p>Update <code>cargo-insta@latest</code> to 1.48.0.</p> </li> <li> <p>Update <code>biome@latest</code> to 2.5.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/15449e3094499af05d8d964a1c884208e4b8b595"><code>15449e3</code></a> Release 2.81.11</li> <li><a href="https://github.com/taiki-e/install-action/commit/dd3bb882c6c552e1478f55a048fb291cdc1f0ef1"><code>dd3bb88</code></a> Update cargo-deny manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/89ed2466baa251f4217203b0084736e4ba24365d"><code>89ed246</code></a> Update <code>wasm-tools@latest</code> to 1.252.0</li> <li><a href="https://github.com/taiki-e/install-action/commit/3d2614471d361398dc4a241305a41a22246608cd"><code>3d26144</code></a> Update <code>wasm-bindgen@latest</code> to 0.2.125</li> <li><a href="https://github.com/taiki-e/install-action/commit/02039d84ff2195b312ef1612583b62012fcc7737"><code>02039d8</code></a> Update <code>uv@latest</code> to 0.11.21</li> <li><a href="https://github.com/taiki-e/install-action/commit/f70d988b18b30949b65c310be1e9e1fd34b1bd80"><code>f70d988</code></a> Update trivy manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/1f7b61373609cdc389de6178ea51d2a069d306ed"><code>1f7b613</code></a> Update <code>protoc@latest</code> to 3.35.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/ace4a195674b1e2219e629001c708779d52f0872"><code>ace4a19</code></a> Update prek manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3fbf11909e319a495b93f6c640f257d1979a9cef"><code>3fbf119</code></a> Update <code>mise@latest</code> to 2026.6.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/e62deab512318d610ad0b017fe426bc6cdb75e0f"><code>e62deab</code></a> Update <code>jaq@latest</code> to 3.1.0</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.81.10...v2.81.11">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
2602a413f7 |
chore: bump awalsh128/cache-apt-pkgs-action from 1.6.0 to 1.6.1 (#3080)
Bumps [awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action) from 1.6.0 to 1.6.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/awalsh128/cache-apt-pkgs-action/releases">awalsh128/cache-apt-pkgs-action's releases</a>.</em></p> <blockquote> <h2>v1.6.1</h2> <h2>What's Changed</h2> <ul> <li>fix: upgrade actions/cache v4→v5 and upload-artifact v4→v7 (Node 24) by <a href="https://github.com/pftg"><code>@pftg</code></a> in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/198">awalsh128/cache-apt-pkgs-action#198</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/pftg"><code>@pftg</code></a> made their first contribution in <a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/198">awalsh128/cache-apt-pkgs-action#198</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.5.4...v1.6.1">https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.5.4...v1.6.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/681749ae568c81c2037cb9185e38b709b261bd2f"><code>681749a</code></a> fix: upgrade actions/cache v4→v5 and upload-artifact v4→v7 (Node 24) (<a href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/198">#198</a>)</li> <li>See full diff in <a href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.0...v1.6.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> |
||
|
|
08539dc75a |
chore(ci): weekly renovation 2026-06-14 (#3071)
## Summary Weekly CI renovation check found the following pin updates: - `cargo-insta`: 1.47.2 → 1.48.0 (MSRV 1.66, compatible with our 1.95.0) — in `claude-setup` and `test-setup` actions - `worktrunk`: 0.55.0 → 0.58.0 (MSRV 1.95, compatible with our 1.95.0) — in `ci.yaml` ### cargo-insta 1.48.0 notes No breaking changes and no MSRV bump. Behavior changes worth noting, none of which affect our `--check`-based snapshot flow: - When `CI=true`, explicit handling options like `--accept` now take precedence over the automatic `--check`. - `--profile` now translates to `--cargo-profile` for nextest; a new `--nextest-profile` selects the runner profile. - New `strip_ansi_escape_codes` filter setting and opt-in YAML literal blocks (`INSTA_YAML_BLOCK_STYLE=1`). ## Already up to date - Rust stable: 1.96.0 → MSRV/toolchain stay at 1.95 (latest stable − 1, no change) - Runner images: ubuntu-24.04, macos-15, windows-2022 - `cargo-nextest`: 0.9.137, `lychee`: 0.24.2, `cargo-msrv`: 0.19.3, `cargo-llvm-cov`: 0.8.7, `cargo-udeps`: 0.1.61 - `hustcer/setup-nu`: 0.113.1 (latest nushell release) - `zola`: 0.22.1 - LLM model pins: Claude Haiku 4.5 and Codex `gpt-5.4-mini` are both current - README month blockquote: "June 2026" matches current month ## Notes - windows-2022 remains pinned (actions/runner-images#12677 — windows-2025 lacks the D: drive) --- 🤖 Automated weekly renovation Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> |
||
|
|
330fa6ee4e |
chore(ci): weekly renovation 2026-05-31 (#2948)
## Summary Weekly CI renovation. MSRV/toolchain bump plus pin bumps where upstream has moved. - **MSRV: 1.94 → 1.95** (Rust 1.96.0 went stable 2026-05-28; policy is latest stable − 1) - **toolchain channel: 1.94.0 → 1.95.0** - `cargo-nextest`: 0.9.136 → 0.9.137 (MSRV 1.91, compatible with 1.95.0) - `worktrunk`: 0.53.0 → 0.55.0 (MSRV 1.94, compatible with 1.95.0) - `hustcer/setup-nu` nushell: 0.113.0 → 0.113.1 - `flake.lock`: `rust-overlay` bumped to `4a408e1` (ships `1.95.0.nix` and `1.96.0.nix`); refreshed in the follow-up commit after @max-sixty asked whether the agent could install Nix — it can, via the Determinate Systems installer. A separate skill PR will codify the Nix install step into the weekly workflow so future runs do this automatically. ## Already up to date - `cargo-insta`: 1.47.2, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2 - `taiki-e/install-action` tool: zola@0.22.1 - `taiki-e/install-action` action ref tracked by Dependabot (open in #2935: 2.79.11 → 2.79.13; latest is 2.80.0 — Dependabot will catch up next cycle) - Runner images: ubuntu-24.04, macos-15, windows-2022 ## Notes - windows-2022 remains pinned (actions/runner-images#12677 — windows-2025 lacks D: drive) --------- Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> |
||
|
|
ea883bd6d6 |
chore: bump taiki-e/install-action from 2.81.8 to 2.81.10 (#3031)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.81.8 to 2.81.10. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.81.10</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.1.3.</p> </li> <li> <p>Update <code>release-plz@latest</code> to 0.3.159.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.1.</p> </li> </ul> <h2>2.81.9</h2> <ul> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.123.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.2.</p> </li> <li> <p>Update <code>parse-changelog@latest</code> to 0.6.17.</p> </li> <li> <p>Update <code>just@latest</code> to 1.52.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.2.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.20.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.81.10] - 2026-06-11</h2> <ul> <li> <p>Update <code>tombi@latest</code> to 1.1.3.</p> </li> <li> <p>Update <code>release-plz@latest</code> to 0.3.159.</p> </li> <li> <p>Update <code>cosign@latest</code> to 3.1.1.</p> </li> </ul> <h2>[2.81.9] - 2026-06-10</h2> <ul> <li> <p>Update <code>wasm-bindgen@latest</code> to 0.2.123.</p> </li> <li> <p>Update <code>tombi@latest</code> to 1.1.2.</p> </li> <li> <p>Update <code>parse-changelog@latest</code> to 0.6.17.</p> </li> <li> <p>Update <code>just@latest</code> to 1.52.0.</p> </li> <li> <p>Update <code>gungraun-runner@latest</code> to 0.19.2.</p> </li> <li> <p>Update <code>cargo-binstall@latest</code> to 1.20.0.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/7a79fe8c3a13344501c80d99cae481c1c9085912"><code>7a79fe8</code></a> Release 2.81.10</li> <li><a href="https://github.com/taiki-e/install-action/commit/13599f4dab5fc9777c7a29b255a9106d1107ee1d"><code>13599f4</code></a> Update uv manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/ee40c2ad7099d51081c7f37b4d3d914a008b8403"><code>ee40c2a</code></a> Update <code>tombi@latest</code> to 1.1.3</li> <li><a href="https://github.com/taiki-e/install-action/commit/c2336861b9e97b4c0e1b19bc5d8968501d4d3b3f"><code>c233686</code></a> Update <code>release-plz@latest</code> to 0.3.159</li> <li><a href="https://github.com/taiki-e/install-action/commit/7f72f38ad02c28b2456e65ab89c50a362bb98aaa"><code>7f72f38</code></a> Update mise manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/f8c685240840f35b073b629510ed9b7a853227f7"><code>f8c6852</code></a> Update <code>cosign@latest</code> to 3.1.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/fd2f5e3d644b484055ebf4268f474c565f148f25"><code>fd2f5e3</code></a> Release 2.81.9</li> <li><a href="https://github.com/taiki-e/install-action/commit/537f98ea83c367b35b9810b787d0b2ded00efc1a"><code>537f98e</code></a> Update <code>wasm-bindgen@latest</code> to 0.2.123</li> <li><a href="https://github.com/taiki-e/install-action/commit/6bf6dde29b365c072c8c9b09b160ba21042e6b1e"><code>6bf6dde</code></a> Update <code>tombi@latest</code> to 1.1.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/c1e16527666111091c11f4145f629c642a3c5aef"><code>c1e1652</code></a> Update release-plz manifest</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.81.8...v2.81.10">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
2823171c7e |
chore: bump taiki-e/install-action from 2.79.11 to 2.81.8 (#3011)
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.79.11 to 2.81.8. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's releases</a>.</em></p> <blockquote> <h2>2.81.8</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.2.</p> </li> <li> <p>Update <code>parse-dockerfile@latest</code> to 0.1.7.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.1.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.1.</p> </li> </ul> <h2>2.81.7</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 45.0.1.</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.29.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.45.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.74.3.</p> </li> <li> <p>Update <code>cargo-audit@latest</code> to 0.22.2.</p> </li> </ul> <h2>2.81.6</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.4.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.0.</p> </li> </ul> <h2>2.81.5</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.19.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.47.2.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.0.</p> </li> </ul> <h2>2.81.4</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.28.4.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.47.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.45.0.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.4.0.</p> </li> <li> <p>Update <code>cargo-mutants@latest</code> to 27.1.0.</p> </li> </ul> <h2>2.81.3</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.28.3.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.18.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's changelog</a>.</em></p> <blockquote> <h2>[2.81.8] - 2026-06-08</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.2.</p> </li> <li> <p>Update <code>parse-dockerfile@latest</code> to 0.1.7.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.1.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.1.</p> </li> </ul> <h2>[2.81.7] - 2026-06-06</h2> <ul> <li> <p>Update <code>wasmtime@latest</code> to 45.0.1.</p> </li> <li> <p>Update <code>vacuum@latest</code> to 0.29.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.45.1.</p> </li> <li> <p>Update <code>rclone@latest</code> to 1.74.3.</p> </li> <li> <p>Update <code>cargo-audit@latest</code> to 0.22.2.</p> </li> </ul> <h2>[2.81.6] - 2026-06-05</h2> <ul> <li> <p>Update <code>prek@latest</code> to 0.4.4.</p> </li> <li> <p>Update <code>cargo-shear@latest</code> to 1.13.0.</p> </li> </ul> <h2>[2.81.5] - 2026-06-05</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.29.0.</p> </li> <li> <p>Update <code>uv@latest</code> to 0.11.19.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.47.2.</p> </li> <li> <p>Update <code>mise@latest</code> to 2026.6.0.</p> </li> </ul> <h2>[2.81.4] - 2026-06-04</h2> <ul> <li> <p>Update <code>vacuum@latest</code> to 0.28.4.</p> </li> <li> <p>Update <code>typos@latest</code> to 1.47.1.</p> </li> <li> <p>Update <code>syft@latest</code> to 1.45.0.</p> </li> <li> <p>Update <code>cargo-neat@latest</code> to 0.4.0.</p> </li> <li> <p>Update <code>cargo-mutants@latest</code> to 27.1.0.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/taiki-e/install-action/commit/0631aa6515c7d545823c67cfae7ef4fc7f490154"><code>0631aa6</code></a> Release 2.81.8</li> <li><a href="https://github.com/taiki-e/install-action/commit/fd382b34adcf901479b928617bf0f0612ca769b3"><code>fd382b3</code></a> Update <code>vacuum@latest</code> to 0.29.2</li> <li><a href="https://github.com/taiki-e/install-action/commit/b1597b4e7dcbcedac8dd1054da307b671f17027d"><code>b1597b4</code></a> Update tombi manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/3869357b4e3cd3a5267685bf8ef038dbef829247"><code>3869357</code></a> Update <code>parse-dockerfile@latest</code> to 0.1.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/734742c1440e1b5aa3d391559c975c507bb14842"><code>734742c</code></a> Update parse-changelog manifest</li> <li><a href="https://github.com/taiki-e/install-action/commit/6a4fb002de1a038994686e6d75688b72283a0b34"><code>6a4fb00</code></a> Update <code>mise@latest</code> to 2026.6.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/ee92d4569affa054448769293cd8fbe22df3fd6c"><code>ee92d45</code></a> Update <code>cargo-shear@latest</code> to 1.13.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/56545b37b57562edd73171cb6c62cc509db4c34e"><code>56545b3</code></a> Release 2.81.7</li> <li><a href="https://github.com/taiki-e/install-action/commit/c8d55710f301270b50680d218c3c8b1c2ed35fa7"><code>c8d5571</code></a> Update <code>wasmtime@latest</code> to 45.0.1</li> <li><a href="https://github.com/taiki-e/install-action/commit/982454fe8df95d1ccbd65fec021e1608efa219eb"><code>982454f</code></a> Update <code>vacuum@latest</code> to 0.29.1</li> <li>Additional commits viewable in <a href="https://github.com/taiki-e/install-action/compare/v2.79.11...v2.81.8">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
9f01f597e8 | ci: revert codecov use_pypi workaround now that v7.0.0 fixes the GPG key (#3016) | ||
|
|
35a4b6292a | chore: bump codecov/codecov-action from 6.0.1 to 7.0.0 (#3012) | ||
|
|
ecf1fa6469 |
ci: install codecov CLI from PyPI to dodge broken Keybase GPG import (#2997)
## Problem The non-required `code-coverage` job failed on `main` (run [27075953927](https://github.com/max-sixty/worktrunk/actions/runs/27075953927)). All tests passed (1942 / 1238 / 703, 0 failed); the failure was in the `codecov/codecov-action@v6.0.1` upload step: ``` ==> Finishing downloading linux:latest Version: v11.2.8 gpg: no valid OpenPGP data found. gpg: Total number processed: 0 ==> Verifying GPG signature integrity gpg: Signature made Tue Apr 21 19:28:03 2026 UTC gpg: using RSA key 27034E7FDB850E0BBC2C62FF806BB28AED779869 gpg: Can't check signature: No public key ==> Could not verify signature. Please contact Codecov if problem continues Exiting... ##[error]Process completed with exit code 1. ``` **Root cause (confirmed upstream).** The action downloads the Codecov CLI from `cli.codecov.io` and verifies its GPG signature against a public key fetched from `https://keybase.io/codecovsecurity/pgp_keys.asc`. That URL is currently returning `404 SELF-SIGNED PUBLIC KEY NOT FOUND`, so the key import produces "no valid OpenPGP data found", the keyring stays empty, and the signature check aborts with "No public key" — before any upload happens. Tracked in [codecov/codecov-action#1955](https://github.com/codecov/codecov-action/issues/1955) (opened the same day) and the related [#1876](https://github.com/codecov/codecov-action/issues/1876). **Why a fix and not a rerun.** This exact failure shape fired three times in ~24h — [#2993](https://github.com/max-sixty/worktrunk/issues/2993), [#2996](https://github.com/max-sixty/worktrunk/issues/2996), and this run. #2996's diagnosis explicitly flagged that a third occurrence should escalate to a durable mitigation, crossing the `running-tend` repeat-occurrence threshold from transient to durable. `v6.0.1` is already the latest action release, so bumping the pin doesn't help. ## Solution Set `use_pypi: true` on both `codecov-action` steps in `ci.yaml` (the test-results upload in the `test` matrix and the coverage upload in `code-coverage`). This is the workaround documented in #1955: it installs the Codecov CLI from PyPI instead of `cli.codecov.io`, bypassing the binary download and its broken Keybase GPG-key import entirely. Both call sites are subject to the same failure mode, so both are patched. `use_pypi` is a documented input on `codecov-action@v6.0.1` (`action.yml` line 155: *"Use the pypi version of the CLI instead of from cli.codecov.io"*). ## Testing YAML validated with `yaml.safe_load`. Behavioral verification is the `code-coverage` job passing on this PR — it exercises the patched upload path. The maintainer can revert `use_pypi: true` once Codecov restores the Keybase key (the `# (codecov/codecov-action#1955)` comments mark both sites). --- Automated fix for [failed run](https://github.com/max-sixty/worktrunk/actions/runs/27075953927) Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com> Co-authored-by: Claude <noreply@anthropic.com> |