Commit Graph

171 Commits

Author SHA1 Message Date
dependabot[bot] 9c13f6e7d4 chore: bump taiki-e/install-action from 2.85.11 to 2.85.13 (#3828)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.11 to 2.85.13.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.13</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.3.3.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.5.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.113.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.4.</p>
</li>
<li>
<p>Update <code>bpf-linker@latest</code> to 0.11.0.</p>
</li>
</ul>
<h2>2.85.12</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.3.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.256.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.10.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.51.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.13.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.4.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.8.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.13] - 2026-08-13</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.3.3.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.5.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.113.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.4.</p>
</li>
<li>
<p>Update <code>bpf-linker@latest</code> to 0.11.0.</p>
</li>
</ul>
<h2>[2.85.12] - 2026-08-12</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.3.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.256.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.10.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.51.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.13.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.4.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.11.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.8.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/82cd3e7658a6f96c86c0234aeeda1748937cb0a1"><code>82cd3e7</code></a>
Release 2.85.13</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4dd6c67d0ecd1fab76c6cecc5931e1239cc16add"><code>4dd6c67</code></a>
Update <code>tombi@latest</code> to 1.3.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/91cb1bb28383045bb69f87d336ede6db3c61927b"><code>91cb1bb</code></a>
Update <code>mise@latest</code> to 2026.8.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/83d968e89df664219ce13abb14808207a131cc64"><code>83d968e</code></a>
Update <code>kingfisher@latest</code> to 1.113.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f7ab7f5d0a3e5a8120f10f39cfc442b2f40642b0"><code>f7ab7f5</code></a>
Update cargo-xwin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3faddd9e3002e0d2922192f5808a78c4118eb58c"><code>3faddd9</code></a>
Update <code>cargo-shear@latest</code> to 1.13.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b4cb4b238691473c8bf1425b4d38120d5058dfc2"><code>b4cb4b2</code></a>
Update <code>bpf-linker@latest</code> to 0.11.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b20dedce73af6905cdc30d6611090c9b67557c8d"><code>b20dedc</code></a>
Release 2.85.12</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/952d13c8bb10d7e37f96fa2c8131338550a62663"><code>952d13c</code></a>
ci: Skip cargo-rdme on x86_64 macOS</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c8724e7258d0b8f8188a94aec0c00ae9da81edd7"><code>c8724e7</code></a>
Update <code>zola@latest</code> to 0.23.3</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.11...v2.85.13">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.11&new-version=2.85.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 01:48:28 -07:00
Worktrunk Bot 1b278042de chore(ci): weekly renovation 2026-08-16 (#3826)
## Summary

Weekly CI renovation check found the following updates:

- `worktrunk`: 0.72.0 → 0.74.0 (MSRV 1.96, compatible with our 1.96.0) —
`ci.yaml` ×2, `nightly.yaml`
- `nushell`: 0.114.1 → 0.115.0 — `nightly.yaml`, `benchmarks.yaml`,
`coverage.yaml`, `actions/test-setup`, and
`scripts/codex-cloud/Taskfile.yaml`
- `pre-commit`: 4.6.1 → 4.6.2 — `scripts/codex-cloud/Taskfile.yaml`
- `PowerShell`: 7.6.4 → 7.6.5 — `scripts/codex-cloud/Taskfile.yaml` and
the root `Taskfile.yaml`'s `setup-web` task

The Codex Cloud archive checksums were recomputed from the new upstream
tarballs, and the resulting `Taskfile.yaml` digest (`f14dbc89…`) is
copied into both README launcher commands.

The `setup-web` PowerShell pin came in as a follow-up commit: the
initial sweep only grepped `.rs`/`.md`/`.toml` for stale versions, so
the root `Taskfile.yaml`'s `PWSH_VERSION="7.6.4"` was missed. Nothing
tests the two PowerShell pins against each other, so that one drifts
silently — worth a note for future renovation runs. The
`powershell_7.6.5-1.deb_amd64.deb` asset the `setup-web` branch
downloads is present in the v7.6.5 release.

## Already up to date

- Rust stable is 1.97.1, so MSRV and toolchain stay at 1.96 (latest
stable − 1) — `Cargo.toml`, `tests/helpers/wt-perf/Cargo.toml`,
`rust-toolchain.toml` need no change, and `flake.lock` is untouched.
- `cargo-insta` 1.48.0, `cargo-nextest` 0.9.143, `cargo-llvm-cov` 0.8.7,
`cargo-msrv` 0.19.3, `cargo-affected` 0.4.0, `cargo-udeps` 0.1.61,
`lychee` 0.24.2
- Task 3.52.0 (mise, Codex Cloud)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Held back: zola 0.22.1 → 0.23.3

Not bumped. Zola 0.23.0 shipped [Tera2 +
refactoring](https://github.com/getzola/zola/pull/3105), which is a
templating-engine swap rather than a routine release. Building `docs/`
with the 0.23.3 binary fails at the first line of `templates/base.html`:

```
ERROR error: Unknown tag
 --> base.html:1:4
  |
1 | {% import "macros.html" as macros %}
  |    ^^^^^^
```

`templates/base.html` and `templates/macros.html` are the two files that
use the `import`/`macro` pair, so the migration looks small, but it is
template work with its own review rather than a pin bump — kept out of
this PR so the rest can land. Raised separately.

<details><summary>Verification</summary>

- Every version above was read from the upstream source of truth:
`crates.io` for the cargo tools, `nushell/nushell` and
`PowerShell/PowerShell` releases, PyPI for pre-commit, and
`static.rust-lang.org/dist/channel-rust-stable.toml` for Rust stable
(1.97.1).
- Checksums were computed from the downloaded archives and the extracted
binaries were run (`nu --version` → `0.115.0`); the archive layouts
(`nu-<ver>-x86_64-unknown-linux-gnu/nu`, top-level `pwsh`) are
unchanged, so the `install_binary` paths still resolve.
- All six edited YAML files parse.
- The nushell bump was exercised against the shell-integration suite:
`cargo test --features shell-integration-tests --test integration --
nushell` with 0.115.0 on `PATH`. 13 of 14 pass;
`test_nushell_install_target_is_a_vendor_autoload_dir` fails — but it
fails identically on the currently-pinned 0.114.1, and passes on *both*
versions when run alone. It is a pre-existing shared-state race in the
sandbox, not a regression from this bump: the test asserts against the
real user `$nu.vendor-autoload-dirs` entry rather than one under its
temp `HOME` (nu resolves the home dir from the passwd database, so the
test's `HOME` override does not move it), and a sibling uninstall test
in the same filter removes `wt.nu` from that shared directory. Noted
rather than fixed here — it is unrelated to the pins.
- The zola failure above was reproduced with the official 0.23.3
`x86_64-unknown-linux-gnu` release binary against this repo's `docs/`.

</details>

---------

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-17 01:48:26 -07:00
dependabot[bot] ab76101b0b chore: bump taiki-e/install-action from 2.85.10 to 2.85.11 (#3801)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.10 to 2.85.11.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.11</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.2.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.3.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.5.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.3.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.112.0.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.11] - 2026-08-09</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.2.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.127.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.3.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.5.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.3.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.112.0.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.10.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/7f4eb899022d8fe70b20c4f3de697aa85c309026"><code>7f4eb89</code></a>
Release 2.85.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c17da6245a7fe549cefa05b31e3614ce0b16c2af"><code>c17da62</code></a>
Update <code>zola@latest</code> to 0.23.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/97e8291c2ba440a7119c03ebe3ed1e584a1f9b7f"><code>97e8291</code></a>
Update <code>wasm-bindgen@latest</code> to 0.2.127</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/91f9e5c61a2dc7936a8f404d01b7c1551b9c581a"><code>91f9e5c</code></a>
Update <code>uv@latest</code> to 0.12.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/bd0cb00440414f36db2f79bca8e27971bb63b2a3"><code>bd0cb00</code></a>
Update <code>osv-scanner@latest</code> to 2.5.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4def957aa80c252e2d4c61387c6a429d377907d1"><code>4def957</code></a>
Update <code>mise@latest</code> to 2026.8.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d149dc3890afe4774d158d353b5a3e55fe90f60"><code>3d149dc</code></a>
Update <code>kingfisher@latest</code> to 1.112.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20d4381a5cf6917520fde30f9ff52387410bfb6e"><code>20d4381</code></a>
Update <code>editorconfig-checker@latest</code> to 3.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/583939ec0c8ee9c523cc60342d3d979ce6730f38"><code>583939e</code></a>
codegen: Ignore clippy::assert_is_empty lint</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.10...v2.85.11">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.10&new-version=2.85.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-12 09:40:35 -07:00
dependabot[bot] ec2aa4d154 chore: bump taiki-e/install-action from 2.85.8 to 2.85.10 (#3793)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.8 to 2.85.10.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.10</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.2.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.7.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.3.</p>
</li>
<li>
<p>Update <code>coreutils@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.3.</p>
</li>
</ul>
<h2>2.85.9</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.1.</p>
</li>
<li>
<p>Update <code>wild@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.2.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.58.0.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.1.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.2.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.7.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.10] - 2026-08-07</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.2.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.7.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.3.</p>
</li>
<li>
<p>Update <code>coreutils@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.2.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.3.</p>
</li>
</ul>
<h2>[2.85.9] - 2026-08-06</h2>
<ul>
<li>
<p>Update <code>zola@latest</code> to 0.23.1.</p>
</li>
<li>
<p>Update <code>wild@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.2.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.58.0.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.1.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.143.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.2.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.7.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/6c6fd71fe4fb72c3697d269963d0e15df8adedad"><code>6c6fd71</code></a>
Release 2.85.10</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/37cec23487191ef9aef8b1315865bd6dc584bef4"><code>37cec23</code></a>
Update zola manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4914ea4fea5759852f8cda51753420130b883d65"><code>4914ea4</code></a>
Update <code>uv@latest</code> to 0.12.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/0ce64163d455e35fedc5f5925221d4a71f05c990"><code>0ce6416</code></a>
Update <code>tombi@latest</code> to 1.2.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1f89e2fb52c482b53fcf083bf64b5abd5d6563ab"><code>1f89e2f</code></a>
Update osv-scanner manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/65ef13f21e6dd200e402682be3b1bc896f6aa862"><code>65ef13f</code></a>
Update kingfisher manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9f6a5a8ec701c59d62ac1013b92714e7410b2cae"><code>9f6a5a8</code></a>
Update <code>cosign@latest</code> to 3.1.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/df08c38f9c0580a749efefc712ba563ff2107db5"><code>df08c38</code></a>
Update <code>coreutils@latest</code> to 0.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dc7bb1f807a876bf372de55372b320860efe4019"><code>dc7bb1f</code></a>
Update <code>cargo-rdme@latest</code> to 2.2.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9970698e35256036b84ecfb8a70b90fe068a934b"><code>9970698</code></a>
Update <code>cargo-crap@latest</code> to 0.4.3</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.8...v2.85.10">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.8&new-version=2.85.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-11 15:52:48 -07:00
Worktrunk Bot ec574b6c35 ci: bump pinned cargo-nextest 0.9.143 and worktrunk 0.72.0 (#3783)
## Summary

Weekly CI pin check found the following drift (these inline `version:`
strings are invisible to Dependabot — it follows `Cargo.toml` deps and
`uses: foo@vN` refs, not pinned versions inside `with:` blocks):

- `cargo-nextest`: 0.9.140 → 0.9.143 (MSRV 1.91, compatible with our
1.96) — pinned in `coverage.yaml`, `actions/test-setup`, and
`actions/claude-setup`; all three moved together.
- `worktrunk`: 0.71.0 → 0.72.0 (MSRV 1.96, compatible with our 1.96) —
the CI-installed `wt` that runs `wt hook pre-merge`, bumped to the
current release; pinned in `ci.yaml` (×2) and `nightly.yaml`.

## Already up to date

- `cargo-affected`: 0.4.0, `cargo-insta`: 1.48.0, `cargo-llvm-cov`:
0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2
- `hustcer/setup-nu` (nushell): 0.114.1 — matches the current nushell
release across all four call sites
- Runner images: ubuntu-24.04, windows-2022

## Notes

- windows-2022 stays pinned
([actions/runner-images#12677](https://github.com/actions/runner-images/issues/12677)
— windows-2025 lacks the D: drive).
- **cargo-nextest 0.9.143 has nothing config-facing to adjust.** The
0.9.140 → 0.9.143 range is dynamic-library-search-path fixes (build-dir
layout v2, `build.build-dir`, `[[example]]` targets), archive filterset
fixes, an opt-in `junit.report-skipped` setting we don't set, and a
listing progress bar. The one behavior change — ordering the Cargo
artifact directory ahead of `deps` on the dylib search path, matching
Cargo since 1.93 — doesn't affect this repo, which links no `dylib`
dependency.
- **worktrunk 0.72.0 is only exercised through `wt hook pre-merge`** in
these three jobs, so the release's `wt merge` / `wt step push` two-tree
changes and the `branch_outcome` JSON rename don't reach CI. The
relevant one is the opposite direction: 0.72.0 fixes `wt` writing ANSI
to a pipe and exiting 101 on `Broken pipe`, which is exactly the non-tty
shape these jobs run in.
- **`zola` is deliberately left at 0.22.1** — see below.

## Deferred: zola 0.22.1 → 0.23.2

`taiki-e/install-action`'s `tool: zola@0.22.1` in `check-docs` (and the
matching pin in `publish-docs.yaml`) is behind, but 0.23.0 is not a
routine bump. Upstream calls it "probably the most breaking version of
Zola that will happen"
([CHANGELOG](https://github.com/getzola/zola/blob/master/CHANGELOG.md)):
**shortcodes are removed entirely** and Tera is updated to v2 with its
own [migration
guide](https://github.com/Keats/tera/blob/master/MIGRATION.md).
`docs/templates/shortcodes/` and `docs/templates/macros.html` both
exist, so this needs a real docs-site migration rather than a
version-string change, and it would land in the same PR as the live-site
publish pin. Left for a separate change; flagging it here so it isn't
silently skipped each week.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-09 04:56:50 -07:00
dependabot[bot] 02a8dc829c chore: bump taiki-e/install-action from 2.85.7 to 2.85.8 (#3758)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.7 to 2.85.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.8</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.29.0.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.49.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.73.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.6.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.12.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.1.</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.1.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.8] - 2026-08-04</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.29.0.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.49.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.73.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.6.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.12.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.8.1.</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.1.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.50.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/cb33e69fad06166ca28a42b2575e4dadabf62ee8"><code>cb33e69</code></a>
Release 2.85.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/205431a517a990dfa58a0f22a02abd8cbef31c11"><code>205431a</code></a>
Update <code>zizmor@latest</code> to 1.29.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e734f91b32f269a08deefc4ceb37d4aa4747a26b"><code>e734f91</code></a>
Update wild manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/2596ecb10ea03dec655fc75e41a3b0f4dad7bc42"><code>2596ecb</code></a>
Update <code>typos@latest</code> to 1.49.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a44271eb2d867e7b1cf13602d4e4f0a93eec2f5e"><code>a44271e</code></a>
Update <code>trivy@latest</code> to 0.73.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9b100e5f66ebcc3ef6c9e7380611a923118c93bd"><code>9b100e5</code></a>
Update <code>tombi@latest</code> to 1.2.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f28498427840d9dc2242c579fe43460aad78fb48"><code>f284984</code></a>
Update <code>prek@latest</code> to 0.4.12</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3b86746a2ded65050e00646b310ebba2a15bdaf6"><code>3b86746</code></a>
Update <code>mise@latest</code> to 2026.8.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9287d185066eec8a77c1f11905ac9727db063430"><code>9287d18</code></a>
Update just manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/32702bef0f7f8c45b9b179686f51a0f2739378c3"><code>32702be</code></a>
Update <code>convco@latest</code> to 0.7.1</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.7...v2.85.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.7&new-version=2.85.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-06 22:59:23 -07:00
dependabot[bot] 5a5f5795c9 chore: bump taiki-e/install-action from 2.85.5 to 2.85.7 (#3739)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.5 to 2.85.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.7</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.3.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.75.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.110.0.</p>
</li>
</ul>
<h2>2.85.6</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.255.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.18.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.3.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.7] - 2026-08-02</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.3.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.12.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.75.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.110.0.</p>
</li>
</ul>
<h2>[2.85.6] - 2026-08-01</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.255.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.18.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.3.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.4.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/67729d5c413db75907f0ad1e39bb04b9c868ff60"><code>67729d5</code></a>
Release 2.85.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d247d7efe4dd236c2b4dee4c768ae8993e3df073"><code>d247d7e</code></a>
Update wasmtime manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9197a82bb72ccea72eb87ca9bcf8dfeebceecb4a"><code>9197a82</code></a>
Update zizmor manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/68f6cd570d5902077df155f8ef44867ad5f57fe7"><code>68f6cd5</code></a>
Update <code>wasmtime@latest</code> to 47.0.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/377ee3f6a005506fab9f724afd7eae3134bc1154"><code>377ee3f</code></a>
Update <code>uv@latest</code> to 0.12.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8724fbfce1efccf3c603dcdece7882571347b0c7"><code>8724fbf</code></a>
Update <code>rclone@latest</code> to 1.75.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8d0062e663b7476d094ab4bc20c4436abdefb289"><code>8d0062e</code></a>
Update mise manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/28977a596b3205a34299d9607ece4eed2c6932eb"><code>28977a5</code></a>
Update <code>kingfisher@latest</code> to 1.110.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b951679bfc703a3cdad770a495203180e58aeb3d"><code>b951679</code></a>
Update cargo-semver-checks manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1beb33eee6d086258184383af9a538940be190ed"><code>1beb33e</code></a>
Release 2.85.6</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.5...v2.85.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.5&new-version=2.85.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-05 09:11:22 -07:00
dependabot[bot] ecde50eabe chore: bump taiki-e/install-action from 2.85.4 to 2.85.5 (#3716)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.4 to 2.85.5.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.5</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.0.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.50.0.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.17.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.16.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.5] - 2026-07-30</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.12.0.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.50.0.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.17.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.16.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/6a1bd70eaac3c8bdf093356838d7ee09fda951cf"><code>6a1bd70</code></a>
Release 2.85.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e55bdcf1dbf7a2b65f2a51365635e9b42fc25b1b"><code>e55bdcf</code></a>
Update <code>uv@latest</code> to 0.12.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/360695b5ac7cbf7052eb841633b06cd5e5cf73cd"><code>360695b</code></a>
Update <code>syft@latest</code> to 1.50.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9dfbbc2988d91169e4279461e8b23ade4a670b52"><code>9dfbbc2</code></a>
Update <code>sccache@latest</code> to 0.17.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/acc58332f7353bf8d3e368d3838b46513a4a90cb"><code>acc5833</code></a>
Update <code>mise@latest</code> to 2026.7.16</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/deaa28d948b4684cf00f14feb5a9267ae3792577"><code>deaa28d</code></a>
Update cargo-neat manifest</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.4...v2.85.5">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.4&new-version=2.85.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-03 13:36:10 -07:00
Worktrunk Bot 1db305f32f ci: bump pinned cargo-affected 0.4.0 and worktrunk 0.71.0 (#3708)
## Summary

Weekly CI pin check found the following drift (these `version:` strings
are invisible to Dependabot — it follows `Cargo.toml` deps and `uses:
foo@vN` refs, not inline pins):

- `cargo-affected`: 0.3.2 → 0.4.0 (MSRV 1.94, compatible with our 1.96)
— pinned twice in `affected.yaml` (`collect-affected` +
`affected-tests`); both moved together.
- `worktrunk`: 0.69.2 → 0.71.0 (MSRV 1.96, compatible with our 1.96) —
the CI-installed `wt`, bumped to the current release; pinned in
`ci.yaml` (×2) and `nightly.yaml`.

## Already up to date

- `cargo-insta`: 1.48.0, `cargo-nextest`: 0.9.140, `cargo-llvm-cov`:
0.8.7, `cargo-msrv`: 0.19.3, `cargo-udeps`: 0.1.61, `lychee`: 0.24.2
- `hustcer/setup-nu` (nushell): 0.114.1
- `zola`: 0.22.1 (taiki-e/install-action)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Notes

- windows-2022 stays pinned (actions/runner-images#12677 — windows-2025
lacks the D: drive).
- Both bumped tools' latest MSRVs are ≤ 1.96, so they stay compatible
with the current toolchain.
- **cargo-affected 0.4.0 DB compatibility:** the
`cargo-affected-db-v1-*` cache marker in `affected.yaml` does **not**
need bumping. The v0.3.2→v0.4.0 diff (`perf(collect): export each
binary's coverage map once`, `Make status predict what run does`)
touches `src/db.rs` only with `pub` → `pub(crate)` visibility changes —
no SQLite schema change to the `fingerprint_components` / coverage
tables — so an existing main DB deserializes unchanged.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-08-02 09:30:13 -07:00
dependabot[bot] 62cc0af7f8 chore: bump taiki-e/install-action from 2.85.3 to 2.85.4 (#3659)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.3 to 2.85.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.4</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.33.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.15.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.6.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.4] - 2026-07-29</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.33.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.15.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.6.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/065d6a08a14e61e89fb0a4c10eecdbdef39c7d8e"><code>065d6a0</code></a>
Release 2.85.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/971197ad86f8f6f161d7a8d91f1d711c4c21f628"><code>971197a</code></a>
Update <code>uv@latest</code> to 0.11.33</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3fc72354cdfd0f85327736793faab9b90a6282bb"><code>3fc7235</code></a>
Update syft manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7e230c19cf947f65a34e4e6f737c5f594c6779ba"><code>7e230c1</code></a>
Update sccache manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/51f77e860854ede202e22ff29a94094601feca62"><code>51f77e8</code></a>
Update <code>mise@latest</code> to 2026.7.15</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/87ddca437422cbc964934ac7b2d8423c1838090a"><code>87ddca4</code></a>
Update <code>biome@latest</code> to 2.5.6</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.3...v2.85.4">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.3&new-version=2.85.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-30 10:15:39 -07:00
dependabot[bot] f1923e9344 chore: bump taiki-e/install-action from 2.85.2 to 2.85.3 (#3649)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.2 to 2.85.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.3</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.2.</p>
</li>
<li>
<p>Update <code>ubi@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.14.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.13.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.3.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.3] - 2026-07-28</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.2.</p>
</li>
<li>
<p>Update <code>ubi@latest</code> to 0.10.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.14.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.13.0.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.3.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/18b1216eba7f8039b0f8d131d5473787f0edce68"><code>18b1216</code></a>
Release 2.85.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3a7eb9d7de04335647f871d88d8831485be842be"><code>3a7eb9d</code></a>
Update <code>xh@latest</code> to 0.26.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d4a0c1c709bc0f907c2a23b1a17cf6296b08298"><code>3d4a0c1</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9e4a53cd83bbbd84b17bc14008d4b067b9e99edb"><code>9e4a53c</code></a>
Update <code>ubi@latest</code> to 0.10.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9f2f6a3c937466e1abfae58f471a04b8835bc6de"><code>9f2f6a3</code></a>
Update <code>mise@latest</code> to 2026.7.14</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e026bd26eeb6a9542c62d43e1f98ced8d56ac346"><code>e026bd2</code></a>
Update <code>martin@latest</code> to 1.13.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f72efa0e99d8d9c15bf7fa6f14f0d4eb369fd084"><code>f72efa0</code></a>
Update <code>cargo-shear@latest</code> to 1.13.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d19664f75e59dd9c49e306b357f78fcb72cd2711"><code>d19664f</code></a>
Update <code>cargo-binstall@latest</code> to 1.21.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4d9bbfb56af57e022493493eecb97d07bf4fddd5"><code>4d9bbfb</code></a>
Update biome manifest</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.2...v2.85.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.2&new-version=2.85.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-29 20:04:34 -07:00
dependabot[bot] 8ef63150b6 chore: bump taiki-e/install-action from 2.85.0 to 2.85.2 (#3623)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.85.0 to 2.85.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.2</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.11.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.13.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.109.0.</p>
</li>
</ul>
<h2>2.85.1</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.30.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.32.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.12.</p>
</li>
<li>
<p>Update <code>cyclonedx@latest</code> to 0.33.1.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.2] - 2026-07-26</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.11.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.13.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.109.0.</p>
</li>
</ul>
<h2>[2.85.1] - 2026-07-25</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.30.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.32.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.12.</p>
</li>
<li>
<p>Update <code>cyclonedx@latest</code> to 0.33.1.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/41049aa56687c35e0afa74eed4f09cec4f9afabf"><code>41049aa</code></a>
Release 2.85.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dfcf36552b1b743e910b9b9b6b114a08e56a1e5e"><code>dfcf365</code></a>
Update <code>prek@latest</code> to 0.4.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/eea03ccfa855b965a301aa52424915fddc32f855"><code>eea03cc</code></a>
Update <code>mise@latest</code> to 2026.7.13</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/81ca2feb84748ed3fa514707ee1004f4f3ad715a"><code>81ca2fe</code></a>
Update martin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cc90ed04bc1a258ea90a83789f24b759a77c9671"><code>cc90ed0</code></a>
Update <code>kingfisher@latest</code> to 1.109.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/55639a3362f508fda5154d3451072205f5c32ca6"><code>55639a3</code></a>
Update cargo-shear manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d7d7cd5ac7f994c1892ae0c06165095b9139094"><code>3d7d7cd</code></a>
Release 2.85.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d09ccb4fe2105ac9ead6376f7a423ff88defeb57"><code>d09ccb4</code></a>
Update <code>vacuum@latest</code> to 0.30.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ac43dee1a92e482c0e244bdb0bb126908159e245"><code>ac43dee</code></a>
Update <code>uv@latest</code> to 0.11.32</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/49b16979f38f30e44b1f68af9115be9a6ffc5215"><code>49b1697</code></a>
Update prek manifest</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.85.0...v2.85.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.85.0&new-version=2.85.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-26 20:49:12 -07:00
Maximilian Roos 4202cffe61 fix(ci): split ci by cadence so coverage uploads on every main commit (#3608)
## What prompted this

Getting #3605 green ran into codecov reporting a `base_commit` three
commits
older than the real merge-base. This audits whether our config causes
that.

## The cause

Codecov picks a PR's base by walking back to the newest ancestor that
has a
coverage report. It used the real merge-base for PRs #3480, #3532 and
#3602,
and a stale one for #3603 and #3605. The difference is whether the
merge-base
uploaded a report. **29 of the last 40 main commits did not.**

`ci` had one concurrency group for main pushes, and GitHub cancels the
*pending* run in a group whenever a newer one joins, even with
`cancel-in-progress: false`. So the question is how long a run holds the
group,
and a run isn't done until its slowest job is:

| job | duration on main |
|-----|------------------|
| `fast-checks` | 2 min |
| `code-coverage` | 3-4 min |
| `test (windows)` | 11 min |
| `collect affected coverage (windows)` | 110-129 min |

Each main run held the group for ~2 hours, so nearly every subsequent
main push
was cancelled while queued, taking the 4-minute coverage job with it.
Every
cancelled main run's `updated_at` lands within a second of the next
push's
`created_at`.

The 2 hours is real work, not queue: 2-5s from `created_at` to
`started_at`,
then 108 minutes inside `cargo affected collect` — 4181 tests under
`-C instrument-coverage` with a per-test LLVM profile, ~5 GB of profraw.

## The fix: one workflow per cadence

The three groups of jobs have incompatible needs, and one group was
serving all
of them.

| workflow | cadence on main | why |
|----------|-----------------|-----|
| `ci` | every commit, ~11 min | required gate + fast checks |
| `coverage` | every commit, keyed per-sha | a skipped upload leaves
later PRs on a stale base |
| `affected` | sampled, ~2 h | a DB a few commits old still anchors a
correct superset |

`affected` keeps exactly the grouping it has today, so its sampling is
unchanged and deliberate. It just no longer drags the other two along.

### Scope of the impact

The posted `codecov/patch` check scopes to the PR's own GitHub diff, so
a stale
base did **not** score PRs against other people's lines. On #3605 the
posted
91.66% is exactly `github.rs`'s 11/12, while the stale-base compare
object
reported 64/65 across 13 files. What a stale base costs:

- `codecov/project` reports "compared to \<stale sha\>"
- the patch `auto` target is the stale base's project coverage (0.02pp
here)
- the compare API object widens to `base..head`, which is what made the
  investigation look like silence

Separately, `test`/`lint`/`fast-checks` also stopped completing on main.
Nothing
load-bearing rode on that (they already ran on the PR), but it left
`tend-ci-fix` with nothing to watch, since it doesn't fire on cancelled
runs.

## Two smaller fixes

- `ignore: "**/tests/**"` compiles to `.*/tests/.*` (confirmed against
codecov's validator), which needs a leading directory and so never
matched
`tests/` itself. Inert today since `cargo llvm-cov` reports only `src/`
(verified against a downloaded `cobertura.xml`), but now correct if that
  changes. Now `tests/**`.
- `fail_ci_if_error` gated on `github.repository_owner`, which is the
*base*
repo's owner on a fork PR too, so the soft-fail its comment describes
never
  applied. It keys off the head repo now.

## Docs

The API behaviour was ours to misuse, not codecov's to explain. Three
traps,
all confirmed against the live API:

- `file_report/<path>/` 404s with `coverage info not found` because the
route
swallows the trailing slash into the path. Without it the endpoint
returns
  `line_coverage`.
- `?pullid=N` always compares the PR's **current** head. `?base=&head=`
asks
  about an earlier commit.
- the compare response has no `patch_totals` key, and `.name` is
`{base, head}` rather than a string, so a filename lookup silently
matches
  nothing.

A working recipe already existed in `running-tend`, but that skill is
scoped to
CI. `tests/CLAUDE.md` owns coverage investigation, so the queries go
there and
`running-tend` points at them instead of keeping a second copy.

Re-running the corrected query against #3605's failing commit reproduces
the
miss exactly: `src/git/remote_ref/github.rs:164`, the `gh repo
set-default`
hint, matching what the session eventually found by hand.

## This PR demonstrates it

It changes no Rust at all, only YAML and markdown. Codecov still
reported a
**10-file, 111-line patch** on its first commit, because it based the
comparison on `203603909` rather than the real merge-base `32f380a27`.
Every
main commit in between has no report:

| commit | ci run | report |
|--------|--------|--------|
| `32f380a27` | queued | no |
| `9645e3e13` | cancelled | no |
| `bcd1ffdfd` | cancelled | no |
| `8865f20ab` | cancelled | no |

Every one of those 111 patch lines belongs to somebody else's merged
commit. It
passed at 100% only because those commits are well covered.

> _This was written by Claude Code on behalf of @max-sixty_

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-26 20:19:15 -07:00
Worktrunk Bot 901b79ab52 ci: bump pinned worktrunk to 0.69.2 (#3612)
Weekly CI pin bump. Only `worktrunk` drifted since last week — every
other `baptiste0928/cargo-install` pin (cargo-msrv `0.19.3`,
cargo-llvm-cov `0.8.7`, cargo-insta `1.48.0`, cargo-nextest `0.9.140`,
cargo-udeps `0.1.61`, lychee `0.24.2`), plus `setup-nu` `0.114.1` and
`zola@0.22.1`, is already at the latest upstream release.

- **worktrunk** `=0.68.0` → `=0.69.2` (3 sites: `ci.yaml` ×2,
`nightly.yaml`)

Compatibility: worktrunk `0.69.2` declares `rust-version = 1.96`,
matching the pinned toolchain (`rust-toolchain.toml` channel `1.96.0`),
so it builds under `baptiste0928/cargo-install`.

MSRV/toolchain needed no bump this week: current stable is `1.97.1`, so
latest−1 is `1.96`, which is already what `Cargo.toml`,
`tests/helpers/wt-perf/Cargo.toml`, and `rust-toolchain.toml` pin.

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-07-26 04:51:25 -07:00
dependabot[bot] 4ea2fe46a3 chore: bump taiki-e/install-action from 2.84.0 to 2.85.0 (#3570)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.84.0 to 2.85.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.85.0</h2>
<ul>
<li>
<p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p>
</li>
<li>
<p>Support <code>bpf-linker</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p>
</li>
<li>
<p>Support <code>rafn</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>,
thanks <a
href="https://github.com/DarkWanderer"><code>@​DarkWanderer</code></a>)</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.1.</p>
</li>
<li>
<p>Update <code>zizmor@latest</code> to 1.28.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.2.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.31.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.49.0.</p>
</li>
</ul>
<h2>2.84.1</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.1.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.254.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.30.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.11.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.5.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.85.0] - 2026-07-23</h2>
<ul>
<li>
<p>Support <code>wild</code> (alias: <code>wild-linker</code>). (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1949">#1949</a>)</p>
</li>
<li>
<p>Support <code>bpf-linker</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1950">#1950</a>)</p>
</li>
<li>
<p>Support <code>rafn</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1935">#1935</a>,
thanks <a
href="https://github.com/DarkWanderer"><code>@​DarkWanderer</code></a>)</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.1.</p>
</li>
<li>
<p>Update <code>zizmor@latest</code> to 1.28.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.2.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.31.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.49.0.</p>
</li>
</ul>
<h2>[2.84.1] - 2026-07-22</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 47.0.1.</p>
</li>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.254.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.30.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.11.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.5.0.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.5.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/7572810d7dd469b651bb7793945692cf78da5dd7"><code>7572810</code></a>
Release 2.85.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d73fed906d8b5a8fbe1165c7635ef41dbf5e6ccd"><code>d73fed9</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20d0440ac8346c2da5bfa9bc79b6d50c30ee7658"><code>20d0440</code></a>
Support bpf-linker (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1950">#1950</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/05a01b63a23569d0bf6dde483954e312dce7d417"><code>05a01b6</code></a>
Update vacuum manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/23a3cce147f42d0975d244f68a4af961ccd8fd53"><code>23a3cce</code></a>
Update <code>cargo-neat@latest</code> to 0.5.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/54ede987e296f0fc0b43f3f75d496577fad36a9c"><code>54ede98</code></a>
Support rafn (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1935">#1935</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/411aa4ba3c7fb6ad60a7421c46e881a3a1ceb8ad"><code>411aa4b</code></a>
Support wild (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1949">#1949</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4427ee328dd40578670ed6724b4a766207e21f0e"><code>4427ee3</code></a>
Update <code>zizmor@latest</code> to 1.28.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/68a5a96ea71119471050840e296140c66135d7b8"><code>68a5a96</code></a>
Update <code>wasmtime@latest</code> to 47.0.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f276a80345c4641da04f6613887cc496c332c232"><code>f276a80</code></a>
Update <code>uv@latest</code> to 0.11.31</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.84.0...v2.85.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.84.0&new-version=2.85.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-24 18:55:20 -07:00
dependabot[bot] 89b58e2522 chore: bump taiki-e/install-action from 2.83.3 to 2.84.0 (#3529)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.83.3 to 2.84.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.84.0</h2>
<ul>
<li>
<p>Support <code>d2</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p>
</li>
<li>
<p>Support <code>protoc-gen-connect-openapi</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>,
thanks <a
href="https://github.com/JasterV"><code>@​JasterV</code></a>)</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.0. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>,
thanks <a
href="https://github.com/graelo"><code>@​graelo</code></a>)</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.57.0.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.4.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.2.</p>
</li>
</ul>
<h2>2.83.4</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.10.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.29.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.10.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.7.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.84.0] - 2026-07-20</h2>
<ul>
<li>
<p>Support <code>d2</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1944">#1944</a>)</p>
</li>
<li>
<p>Support <code>protoc-gen-connect-openapi</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1922">#1922</a>,
thanks <a
href="https://github.com/JasterV"><code>@​JasterV</code></a>)</p>
</li>
<li>
<p>Update <code>convco@latest</code> to 0.7.0. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1941">#1941</a>,
thanks <a
href="https://github.com/graelo"><code>@​graelo</code></a>)</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.57.0.</p>
</li>
<li>
<p>Update <code>cargo-semver-checks@latest</code> to 0.49.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.2.4.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.2.</p>
</li>
</ul>
<h2>[2.83.4] - 2026-07-17</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.10.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.29.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.10.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.7.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/a6b2e2dcd845ddd7f509ce4f3ed3d922b80cc5d9"><code>a6b2e2d</code></a>
Release 2.84.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fbdd9c50c029b1f2d5667c090563e4a31cc3f43c"><code>fbdd9c5</code></a>
Update cargo-neat manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/424c5f90440984601897d473b7936cc3fd52bda8"><code>424c5f9</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a1fa02c1f9b8ef65d443ad6b3f0b99f5863b6f4f"><code>a1fa02c</code></a>
Support <code>protoc-gen-connect-openapi</code> (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1922">#1922</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9e22773f98774c41688b7cc39a5f7f7eaa4ca97d"><code>9e22773</code></a>
Update DEVELOPMENT.md</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8d5009fee2da9de26fee96bb727c2df318ffce42"><code>8d5009f</code></a>
Support d2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/5193316cc852ca0f37d4819875e939522c4f7c47"><code>5193316</code></a>
Update <code>tombi@latest</code> to 1.2.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4c740c71c8320819d812216022c3ff178e1a3394"><code>4c740c7</code></a>
Update <code>tombi@latest</code> to 1.2.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/de240ff26f6e8b33bacd85a1a7c621c92d8d7c70"><code>de240ff</code></a>
Update <code>just@latest</code> to 1.57.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dfca8548668aebabd66da598ea31d87a03819d43"><code>dfca854</code></a>
Update <code>cargo-semver-checks@latest</code> to 0.49.0</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.83.3...v2.84.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.83.3&new-version=2.84.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-21 18:46:09 -07:00
dependabot[bot] 99704db62f chore: bump taiki-e/install-action from 2.83.2 to 2.83.3 (#3497)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.83.2 to 2.83.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.83.3</h2>
<ul>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.160.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.9.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.6.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.2.</p>
</li>
<li>
<p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.4.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.83.3] - 2026-07-16</h2>
<ul>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.160.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.9.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.6.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.2.</p>
</li>
<li>
<p>Update <code>cargo-dinghy@latest</code> to 0.8.5.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.21.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.4.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/ed67fa35ac944f3a9b33f12c4dd43b6f31a47e20"><code>ed67fa3</code></a>
Release 2.83.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/618fa5589cc587c869ec39ae0606a6cf6ef03c0b"><code>618fa55</code></a>
Update prek manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/47579092c792f14738b668ee240d199bcad0d8e2"><code>4757909</code></a>
Update zizmor manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f1fa00538cc2e7231cb60e4d47c24597e0c387b7"><code>f1fa005</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/aa8dc906017e56077bc125256c4d9301b1cde72a"><code>aa8dc90</code></a>
Update <code>release-plz@latest</code> to 0.3.160</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b9654978ff643e657a453245addf012127caa2c5"><code>b965497</code></a>
Update <code>prek@latest</code> to 0.4.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7aab3a9c373d60a23a5b89c212174c0baa6a0fa0"><code>7aab3a9</code></a>
Update <code>mise@latest</code> to 2026.7.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/bfee8d1ca4d6f82a5c3f7151f046e75e6c202ff5"><code>bfee8d1</code></a>
Update kingfisher manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b65771b2e228b44f33eb596fbf78979075cd8aa7"><code>b65771b</code></a>
Update <code>dprint@latest</code> to 0.55.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20468927b3c1d5f14e6c4c1379ced0c6cc1ed103"><code>2046892</code></a>
Update <code>cargo-dinghy@latest</code> to 0.8.5</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.83.2...v2.83.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.83.2&new-version=2.83.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-19 11:21:30 -07:00
Worktrunk Bot 5967df2dfc chore(ci): weekly renovation 2026-07-19 (#3518) 2026-07-19 08:39:31 -07:00
Maximilian Roos 0a1cd19cc9 chore: drop the NEXTEST_NO_INPUT_HANDLER workaround (#3482)
nextest#2878 (the run suspending with SIGTTOU when a test spawns an
interactive shell, as the `shell-integration-tests` feature does) was
fixed in nextest 0.9.118, so the `NEXTEST_NO_INPUT_HANDLER=1` workaround
threaded through the insta hook, CI, and the test docs is obsolete.
Verified on nextest 0.9.132: the shell-wrapper tests run to completion
under a real PTY without the variable.

`.config/nextest.toml` now pins `nextest-version = "0.9.118"`, so an
older nextest fails with a clear version error instead of suspending
mid-run.

> _This was written by Claude Code on behalf of max_

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-15 15:02:56 -07:00
dependabot[bot] 334b9c6165 chore: bump taiki-e/install-action from 2.83.0 to 2.83.2 (#3444)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.83.0 to 2.83.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.83.2</h2>
<ul>
<li>
<p>Update <code>parse-dockerfile@latest</code> to 0.1.8.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.5.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.56.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.4.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.4.1.</p>
</li>
</ul>
<h2>2.83.1</h2>
<ul>
<li>
<p>Update <code>rclone@latest</code> to 1.74.4.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.4.</p>
</li>
<li>
<p>Update <code>cargo-deny@latest</code> to 0.20.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.83.2] - 2026-07-12</h2>
<ul>
<li>
<p>Update <code>parse-dockerfile@latest</code> to 0.1.8.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.5.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.56.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.4.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.4.1.</p>
</li>
</ul>
<h2>[2.83.1] - 2026-07-10</h2>
<ul>
<li>
<p>Update <code>rclone@latest</code> to 1.74.4.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.4.</p>
</li>
<li>
<p>Update <code>cargo-deny@latest</code> to 0.20.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/43aecc8d72668fbcfe75c31400bc4f890f1c5853"><code>43aecc8</code></a>
Release 2.83.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fca47892c74f4dffa1e86ad93eca31cf898c2541"><code>fca4789</code></a>
Update prek manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b41cc1f9ab348b9db341d8597853df93b08652f0"><code>b41cc1f</code></a>
Update <code>parse-dockerfile@latest</code> to 0.1.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8d866f8ca86db77044d7d29639e24660d0b37b88"><code>8d866f8</code></a>
Update <code>mise@latest</code> to 2026.7.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7ebe462223a33af951eed3c3ab1f754ddf2992e2"><code>7ebe462</code></a>
Update <code>just@latest</code> to 1.56.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/01ab5633b01b19988c158b5366d64947fd6cacce"><code>01ab563</code></a>
Update <code>gungraun-runner@latest</code> to 0.19.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f164a682e7e0033cf72f1d5722d079fe82275c1e"><code>f164a68</code></a>
Update <code>cargo-neat@latest</code> to 0.4.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/2ca9b94c269419b7b0c711c09d0b21c4e1d51145"><code>2ca9b94</code></a>
Release 2.83.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8598f86981150fb7f6511798af658bbf80a8ea46"><code>8598f86</code></a>
Update parse-dockerfile manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/76cfe4de2d710e12bae93580164f20dff9fd96e9"><code>76cfe4d</code></a>
Update <code>rclone@latest</code> to 1.74.4</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.83.0...v2.83.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.83.0&new-version=2.83.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-13 16:01:45 -07:00
Worktrunk Bot d7e3aac9a0 ci: bump pinned tool versions (cargo-nextest, worktrunk, nushell) (#3429) 2026-07-12 08:16:40 -07:00
dependabot[bot] fbf380b447 chore: bump taiki-e/install-action from 2.82.11 to 2.83.0 (#3405)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.11 to 2.83.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.83.0</h2>
<ul>
<li>
<p>Support <code>cargo-about</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1924">#1924</a>,
thanks <a
href="https://github.com/ruffsl"><code>@​ruffsl</code></a>)</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.28.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.12.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.106.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.3.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.83.0] - 2026-07-09</h2>
<ul>
<li>
<p>Support <code>cargo-about</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1924">#1924</a>,
thanks <a
href="https://github.com/ruffsl"><code>@​ruffsl</code></a>)</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.28.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.12.0.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.106.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.3.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/c7eb1735f09259a5035e8e5d44b1406b1cddc0fb"><code>c7eb173</code></a>
Release 2.83.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/84d4171800adc3ccfe039969324217bde4ca0f25"><code>84d4171</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/21e5d859bea44c4a9c990a48a63fed2203e01d68"><code>21e5d85</code></a>
Support cargo-about (<a
href="https://redirect.github.com/taiki-e/install-action/issues/1924">#1924</a>)</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/786ded99bea7500a913f1f19b18bfcfdf782fb97"><code>786ded9</code></a>
Update <code>uv@latest</code> to 0.11.28</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1c1bbcf779fa11c2ef8cf0bda69bba43465230e6"><code>1c1bbcf</code></a>
Update rclone manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4e5eb09101d68b0b5f52740d1abc011ae003ac6f"><code>4e5eb09</code></a>
Update <code>martin@latest</code> to 1.12.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dc84fc5f1a7ad878e27656eb3ed173e393c62867"><code>dc84fc5</code></a>
Update <code>kingfisher@latest</code> to 1.106.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cf10e546be4ee50afcfd94a851bcd9eb64cba30d"><code>cf10e54</code></a>
Update <code>biome@latest</code> to 2.5.3</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.11...v2.83.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.11&new-version=2.83.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-10 03:43:43 -07:00
Maximilian Roos c8de0d872a ci: move lychee link check to the nightly workflow (#3402)
Moves the lychee link check out of PR CI into the `nightly` workflow.
Link health depends on external sites (429s, bot-blocking, link rot),
which made `lint` the flakiest PR check, and breakage isn't correlated
with the PR that trips it: the most recent main run's lint job went red
on the docs.anthropic.com restructure (fixed in #3399) with no code
change involved.

The hook stays defined once in `.pre-commit-config.yaml`, moved to the
`manual` stage, so the PR `lint` job, local `pre-commit run
--all-files`, and the `wt merge` gate all skip it (the wt.toml Windows
conditional existed only to skip lychee and collapses). The new
`link-check` nightly job runs that stage with the pinned lychee and is
wired into `create-issue-on-nightly-failure`, so breakage lands in the
nightly-failure issue for tend instead of blocking unrelated PRs.
Running through pre-commit rather than `git ls-files | xargs lychee`
keeps file selection at one definition: pre-commit's `types: [file]`
filter excludes the 16 tracked `.md`/`.txt` symlinks, which would
otherwise false-positive on relative links resolved against the
symlink's directory.

The trade: a PR that introduces a genuinely wrong URL now merges green
and is caught up to a day later, asynchronously.

Verified locally that the default stage no longer selects the hook and
that `pre-commit run lychee-system --all-files --hook-stage manual`
reproduces the CI lint run's selection exactly (same two flagged
inputs). The nightly job itself first runs on the next cron or a
`workflow_dispatch`.

> _This was written by Claude Code on behalf of max_

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-09 20:12:03 -07:00
dependabot[bot] b4aba5c4a3 chore: bump taiki-e/install-action from 2.82.9 to 2.82.11 (#3387)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.9 to 2.82.11.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.11</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.253.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.27.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.2.</p>
</li>
<li>
<p>Update <code>mdbook@latest</code> to 0.5.4.</p>
</li>
</ul>
<h2>2.82.10</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.2.0.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.140.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.11] - 2026-07-08</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.253.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.27.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.2.</p>
</li>
<li>
<p>Update <code>mdbook@latest</code> to 0.5.4.</p>
</li>
</ul>
<h2>[2.82.10] - 2026-07-07</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.2.0.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.140.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/5ebac0d9522d786674368e47e92963ba13f2c376"><code>5ebac0d</code></a>
Release 2.82.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/0ef1b06f246983bfc9b14d94cff7855d90529e46"><code>0ef1b06</code></a>
Update <code>wasm-tools@latest</code> to 1.253.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/78ce37c0ce7da0b633b3ee9a800d18e6d4fb11e7"><code>78ce37c</code></a>
Update <code>mise@latest</code> to 2026.7.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/080cc5c6de6a4709eb3c099c56ad225fa3db5492"><code>080cc5c</code></a>
Update wasm-tools manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c870c7a1dbaa5d99671937765392df21151c7808"><code>c870c7a</code></a>
Update <code>uv@latest</code> to 0.11.27</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dcc765d42b0daa9842059edfb11fda14143027e2"><code>dcc765d</code></a>
Update <code>mise@latest</code> to 2026.7.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/98fa0bac11003b6f1143fd1634b47d42624003b2"><code>98fa0ba</code></a>
Update <code>mdbook@latest</code> to 0.5.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/544756b7938b454b9339922116f9f21301cc8169"><code>544756b</code></a>
Update martin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/116765984988a711571bdb8292667a67de89b08e"><code>1167659</code></a>
Update kingfisher manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ca5e0a7228a263c12320511f1b10890972a12bbc"><code>ca5e0a7</code></a>
Update biome manifest</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.9...v2.82.11">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.9&new-version=2.82.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-09 09:22:36 -07:00
dependabot[bot] c9044d01b5 chore: bump taiki-e/install-action from 2.82.7 to 2.82.9 (#3375)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.7 to 2.82.9.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.9</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.9.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.8.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.0.</p>
</li>
<li>
<p>Update <code>cargo-leptos@latest</code> to 0.3.7.</p>
</li>
</ul>
<h2>2.82.8</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.8.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.26.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.72.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.7.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.6.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.0.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.55.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.9] - 2026-07-05</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.9.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.8.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.37.0.</p>
</li>
<li>
<p>Update <code>cargo-leptos@latest</code> to 0.3.7.</p>
</li>
</ul>
<h2>[2.82.8] - 2026-07-03</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.8.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.26.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.72.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.7.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.6.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.7.0.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.55.1.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.2.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/4684b8405694ae9dd42c9f39ba901a70ae83f4a3"><code>4684b84</code></a>
Release 2.82.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/29fb1dbe52c0247f03f90f9dd43b08d3c603510b"><code>29fb1db</code></a>
Update <code>vacuum@latest</code> to 0.29.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/584230b16680bbb1ddef3c65a89568570fd36f69"><code>584230b</code></a>
Update tombi manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1872019a1c4268421e4c2d5f230285190a08b258"><code>1872019</code></a>
Update <code>prek@latest</code> to 0.4.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3e817d29dde43a866e242560569eb7f418035f1a"><code>3e817d2</code></a>
Update <code>cargo-tarpaulin@latest</code> to 0.37.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a71dd1a66df622ab4134f69df1b8c4b7a8889ddf"><code>a71dd1a</code></a>
Update <code>cargo-leptos@latest</code> to 0.3.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c93ccc03e00cd0e08e494f5fd058a6c55a6a1907"><code>c93ccc0</code></a>
Release 2.82.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/5083f1886534d6d96c49df934ae7106b35fd488e"><code>5083f18</code></a>
Update <code>vacuum@latest</code> to 0.29.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fdd68a857612ac3f29f4abaa6be9f4d379946632"><code>fdd68a8</code></a>
Update <code>uv@latest</code> to 0.11.26</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3b61d4b2086bc6aee10b8e58f1e6a25675e03da4"><code>3b61d4b</code></a>
Update <code>typos@latest</code> to 1.48.0</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.7...v2.82.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.7&new-version=2.82.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-06 19:41:42 -07:00
Worktrunk Bot 0beeb3b738 chore(ci): weekly renovation 2026-07-05 (#3368) 2026-07-05 06:51:48 -07:00
dependabot[bot] 9478fc6675 chore: bump taiki-e/install-action from 2.82.6 to 2.82.7 (#3342)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.6 to 2.82.7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.7</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.1.6.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.105.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.3.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.8.0.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.36.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.7] - 2026-06-30</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.1.6.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.105.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.3.</p>
</li>
<li>
<p>Update <code>editorconfig-checker@latest</code> to 3.8.0.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.1.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.36.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/16b05812d776ae1dfaabc8277e421fb6d2506419"><code>16b0581</code></a>
Release 2.82.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/68c845308d9b56d38e797c62e48eddfe1b4ba94f"><code>68c8453</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8532697fda4ee37ccd65901e90d87a785c45d7bd"><code>8532697</code></a>
Update trivy manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/2959f9e73b89d18f2d72d0aa55ed797e70062732"><code>2959f9e</code></a>
Update <code>tombi@latest</code> to 1.1.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9bfa119f6c347b458726d629758b16dd861727a4"><code>9bfa119</code></a>
Update <code>kingfisher@latest</code> to 1.105.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f198b91ffb69aa6008cb3b0ea9cf6eb6b0af01f4"><code>f198b91</code></a>
Update just manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/20feedd5827d6d189bca20753dbd5582948e7478"><code>20feedd</code></a>
Update <code>gungraun-runner@latest</code> to 0.19.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/314197aa953241335b4a4c41c2d6e8066d6150da"><code>314197a</code></a>
Update <code>editorconfig-checker@latest</code> to 3.8.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f8632ebbd28b43dce012ff3db91c959c7751db33"><code>f8632eb</code></a>
Update <code>dprint@latest</code> to 0.55.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4234dc0f7acb7e7774a1716b103fcaf2d9ed9b4d"><code>4234dc0</code></a>
Update <code>cargo-tarpaulin@latest</code> to 0.36.0</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.6...v2.82.7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.6&new-version=2.82.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-30 20:57:07 -07:00
Maximilian Roos fb20a315a1 ci: split fast checks from the full suite; add nightly full-tests safety net (#3332)
Prep work toward making the advisory `cargo-affected` legs the PR test
path, without flipping any merge gate yet.

## What changed

- **`ci.yaml`** — the `test (linux/macos/windows)` job bundled five
gates through one `wt hook pre-merge` call. Split the
platform-independent ones — `Cargo.lock` freshness, doctests, and the
rustdoc `-Dwarnings` build — into a new Linux-only `fast-checks` job.
`test` now runs *only* the full nextest suite (`insta`), so it's a clean
drop-in shape for the affected legs later. `fast-checks` stays required
and unchanged across the eventual flip.
- **`nightly.yaml`** — added a `full-tests` matrix job
(linux/macos/windows, the full suite). This is the safety net for what
cargo-affected can't cover: tests it under-selects, plus non-Rust/build
inputs it can't trace (`include_str!`, templates, `build.rs`, toolchain,
proc-macros). It also hosts the Linux `--unreferenced reject` orphan
check. It runs on nightly cron, the `nightly` label, dispatch, and
dep-pushes — deliberately **not** on the main-gating path, so a
cargo-affected miss surfaces in nightly (non-blocking, Tend-fixable)
rather than reddening main.

Nothing is gated by the affected legs yet; `test (*)` stays the required
PR gate during calibration. The flip (make affected required, delete the
PR `test` job) is a later, separate change — documented in the `ci.yaml`
comment block.

## ⚠️ Branch-protection follow-up

Splitting `lockfile`/`doctest`/`doc` out of the required `test` job
means **`fast-checks` must be added to the required status checks** (the
"Merge access" ruleset). Until it is, those three gates don't block PRs.
This is an admin action that should accompany the merge.

## Testing

CI-config only; validated with `actionlint` and pre-commit
(yaml/eof/whitespace/typos). The workflow behavior itself validates on
this PR's run.

> _This was written by Claude Code on behalf of max_

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 22:53:00 -07:00
Maximilian Roos 16027a6a58 fix(ci): install zsh/fish via apt-get, drop cache-apt-pkgs-action (#3324)
## What this does

Removes the third-party `awalsh128/cache-apt-pkgs-action` from CI
entirely, installing zsh + fish with a plain `sudo apt-get update &&
sudo apt-get install -y zsh fish` at all four call sites:

- `ci.yaml` — `code-coverage`
- `nightly.yaml` — `feature-powerset` and `benchmarks`
- `.github/actions/test-setup/action.yaml` — composite action used by
the required `test` matrix

It also drops the Dependabot `ignore` entry for the action (no longer
needed once the action is gone).

## Why (and why this supersedes #3321)

`awalsh128/cache-apt-pkgs-action@v1.6.2` (dependabot bump #3311) empties
its own `packages: zsh fish` argument in the "Normalizing package list"
step and aborts with `Packages argument is empty`, in ~20s, before any
compilation — killing `code-coverage` on every PR, which in turn stopped
`codecov/patch` from posting anywhere. Root cause is upstream PR #177
quoting `${packages}`, tracked at
[awalsh128/cache-apt-pkgs-action#210](https://github.com/awalsh128/cache-apt-pkgs-action/issues/210).

#3321 already fixed main by pinning back to `v1.6.1`. This PR takes the
sturdier route — dropping the dependency — based on the upstream's
health:

- Issue #210 is open with **no maintainer engagement**; affected users
call the action "basically non-functional," with a fresh repro confirmed
on 2026-06-29.
- **No open PR** reverts #177 or fixes the regression; v1.6.2 (broken)
is still tagged `Latest`, and contributor PRs sit unmerged for months.
- The action's mutable `v1`/`latest` tags are actively being retargeted
upstream (open PR #211), which is how a `@v1.6.1` ref can resolve to
drifted code — so even the pin isn't a stable anchor.

`zsh` and `fish` are in the standard Ubuntu repos (no PPA), so the
action only *cached* an install of two tiny packages — a negligible
speed-up for a third-party dependency that is under-maintained, broke CI
repo-wide, and can't be stably pinned. Dropping it removes the whole
failure class and matches the existing `musl-tools` install already in
`nightly.yaml`. Verified: the identical `apt-get` step already runs
green in the required `test (linux)` job (installs zsh 5.9 + fish
3.7.0), and a full `code-coverage` run on this branch completed green
end-to-end with `codecov/patch` posting again.

## Guard against recurrence

#3311 merged while its own `code-coverage` was red because
`code-coverage`/`codecov/patch` aren't *required* status checks (only
`test (linux/macos/windows)` are), and `codecov/patch` was absent rather
than red (the job died before uploading), so the mechanical-bump merge
saw nothing blocking. Recommended guard: make the `code-coverage` job a
required status check — it fails only on genuine breakage (the codecov
upload already soft-fails on fork PRs), so it blocks this class without
re-introducing the flake that keeps `codecov/patch` itself advisory.

> _This was written by Claude Code on behalf of max_

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 16:48:37 -07:00
Maximilian Roos 225b232b51 ci: gate rust caches to main and share one per OS to fit the 10 GB cap (#3323)
## What

The Actions cache sat at **11.1 GB across 57 caches** against GitHub's
hard **10 GB per-repo cap**, so every run was evicting older caches
LRU-style — constant churn. ~57% of that was single-PR caches
(`refs/pull/N/merge`) that no other PR can ever restore, depositing
budget that evicted the reusable `main` caches.

## Changes

- **`save-if` gated to `main` on every rust-cache call.** PRs restore
`main`'s cache via the restore-key fallback and never deposit their own.
This alone drops the footprint under the cap.
- **One shared cache per OS for the test family.** `test-setup` now sets
`shared-key`, with `test` as the sole saver (new `save-cache` input,
default `true`); `affected-tests` / `collect-affected` /
`release-target` pass `save-cache: "false"`. The PR-only
`affected-tests` job needed this most — it never runs on `main`, so a
per-job key had no baseline and cold-built every PR; it now rides
`test`'s `main` cache.
- **Nightly/release jobs stop saving.** Stable ones (`feature-powerset`,
`benchmarks`, `crate-build`) restore the shared cache read-only; the
nightly-toolchain ones (`check-unused`, `minimal-versions`) and the
cross-target `release-target` just don't save — near-zero reuse against
the cap.
- **`cache-bin: false` applied to the v0 jobs too** (`lint`,
`feature-check`, `msrv`, `code-coverage`), closing the latent
rustup-proxy bug that `test-setup` already guarded against.

## Deliberate non-changes

- `lint` / `feature-check` / `code-coverage` keep their own `main`-gated
caches rather than joining the shared one. They build divergent
artifacts (clippy-check, `--no-default-features`,
coverage-instrumented), and we're no longer space-constrained after the
above — a right-sized own cache beats a 1.3 GB restore for partial
reuse.
- Did **not** add PRQL's `Cargo.lock`-hash-in-prefix-key: rust-cache
already keys on the lockfile, and `save-if: main` already prevents the
PR-junk accumulation that trick fights (one mechanism per guarantee).
- The `awalsh128/cache-apt-pkgs-action` stays pinned at `v1.6.1` (per
#3321, merged into this branch) — not replaced. Only
`Swatinem/rust-cache` config changes here.

Projected active cache: **~3–5 GB**, all `main`-scoped. No `wt` behavior
change, so no changelog entry.

> _This was written by Claude Code on behalf of max_

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 12:39:55 -07:00
Worktrunk Bot 7daa0763d7 fix(ci): pin cache-apt-pkgs-action back to v1.6.1 (#3321)
## Problem

CI on `main` fails in the required `code-coverage` job ([failed
run](https://github.com/max-sixty/worktrunk/actions/runs/28358354325)).
The `Install shells (zsh, fish)` step aborts:

```
PACKAGES: zsh fish
Normalizing package list...
Validating action arguments (version='1', packages='')...
exit status 100Packages argument is empty.
##[error]Process completed with exit code 3.
```

This is a deterministic regression in
`awalsh128/cache-apt-pkgs-action@v1.6.2`, introduced by the bump in
#3311. v1.6.2's new "Normalize package list" step turns the input `zsh
fish` into an empty string before validation. Upstream root cause: PR
#177 added quotes around `${packages}` in `get_normalized_package_list`,
so `apt_query` treats the entire space-separated list as one package
name and the normalization yields nothing — tracked at
[awalsh128/cache-apt-pkgs-action#210](https://github.com/awalsh128/cache-apt-pkgs-action/issues/210).
v1.6.2 is still the latest release with no fix.

#3311 bumped three of the four call sites (`ci.yaml` `code-coverage`,
two in `nightly.yaml`); `.github/actions/test-setup/action.yaml` was
never bumped and stayed on v1.6.1 — which is why test-setup-based jobs
passed while `code-coverage` failed.

## Solution

Revert the three v1.6.2 references to v1.6.1, the known-good version the
test-setup action already uses, so all four sites are consistent again.
Also add a Dependabot `ignore` for v1.6.2 of this action so the daily
github-actions update doesn't immediately re-create the same broken
bump; the entry is scoped to that one version, so Dependabot can bump
forward once a fixed release ships.

This is the right level: the failure is entirely upstream, the fix
matches the existing precedent (#2583 pinned this action), and pinning
back is a clean revert rather than a workaround layered on a broken
release.

## Testing

The fix is a CI-config change; correctness is verified by CI itself
re-running the `code-coverage` job with v1.6.1. The v1.6.1 path is
already exercised by every existing run via `test-setup`, which never
failed on this step.

Note: the advisory (non-required) `collect affected coverage (windows)`
leg in the failed run also failed, on an unrelated PTY flake
(`test_switch_picker_create_validates_templates_before_worktree`) — a
separate known-flaky Windows shell-integration test, not caused by this
commit and not addressed here.

---
Automated fix for [failed
run](https://github.com/max-sixty/worktrunk/actions/runs/28358354325)

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-06-29 11:28:52 -07:00
dependabot[bot] b7cf4f0cf0 chore: bump taiki-e/install-action from 2.82.4 to 2.82.6 (#3312)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.4 to 2.82.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.6</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.7.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.25.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.46.0.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.0.</p>
</li>
<li>
<p>Update <code>cargo-auditable@latest</code> to 0.7.5.</p>
</li>
</ul>
<h2>2.82.5</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 46.0.1.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.126.</p>
</li>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.6.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.14.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.1.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.6] - 2026-06-29</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.7.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.25.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.46.0.</p>
</li>
<li>
<p>Update <code>dprint@latest</code> to 0.55.0.</p>
</li>
<li>
<p>Update <code>cargo-auditable@latest</code> to 0.7.5.</p>
</li>
</ul>
<h2>[2.82.5] - 2026-06-26</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 46.0.1.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.126.</p>
</li>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.6.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.14.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.1.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/9bcaee1dcae34154180f412e2fa69355a7cda9f6"><code>9bcaee1</code></a>
Release 2.82.6</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e43cd7ce2e2c5a6d08d652405a0ead8cda7bf2db"><code>e43cd7c</code></a>
Update <code>vacuum@latest</code> to 0.29.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3761407ad0b5e4e5b42ccb62e48ffa2712e94703"><code>3761407</code></a>
Update <code>uv@latest</code> to 0.11.25</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cb6ad0dba1ff078e589e75ae88bb03120688feef"><code>cb6ad0d</code></a>
Update tombi manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/6022671c93f20efad71663e3adc06d63e7f1ec8a"><code>6022671</code></a>
Update <code>syft@latest</code> to 1.46.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ab5aae8354703341b0939f4e6c1bb66372b446db"><code>ab5aae8</code></a>
Update gungraun-runner manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/867613b49949fba1c8fe194d323c7c51b77b24d2"><code>867613b</code></a>
Update editorconfig-checker manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c5837ef63439ac9ebc0ecce97e23cca6a4a5aac4"><code>c5837ef</code></a>
Update <code>dprint@latest</code> to 0.55.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7d41d74582778d0345db89bc1054e86f3802b6d2"><code>7d41d74</code></a>
Update <code>cargo-auditable@latest</code> to 0.7.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/bffeee26d4db9be238a4ea78d8826604ebcb594d"><code>bffeee2</code></a>
Release 2.82.5</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.4...v2.82.6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.4&new-version=2.82.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-29 01:18:52 -07:00
dependabot[bot] 1c31672a62 chore: bump awalsh128/cache-apt-pkgs-action from 1.6.1 to 1.6.2 (#3311)
Bumps
[awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action)
from 1.6.1 to 1.6.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/releases">awalsh128/cache-apt-pkgs-action's
releases</a>.</em></p>
<blockquote>
<h2>v1.6.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Apply PR <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/193">#193</a>
dependency pinning to <code>action.yml</code> (overwrite current action
refs) by <a
href="https://github.com/awalsh128"><code>@​awalsh128</code></a> with <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/201">awalsh128/cache-apt-pkgs-action#201</a></li>
<li>install_and_cache_pkgs.sh: Fix two issues saving preinst and
postinst scripts. by <a
href="https://github.com/gtjoseph"><code>@​gtjoseph</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/195">awalsh128/cache-apt-pkgs-action#195</a></li>
<li>[WIP] Fix test workflows for actions by <a
href="https://github.com/awalsh128"><code>@​awalsh128</code></a> with <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/184">awalsh128/cache-apt-pkgs-action#184</a></li>
<li>Fix apt-cache package lookup failure in nektos/act environments by
<a href="https://github.com/awalsh128"><code>@​awalsh128</code></a> with
<a href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/172">awalsh128/cache-apt-pkgs-action#172</a></li>
<li>add shellcheck linting by <a
href="https://github.com/mac-anysphere"><code>@​mac-anysphere</code></a>
in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/177">awalsh128/cache-apt-pkgs-action#177</a></li>
<li>Harden <code>apt_query</code> virtual package resolution against
<code>apt-cache showpkg</code> warnings by <a
href="https://github.com/awalsh128"><code>@​awalsh128</code></a> with <a
href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/202">awalsh128/cache-apt-pkgs-action#202</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/gtjoseph"><code>@​gtjoseph</code></a>
made their first contribution in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/195">awalsh128/cache-apt-pkgs-action#195</a></li>
<li><a
href="https://github.com/mac-anysphere"><code>@​mac-anysphere</code></a>
made their first contribution in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/177">awalsh128/cache-apt-pkgs-action#177</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2">https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/5513791f75b039e2a79653b1a92238d3fb8d99b4"><code>5513791</code></a>
fix: handle apt showpkg warnings</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/fe5b289324486feb07d9025df8e9238a624f28d8"><code>fe5b289</code></a>
test: add apt warning regression coverage</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/e58a49f1deb2c70b97469d56a30a7a344b7cdf25"><code>e58a49f</code></a>
add shellcheck linting</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/599df6ec23f0ff55f24e458f4092a0264e02a1c9"><code>599df6e</code></a>
Fix apt-cache package lookup failure in nektos/act environments (<a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/172">#172</a>)</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/cd5ee21d96e6e91cfd14e1b6437aa31ae6b1026d"><code>cd5ee21</code></a>
[WIP] Fix test workflows for actions (<a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/184">#184</a>)</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/c0e0741be64938eb55bb4e1831c6eaab079ca3b6"><code>c0e0741</code></a>
install_and_cache_pkgs.sh: Fix two issues saving preinst and postinst
scripts...</li>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/497648d2e1b97f712a3941670092a4a578235fe2"><code>497648d</code></a>
Apply PR <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/193">#193</a>
dependency pinning to <code>action.yml</code> (overwrite current action
re...</li>
<li>See full diff in <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.1...v1.6.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=awalsh128/cache-apt-pkgs-action&package-manager=github_actions&previous-version=1.6.1&new-version=1.6.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-29 01:18:49 -07:00
Worktrunk Bot 93325018af chore(ci): weekly renovation 2026-06-28 (#3284) 2026-06-28 08:45:45 -07:00
dependabot[bot] 0b0f10497d chore: bump taiki-e/install-action from 2.82.3 to 2.82.4 (#3255)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.3 to 2.82.4.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.4</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.24.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.13.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.54.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.4] - 2026-06-25</h2>
<ul>
<li>
<p>Update <code>uv@latest</code> to 0.11.24.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.13.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.54.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/682e7d9e49c5e653d371fc6adbda67653461378a"><code>682e7d9</code></a>
Release 2.82.4</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/88e83503037db61d4f066a4d9cb32e6fc06b70c2"><code>88e8350</code></a>
Update wasmtime manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cf0e00b44cf05faddafcc8082c6c2366e2a02380"><code>cf0e00b</code></a>
Update wasm-bindgen manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/a130ea674166df9065f363cbb53f1f2bc4a6298c"><code>a130ea6</code></a>
Update vacuum manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/0bdcc65dc21d0ae46842dc5ad063d69ce8991365"><code>0bdcc65</code></a>
Update <code>uv@latest</code> to 0.11.24</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3f52215559b820ee57b68e3fa9b38f6cd205e9c8"><code>3f52215</code></a>
Update <code>mise@latest</code> to 2026.6.13</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/294a073b0ebe66401c699c21b98e9ecb5a6da735"><code>294a073</code></a>
Update <code>just@latest</code> to 1.54.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f9bf24932b3cbfe7ae26b5addcd257989e14ec4d"><code>f9bf249</code></a>
Update cargo-rdme manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/98288d38cbfc5fa065ff61c6971d50dc3ba7d408"><code>98288d3</code></a>
Update <code>biome@latest</code> to 2.5.1</li>
<li>See full diff in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.3...v2.82.4">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.3&new-version=2.82.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 17:44:59 -07:00
dependabot[bot] daf432666c chore: bump taiki-e/install-action from 2.82.2 to 2.82.3 (#3190)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.2 to 2.82.3.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.3</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.26.1.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 46.0.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.12.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.104.0.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.35.5.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.138.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.0.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.20.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.0.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.3] - 2026-06-24</h2>
<ul>
<li>
<p>Update <code>zizmor@latest</code> to 1.26.1.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 46.0.0.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.5.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.12.</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.104.0.</p>
</li>
<li>
<p>Update <code>cargo-tarpaulin@latest</code> to 0.35.5.</p>
</li>
<li>
<p>Update <code>cargo-nextest@latest</code> to 0.9.138.</p>
</li>
<li>
<p>Update <code>cargo-crap@latest</code> to 0.3.0.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.20.1.</p>
</li>
<li>
<p>Update <code>cargo-rdme@latest</code> to 2.0.1.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/ace6ebe54a6a0c86dfb5f7764b17f793b6925bc3"><code>ace6ebe</code></a>
Release 2.82.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/9593d26a566b2dea5528756ce1b593cda56ddf7f"><code>9593d26</code></a>
Update <code>zizmor@latest</code> to 1.26.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/0569c0141a12a1553b9c9a83491ff772d114a6e5"><code>0569c01</code></a>
Update <code>wasmtime@latest</code> to 46.0.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/5ea9fc8c273a1ac2a9f4c160d34b2e37dd1cb9e7"><code>5ea9fc8</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d9b6e0d11a25ad9f54aabdb65b4b4fe88d20f710"><code>d9b6e0d</code></a>
Update <code>tombi@latest</code> to 1.1.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/d22450fe07f49b408f280b0c4e4ec6c581dd7154"><code>d22450f</code></a>
Update <code>mise@latest</code> to 2026.6.12</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/586c055e27e0fa5c61e72baabffb3c90a6ec9cda"><code>586c055</code></a>
Update <code>kingfisher@latest</code> to 1.104.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/5e27d3091b1094b517876d28ce9933e444be309a"><code>5e27d30</code></a>
Update just manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/eda88a4fdb0862974fa83c21b8ebec7d1ec53972"><code>eda88a4</code></a>
Update <code>cargo-tarpaulin@latest</code> to 0.35.5</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/30ff9da4b104d9918bd41562f2981303f48d3402"><code>30ff9da</code></a>
Update <code>cargo-nextest@latest</code> to 0.9.138</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.2...v2.82.3">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.2&new-version=2.82.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 09:53:10 -07:00
dependabot[bot] e3664c6343 chore: bump actions/cache from 5 to 6 (#3191)
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/releases">actions/cache's
releases</a>.</em></p>
<blockquote>
<h2>v6.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Update packages, migrate to ESM by <a
href="https://github.com/Samirat"><code>@​Samirat</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
<h2>v5.0.5</h2>
<h2>What's Changed</h2>
<ul>
<li>Update ts-http-runtime dependency by <a
href="https://github.com/yacaovsnc"><code>@​yacaovsnc</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1747">actions/cache#1747</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.5">https://github.com/actions/cache/compare/v5...v5.0.5</a></p>
<h2>v5.0.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Add release instructions and update maintainer docs by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1696">actions/cache#1696</a></li>
<li>Potential fix for code scanning alert no. 52: Workflow does not
contain permissions by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1697">actions/cache#1697</a></li>
<li>Fix workflow permissions and cleanup workflow names / formatting by
<a href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1699">actions/cache#1699</a></li>
<li>docs: Update examples to use the latest version by <a
href="https://github.com/XZTDean"><code>@​XZTDean</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li>Fix proxy integration tests by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1701">actions/cache#1701</a></li>
<li>Fix cache key in examples.md for bun.lock by <a
href="https://github.com/RyPeck"><code>@​RyPeck</code></a> in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
<li>Update dependencies &amp; patch security vulnerabilities by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/cache/pull/1738">actions/cache#1738</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/XZTDean"><code>@​XZTDean</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1690">actions/cache#1690</a></li>
<li><a href="https://github.com/RyPeck"><code>@​RyPeck</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/cache/pull/1722">actions/cache#1722</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.4">https://github.com/actions/cache/compare/v5...v5.0.4</a></p>
<h2>v5.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/cache/compare/v5...v5.0.3">https://github.com/actions/cache/compare/v5...v5.0.3</a></p>
<h2>v.5.0.2</h2>
<h1>v5.0.2</h1>
<h2>What's Changed</h2>
<p>When creating cache entries, 429s returned from the cache service
will not be retried.</p>
<h2>v5.0.1</h2>
<blockquote>
<p>[!IMPORTANT]
<strong><code>actions/cache@v5</code> runs on the Node.js 24 runtime and
requires a minimum Actions Runner version of
<code>2.327.1</code>.</strong></p>
</blockquote>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache's
changelog</a>.</em></p>
<blockquote>
<h1>Releases</h1>
<h2>How to prepare a release</h2>
<blockquote>
<p>[!NOTE]
Relevant for maintainers with write access only.</p>
</blockquote>
<ol>
<li>Switch to a new branch from <code>main</code>.</li>
<li>Run <code>npm test</code> to ensure all tests are passing.</li>
<li>Update the version in <a
href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
<li>Run <code>npm run build</code> to update the compiled files.</li>
<li>Update this <a
href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
with the new version and changes in the <code>## Changelog</code>
section.</li>
<li>Run <code>licensed cache</code> to update the license report.</li>
<li>Run <code>licensed status</code> and resolve any warnings by
updating the <a
href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
file with the exceptions.</li>
<li>Commit your changes and push your branch upstream.</li>
<li>Open a pull request against <code>main</code> and get it reviewed
and merged.</li>
<li>Draft a new release <a
href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a>
use the same version number used in <code>package.json</code>
<ol>
<li>Create a new tag with the version number.</li>
<li>Auto generate release notes and update them to match the changes you
made in <code>RELEASES.md</code>.</li>
<li>Toggle the set as the latest release option.</li>
<li>Publish the release.</li>
</ol>
</li>
<li>Navigate to <a
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
<ol>
<li>There should be a workflow run queued with the same version
number.</li>
<li>Approve the run to publish the new version and update the major tags
for this action.</li>
</ol>
</li>
</ol>
<h2>Changelog</h2>
<h3>6.1.0</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435
Handle cache write error due to read-only token</a></li>
<li>Switch redundant &quot;Cache save failed&quot; warning to debug log
in save-only</li>
</ul>
<h3>6.0.0</h3>
<ul>
<li>Updated <code>@actions/cache</code> to ^6.0.1,
<code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
<li>Migrated to ESM module system</li>
<li>Upgraded Jest to v30 and test infrastructure to be ESM
compatible</li>
</ul>
<h3>5.0.4</h3>
<ul>
<li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
patterns)</li>
<li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
protection, header validation fixes)</li>
<li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
</ul>
<h3>5.0.3</h3>
<ul>
<li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
<li>Bump <code>@actions/core</code> to v2.0.3</li>
</ul>
<h3>5.0.2</h3>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/cache/issues/1760">#1760</a>
from actions/samirat/esm_migration_and_package_update</li>
<li><a
href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a>
Prettier fixes</li>
<li><a
href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a>
Rebuild dist</li>
<li><a
href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a>
Fixed licenses</li>
<li><a
href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a>
Fix test mock return order</li>
<li><a
href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a>
PR feedback</li>
<li><a
href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a>
Rebuild dist bundles as ESM to match type:module</li>
<li><a
href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a>
Fix lint and jest issues</li>
<li><a
href="https://github.com/actions/cache/commit/b9bf592b98b6a5d0cad9929c76247de1cac78abe"><code>b9bf592</code></a>
Update documentation for v6 release</li>
<li><a
href="https://github.com/actions/cache/commit/80f777761d0990932f64ed2740522d7226a49062"><code>80f7777</code></a>
Update packages, migrate to ESM</li>
<li>See full diff in <a
href="https://github.com/actions/cache/compare/v5...v6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/cache&package-manager=github_actions&previous-version=5&new-version=6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-24 09:53:07 -07:00
dependabot[bot] 9e8d4612c8 chore: bump actions/checkout from 6 to 7 (#3131)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to
7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/releases">actions/checkout's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>What's Changed</h2>
<ul>
<li>block checking out fork pr for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
<li>getting ready for checkout v7 release by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
<li>update error wording by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
<h2>v6.0.3</h2>
<h2>What's Changed</h2>
<ul>
<li>Update changelog by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>Update changelog for v6.0.3 by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
made their first contribution in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
<h2>v6.0.2</h2>
<h2>What's Changed</h2>
<ul>
<li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID
is set by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p>
<h2>v6.0.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Update all references from v5 and v4 to v6 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
<li>Clarify v6 README by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<h2>v7.0.0</h2>
<ul>
<li>Block checking out fork PR for pull_request_target and workflow_run
by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
<li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
minor-actions-dependencies group across 1 directory by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
<li>Bump flatted from 3.3.1 to 3.4.2 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
<li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
<li>Bump <code>@​actions/core</code> and
<code>@​actions/tool-cache</code> and Remove uuid by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
<li>upgrade module to esm and update dependencies by <a
href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
<li>Bump the minor-npm-dependencies group across 1 directory with 3
updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
</ul>
<h2>v6.0.3</h2>
<ul>
<li>Fix checkout init for SHA-256 repositories by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
<li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
</ul>
<h2>v6.0.2</h2>
<ul>
<li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
</ul>
<h2>v6.0.1</h2>
<ul>
<li>Add worktree support for persist-credentials includeIf by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
</ul>
<h2>v6.0.0</h2>
<ul>
<li>Persist creds to a separate file by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
<li>Update README to include Node.js 24 support details and requirements
by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
</ul>
<h2>v5.0.1</h2>
<ul>
<li>Port v6 cleanup to v5 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
</ul>
<h2>v5.0.0</h2>
<ul>
<li>Update actions checkout to use node 24 by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
</ul>
<h2>v4.3.1</h2>
<ul>
<li>Port v6 cleanup to v4 by <a
href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
</ul>
<h2>v4.3.0</h2>
<ul>
<li>docs: update README.md by <a
href="https://github.com/motss"><code>@​motss</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
<li>Add internal repos for checking out multiple repositories by <a
href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
<li>Documentation update - add recommended permissions to Readme by <a
href="https://github.com/benwells"><code>@​benwells</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
<li>Adjust positioning of user email note and permissions heading by <a
href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
<li>Update CODEOWNERS for actions by <a
href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
<li>Update package dependencies by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
</ul>
<h2>v4.2.2</h2>
<ul>
<li><code>url-helper.ts</code> now leverages well-known environment
variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
in <a
href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
<li>Expand unit test coverage for <code>isGhes</code> by <a
href="https://github.com/jww3"><code>@​jww3</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
</ul>
<h2>v4.2.1</h2>
<ul>
<li>Check out other refs/* by commit if provided, fall back to ref by <a
href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
update error wording (<a
href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
getting ready for checkout v7 release (<a
href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
Bump the minor-npm-dependencies group across 1 directory with 3 updates
(<a
href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
upgrade module to esm and update dependencies (<a
href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
and Remove uuid (<a
href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
Bump js-yaml from 4.1.0 to 4.2.0 (<a
href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
Bump flatted from 3.3.1 to 3.4.2 (<a
href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
Bump actions/publish-immutable-action (<a
href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
<li><a
href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
block checking out fork pr for pull_request_target and workflow_run (<a
href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
<li>See full diff in <a
href="https://github.com/actions/checkout/compare/v6...v7">compare
view</a></li>
</ul>
</details>
<br />

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 14:03:53 -07:00
Worktrunk Bot e0cfd884e9 chore(ci): weekly renovation 2026-06-21 (#3147)
## Summary

Weekly CI renovation check. One pinned-version drift found and bumped:

- `worktrunk`: `=0.58.0` → `=0.60.0` (MSRV 1.95, compatible with our
pinned 1.95.0 toolchain) — `ci.yaml` `test` job. Flagged by a workflow
annotation on the latest green `main` run ("New version for worktrunk
available: 0.60.0").

## Already up to date

- **Rust stable**: latest is 1.96.0, so latest−1 = 1.95 —
`rust-toolchain.toml` (1.95.0) and both `rust-version` pins (1.95)
already match. No MSRV/toolchain bump.
- **cargo-install pins**: cargo-insta 1.48.0, cargo-nextest 0.9.137,
lychee 0.24.2, cargo-msrv 0.19.3, cargo-llvm-cov 0.8.7, cargo-udeps
0.1.61 — all current against crates.io.
- **setup-nu**: 0.113.1 (latest nushell release).
- **zola**: 0.22.1 (latest getzola release).
- **Runner images**: ubuntu-24.04, macos-15, windows-2022 (windows-2022
stays pinned — actions/runner-images#12677).

## Notes

- worktrunk 0.59.0 and 0.60.0 both declare `rust-version = "1.95"`;
verified via crates.io API against the pinned toolchain.
- Only the `test` job pins a specific worktrunk version; the
`cargo-affected` install follows the default branch and is intentionally
unpinned.

---
🤖 Automated weekly renovation

Co-authored-by: worktrunk-bot <worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 13:59:05 -07:00
dependabot[bot] 56cc99c780 chore: bump taiki-e/install-action from 2.82.0 to 2.82.2 (#3155)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.82.0 to 2.82.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.2</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.1.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.23.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.71.2.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.16.0.</p>
</li>
</ul>
<h2>2.82.1</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.4.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.22.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.4.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.11.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.11.0.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.53.0.</p>
</li>
<li>
<p>Update <code>cargo-zigbuild@latest</code> to 0.23.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.2] - 2026-06-21</h2>
<ul>
<li>
<p>Update <code>xh@latest</code> to 0.26.1.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.23.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.71.2.</p>
</li>
<li>
<p>Update <code>sccache@latest</code> to 0.16.0.</p>
</li>
</ul>
<h2>[2.82.1] - 2026-06-20</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.4.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.22.</p>
</li>
<li>
<p>Update <code>osv-scanner@latest</code> to 2.4.0.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.11.</p>
</li>
<li>
<p>Update <code>martin@latest</code> to 1.11.0.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.53.0.</p>
</li>
<li>
<p>Update <code>cargo-zigbuild@latest</code> to 0.23.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/9e1e5806d4a4822de933115878265be9aaa786d9"><code>9e1e580</code></a>
Release 2.82.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/788896b6163ee187bf02f51161e573dbc028dba0"><code>788896b</code></a>
Update zizmor manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7631577b669c94d73e58cb9f217d0f56abd33a48"><code>7631577</code></a>
Update <code>xh@latest</code> to 0.26.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e0f1a05cc9f43f4fd57d15fe7ee20ca5b78f65fc"><code>e0f1a05</code></a>
Update <code>uv@latest</code> to 0.11.23</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3cda1e20d17fde3f9958653d219495e0591233ec"><code>3cda1e2</code></a>
Update <code>trivy@latest</code> to 0.71.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/11ac3210af3c20497864c3d27d4499b6a7108098"><code>11ac321</code></a>
Update tombi manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b5f9e335d3eaba5117342d9d9fda485aea29c524"><code>b5f9e33</code></a>
Update <code>sccache@latest</code> to 0.16.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4e48cd5f5170589da6cad450be3e62ca61534cc1"><code>4e48cd5</code></a>
Update cargo-tarpaulin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e0a923573389b28b6cefdbe8309332b471f55583"><code>e0a9235</code></a>
Update cargo-rdme manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/8b3c737da4b541bf0fb5a3e0488ff20535badac9"><code>8b3c737</code></a>
Release 2.82.1</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.82.0...v2.82.2">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.82.0&new-version=2.82.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-22 13:59:03 -07:00
dependabot[bot] e25a7a9bd7 chore: bump taiki-e/install-action from 2.81.11 to 2.82.0 (#3114)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.81.11 to 2.82.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.82.0</h2>
<ul>
<li>
<p>Support <code>cargo-vet</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1908">#1908</a>,
thanks <a
href="https://github.com/jakewimmer"><code>@​jakewimmer</code></a>)</p>
</li>
<li>
<p>Support <code>cargo-crap</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1905">#1905</a>,
thanks <a
href="https://github.com/BartoszCiesla"><code>@​BartoszCiesla</code></a>)</p>
</li>
<li>
<p>Support <code>cargo-leptos</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1903">#1903</a>,
thanks <a
href="https://github.com/404Simon"><code>@​404Simon</code></a>)</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.103.0.</p>
</li>
<li>
<p>Update <code>cargo-xwin@latest</code> to 0.23.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 45.0.2.</p>
</li>
<li>
<p>Update <code>cargo-deny@latest</code> to 0.19.9.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.5.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.71.1.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.10.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.82.0] - 2026-06-17</h2>
<ul>
<li>
<p>Support <code>cargo-vet</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1908">#1908</a>,
thanks <a
href="https://github.com/jakewimmer"><code>@​jakewimmer</code></a>)</p>
</li>
<li>
<p>Support <code>cargo-crap</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1905">#1905</a>,
thanks <a
href="https://github.com/BartoszCiesla"><code>@​BartoszCiesla</code></a>)</p>
</li>
<li>
<p>Support <code>cargo-leptos</code>. (<a
href="https://redirect.github.com/taiki-e/install-action/pull/1903">#1903</a>,
thanks <a
href="https://github.com/404Simon"><code>@​404Simon</code></a>)</p>
</li>
<li>
<p>Update <code>kingfisher@latest</code> to 1.103.0.</p>
</li>
<li>
<p>Update <code>cargo-xwin@latest</code> to 0.23.0.</p>
</li>
<li>
<p>Update <code>wasmtime@latest</code> to 45.0.2.</p>
</li>
<li>
<p>Update <code>cargo-deny@latest</code> to 0.19.9.</p>
</li>
<li>
<p>Update <code>prek@latest</code> to 0.4.5.</p>
</li>
<li>
<p>Update <code>trivy@latest</code> to 0.71.1.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.10.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/b8cecb83565409bcc297b2df6e77f030b2a468d5"><code>b8cecb8</code></a>
Release 2.82.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/981171473775d521e3ae1e0b14c569b51c48651e"><code>9811714</code></a>
Update changelog</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e7005464717d3cca03b48509ba65ebbde552e10c"><code>e700546</code></a>
Update wasmtime manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fdfb4a4a7c8af40d72ebb849dac38e8718ea669c"><code>fdfb4a4</code></a>
Update mise manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ef03904287f8419ca540ee664cc9227c6d501867"><code>ef03904</code></a>
Update martin manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b6d098313f0ccec3f73270982ba4474205dbd7fd"><code>b6d0983</code></a>
Update <code>kingfisher@latest</code> to 1.103.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ebeb9b1a53c2307773f018dca9868b795675e6c5"><code>ebeb9b1</code></a>
Update just manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/119edcf29d9a2c67fad2ed58e04242daceb433e5"><code>119edcf</code></a>
Update <code>cargo-xwin@latest</code> to 0.23.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/cd319da91ecc8685df284d89c5435723973a5668"><code>cd319da</code></a>
Update <code>wasmtime@latest</code> to 45.0.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/4942894b57b5ad6fdcb38216eb1f7df561374b20"><code>4942894</code></a>
Update cargo-xwin manifest</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.81.11...v2.82.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.81.11&new-version=2.82.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-17 22:59:48 -07:00
dependabot[bot] 08b0fc8a0d chore: bump taiki-e/install-action from 2.81.10 to 2.81.11 (#3088)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.81.10 to 2.81.11.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.81.11</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.252.0.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.125.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.21.</p>
</li>
<li>
<p>Update <code>protoc@latest</code> to 3.35.1.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.9.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.0.</p>
</li>
<li>
<p>Update <code>cargo-insta@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.81.11] - 2026-06-15</h2>
<ul>
<li>
<p>Update <code>wasm-tools@latest</code> to 1.252.0.</p>
</li>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.125.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.21.</p>
</li>
<li>
<p>Update <code>protoc@latest</code> to 3.35.1.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.9.</p>
</li>
<li>
<p>Update <code>jaq@latest</code> to 3.1.0.</p>
</li>
<li>
<p>Update <code>cargo-insta@latest</code> to 1.48.0.</p>
</li>
<li>
<p>Update <code>biome@latest</code> to 2.5.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/15449e3094499af05d8d964a1c884208e4b8b595"><code>15449e3</code></a>
Release 2.81.11</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/dd3bb882c6c552e1478f55a048fb291cdc1f0ef1"><code>dd3bb88</code></a>
Update cargo-deny manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/89ed2466baa251f4217203b0084736e4ba24365d"><code>89ed246</code></a>
Update <code>wasm-tools@latest</code> to 1.252.0</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3d2614471d361398dc4a241305a41a22246608cd"><code>3d26144</code></a>
Update <code>wasm-bindgen@latest</code> to 0.2.125</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/02039d84ff2195b312ef1612583b62012fcc7737"><code>02039d8</code></a>
Update <code>uv@latest</code> to 0.11.21</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f70d988b18b30949b65c310be1e9e1fd34b1bd80"><code>f70d988</code></a>
Update trivy manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/1f7b61373609cdc389de6178ea51d2a069d306ed"><code>1f7b613</code></a>
Update <code>protoc@latest</code> to 3.35.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ace4a195674b1e2219e629001c708779d52f0872"><code>ace4a19</code></a>
Update prek manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3fbf11909e319a495b93f6c640f257d1979a9cef"><code>3fbf119</code></a>
Update <code>mise@latest</code> to 2026.6.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/e62deab512318d610ad0b017fe426bc6cdb75e0f"><code>e62deab</code></a>
Update <code>jaq@latest</code> to 3.1.0</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.81.10...v2.81.11">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.81.10&new-version=2.81.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-16 12:47:50 -07:00
dependabot[bot] 2602a413f7 chore: bump awalsh128/cache-apt-pkgs-action from 1.6.0 to 1.6.1 (#3080)
Bumps
[awalsh128/cache-apt-pkgs-action](https://github.com/awalsh128/cache-apt-pkgs-action)
from 1.6.0 to 1.6.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/releases">awalsh128/cache-apt-pkgs-action's
releases</a>.</em></p>
<blockquote>
<h2>v1.6.1</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: upgrade actions/cache v4→v5 and upload-artifact v4→v7 (Node 24)
by <a href="https://github.com/pftg"><code>@​pftg</code></a> in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/198">awalsh128/cache-apt-pkgs-action#198</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/pftg"><code>@​pftg</code></a> made their
first contribution in <a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/pull/198">awalsh128/cache-apt-pkgs-action#198</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.5.4...v1.6.1">https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.5.4...v1.6.1</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/awalsh128/cache-apt-pkgs-action/commit/681749ae568c81c2037cb9185e38b709b261bd2f"><code>681749a</code></a>
fix: upgrade actions/cache v4→v5 and upload-artifact v4→v7 (Node 24) (<a
href="https://redirect.github.com/awalsh128/cache-apt-pkgs-action/issues/198">#198</a>)</li>
<li>See full diff in <a
href="https://github.com/awalsh128/cache-apt-pkgs-action/compare/v1.6.0...v1.6.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=awalsh128/cache-apt-pkgs-action&package-manager=github_actions&previous-version=1.6.0&new-version=1.6.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-06-14 20:54:58 -07:00
Worktrunk Bot 08539dc75a chore(ci): weekly renovation 2026-06-14 (#3071)
## Summary

Weekly CI renovation check found the following pin updates:

- `cargo-insta`: 1.47.2 → 1.48.0 (MSRV 1.66, compatible with our 1.95.0)
— in `claude-setup` and `test-setup` actions
- `worktrunk`: 0.55.0 → 0.58.0 (MSRV 1.95, compatible with our 1.95.0) —
in `ci.yaml`

### cargo-insta 1.48.0 notes

No breaking changes and no MSRV bump. Behavior changes worth noting,
none of which affect our `--check`-based snapshot flow:

- When `CI=true`, explicit handling options like `--accept` now take
precedence over the automatic `--check`.
- `--profile` now translates to `--cargo-profile` for nextest; a new
`--nextest-profile` selects the runner profile.
- New `strip_ansi_escape_codes` filter setting and opt-in YAML literal
blocks (`INSTA_YAML_BLOCK_STYLE=1`).

## Already up to date

- Rust stable: 1.96.0 → MSRV/toolchain stay at 1.95 (latest stable − 1,
no change)
- Runner images: ubuntu-24.04, macos-15, windows-2022
- `cargo-nextest`: 0.9.137, `lychee`: 0.24.2, `cargo-msrv`: 0.19.3,
`cargo-llvm-cov`: 0.8.7, `cargo-udeps`: 0.1.61
- `hustcer/setup-nu`: 0.113.1 (latest nushell release)
- `zola`: 0.22.1
- LLM model pins: Claude Haiku 4.5 and Codex `gpt-5.4-mini` are both
current
- README month blockquote: "June 2026" matches current month

## Notes

- windows-2022 remains pinned (actions/runner-images#12677 —
windows-2025 lacks the D: drive)

---
🤖 Automated weekly renovation

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 10:21:25 -07:00
Worktrunk Bot 330fa6ee4e chore(ci): weekly renovation 2026-05-31 (#2948)
## Summary

Weekly CI renovation. MSRV/toolchain bump plus pin bumps where upstream
has moved.

- **MSRV: 1.94 → 1.95** (Rust 1.96.0 went stable 2026-05-28; policy is
latest stable − 1)
- **toolchain channel: 1.94.0 → 1.95.0**
- `cargo-nextest`: 0.9.136 → 0.9.137 (MSRV 1.91, compatible with 1.95.0)
- `worktrunk`: 0.53.0 → 0.55.0 (MSRV 1.94, compatible with 1.95.0)
- `hustcer/setup-nu` nushell: 0.113.0 → 0.113.1
- `flake.lock`: `rust-overlay` bumped to `4a408e1` (ships `1.95.0.nix`
and `1.96.0.nix`); refreshed in the follow-up commit after @max-sixty
asked whether the agent could install Nix — it can, via the Determinate
Systems installer. A separate skill PR will codify the Nix install step
into the weekly workflow so future runs do this automatically.

## Already up to date

- `cargo-insta`: 1.47.2, `cargo-llvm-cov`: 0.8.7, `cargo-msrv`: 0.19.3,
`cargo-udeps`: 0.1.61, `lychee`: 0.24.2
- `taiki-e/install-action` tool: zola@0.22.1
- `taiki-e/install-action` action ref tracked by Dependabot (open in
#2935: 2.79.11 → 2.79.13; latest is 2.80.0 — Dependabot will catch up
next cycle)
- Runner images: ubuntu-24.04, macos-15, windows-2022

## Notes

- windows-2022 remains pinned (actions/runner-images#12677 —
windows-2025 lacks D: drive)

---------

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
2026-06-12 00:30:17 -07:00
dependabot[bot] ea883bd6d6 chore: bump taiki-e/install-action from 2.81.8 to 2.81.10 (#3031)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.81.8 to 2.81.10.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.81.10</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.1.3.</p>
</li>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.159.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.1.</p>
</li>
</ul>
<h2>2.81.9</h2>
<ul>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.123.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.2.</p>
</li>
<li>
<p>Update <code>parse-changelog@latest</code> to 0.6.17.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.52.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.2.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.20.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.81.10] - 2026-06-11</h2>
<ul>
<li>
<p>Update <code>tombi@latest</code> to 1.1.3.</p>
</li>
<li>
<p>Update <code>release-plz@latest</code> to 0.3.159.</p>
</li>
<li>
<p>Update <code>cosign@latest</code> to 3.1.1.</p>
</li>
</ul>
<h2>[2.81.9] - 2026-06-10</h2>
<ul>
<li>
<p>Update <code>wasm-bindgen@latest</code> to 0.2.123.</p>
</li>
<li>
<p>Update <code>tombi@latest</code> to 1.1.2.</p>
</li>
<li>
<p>Update <code>parse-changelog@latest</code> to 0.6.17.</p>
</li>
<li>
<p>Update <code>just@latest</code> to 1.52.0.</p>
</li>
<li>
<p>Update <code>gungraun-runner@latest</code> to 0.19.2.</p>
</li>
<li>
<p>Update <code>cargo-binstall@latest</code> to 1.20.0.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/7a79fe8c3a13344501c80d99cae481c1c9085912"><code>7a79fe8</code></a>
Release 2.81.10</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/13599f4dab5fc9777c7a29b255a9106d1107ee1d"><code>13599f4</code></a>
Update uv manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ee40c2ad7099d51081c7f37b4d3d914a008b8403"><code>ee40c2a</code></a>
Update <code>tombi@latest</code> to 1.1.3</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c2336861b9e97b4c0e1b19bc5d8968501d4d3b3f"><code>c233686</code></a>
Update <code>release-plz@latest</code> to 0.3.159</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/7f72f38ad02c28b2456e65ab89c50a362bb98aaa"><code>7f72f38</code></a>
Update mise manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/f8c685240840f35b073b629510ed9b7a853227f7"><code>f8c6852</code></a>
Update <code>cosign@latest</code> to 3.1.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fd2f5e3d644b484055ebf4268f474c565f148f25"><code>fd2f5e3</code></a>
Release 2.81.9</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/537f98ea83c367b35b9810b787d0b2ded00efc1a"><code>537f98e</code></a>
Update <code>wasm-bindgen@latest</code> to 0.2.123</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/6bf6dde29b365c072c8c9b09b160ba21042e6b1e"><code>6bf6dde</code></a>
Update <code>tombi@latest</code> to 1.1.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c1e16527666111091c11f4145f629c642a3c5aef"><code>c1e1652</code></a>
Update release-plz manifest</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.81.8...v2.81.10">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.81.8&new-version=2.81.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-11 05:55:02 -07:00
dependabot[bot] 2823171c7e chore: bump taiki-e/install-action from 2.79.11 to 2.81.8 (#3011)
Bumps
[taiki-e/install-action](https://github.com/taiki-e/install-action) from
2.79.11 to 2.81.8.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/releases">taiki-e/install-action's
releases</a>.</em></p>
<blockquote>
<h2>2.81.8</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.2.</p>
</li>
<li>
<p>Update <code>parse-dockerfile@latest</code> to 0.1.7.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.1.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.1.</p>
</li>
</ul>
<h2>2.81.7</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 45.0.1.</p>
</li>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.1.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.45.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.74.3.</p>
</li>
<li>
<p>Update <code>cargo-audit@latest</code> to 0.22.2.</p>
</li>
</ul>
<h2>2.81.6</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.4.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.0.</p>
</li>
</ul>
<h2>2.81.5</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.19.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.47.2.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.0.</p>
</li>
</ul>
<h2>2.81.4</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.28.4.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.47.1.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.45.0.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.4.0.</p>
</li>
<li>
<p>Update <code>cargo-mutants@latest</code> to 27.1.0.</p>
</li>
</ul>
<h2>2.81.3</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.28.3.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.18.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md">taiki-e/install-action's
changelog</a>.</em></p>
<blockquote>
<h2>[2.81.8] - 2026-06-08</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.2.</p>
</li>
<li>
<p>Update <code>parse-dockerfile@latest</code> to 0.1.7.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.1.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.1.</p>
</li>
</ul>
<h2>[2.81.7] - 2026-06-06</h2>
<ul>
<li>
<p>Update <code>wasmtime@latest</code> to 45.0.1.</p>
</li>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.1.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.45.1.</p>
</li>
<li>
<p>Update <code>rclone@latest</code> to 1.74.3.</p>
</li>
<li>
<p>Update <code>cargo-audit@latest</code> to 0.22.2.</p>
</li>
</ul>
<h2>[2.81.6] - 2026-06-05</h2>
<ul>
<li>
<p>Update <code>prek@latest</code> to 0.4.4.</p>
</li>
<li>
<p>Update <code>cargo-shear@latest</code> to 1.13.0.</p>
</li>
</ul>
<h2>[2.81.5] - 2026-06-05</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.29.0.</p>
</li>
<li>
<p>Update <code>uv@latest</code> to 0.11.19.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.47.2.</p>
</li>
<li>
<p>Update <code>mise@latest</code> to 2026.6.0.</p>
</li>
</ul>
<h2>[2.81.4] - 2026-06-04</h2>
<ul>
<li>
<p>Update <code>vacuum@latest</code> to 0.28.4.</p>
</li>
<li>
<p>Update <code>typos@latest</code> to 1.47.1.</p>
</li>
<li>
<p>Update <code>syft@latest</code> to 1.45.0.</p>
</li>
<li>
<p>Update <code>cargo-neat@latest</code> to 0.4.0.</p>
</li>
<li>
<p>Update <code>cargo-mutants@latest</code> to 27.1.0.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/taiki-e/install-action/commit/0631aa6515c7d545823c67cfae7ef4fc7f490154"><code>0631aa6</code></a>
Release 2.81.8</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/fd382b34adcf901479b928617bf0f0612ca769b3"><code>fd382b3</code></a>
Update <code>vacuum@latest</code> to 0.29.2</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/b1597b4e7dcbcedac8dd1054da307b671f17027d"><code>b1597b4</code></a>
Update tombi manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/3869357b4e3cd3a5267685bf8ef038dbef829247"><code>3869357</code></a>
Update <code>parse-dockerfile@latest</code> to 0.1.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/734742c1440e1b5aa3d391559c975c507bb14842"><code>734742c</code></a>
Update parse-changelog manifest</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/6a4fb002de1a038994686e6d75688b72283a0b34"><code>6a4fb00</code></a>
Update <code>mise@latest</code> to 2026.6.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/ee92d4569affa054448769293cd8fbe22df3fd6c"><code>ee92d45</code></a>
Update <code>cargo-shear@latest</code> to 1.13.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/56545b37b57562edd73171cb6c62cc509db4c34e"><code>56545b3</code></a>
Release 2.81.7</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/c8d55710f301270b50680d218c3c8b1c2ed35fa7"><code>c8d5571</code></a>
Update <code>wasmtime@latest</code> to 45.0.1</li>
<li><a
href="https://github.com/taiki-e/install-action/commit/982454fe8df95d1ccbd65fec021e1608efa219eb"><code>982454f</code></a>
Update <code>vacuum@latest</code> to 0.29.1</li>
<li>Additional commits viewable in <a
href="https://github.com/taiki-e/install-action/compare/v2.79.11...v2.81.8">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=taiki-e/install-action&package-manager=github_actions&previous-version=2.79.11&new-version=2.81.8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-09 09:38:00 -07:00
Worktrunk Bot 9f01f597e8 ci: revert codecov use_pypi workaround now that v7.0.0 fixes the GPG key (#3016) 2026-06-08 00:22:40 -07:00
dependabot[bot] 35a4b6292a chore: bump codecov/codecov-action from 6.0.1 to 7.0.0 (#3012) 2026-06-08 00:06:21 -07:00
Worktrunk Bot ecf1fa6469 ci: install codecov CLI from PyPI to dodge broken Keybase GPG import (#2997)
## Problem

The non-required `code-coverage` job failed on `main` (run
[27075953927](https://github.com/max-sixty/worktrunk/actions/runs/27075953927)).
All tests passed (1942 / 1238 / 703, 0 failed); the failure was in the
`codecov/codecov-action@v6.0.1` upload step:

```
==> Finishing downloading linux:latest
      Version: v11.2.8
gpg: no valid OpenPGP data found.
gpg: Total number processed: 0
==> Verifying GPG signature integrity
gpg: Signature made Tue Apr 21 19:28:03 2026 UTC
gpg:                using RSA key 27034E7FDB850E0BBC2C62FF806BB28AED779869
gpg: Can't check signature: No public key
==> Could not verify signature. Please contact Codecov if problem continues
    Exiting...
##[error]Process completed with exit code 1.
```

**Root cause (confirmed upstream).** The action downloads the Codecov
CLI from `cli.codecov.io` and verifies its GPG signature against a
public key fetched from
`https://keybase.io/codecovsecurity/pgp_keys.asc`. That URL is currently
returning `404 SELF-SIGNED PUBLIC KEY NOT FOUND`, so the key import
produces "no valid OpenPGP data found", the keyring stays empty, and the
signature check aborts with "No public key" — before any upload happens.
Tracked in
[codecov/codecov-action#1955](https://github.com/codecov/codecov-action/issues/1955)
(opened the same day) and the related
[#1876](https://github.com/codecov/codecov-action/issues/1876).

**Why a fix and not a rerun.** This exact failure shape fired three
times in ~24h —
[#2993](https://github.com/max-sixty/worktrunk/issues/2993),
[#2996](https://github.com/max-sixty/worktrunk/issues/2996), and this
run. #2996's diagnosis explicitly flagged that a third occurrence should
escalate to a durable mitigation, crossing the `running-tend`
repeat-occurrence threshold from transient to durable. `v6.0.1` is
already the latest action release, so bumping the pin doesn't help.

## Solution

Set `use_pypi: true` on both `codecov-action` steps in `ci.yaml` (the
test-results upload in the `test` matrix and the coverage upload in
`code-coverage`). This is the workaround documented in #1955: it
installs the Codecov CLI from PyPI instead of `cli.codecov.io`,
bypassing the binary download and its broken Keybase GPG-key import
entirely. Both call sites are subject to the same failure mode, so both
are patched.

`use_pypi` is a documented input on `codecov-action@v6.0.1`
(`action.yml` line 155: *"Use the pypi version of the CLI instead of
from cli.codecov.io"*).

## Testing

YAML validated with `yaml.safe_load`. Behavioral verification is the
`code-coverage` job passing on this PR — it exercises the patched upload
path. The maintainer can revert `use_pypi: true` once Codecov restores
the Keybase key (the `# (codecov/codecov-action#1955)` comments mark
both sites).

---
Automated fix for [failed
run](https://github.com/max-sixty/worktrunk/actions/runs/27075953927)

Co-authored-by: worktrunk-bot <254187624+worktrunk-bot@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-06-06 18:49:56 -07:00