dependabot-bot's Description of Work
Bumps the ci-dependencies group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| actions/checkout | 6.0.3 | 7.0.1 |
| lycheeverse/lychee-action | 2.8.0 | 2.9.0 |
| prefix-dev/setup-pixi | 0.9.6 | 0.10.0 |
| r-lib/actions/setup-pandoc | 2.12.0 | 2.12.1 |
| r-lib/actions/setup-tinytex | 2.12.0 | 2.12.1 |
| release-drafter/release-drafter | 7.4.0 | 7.5.1 |
Updates actions/checkout from 6.0.3 to 7.0.1
Release notes
Sourced from actions/checkout's releases.
v7.0.1
What's Changed
- skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1
v7.0.0
What's Changed
- block checking out fork pr for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by
@dependabot[bot] in actions/checkout#2458- Bump flatted from 3.3.1 to 3.4.2 by
@dependabot[bot] in actions/checkout#2460- Bump js-yaml from 4.1.0 to 4.2.0 by
@dependabot[bot] in actions/checkout#2461- Bump
@actions/coreand@actions/tool-cacheand Remove uuid by@dependabot[bot] in actions/checkout#2459- upgrade module to esm and update dependencies by
@aiqiaoyin actions/checkout#2463- Bump the minor-npm-dependencies group across 1 directory with 3 updates by
@dependabot[bot] in actions/checkout#2462- getting ready for checkout v7 release by
@aiqiaoyin actions/checkout#2464- update error wording by
@aiqiaoyin actions/checkout#2467New Contributors
@aiqiaoymade their first contribution in actions/checkout#2454Full Changelog: https://github.com/actions/checkout/compare/v6.0.3...v7.0.0
v6.1.0
What's Changed
[BREAKING] backportallow-unsafe-pr-checkoutto v6 by@aiqiaoyin actions/checkout#2500- backport fixes to releases-v6 by
@aiqiaoyin actions/checkout#2527https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change
Full Changelog: https://github.com/actions/checkout/compare/v6.0.3...v6.1.0
Changelog
Sourced from actions/checkout's changelog.
Changelog
v7.0.1
- Skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- Trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- Escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
v7.0.0
- Block checking out fork PR for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Various dependency updates
v6.0.3
- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414v6.0.2
- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356v6.0.1
- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327v6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248v5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301v5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226v4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305v4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924
<!-- raw HTML omitted -->
... (truncated)
Commits
-
3d3c42eprep v7.0.1 release (#2531) -
2880268escape values passed to --unset (#2530) -
12cd223trim only ascii whitespace for branch (#2521) -
62661c4skip running unsafe pr check if input is default (#2518) -
e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499) -
631c942eslint 9 (#2474) -
4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476) -
ba09753Bump actions/checkout from 6 to 7 (#2488) -
b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479) -
e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478) - Additional commits viewable in compare view
Updates lycheeverse/lychee-action from 2.8.0 to 2.9.0
Release notes
Sourced from lycheeverse/lychee-action's releases.
v2.9.0
Summary
This release updates the default lychee version from
v0.23.0tov0.24.2.The main reason for this release is compatibility with the new lychee
0.24.xrelease artifacts. Starting with lycheev0.24.0, the archive layout changed, and thelycheebinary may now be packaged inside a subdirectory.lychee-actionnow detects that layout automatically, so users can upgrade without changing their workflows.If you use:
uses: lycheeverse/lychee-action@v2you will get the new version once the floating
v2tag has been updated. If you pin exact versions, update to:uses: lycheeverse/[email protected]What’s new from lychee
v0.24.xBetter diagnostics
lychee now reports line and column numbers for detected links. This makes broken link reports easier to act on, especially in larger documentation sites or generated reports.
Text fragment checking
lychee can now check URL text fragments, such as links containing
#:~:text=.... This helps catch links that point to a valid page but no longer points to the intended highlighted text.Sitemap support
lychee can now read
sitemap.xmlinputs. This is useful for checking published websites or generated documentation sites where the sitemap is the easiest source of URLs to validate.JUnit output
lychee now supports JUnit output. This makes it easier to integrate link checking results with CI systems and test reporting tools that understand JUnit XML.
Redirect and remap visibility
lychee can now show redirects and remaps more clearly. This helps explain why a URL was checked as a different final URL and makes debugging link-checking behavior easier.
Multiple config files
lychee now supports multiple configuration files and expanded config handling. This is useful for repositories that split documentation, website, or package-specific link-checking settings.
Timeout handling
lychee can now accept timeouts explicitly. This gives users more control over how strict their link checks should be for flaky or slow endpoints.
Fixes and reliability improvements
<!-- raw HTML omitted -->
... (truncated)
Commits
-
e747777Bump actions/cache from 5 to 6 (#340) -
39066c6Bump actions/checkout from 6 to 7 (#339) -
6da1d14Install into $RUNNER_TEMP instead of $HOME (#338) -
a63497cfixes #322 check for null (#336) -
b40e218[create-pull-request] automated change -
faea714bump default to 0.24.1 and auto-detect lychee bin in subfolder (#330) - See full diff in compare view
Updates prefix-dev/setup-pixi from 0.9.6 to 0.10.0
Release notes
Sourced from prefix-dev/setup-pixi's releases.
v0.10.0
<!-- raw HTML omitted -->What's Changed
💥 Breaking changes
- feat: change post-cleanup default to false by
@Hofer-Julianin prefix-dev/setup-pixi#272⬆️ Dependency updates
- chore(deps): bump the gh-actions group with 2 updates by
@dependabot[bot] in prefix-dev/setup-pixi#268- chore(deps): bump the nodejs group with 6 updates by
@dependabot[bot] in prefix-dev/setup-pixi#269New Contributors
@Hofer-Julianmade their first contribution in prefix-dev/setup-pixi#272Full Changelog: https://github.com/prefix-dev/setup-pixi/compare/v0.9.6...v0.10.0
Commits
-
a09b624feat: change post-cleanup default to false (#272) -
947fc1fchore(deps): bump the nodejs group with 6 updates (#269) -
36c1c8cchore(deps): bump the gh-actions group with 2 updates (#268) - See full diff in compare view
Updates r-lib/actions/setup-pandoc from 2.12.0 to 2.12.1
Changelog
Sourced from r-lib/actions/setup-pandoc's changelog.
v2.12.1(2026-06-23)
[setup-r]now avoids a warning about anurl.parse()deprecation
(#1074).
[setup-r-dependencies]now usesquarto-dev/quarto-actionsv2.2.0
(@jdblischak, #1076).Examples:
test-coverage.yamlnow usescodecov/codecov-actionv7
(@shikokuchuo, #1081).New example
claude-investigate.yamlworkflow (@DavisVaughan, #1084).
v2.12.0(2026-04-29)
All node.js actions use node 24 now. Relatedly, all example workflows
use recent versions of actions that use node 24.
[setup-r]now usesuse-public-rspm: trueby default on Linux and
Windows. macOS binaries require further opt-in withuse-public-rspm: always.It is now possible to require actions to be pinned to a full-length
commit SHA in repositories usingr-lib/actions(#1070).
[setup-pandoc][setup-r-dependencies]now default to Pandoc
version 3.8.3.
[setup-r-dependencies]now includes the R architecture in the
cache key, so caches formacos-15(Apple Silicon) andmacos-15-intel(Rosetta/x86_64) no longer collide (#1035).
[setup-r]runapt-get updatewithout
debugging update failures easier (#1058).
v2.11.4(2025-10-08)
[setup-r]correctly installs Rtools again on aarch64 Windows,
as needed.
v2.11.3(2025-03-24)
[setup-r]now supports Rtools45, and installs it by default
for R >= 4.5.0.
v2.11.2(2025-02-19)
[setup-r]now installs gfortran 14.2 for R 4.5.0 and later (#965).
[setup-r]now does not use PPM on aarch64 Linux, because PPM
<!-- raw HTML omitted -->
... (truncated)
Commits
-
d3c5be5Update NEWS for v1.12.1 (#1087) -
0d1fbb4Add/investigateworkflow (#1084) -
ed1849bUse codecov/codecov-action v7 (#1082) -
173cb9dUpdate lock-threads and scorecard action versions -
2e3959dUpdate quarto-dev/quarto-actions/setup to v2.2.0 (#1076) -
ff9d3a3[setup-r] avoid typed-rest-client (#1075) -
122fa05Fix typo (#1073) - See full diff in compare view
Updates r-lib/actions/setup-tinytex from 2.12.0 to 2.12.1
Changelog
Sourced from r-lib/actions/setup-tinytex's changelog.
v2.12.1(2026-06-23)
[setup-r]now avoids a warning about anurl.parse()deprecation
(#1074).
[setup-r-dependencies]now usesquarto-dev/quarto-actionsv2.2.0
(@jdblischak, #1076).Examples:
test-coverage.yamlnow usescodecov/codecov-actionv7
(@shikokuchuo, #1081).New example
claude-investigate.yamlworkflow (@DavisVaughan, #1084).
v2.12.0(2026-04-29)
All node.js actions use node 24 now. Relatedly, all example workflows
use recent versions of actions that use node 24.
[setup-r]now usesuse-public-rspm: trueby default on Linux and
Windows. macOS binaries require further opt-in withuse-public-rspm: always.It is now possible to require actions to be pinned to a full-length
commit SHA in repositories usingr-lib/actions(#1070).
[setup-pandoc][setup-r-dependencies]now default to Pandoc
version 3.8.3.
[setup-r-dependencies]now includes the R architecture in the
cache key, so caches formacos-15(Apple Silicon) andmacos-15-intel(Rosetta/x86_64) no longer collide (#1035).
[setup-r]runapt-get updatewithout
debugging update failures easier (#1058).
v2.11.4(2025-10-08)
[setup-r]correctly installs Rtools again on aarch64 Windows,
as needed.
v2.11.3(2025-03-24)
[setup-r]now supports Rtools45, and installs it by default
for R >= 4.5.0.
v2.11.2(2025-02-19)
[setup-r]now installs gfortran 14.2 for R 4.5.0 and later (#965).
[setup-r]now does not use PPM on aarch64 Linux, because PPM
<!-- raw HTML omitted -->
... (truncated)
Commits
-
d3c5be5Update NEWS for v1.12.1 (#1087) -
0d1fbb4Add/investigateworkflow (#1084) -
ed1849bUse codecov/codecov-action v7 (#1082) -
173cb9dUpdate lock-threads and scorecard action versions -
2e3959dUpdate quarto-dev/quarto-actions/setup to v2.2.0 (#1076) -
ff9d3a3[setup-r] avoid typed-rest-client (#1075) -
122fa05Fix typo (#1073) - See full diff in compare view
Updates release-drafter/release-drafter from 7.4.0 to 7.5.1
Release notes
Sourced from release-drafter/release-drafter's releases.
v7.5.1
What's Changed
Bug Fixes
- fix: use PR changed files as the source of truth for path filtering (#1640)
@cchancheFull Changelog: https://github.com/release-drafter/release-drafter/compare/v7.5.0...v7.5.1
v7.5.0
What's Changed
New
- feat: align increments to semver lib from 0.0.0 (#1636)
@cchancheBug Fixes
- fix: require actual matches for category mode
only(#1639)@cchancheDependency Updates
- build(deps): bump undici from 6.24.1 to 6.27.0 (#1637) @dependabot[bot]
Full Changelog: https://github.com/release-drafter/release-drafter/compare/v7.4.0...v7.5.0
Commits
-
4d75298chore: release v7.5.1 -
87be2bffix: use PR changed files as the source of truth for path filtering (#1640) -
73b95fachore: release v7.5.0 -
46fd415Fix/align increments to semver lib from 0.0.0 (#1636) -
ee02572chore: upgrade various deps -
cd91445build(deps): bump undici from 6.24.1 to 6.27.0 (#1637) -
33c969bfix: require actual matches for category modeonly(#1639) -
5d6d314ci: support label 'dependencies' for dependabot - See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions