dependabot-bot's Description of Work
Bumps the ci-dependencies group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| re-actors/alls-green | 1.2.2 | 1.3.0 |
| docker/build-push-action | 7.3.0 | 7.4.0 |
| prefix-dev/setup-pixi | 0.10.1 | 0.10.2 |
| r-lib/actions/setup-pandoc | 2.12.1 | 2.13.0 |
| r-lib/actions/setup-tinytex | 2.12.1 | 2.13.0 |
Updates re-actors/alls-green from 1.2.2 to 1.3.0
Release notes
Sourced from re-actors/alls-green's releases.
v1.3.0
<!-- raw HTML omitted -->🛡️ What's Unmessed
[!caution]
There was a small command injection risk in prior versions. I consider it very low because of the specifics of the action use case. But still, do upgrade, okay?
@illera88💰 fixed this template injection bug in #37 by passing inputs via env vars.See GHSA-gj76-h2ch-5m76 for more detail that was first reported by
@Corbynx010💰 while I was at EuroPython.✨ What's Improved
I did a bunch of internal refactoring including hints of what
@max-sixty💰 reported in #23. And took a small patch of@krokofant💰 in. This involved a bunch of preparatory infra work with testing infra.One notable improvement is that now thanks to
@tomasr8💰's and@hugovk💰's UX suggestions in #31, the gate status output is colored in the console and should be easier to scan in the log output per line. They entries now have leading✓/❌acceptance marks and the actual incoming job outcomes are labeled with🟢/🔴/⬜/⚫.🐛 What's Fixed
The job-statuses summary could print "Some of the allowed to be skipped jobs did not succeed" based on the wrong condition — it's now tied to
allowed-skipsas intended, notallowed-failures.💪 New Contributors
@Corbynx010💰 lurked in GHSA-gj76-h2ch-5m76 before everyone else :wink:@illera88made their first contribution in #37 and GHSA-gj76-h2ch-5m76@krokofantand@max-sixtyfirst contributed in #23@tomasr8and@hugovkin #31🪞 Full Diff: https://github.com/re-actors/alls-green/compare/v1.2.2...v1.3.0
🧔♂️ Release Manager:
@webknjaz🇺🇦💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.
Commits
-
b5b5b37Merge pull request #38 from re-actors/pre-commit-ci-update-config -
bd6edd6[pre-commit.ci] pre-commit autoupdate -
3967c81💅 Make the output easier to scan -
e68df08💅 Style job statuses title with a 🔮 -
62d37b2🧪 Unxfail 'success-of-some-allowed-to-skip-or-fail' -
7b5df6d💅 Add a Codecov badge to README -
2410c4c🐛 Correct reporting failed skipped jobs -
6457593💅 Add a GH Sponsors badge -
a617895💅 Add a pre-commit.ci badge -
8de05dc🧪 Forcectracecore in coveragepy - Additional commits viewable in compare view
Updates docker/build-push-action from 7.3.0 to 7.4.0
Release notes
Sourced from docker/build-push-action's releases.
v7.4.0
- Use the shared error helper for Buildx commands by
@crazy-maxin docker/build-push-action#1620- Prevent workflow command injection in metadata logs by
@crazy-maxin docker/build-push-action#1617- Bump
@docker/actions-toolkitfrom 0.92.0 to 0.100.0 in docker/build-push-action#1614 docker/build-push-action#1618 docker/build-push-action#1621- Bump
@humanfs/nodefrom 0.16.7 to 0.16.8 in docker/build-push-action#1609- Bump brace-expansion from 1.1.13 to 1.1.18 in docker/build-push-action#1592
- Bump csv-parse from 7.0.0 to 7.0.2 in docker/build-push-action#1613
- Bump js-yaml from 4.3.0 to 4.3.2 in docker/build-push-action#1605 docker/build-push-action#1615
- Bump nanoid from 3.3.16 to 3.3.18 in docker/build-push-action#1611
- Bump postcss from 8.5.10 to 8.5.25 in docker/build-push-action#1590
- Bump postcss-selector-parser from 7.1.1 to 7.1.5 in docker/build-push-action#1606
- Bump sigstore from 4.1.0 to 4.1.1 in docker/build-push-action#1577
- Bump undici from 6.27.0 to 6.28.0 in docker/build-push-action#1594
Full Changelog: https://github.com/docker/build-push-action/compare/v7.3.0...v7.4.0
Commits
-
c3c9e26Merge pull request #1621 from docker/dependabot/npm_and_yarn/docker/actions-t... -
459b674[dependabot skip] chore: update generated content -
4dedcb2chore(deps): Bump@docker/actions-toolkitfrom 0.99.0 to 0.100.0 -
379bf63Merge pull request #1620 from crazy-max/buildx-error-message -
9877975chore: update generated content -
7ed0556use the shared Buildx error summary helper -
91670baMerge pull request #1618 from docker/dependabot/npm_and_yarn/docker/actions-t... -
80dbc86[dependabot skip] chore: update generated content -
50cac3achore(deps): Bump@docker/actions-toolkitfrom 0.98.0 to 0.99.0 -
03b4d6cMerge pull request #1617 from crazy-max/fix-metadata-workflow-commands - Additional commits viewable in compare view
Updates prefix-dev/setup-pixi from 0.10.1 to 0.10.2
Release notes
Sourced from prefix-dev/setup-pixi's releases.
v0.10.2
<!-- raw HTML omitted -->What's Changed
✨ New features
- feat: Add support for linux-riscv64 by
@pavelzwin prefix-dev/setup-pixi#282Full Changelog: https://github.com/prefix-dev/setup-pixi/compare/v0.10.1...v0.10.2
Commits
-
d3f436afeat: Add support for linux-riscv64 (#282) - See full diff in compare view
Updates r-lib/actions/setup-pandoc from 2.12.1 to 2.13.0
Changelog
Sourced from r-lib/actions/setup-pandoc's changelog.
'v2.14.0` (2026-09-21)
[setup-r]:use-public-rspm: truenow sets up P3M (https://p3m.dev)
on macOS as well, for all repositories.
[setup-r]now installs flang 23 on R 4.7.0 (current R-devel) and
later, as this is what CRAN uses now (#1107,@andrjohns).
[check-r-package]now uses the correct check directory when showing
the testthat output (#1109,@NotAFlightRisk).
v2.13.0(2026-08-28)
[setup-r]now retries r-hub.io HTTP failures (#1088,@nbenn).
[setup-r]now sets the correct RTOOLS environment variables on
aarch64 Windows (@vjymisal0, #1104).
[setup-r]keep repositories if they are set by the build.
E.g. aarch64 Windows builds now set them (@jeroen, #1101).
[setup-r]now retries transient failures when resolving the R
version fromapi.r-hub.io, rather than failing the job on the first
timeout or server error (@nbenn, #1086).
[setup-r-dependencies]now switches back to classicsudo, if
available, on Linux. This fixes installing pak on Ubuntu 26.04 runners
(@jeroen, #1096).
v2.12.1(2026-06-23)
[setup-r]now avoids a warning about anurl.parse()deprecation
(#1074).
[setup-r-dependencies]now usesquarto-dev/quarto-actionsv2.2.0
(@jdblischak, #1076).Examples:
test-coverage.yamlnow usescodecov/codecov-actionv7
(@shikokuchuo, #1081).New example
claude-investigate.yamlworkflow (@DavisVaughan, #1084).
v2.12.0(2026-04-29)
All node.js actions use node 24 now. Relatedly, all example workflows
use recent versions of actions that use node 24.
[setup-r]now usesuse-public-rspm: trueby default on Linux and
Windows. macOS binaries require further opt-in withuse-public-rspm: always.
<!-- raw HTML omitted -->
... (truncated)
Commits
-
465b7d8NEWS for 2.13.0 (#1105) -
d06a540[setup-r] retry transient r-hub.io request failures (#1088) -
ed9aa85fix(setup-r): export correct RTOOLS HOME env vars on Windows ARM64 and x64 (#... -
c86f32csetup-r-dependencies: set JAVA_HOME on Windows runners from Java 21 env vars ... -
2a66450setup-r-dependencies: switch back to classic sudo on runners with sudo-rs (#1... -
5cc1f0dFix minor typo (#1098) -
33d09fbfix: Remove stray::group::(#1103) -
aae88a2Special-case CRAN mirror for Windows ARM64 (#1101) -
b7484da[setup-r] Support installing RTools without installing R (#1093) - See full diff in compare view
Updates r-lib/actions/setup-tinytex from 2.12.1 to 2.13.0
Changelog
Sourced from r-lib/actions/setup-tinytex's changelog.
'v2.14.0` (2026-09-21)
[setup-r]:use-public-rspm: truenow sets up P3M (https://p3m.dev)
on macOS as well, for all repositories.
[setup-r]now installs flang 23 on R 4.7.0 (current R-devel) and
later, as this is what CRAN uses now (#1107,@andrjohns).
[check-r-package]now uses the correct check directory when showing
the testthat output (#1109,@NotAFlightRisk).
v2.13.0(2026-08-28)
[setup-r]now retries r-hub.io HTTP failures (#1088,@nbenn).
[setup-r]now sets the correct RTOOLS environment variables on
aarch64 Windows (@vjymisal0, #1104).
[setup-r]keep repositories if they are set by the build.
E.g. aarch64 Windows builds now set them (@jeroen, #1101).
[setup-r]now retries transient failures when resolving the R
version fromapi.r-hub.io, rather than failing the job on the first
timeout or server error (@nbenn, #1086).
[setup-r-dependencies]now switches back to classicsudo, if
available, on Linux. This fixes installing pak on Ubuntu 26.04 runners
(@jeroen, #1096).
v2.12.1(2026-06-23)
[setup-r]now avoids a warning about anurl.parse()deprecation
(#1074).
[setup-r-dependencies]now usesquarto-dev/quarto-actionsv2.2.0
(@jdblischak, #1076).Examples:
test-coverage.yamlnow usescodecov/codecov-actionv7
(@shikokuchuo, #1081).New example
claude-investigate.yamlworkflow (@DavisVaughan, #1084).
v2.12.0(2026-04-29)
All node.js actions use node 24 now. Relatedly, all example workflows
use recent versions of actions that use node 24.
[setup-r]now usesuse-public-rspm: trueby default on Linux and
Windows. macOS binaries require further opt-in withuse-public-rspm: always.
<!-- raw HTML omitted -->
... (truncated)
Commits
-
465b7d8NEWS for 2.13.0 (#1105) -
d06a540[setup-r] retry transient r-hub.io request failures (#1088) -
ed9aa85fix(setup-r): export correct RTOOLS HOME env vars on Windows ARM64 and x64 (#... -
c86f32csetup-r-dependencies: set JAVA_HOME on Windows runners from Java 21 env vars ... -
2a66450setup-r-dependencies: switch back to classic sudo on runners with sudo-rs (#1... -
5cc1f0dFix minor typo (#1098) -
33d09fbfix: Remove stray::group::(#1103) -
aae88a2Special-case CRAN mirror for Windows ARM64 (#1101) -
b7484da[setup-r] Support installing RTools without installing R (#1093) - See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions