build(deps): Bump lfreleng-actions/github2gerrit-action from 1.0.2 to 1.0.6#4128
Conversation
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
|
PR: #4128 Note: This metadata is also included in the Gerrit commit message for reconciliation. |
|
Change raised in Gerrit by GitHub2Gerrit: https://gerrit.fd.io/r/c/csit/+/45010 |
… 1.0.6 Bumps lfreleng-actions/github2gerrit-action from 1.0.2 to 1.0.6. ## Release notes Sourced from lfreleng-actions/github2gerrit-action's releases. v1.0.6 Bug Fixes Fix: Add shallow clone deepening fallback for git merge --squash @ModeSevenIndustrialSolutions (#134) Maintenance Chore: Bump step-security/harden-runner from 2.14.1 to 2.14.2 @dependabot[bot] (#124) Chore: Bump lfreleng-actions/python-build-action from 1.0.2 to 1.0.3 @dependabot[bot] (#128) Chore: Bump astral-sh/setup-uv from 7.2.1 to 7.3.0 @dependabot[bot] (#126) Chore: Bump anchore/scan-action from 7.3.1 to 7.3.2 @dependabot[bot] (#125) Chore: Bump ruff from 0.14.14 to 0.15.0 @dependabot[bot] (#127) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#129) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#132) Chore: Bump typer from 0.21.1 to 0.23.1 @dependabot[bot] (#130) Chore: Bump ruff from 0.15.0 to 0.15.1 @dependabot[bot] (#131) Chore: Bump responses from 0.25.8 to 0.26.0 @dependabot[bot] (#138) Chore: Bump ruff from 0.15.1 to 0.15.2 @dependabot[bot] (#137) Chore: Bump typer from 0.23.1 to 0.24.0 @dependabot[bot] (#135) Chore: Bump rich from 14.3.2 to 14.3.3 @dependabot[bot] (#136) Links Submit bugs/feature requests v1.0.5 Bug Fixes Fix: Multiple bugs, minor feature enhancements @ModeSevenIndustrialSolutions (#123) Links Submit bugs/feature requests v1.0.4 New Features Feat: add .netrc file support for Gerrit @ModeSevenIndustrialSolutions (#116) Maintenance Chore: Bump release-drafter/release-drafter from 6.1.1 to 6.2.0 @dependabot[bot] (#109) Chore: Bump actions/checkout from 6.0.1 to 6.0.2 @dependabot[bot] (#112) Chore: Bump actions/setup-python from 6.1.0 to 6.2.0 @dependabot[bot] (#110) Chore: Bump anchore/scan-action from 7.2.3 to 7.3.0 @dependabot[bot] (#111) Chore: Bump ruff from 0.14.13 to 0.14.14 @dependabot[bot] (#113) Chore: Bump rich from 14.2.0 to 14.3.1 @dependabot[bot] (#114) Chore: pre-commit autoupdate @pre-commit-ci[bot] (#115) Chore: Bump step-security/harden-runner from 2.14.0 to 2.14.1 @dependabot[bot] (#119) Chore: Bump lfreleng-actions/tag-validate-action from 0.3.0 to 1.0.0 @dependabot[bot] (#117) Chore: Bump anchore/scan-action from 7.3.0 to 7.3.1 @dependabot[bot] (#118) Chore: Bump astral-sh/setup-uv from 7.2.0 to 7.2.1 @dependabot[bot] (#120) ... (truncated) ## Commits 7589e2f Merge pull request #134 from modeseven-lfreleng-actions/bug-fix c869088 Fix: SBOM audit failure due to CVE-2026-26007 c74a983 Fix: Add shallow clone deepening fallback for git merge --squash 192e613 Merge pull request #136 from lfreleng-actions/dependabot/uv/rich-14.3.3 e7952c6 Merge pull request #135 from lfreleng-actions/dependabot/uv/typer-0.24.0 d006f61 Merge pull request #137 from lfreleng-actions/dependabot/uv/ruff-0.15.2 5e48d2d Merge pull request #138 from lfreleng-actions/dependabot/uv/responses-0.26.0 8901bf1 Chore: Bump responses from 0.25.8 to 0.26.0 fbd6535 Chore: Bump ruff from 0.15.1 to 0.15.2 d4858dc Chore: Bump rich from 14.3.2 to 14.3.3 Additional commits viewable in compare view  Signed-off-by: dependabot[bot] <support@github.com> Change-Id: I000f9525c116773f7ab2eb10bad80d864b11a5ae GitHub-PR: #4128 GitHub-Hash: 58acd5527e495fab Signed-off-by: fdio.github <releng+fdio-github@linuxfoundation.org>
Bumps [lfreleng-actions/github2gerrit-action](https://github.com/lfreleng-actions/github2gerrit-action) from 1.0.2 to 1.0.6. - [Release notes](https://github.com/lfreleng-actions/github2gerrit-action/releases) - [Changelog](https://github.com/lfreleng-actions/github2gerrit-action/blob/main/docs/RELEASE-v0.2.0.md) - [Commits](lfreleng-actions/github2gerrit-action@cf7b647...7589e2f) --- updated-dependencies: - dependency-name: lfreleng-actions/github2gerrit-action dependency-version: 1.0.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
7c51b87 to
bd4dc19
Compare
|
Superseded by #4129. |
Bumps lfreleng-actions/github2gerrit-action from 1.0.2 to 1.0.6.
Release notes
Sourced from lfreleng-actions/github2gerrit-action's releases.
... (truncated)
Commits
7589e2fMerge pull request #134 from modeseven-lfreleng-actions/bug-fixc869088Fix: SBOM audit failure due to CVE-2026-26007c74a983Fix: Add shallow clone deepening fallback for git merge --squash192e613Merge pull request #136 from lfreleng-actions/dependabot/uv/rich-14.3.3e7952c6Merge pull request #135 from lfreleng-actions/dependabot/uv/typer-0.24.0d006f61Merge pull request #137 from lfreleng-actions/dependabot/uv/ruff-0.15.25e48d2dMerge pull request #138 from lfreleng-actions/dependabot/uv/responses-0.26.08901bf1Chore: Bump responses from 0.25.8 to 0.26.0fbd6535Chore: Bump ruff from 0.15.1 to 0.15.2d4858dcChore: Bump rich from 14.3.2 to 14.3.3Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)