Skip to content

Bump EndBug/add-and-commit from 10.0.0 to 11.1.1 - #206

Merged
lmajano merged 1 commit into
developmentfrom
dependabot/github_actions/EndBug/add-and-commit-11.1.1
Sep 10, 2026
Merged

Bump EndBug/add-and-commit from 10.0.0 to 11.1.1#206
lmajano merged 1 commit into
developmentfrom
dependabot/github_actions/EndBug/add-and-commit-11.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps EndBug/add-and-commit from 10.0.0 to 11.1.1.

Release notes

Sourced from EndBug/add-and-commit's releases.

v11.1.1

What's Changed

New Contributors

Full Changelog: EndBug/add-and-commit@v11.1.0...v11.1.1

v11.1.0

What's Changed

Full Changelog: EndBug/add-and-commit@v11.0.0...v11.1.0

v11.0.0

What's Changed

... (truncated)

Commits
  • cc9c08b 11.1.1
  • 3446398 fix: validate denylisted git args on every token (#784)
  • b0ca327 fix: Remove GH var interpolation in action.yml docstring (#783)
  • 3e1240d docs: highlight untrusted git-arg interpolation as a warning callout (#781)
  • fc1cf1d 11.1.0
  • f14ee6d chore(deps-dev): bump @​vercel/ncc from 0.44.1 to 0.45.0 (#779)
  • bccc19e chore(deps): bump js-yaml from 5.2.3 to 5.3.0 (#780)
  • 7a6d750 ci: rebuild lib on Dependabot PRs so CI can re-run
  • 66d71de fix: reject glued quotes that string-argv would split into extra git flags (#...
  • 60ff4bb fix: neutralize workflow-command injection in info logs (#776)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) from 10.0.0 to 11.1.1.
- [Release notes](https://github.com/endbug/add-and-commit/releases)
- [Commits](EndBug/add-and-commit@v10.0.0...v11.1.1)

---
updated-dependencies:
- dependency-name: EndBug/add-and-commit
  dependency-version: 11.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 1, 2026
@lmajano
lmajano merged commit 6860105 into development Sep 10, 2026
3 of 19 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/EndBug/add-and-commit-11.1.1 branch September 10, 2026 17:21
lmajano added a commit that referenced this pull request Sep 11, 2026
* Version bump

* Encode HTML for bundle and spec names in simple.cfm (#196)

If you have HTML tags `<>` in your tests, it will break the output. This change fixes that by escaping HTML tags.

* missing isLucee() detection check for boxlang

* Phases 1 & 2: expectation context and collection expectation modes

Phase 1 - withContext():
- Add  chainable method
- Context prepended to all matcher failure messages, negated matchers,
  dynamic not* matchers, and custom matcher failures
- resolveMessage() helper only injects when both context and message
  are non-empty to preserve Assertion default messages

Phase 2 - Collection modes:
- Add expectAny(), expectSome(), expectNone() to BaseSpec
- Rewrite CollectionExpectation.cfc with mode dispatch
- Detailed failure summaries with pass counts and element index/key
- Use return-struct pattern for CFML pass-by-value safety
- 22 new tests covering arrays, structs, edges, and chainability

Verification: 381 passed, 0 failed, format check clean
See plan.md for full roadmap

* Fix BoxLang expectAll failure message assertion after CollectionExpectation rewrite

* Phase 3: grouped assertions via $assert.all() and assertAll()

Add $assert.all( executables, heading ) to Assertion.cfc that runs
multiple closures and reports every assertion failure at once instead
of stopping at the first. Non-assertion exceptions rethrow immediately.

- assertAll() facade on BaseSpec delegates to $assert.all()
- Aggregated failure message with heading and numbered detail list
- 6 tests: all-pass, multi-fail, single-fail, heading, unexpected
  exception rethrow, and facade shortcut

Verification: 387 passed, 0 failed, format check clean

* tons of more updates

* phase 7 done

* Apply cfformat changes

* Bump taiki-e/create-gh-release-action from 1.9.2 to 1.11.0 (#195)

Bumps [taiki-e/create-gh-release-action](https://github.com/taiki-e/create-gh-release-action) from 1.9.2 to 1.11.0.
- [Release notes](https://github.com/taiki-e/create-gh-release-action/releases)
- [Changelog](https://github.com/taiki-e/create-gh-release-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/create-gh-release-action@v1.9.2...v1.11.0)

---
updated-dependencies:
- dependency-name: taiki-e/create-gh-release-action
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump EndBug/add-and-commit from 9.1.4 to 10.0.0 (#193)

Bumps [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) from 9.1.4 to 10.0.0.
- [Release notes](https://github.com/endbug/add-and-commit/releases)
- [Commits](EndBug/add-and-commit@v9.1.4...v10.0.0)

---
updated-dependencies:
- dependency-name: EndBug/add-and-commit
  dependency-version: 10.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Data Navigator Phase

* ranges finalized

* Apply cfformat changes

* double method removed

* Update whats-new-with-7.0.0.md

* commit

* TESTBOX-450 #resolve
equalize assertions should handle different types of date and date/time objects for equality, instead of blindly doing actual.equals()

* almost ready for release

* Apply cfformat changes

* Bump actions/checkout from 6 to 7 (#197)

Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* bad lucee parser, bad

* TESTBOX-451 #resolve
BDD class support for skip annotation

* Apply cfformat changes

* update default value of coverage

* Bump actions/setup-java from 5 to 5.6.0 (#199)

Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 5.6.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@v5...v5.6.0)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* TESTBOX-452: Fixes error while running BoxLang in adobe compat (#198) #resolve

* Adjusts response retrieval for BoxLang

Modifies the condition for retrieving the page context response to ensure BoxLang environments do not perform a ColdFusion-specific double `getResponse()` call. This prevents incorrect response handling when running on BoxLang.

* TESTBOX-452: Adjusts response retrieval for BoxLang

Modifies the condition for retrieving the page context response to ensure BoxLang environments do not perform a ColdFusion-specific double `getResponse()` call. This prevents incorrect response handling when running on BoxLang.

* fix: support full null runtimes (#200)

* TESTBOX-453: Fix BoxLang CLI runner misreading its own path as a bundle argument (#201)

* Avoid absolute entry-point path in the BoxLang CLI launcher

The `run` launcher resolved its own directory to an absolute path
before invoking `boxlang`, so BoxLangRunner.bx was executed via an
absolute filesystem path. BoxLang 1.17.0 hardened path resolution to
force absolute-looking paths through mappings/webroot instead of the
OS filesystem, which intermittently broke the entry point's own
self-resolution later in the run (surfacing as a ClassNotFoundBoxLangException
during TestBox's bundle discovery) on CI runners invoking `./testbox/run`.

Passing boxlang a relative path avoids exercising that code path, and
leaves server.cli.executionPath pointing at the caller's working
directory as before.

* Fix actual root cause: strip runner's own path from CLI positionals

Installed BoxLang v1.17.0+58 (the exact engine build from the CI
failure reports) and reproduced the crash locally with a scratch
project mirroring bx-sites' setup. Instrumented TestBox.cfc and
BoxLangRunner.bx to trace the failure and found the real cause:
`server.cli.parsed.positionals` on this engine build always includes
the entry-point script's own invocation path as its first entry
(effectively an argv[0] leak), regardless of whether boxlang was
invoked with a relative or absolute path.

BoxLangRunner.bx's `if( positional.len() ) { initArgs.bundles =
positional[1] }` therefore always treats a plain `./testbox/run
--verbose --stream` invocation (no bundle argument) as if the user
had passed the runner's own path as a bundle to test, which then
fails GetClassMetadata() resolution downstream in TestBox.cfc's
bundle-discovery loop with the reported ClassNotFoundBoxLangException.

This supersedes the previous commit on this branch, which changed
`run` to pass a relative path under the theory that BoxLang 1.17.0's
include-path hardening was responsible. That was disproven by testing:
the crash reproduces identically with a relative invocation, and the
real fix below resolves it under both relative and absolute
invocation. `run` is reverted to its original form.

Fix: filter `server.cli.parsed.positionals` to drop any entry that
resolves (relative to the invocation directory, following symlinks)
to this same script, before treating what remains as a user-supplied
bundle argument. Verified locally: 8/8 consecutive green runs via
`./testbox/run --stream`, and explicit `run my.bundle`-style
invocations still work correctly.

---------

Co-authored-by: Claude <noreply@anthropic.com>

* Fix KeyNotFoundException [url] crashing every CLI run on BoxLang 1.17+ (#202)

Reported by the maintainer running ./testbox/run --stream --verbose
against BoxLang v1.17.0+58: every CLI run crashed immediately after
the recent CLI-runner fix (#201) cleared the way to reach this code,
with:

  KeyNotFoundException: The requested key [url] was not located in
  any scope or it's undefined
    at ...ScriptingRequestBoxContext.scopeFind
    at ...Testbox$cfc.invokeFunction_runRaw(TestBox.cfc:408)

Root cause: runRaw() and dryRun() unconditionally reference the `url`
scope to support web-request query-string test filters (?testBundles=,
?testSuites=, etc.). The `url` scope only exists in a real HTTP
request context - it is never registered at all when TestBox runs via
the BoxLang CLI. #200 ("support full null runtimes") added a
`structKeyExists( url, "testBundles" )` guard, but that doesn't help
here: resolving the bare `url` identifier itself is what throws -
structKeyExists() never gets a chance to run, since BoxLang has to
look up `url` as a scope before it can pass it as an argument.

Fix: skip these URL-based filter blocks entirely when
variables.IS_CLI is true (already computed at class init). CLI users
already have --filter-bundles/--filter-suites/--filter-specs for the
same purpose via BoxLangRunner.bx, so nothing is lost.

Verified locally against BoxLang v1.17.0+58: reproduced the exact
reported crash against the real merged development branch first
(structKeyExists guard included), then confirmed the fix with the
maintainer's exact command (./testbox/run --streamingj --verbose,
4/4 clean runs), plus --dry-run and --stream, which exercise both
patched call sites (runRaw() and dryRun()).

Co-authored-by: Claude <noreply@anthropic.com>

* Expand url-scope guard: skip only when the scope truly isn't there (#203)

#202 guarded the URL-based test filter blocks in runRaw()/dryRun()
with plain `!variables.IS_CLI`, which assumes the url scope is never
present in CLI mode. That's true today, but the guard shouldn't bake
in that assumption - it should check reality instead of the engine
mode. If a CLI context is ever running with a url scope registered
(a future BoxLang change, an embedding runner, etc.), skipping unconditionally
on IS_CLI would silently drop those overrides for no reason.

Confirmed isDefined( "url" ) is the safe way to probe for this: unlike
referencing the bare `url` identifier (which throws when the scope
isn't registered), isDefined() on a scope name returns false without
error.

New guard: `!variables.IS_CLI || isDefined( "url" )` - run the block
whenever we're not in CLI mode (unchanged, existing behavior) OR the
url scope actually exists (covers any CLI context where it does).
Only skip when neither holds, i.e. CLI with no url scope - which is
where the original #202 crash happened.

Verified locally against BoxLang v1.17.0+58: confirmed isDefined("url")
returns false without throwing where a bare `url` reference does
throw, then re-ran the full local repro (./testbox/run --streamingj
--verbose, --stream, --dry-run) with the expanded guard - all clean,
same as after #202.

Co-authored-by: Claude <noreply@anthropic.com>

* TESTBOX-448: Fix MockBox $args() struct-order fragility + Set/Range support (#204)

* TESTBOX-448: Fix MockBox $args() struct-order fragility + cross-engine value normalization

normalizeArguments() built its arg hash from struct.toString()/Java
Map.toString() for non-simple values, whose output depends on HashMap
iteration order - never guaranteed in CFML. Two structurally-equal
structs built in different insertion order could hash differently,
so $args() would silently miss a match. Latent for years; Lucee 7.1's
new ConcurrentHashMap-backed struct implementation (LDEV-5098) made
the fragility consistently visible.

Fix: normalizeValue() recursively canonicalizes composite argument
values instead of relying on raw Map/struct toString():
 - Structs: keys sorted via java.util.TreeMap (order-independent),
   values recursively normalized, then the whole thing is JSON-encoded
   rather than hand-joined with bare "," / "=" / "{}" - hand-joining
   let a string value containing those characters collide with a
   completely different struct that happened to serialize to the same
   raw text (e.g. {a:"1,b=2"} and {a:1,b:2} previously hashed
   identically). JSON escaping closes that off for both structs and
   arrays.
 - BoxLang Range: canonicalized via toString(), which fully captures
   bounds/step/exclusivity ("1..5" vs "1>..<5" vs "1..10.step(3)" all
   differ) - never iterated/materialized, since ranges can be huge or
   unbounded (an open-start range even throws if you try to iterate
   it). Checked before the array branch, since isArray() is true for
   a Range.
 - BoxLang Set: unordered by definition, so elements are normalized
   then sorted before JSON-encoding - the same order-independence
   struct keys get, applied to set elements. Type-tagged (as is Range)
   so a Set can never collide with an Array/string holding equivalent
   content.
 - CFC values: unchanged, still serialized via getMetadata() (moved
   into the same recursive helper so nested CFCs inside structs/arrays
   get the same treatment as top-level CFC args).

Range/Set checks are gated behind a computed IS_BOXLANG flag so
isRange()/isBoxSet() - which don't exist on Lucee/Adobe - are never
even attempted on those engines; short-circuit evaluation keeps the
whole branch inert there.

Tests: cross-engine coverage (struct order-independence, CFC-in-struct,
deep struct>array>struct nesting, and the delimiter-collision
regression) added to tests/specs/mockbox/MockBoxTest.cfc. Set/Range
coverage added as tests/specs/mockbox/MockBoxSetRangeTest.bx - a .bx
file, since BoxLang's `..` range operator isn't valid CFML syntax at
all on Lucee/Adobe (a parse-time failure, not just a missing-BIF one)
and TestBox's own bundle discovery already skips *.bx files entirely
on non-BoxLang engines, so this file is never compiled or run there.

Verified against BoxLang v1.17.0+58 end-to-end via the real
MockBox/$args()/createStub() API (not just the isolated normalization
logic): struct order-independence, delimiter-collision non-match, Set
order-independence across all three backing variants, Set-vs-Array
non-collision, Set-of-structs, Range match/non-match (bounds, step,
exclusivity), Range-vs-string non-collision, and unbounded-range
normalization all pass. Self-ran the full MockBoxTest + new
MockBoxSetRangeTest bundles (41 specs) - all new tests green; the
only 2 errors are a pre-existing, unrelated MockGenerator interface-stub
issue confirmed present on unmodified development too.

Supersedes #194 (external contributor PR for the same ticket): fixes
the delimiter-collision bug in that PR's normalizeValue() rewrite
(verified reproducible there against the real code, confirmed absent
on the current merged development baseline) and adds BoxLang Set/Range
support, which #194 did not handle.

* Fix cfformat alignment violation in testMockArgsNoDelimiterCollision

Inline the struct literal directly into save() instead of a separate
var declaration, avoiding a miscomputed manual alignment column
against the adjacent var statement.

---------

Co-authored-by: Claude <noreply@anthropic.com>

* TESTBOX-456: Simplify BoxLang CLI url scope guard to a param (#205)

Replace the two-condition if-guard (!IS_CLI || isDefined("url")) with
a plain `param name="url" default={};` at the top of runRaw()/dryRun().
param is a no-op wherever the scope already exists (every engine, every
non-CLI request) and only defaults it in the one case that was ever
broken - BoxLang CLI, where the scope isn't registered at all.

Verified against real BoxLang v1.17.0+58: dryRun()/runRaw() both
complete without throwing in CLI mode (isDefined('url') == false).

Co-authored-by: Claude <noreply@anthropic.com>

* Complete 7.1.0 changelog and move release docs to testbox-docs (#208)

Audits the changelog against every commit since the 7.0.0 release
(dc89555) and fills in the eleven user-facing changes that were missing,
each tagged with its Jira ticket.

Changelog:
- Add the missing MockBox, reporter, date-equality, engine-detection,
  full-null and BoxLang CLI entries under [Unreleased]
- Add a Changed section for the coverageEnabled default flip, which is a
  behavioral change
- Correct the stale whats-new-with-7.0.0 filename reference

The [Unreleased] section is left as-is. The release workflow stamps the
version heading and compare links via keep-a-changelog-new-release.

Removes the local docs/ folder. The 7.1.0 release page now lives in
testbox-docs under readme/release-history/, alongside every prior
release, and the changelog links to the published page instead.


Claude-Session: https://claude.ai/code/session_0126haQX77C4MLiK3fxwQ59A

Co-authored-by: Claude <noreply@anthropic.com>

* Complete 7.1.0 changelog and move release docs to testbox-docs (#209)

Audits the changelog against every commit since the 7.0.0 release
(dc89555) and fills in the eleven user-facing changes that were missing,
each tagged with its Jira ticket.

Changelog:
- Add the missing MockBox, reporter, date-equality, engine-detection,
  full-null and BoxLang CLI entries under [Unreleased]
- Add a Changed section for the coverageEnabled default flip, which is a
  behavioral change
- Correct the stale whats-new-with-7.0.0 filename reference

The [Unreleased] section is left as-is. The release workflow stamps the
version heading and compare links via keep-a-changelog-new-release.

Removes the local docs/ folder. The 7.1.0 release page now lives in
testbox-docs under readme/release-history/, alongside every prior
release, and the changelog links to the published page instead.


Claude-Session: https://claude.ai/code/session_0126haQX77C4MLiK3fxwQ59A

Co-authored-by: Claude <noreply@anthropic.com>

* Bump actions/setup-java from 5.6.0 to 6.0.0 (#207)

Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.6.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@v5.6.0...v6.0.0)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump EndBug/add-and-commit from 10.0.0 to 11.1.1 (#206)

Bumps [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) from 10.0.0 to 11.1.1.
- [Release notes](https://github.com/endbug/add-and-commit/releases)
- [Commits](EndBug/add-and-commit@v10.0.0...v11.1.1)

---
updated-dependencies:
- dependency-name: EndBug/add-and-commit
  dependency-version: 11.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Github Actions <info@ortussolutions.com>
Co-authored-by: Dave L <dave@angrysam.com>
Co-authored-by: lmajano <137111+lmajano@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Rodney Enke Jr. <renkejr@gmail.com>
Co-authored-by: Eric Peterson <eric@elpete.com>
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant