-
Notifications
You must be signed in to change notification settings - Fork 18
Commit 17ce395
authored
chore: Bump hynek/build-and-inspect-python-package from 2.12.0 to 2.13.0 in the actions group (#544)
Bumps the actions group with 1 update:
[hynek/build-and-inspect-python-package](https://github.com/hynek/build-and-inspect-python-package).
Updates `hynek/build-and-inspect-python-package` from 2.12.0 to 2.13.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/hynek/build-and-inspect-python-package/releases">hynek/build-and-inspect-python-package's
releases</a>.</em></p>
<blockquote>
<h2>v2.13.0</h2>
<h3>Added</h3>
<ul>
<li>
<p>New output: <code>package_name</code> is the name of the built
package as stored in metadata.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/162">#162</a></p>
</li>
<li>
<p>The package name is now part of the action summary which is helpful
when you build more than one package from a repository.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/169">#169</a></p>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>
<p>All GitHub actions are now pinned to exact hashes for better
reproducibility and mild security improvements.</p>
<p>Since chosen prefix SHA-1 hash collision attacks <a
href="https://eprint.iacr.org/2020/014.pdf">exist</a>, this is but
security theater against serious attackers.</p>
</li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/hynek/build-and-inspect-python-package/blob/main/CHANGELOG.md">hynek/build-and-inspect-python-package's
changelog</a>.</em></p>
<blockquote>
<h1>Changelog</h1>
<p>All notable changes to this project will be documented in this
file.</p>
<p>The format is based on <a
href="https://keepachangelog.com/en/1.0.0/">Keep a Changelog</a>, and
this project adheres to <a
href="https://semver.org/spec/v2.0.0.html">Semantic Versioning</a>.</p>
<h2><a
href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.13.0...main">Unreleased</a></h2>
<h2><a
href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.12.0...2.13.0">2.13.0</a></h2>
<h3>Added</h3>
<ul>
<li>
<p>New output: <code>package_name</code> is the name of the built
package as stored in metadata.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/162">#162</a></p>
</li>
<li>
<p>The package name is now part of the action summary which is helpful
when you build more than one package from a repository.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/169">#169</a></p>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>All GitHub actions are now pinned to exact hashes for better
reproducibility and mild security improvements[^st].</li>
</ul>
<p>[^st]: Chosen prefix SHA-1 hash collision attacks <a
href="https://eprint.iacr.org/2020/014.pdf">exist</a>. Against serious
attackers, this is but security theater.</p>
<h2><a
href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.11.0...v2.12.0">2.12.0</a></h2>
<h3>Changed</h3>
<ul>
<li>This release only updates the tools we use.
It's important for being able to handle packaging metadata 2.4, as
published by recent versions of Hatchling, though.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/161">#161</a></li>
</ul>
<h2><a
href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.10.0...v2.11.0">2.11.0</a></h2>
<h3>Added</h3>
<ul>
<li>New output: <code>package_version</code> is the version of the
package that was built.
<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/pull/152">#152</a></li>
</ul>
<h2><a
href="https://github.com/hynek/build-and-inspect-python-package/compare/v2.9.0...2.10.0">2.10.0</a></h2>
<h3>Changed</h3>
<ul>
<li>Remove <code>.gitignore</code> from the build target directory to
avoid <a href="https://github.com/hynek/svcs/attestations/2821122">silly
attestations</a>.</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/c52c3a4710070b50470d903818a7b25115dcd076"><code>c52c3a4</code></a>
v2.13.0</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/3b7844e33dd93f56bf6ea6a05cdd62bf89bbb73a"><code>3b7844e</code></a>
Automated dependency upgrades (<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/170">#170</a>)</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/6e44b71e77bc75b61bc8b65a1f8249637351332b"><code>6e44b71</code></a>
Make package name part of contents header (<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/169">#169</a>)</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/296c43280749a6877648d64899fa4e729d58c2b4"><code>296c432</code></a>
Add changelog for <a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/162">#162</a></li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/62f7d4c5acebc640850c7be5a6604b3121ea9c5a"><code>62f7d4c</code></a>
Output the package name (<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/162">#162</a>)</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/8fe98a6d36e74e429839a0f66705ff66eaf8508f"><code>8fe98a6</code></a>
doc: fix typo</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/8913d5995fa4e8d91f8f6e3bfc3a6ea93a2f7add"><code>8913d59</code></a>
Automated dependency upgrades (<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/168">#168</a>)</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/0e544fa476bb2294dc7e58299601b672a92ca5cd"><code>0e544fa</code></a>
Document hard pins</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/970d68513b506d086fb08d1f8b4b2c293b8b4237"><code>970d685</code></a>
Hard-pin dependencies for better reproducability</li>
<li><a
href="https://github.com/hynek/build-and-inspect-python-package/commit/ce3cfd0d55922dfb29d3153f789cbbe05ebfca45"><code>ce3cfd0</code></a>
Automated dependency upgrades (<a
href="https://redirect.github.com/hynek/build-and-inspect-python-package/issues/167">#167</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/hynek/build-and-inspect-python-package/compare/b5076c307dc91924a82ad150cdd1533b444d3310...c52c3a4710070b50470d903818a7b25115dcd076">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>1 parent 30eaca0 commit 17ce395Copy full SHA for 17ce395
File tree
Expand file treeCollapse file tree
1 file changed
+1
-1
lines changedFilter options
- .github/workflows
Expand file treeCollapse file tree
1 file changed
+1
-1
lines changed.github/workflows/release_workflow.yml
Copy file name to clipboardExpand all lines: .github/workflows/release_workflow.yml+1-1Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
|
0 commit comments