Skip to content

Update github-actions - #225

Merged
staabm merged 1 commit into
2.0.xfrom
renovate/github-actions
Aug 17, 2026
Merged

Update github-actions#225
staabm merged 1 commit into
2.0.xfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
github/codeql-action action patch v4.37.6v4.37.7
metcalfc/changelog-generator action minor v4.7.0v4.8.0
step-security/harden-runner action minor v2.20.1v2.21.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

github/codeql-action (github/codeql-action)

v4.37.7

Compare Source

metcalfc/changelog-generator (metcalfc/changelog-generator)

v4.8.0

Compare Source

Highlights

Failed changelog generation now fails the step

If the changelog could not be generated — an unresolvable ref, any git error — the action printed an ::error:: annotation and then exited 0. The step went green, outputs.changelog was never set, and downstream steps consumed an empty string without anything indicating a problem.

It now exits non-zero.

[!WARNING]
This is a behavior change. A workflow that was quietly passing on a broken changelog will now fail. That is the point — but expect it to surface as new red builds rather than as new errors, since the errors were always being printed.

fetch: true no longer intermittently fails on shallow checkouts

The default fetch path chained two git fetch --depth=1 calls ahead of git fetch --unshallow. Each rewrites .git/shallow while the next has already read it, so git would intermittently abort with:

fatal: shallow file has changed since we read it

Because fetch: true is the default and the exit code was being discarded, this produced a silently empty changelog rather than a visible failure. It was happening in this repository's own CI.

Now a single fetch, requesting --unshallow only when the checkout is actually shallow.

Testing

make test previously ran npm test || echo "no tests available", where npm test was exit 1 — it reported success unconditionally. The project now has a real suite covering changelog.sh against live git fixtures, ref validation, the release scripts, and the built dist/ bundle as the runner executes it. Both fixes above were found by adding it.

Full changelog

  • 98b1282 - 4.8.0
  • 32f61b2 - fix: make the version bump scripts portable (#​466)
  • f64bf35 - build(deps-dev): bump eslint from 10.1.0 to 10.8.1 (#​460)
  • e5f3244 - build(deps-dev): bump brace-expansion from 5.0.5 to 5.0.7 (#​448)
  • 57d0aa3 - build(deps-dev): bump globals from 17.4.0 to 17.9.0 (#​457)
  • ce20209 - build(deps-dev): bump prettier from 3.8.1 to 3.9.6 (#​454)
  • 89d0cce - build(deps): bump actions/attest-build-provenance from 4.1.0 to 4.2.2 (#​464)
  • daae4ab - build(deps): bump the codeql-action group with 3 updates (#​461)
  • 58f7ad5 - fix: fail the step when the changelog cannot be generated (#​465)
  • 4ffdab6 - build(deps-dev): bump @​vercel/ncc from 0.38.4 to 0.44.1 (#​441)
  • ce7d426 - ci: bump codeql-action to v4.37.1 and group its future updates (#​459)
  • cbc6a25 - test: replace the no-op test target with a real suite (#​458)
  • f278f3b - docs: update README example to use actions/checkout v6
  • 3f3af1f - fix: bump actions to Node 24-compatible versions
  • 10c0451 - fix: pin codeql-action to SHA and document supply chain security
step-security/harden-runner (step-security/harden-runner)

v2.21.0

Compare Source

What's Changed
  • Support for denied endpoints in block mode. This is included in the enterprise tier. Customers can deny outbound calls, for example, to public package registries.
  • Improved Support for AWS CodeBuild GitHub Actions Runners.
  • Bug fixes.

Full Changelog: step-security/harden-runner@v2.20.1...v2.21.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

- name: Generate changelog
id: changelog
uses: metcalfc/changelog-generator@0440d0932f9a0dd1cc9ecd8412830761351323bd # v4.7.0
uses: metcalfc/changelog-generator@98b12822c5dc6bad335d1d60d920cb69831b9c5d # v4.8.0
@staabm
staabm merged commit 3e1bff9 into 2.0.x Aug 17, 2026
45 checks passed
@renovate
renovate Bot deleted the renovate/github-actions branch August 17, 2026 06:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants