github dependabot/dependabot-core v0.347.0

17 hours ago

What's Changed

  • consider directory when checking for existing PR by @jakecoffman in #13058
  • Remove unused grouped_security_updates_disabled feature flag by @Copilot in #13492
  • Reduce API quota usage in smoke tests by centralizing CLI download by @Copilot in #13491
  • Add MODULE.bazel.lock lockfile update support by @markhallen in #13467
  • Fix nil dependency crash in ErrorHandler when refreshing PRs by @Copilot in #13480
  • Add support for *.MODULE.bazel files in Bazel file fetcher by @Copilot in #13475
  • Fix logging format when previous_version is nil for pip dependencies by @Copilot in #13487
  • bazel: simplify, harden, and fix version handling by @markhallen in #13508
  • Add metadata finder to bazel by @robaiken in #13507
  • remove pruned dependencies from graph payload by @jakecoffman in #13509
  • Fix Poetry lock file updates for PEP 621 projects by @Copilot in #13499
  • Validate dependency-type option is only used with supported package managers by @Copilot in #13413
  • Ensure package_hashes_for uses absolute index_url by @thavaahariharangit in #13518
  • Fix: Gradle Wrapper native updated run for every dependency by @gmazzo in #13501
  • add net10 as a supported framework and update others by @brettfo in #13512
  • Fix: Preserve tilde (~=) compatible version format in setup.py/setup.cfg by @Copilot in #13513
  • Upgrade uv to v0.9.8 by @charliermarsh in #13502
  • report update process exit code by @brettfo in #13483
  • Set persist-credentials: false for actions/checkout by @JamieMagee in #13530
  • Bump the all-actions group across 1 directory with 14 updates by @dependabot[bot] in #13493
  • Add zizmor workflow by @JamieMagee in #13531
  • feat(bazel): Fetch referenced lock files and BUILD files for MODULE.bazel by @markhallen in #13528
  • Enable credential persistence in gems-bump-version workflow by @a-schur in #13535
  • v0.347.0 by @dependabot-core-action-automation[bot] in #13538

New Contributors

Full Changelog: v0.346.0...v0.347.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.