github dependabot/dependabot-core v0.352.0

4 days ago

What's Changed

  • Fix: Gradle wrapper scripts not getting updated by @gmazzo in #13579
  • bun: preserve configVersion field in lockfiles by @a-schur in #13694
  • Centralize corepack credential handling by @thavaahariharangit in #13719
  • Update beta ecosystem error message to include enablement instructions by @Copilot in #13717
  • added existing group pr number in logs by @alhss in #13594
  • Fix pip-compile to update all lockfiles from single input file by @Copilot in #13687
  • Add support for include() statements in Bazel MODULE.bazel files by @markhallen in #13701
  • Filter pre-released tags from version updates, github-action by @thavaahariharangit in #13731
  • Update the Go grapher to recognise when a parsing problem relates to repo reachability by @brrygrdn in #13732
  • Add security update support for UV lock file resolver by @markhallen in #13736
  • Adding ecosystem information for file parse for julia by @robaiken in #13737
  • Fix Cargo ignore commands to follow Rust semver for pre-1.0 versions by @Copilot in #13710
  • Remove unnecessary path modification by @yeikel in #13671
  • Add support for Python 3.14.2 and 3.13.11 by @yeikel in #13744
  • Remove opentufo and julia from beta by @robaiken in #13750
  • Fix npm peer dependency incorrect commit message issue by @AbhishekBhaskar in #13748
  • Bump the dev-dependencies group across 1 directory with 3 updates by @dependabot[bot] in #13666
  • Fix UV pyproject marker preservation by @markhallen in #13758
  • use Path.Combine instead of Path.Join to account for possibly rooted paths by @brettfo in #13762
  • Fix unqualified MANIFEST_FILENAME constant reference in DependencyGrapher by @jurre in #13757
  • Remove confusing npm 6 hack warning in npm/Dockerfile and remove global .npmrc by @jeffwidman in #13681
  • fix handling of existing prs by @brettfo in #13753
  • Fix Poetry file updater to handle CRLF line endings by @Copilot in #13495
  • Skip Lockfile generation for Build Systems Dependencies by @robaiken in #13760
  • v0.352.0 by @dependabot-core-action-automation[bot] in #13755

Full Changelog: v0.351.0...v0.352.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.