github dependabot/dependabot-core v0.363.0

9 hours ago

What's Changed

  • fix: fall back to older versions when pnpm trust downgrade blocks latest by @thavaahariharangit in #14213
  • Implement metadata finder for pre-commit by @AbhishekBhaskar in #14222
  • Bump Microsoft.Extensions.FileSystemGlobbing from 9.0.7 to 10.0.3 by @dependabot[bot] in #14190
  • Bump the all-actions group across 1 directory with 3 updates by @dependabot[bot] in #14216
  • Bump nokogiri from 1.18.9 to 1.19.1 in /updater by @dependabot[bot] in #14226
  • Bump the dev-dependencies group across 1 directory with 11 updates by @dependabot[bot] in #14185
  • add support for hex aliases by @efcasado in #14225
  • Validate that the dependabot ref namespace is available by @yeikel in #14218
  • Bump the prod-dependencies group across 1 directory with 24 updates by @dependabot[bot] in #14233
  • Bump rspec-its from 1.3.0 to 2.0.0 in /updater by @dependabot[bot] in #13387
  • Bump Microsoft.Extensions.FileProviders.Abstractions from 9.0.7 to 10.0.3 by @dependabot[bot] in #14189
  • Fix required_ruby_version in placeholder gemspec by @JamieMagee in #14243
  • Fix FileUpdater error for pnpm catalog dependencies fetched from parent directories by @Copilot in #14255
  • Bump the all-actions group with 2 updates by @dependabot[bot] in #14249
  • Bump sigstore/cosign/cosign from v3.0.4 to v3.0.5 in /docker in the regclient group by @dependabot[bot] in #14250
  • Exclude JSON files from changelog detection by @Copilot in #14206
  • Add support for version comments in pre-commit configuration by @robaiken in #14260
  • Use DG ecosystem in snapshot metadata by @brrygrdn in #14259
  • Update dockerfile to import images of dependent ecosystems by @AbhishekBhaskar in #14229
  • fix: Prevent per-directory individual PRs when group-by-name deps are rejected by semver rules by @markhallen in #14270
  • Fix go modules reachability error classification by @thavaahariharangit in #14283
  • Add pre-commit additional dependencies support for Dart by @AbhishekBhaskar in #14274
  • v0.363.0 by @dependabot-core-action-automation[bot] in #14288

New Contributors

Full Changelog: v0.362.0...v0.363.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.