github dependabot/dependabot-core v0.366.0

7 hours ago

What's Changed

  • Add scanned_manifests_path metadata to snapshots by @brrygrdn in #14406
  • Fix regex pattern in pre-commit file parser and file-updater by @AbhishekBhaskar in #14429
  • Handle unhandled uv errors prefixed with CPython interpreter info by @thavaahariharangit in #14433
  • Handle Docker API version mismatch in script/build by @thavaahariharangit in #14436
  • Remove avoid_duplicate_updates_package_json FF from dependabot-core by @Copilot in #14428
  • Avoid sheering off directories by using manifest_file.directory by @brrygrdn in #14439
  • Fix: Bundler ignore rules now suppress path_dependencies_not_reachable errors during file fetching by @Copilot in #14435
  • Extend Swift UpdateChecker to support Xcode-managed SwiftPM projects by @AbhishekBhaskar in #14411
  • Extend Swift file updater to support xcode swiftpm dependency update by @AbhishekBhaskar in #14394
  • strip extras from Python PURLs in DG payload by @jakecoffman in #14462
  • only try to create pr if update operations were performed by @brettfo in #14463
  • additional unparseable file message by @brettfo in #14464
  • fix(github_actions): use most specific version tag when updating comments by @jeffwidman in #14461
  • fix(uv): strip extras from dependency names in PURL generation by @Copilot in #14468
  • Update corepack to 0.34.6 by @yeikel in #14371
  • Bump maven from 3.9.12 to 3.9.14 in /maven by @dependabot[bot] in #14446
  • honor update-types in grouped/ungrouped updater by @brettfo in #14475
  • feat: add .xcworkspace support for xcode swiftpm by @markhallen in #14459
  • fix(hex): correct tuple order for Hex.Repo.get_public_key response by @georgeguimaraes in #14380
  • Bump patch-package from 8.0.0 to 8.0.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14445
  • Fix "Multiple sources!" error for case-variant Terraform/OpenTofu provider declarations by @Copilot in #14434
  • v0.366.0 by @dependabot-core-action-automation[bot] in #14481

New Contributors

Full Changelog: v0.365.0...v0.366.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.