github dependabot/dependabot-core v0.388.0

13 hours ago

What's Changed

  • Type GitHub release metadata by @JamieMagee in #15597
  • Make GitCommitChecker strongly typed by @JamieMagee in #15598
  • Retry corepack prepare and install on signature metadata errors from private registries by @kbukum1 in #15606
  • Fix UV DependencyGrapher to detect nested uv.lock in monorepos by @thavaahariharangit with @Copilot in #15520
  • Bump library/rust from 1.95.0-bookworm to 1.97.0-bookworm in /cargo by @dependabot[bot] in #15560
  • Bump @sigstore/core from 3.1.0 to 3.2.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15455
  • Bump maven from 3.9.14 to 3.9.16 in /maven by @dependabot[bot] in #15127
  • Support Bundler source cooldown in Dependabot cooldown flow by @robaiken in #15517
  • Type shared release metadata by @JamieMagee in #15607
  • Make Job strongly typed by @JamieMagee in #15608
  • Type Job wire models by @JamieMagee in #15610
  • Type Service and ApiClient by @JamieMagee in #15614
  • Add support for calendar-based versions for Maven and Gradle by @yeikel in #14114
  • Type error reporting by @JamieMagee in #15615
  • Type updater dependency helpers by @JamieMagee in #15617
  • ensure proper formatting when patching element attributes by @brettfo in #15629
  • Bump ws from 8.18.3 to 8.21.1 in /npm_and_yarn/helpers/test/npm/fixtures/vulnerability-auditor/update-needed-across-two-versions by @dependabot[bot] in #15329
  • Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14608
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14609
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14610
  • Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #14694
  • Bump pip from 26.1.1 to 26.1.2 in /python/helpers in the pip group across 1 directory by @dependabot[bot] in #11830
  • Bump yaml from 2.3.1 to 2.9.0 in /bun/helpers by @dependabot[bot] in #14535
  • npm_and_yarn: group vulnerability auditor blocking-dependency messages by top-level ancestor by @thavaahariharangit in #15627
  • Bump ip-address and socks in /bun/helpers by @dependabot[bot] in #14924
  • Bump brace-expansion from 1.1.13 to 1.1.16 in /bun/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15634
  • Bump brace-expansion from 1.1.13 to 1.1.16 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15633
  • Bump sigstore/cosign/cosign from v3.1.1 to v3.1.2 in /docker in the regclient group across 1 directory by @dependabot[bot] in #15621
  • Bump lodash from 4.17.23 to 4.18.1 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #14606
  • Bump @tootallnate/once from 2.0.0 to 2.0.1 in /bun/helpers by @dependabot[bot] in #15107
  • Bump the "uv-ecosystem" group with 1 update across multiple ecosystems by @dependabot[bot] in #14969
  • Bump ip-address and socks in /npm_and_yarn/helpers by @dependabot[bot] in #14923
  • Bump yaml from 2.3.1 to 2.9.0 in /npm_and_yarn/helpers by @dependabot[bot] in #14533
  • Bump golang.org/x/mod from 0.37.0 to 0.38.0 in /go_modules/helpers by @dependabot[bot] in #15559
  • Bump @sigstore/verify from 3.1.0 to 3.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15477
  • julia: don't propose compat updates for workspace packages or synthesize member compat entries by @IanButterworth in #15643
  • fix: guard against unparseable versions in cooldown fallback by @currantw in #15632
  • Type dependency requirement readers by @JamieMagee in #15646
  • v0.388.0 by @dependabot-core-action-automation[bot] in #15623

New Contributors

Full Changelog: v0.387.0...v0.388.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.