github dependabot/dependabot-core v0.389.0

3 hours ago

What's Changed

  • Rescue errors in metadata_cascades_for_dep to prevent PR message loss by @yeikel in #14905
  • Bump sigstore from 4.1.0 to 4.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15484
  • Bump handlebars from 4.7.8 to 4.7.9 in /npm_and_yarn/helpers by @dependabot[bot] in #14547
  • Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14605
  • fix: use canonical LOCKFILE_ENTRY_REGEX in replace-lockfile-declaration.ts by @thavaahariharangit with @Copilot in #15642
  • Prevent update job crash when a pinned GitHub Actions SHA is missing by @robaiken in #15628
  • feat(npm_and_yarn): enhance downgrade conflict messages with detailed blocking dependencies by @thavaahariharangit in #15656
  • Cargo: handle crates locked at multiple versions by @p-linnane in #15638
  • Revert "Cargo: handle crates locked at multiple versions" by @kbukum1 in #15667
  • Paginate Docker tag listing and classify registry error responses by @robaiken in #15651
  • fix: Import proxy CA certificate into Java truststore for Java package managers by @thavaahariharangit in #15670
  • Bump gradle from 4a253a2 to 2a6880c in /gradle by @dependabot[bot] in #15620
  • Fix security update jobs failing with dependency_file_not_found for single-directory manifests by @thavaahariharangit with @Copilot in #15658
  • Make Dependency strongly typed by @JamieMagee in #15647
  • v0.389.0 by @dependabot-core-action-automation[bot] in #15691

New Contributors

Full Changelog: v0.388.0...v0.389.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.