What's Changed
- Rescue errors in metadata_cascades_for_dep to prevent PR message loss by @yeikel in #14905
- Bump sigstore from 4.1.0 to 4.1.1 in /npm_and_yarn/helpers by @dependabot[bot] in #15484
- Bump handlebars from 4.7.8 to 4.7.9 in /npm_and_yarn/helpers by @dependabot[bot] in #14547
- Bump lodash from 4.17.23 to 4.18.1 in /npm_and_yarn/helpers by @dependabot[bot] in #14605
- fix: use canonical LOCKFILE_ENTRY_REGEX in replace-lockfile-declaration.ts by @thavaahariharangit with @Copilot in #15642
- Prevent update job crash when a pinned GitHub Actions SHA is missing by @robaiken in #15628
- feat(npm_and_yarn): enhance downgrade conflict messages with detailed blocking dependencies by @thavaahariharangit in #15656
- Cargo: handle crates locked at multiple versions by @p-linnane in #15638
- Revert "Cargo: handle crates locked at multiple versions" by @kbukum1 in #15667
- Paginate Docker tag listing and classify registry error responses by @robaiken in #15651
- fix: Import proxy CA certificate into Java truststore for Java package managers by @thavaahariharangit in #15670
- Bump gradle from
4a253a2to2a6880cin /gradle by @dependabot[bot] in #15620 - Fix security update jobs failing with dependency_file_not_found for single-directory manifests by @thavaahariharangit with @Copilot in #15658
- Make Dependency strongly typed by @JamieMagee in #15647
- v0.389.0 by @dependabot-core-action-automation[bot] in #15691
New Contributors
- @p-linnane made their first contribution in #15638
Full Changelog: v0.388.0...v0.389.0