github dependabot/dependabot-core v0.391.0

5 hours ago

What's Changed

  • Add typed requirement metadata readers by @JamieMagee in #15740
  • Type common requirement access by @JamieMagee in #15741
  • gracefully handle exceptions generated during package detail fetch by @brettfo in #15762
  • Bump the dev-dependencies group across 2 directories with 7 updates by @dependabot[bot] in #15563
  • Upgrade uv to 0.11.31 by @ABruihler in #15424
  • Bump ip-address from 10.2.0 to 10.4.0 in /bun/helpers by @dependabot[bot] in #15768
  • Bump brace-expansion from 1.1.13 to 1.1.18 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15769
  • Bump brace-expansion from 1.1.11 to 1.1.18 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15765
  • Bump brace-expansion from 1.1.16 to 1.1.18 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in #15743
  • Bump ip-address from 10.2.0 to 10.4.0 in /npm_and_yarn/helpers by @dependabot[bot] in #15767
  • Bump brace-expansion in /npm_and_yarn/helpers by @dependabot[bot] in #15763
  • Keep GitHub Actions ref precision when cooldown filters out the latest tag by @v-robaiken in #15760
  • Gradle: fall back to the running JVM when a Java toolchain is unavailable by @saefty in #15722
  • Bump the all-actions group across 1 directory with 22 updates by @dependabot[bot] in #15688
  • only call package restore targets on transitive projects by @brettfo in #15717
  • fix(uv): use env var auth for all matching pyproject.toml indexes, not just explicit ones by @benjaminaltieri in #14382
  • uv: regression test for versionless back-references not producing false-positive alerts (#15259) by @kbukum1 in #15778
  • Type shared container requirement access by @JamieMagee in #15780
  • Type Docker requirement access by @JamieMagee in #15781
  • Type Helm requirement access by @JamieMagee in #15782
  • Type shared JVM requirement readers by @JamieMagee in #15794
  • Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #15748
  • Type Maven requirement access by @JamieMagee in #15795
  • Fix Maven fetcher treating .xml directories as pom files by @v-HaripriyaC in #15787
  • Add dependency group subgroup naming helpers by @thavaahariharangit in #15826
  • Type Gradle requirement access by @JamieMagee in #15796
  • Fix Corepack signature verification against replaces-base private registries (#15567) by @opswithranjan in #15568
  • Don't omit the Release notes section if the release name includes more periods than the release version by @jeffwidman in #15801
  • Type SBT requirement access by @JamieMagee in #15797
  • Bump brace-expansion in /bun/helpers by @dependabot[bot] in #15788
  • v0.391.0 by @dependabot-core-action-automation[bot] in #15835

New Contributors

Full Changelog: v0.390.0...v0.391.0

Don't miss a new dependabot-core release

NewReleases is sending notifications on new releases.