build(deps): bump the actions group across 1 directory with 9 updates - #835
Open
dependabot[bot] wants to merge 2 commits into
Open
dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps the actions group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | [huggingface/doc-builder/.github/workflows/build_main_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | | [DeterminateSystems/nix-installer-action](https://github.com/determinatesystems/nix-installer-action) | `22` | `23` | | [cachix/install-nix-action](https://github.com/cachix/install-nix-action) | `31.11.0` | `31.11.1` | | [Swatinem/rust-cache](https://github.com/swatinem/rust-cache) | `2.9.1` | `2.9.2` | | [huggingface/doc-builder/.github/workflows/build_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `9.0.0` | `10.1.0` | | [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) | `1.14.1` | `1.14.2` | | [sigstore/gh-action-sigstore-python](https://github.com/sigstore/gh-action-sigstore-python) | `3.4.0` | `3.5.0` | | [huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml](https://github.com/huggingface/doc-builder) | `7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c` | `17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169` | Updates `huggingface/doc-builder/.github/workflows/build_main_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](huggingface/doc-builder@7ccf6c0...17ccdf1) Updates `DeterminateSystems/nix-installer-action` from 22 to 23 - [Release notes](https://github.com/determinatesystems/nix-installer-action/releases) - [Commits](DeterminateSystems/nix-installer-action@ef8a148...3138316) Updates `cachix/install-nix-action` from 31.11.0 to 31.11.1 - [Release notes](https://github.com/cachix/install-nix-action/releases) - [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md) - [Commits](cachix/install-nix-action@630ae54...13d8dd5) Updates `Swatinem/rust-cache` from 2.9.1 to 2.9.2 - [Release notes](https://github.com/swatinem/rust-cache/releases) - [Changelog](https://github.com/Swatinem/rust-cache/blob/master/CHANGELOG.md) - [Commits](Swatinem/rust-cache@c193711...6323deb) Updates `huggingface/doc-builder/.github/workflows/build_pr_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](huggingface/doc-builder@7ccf6c0...17ccdf1) Updates `astral-sh/setup-uv` from 9.0.0 to 10.1.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@c771a70...bec219d) Updates `pypa/gh-action-pypi-publish` from 1.14.1 to 1.14.2 - [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases) - [Commits](pypa/gh-action-pypi-publish@ba38be9...dc37677) Updates `sigstore/gh-action-sigstore-python` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/sigstore/gh-action-sigstore-python/releases) - [Changelog](https://github.com/sigstore/gh-action-sigstore-python/blob/main/CHANGELOG.md) - [Commits](sigstore/gh-action-sigstore-python@5b79a39...790bc6b) Updates `huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml` from 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 - [Release notes](https://github.com/huggingface/doc-builder/releases) - [Changelog](https://github.com/huggingface/doc-builder/blob/main/RELEASE.md) - [Commits](huggingface/doc-builder@7ccf6c0...17ccdf1) --- updated-dependencies: - dependency-name: huggingface/doc-builder/.github/workflows/build_main_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions - dependency-name: DeterminateSystems/nix-installer-action dependency-version: '23' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: cachix/install-nix-action dependency-version: 31.11.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: Swatinem/rust-cache dependency-version: 2.9.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/build_pr_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions - dependency-name: astral-sh/setup-uv dependency-version: 10.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pypa/gh-action-pypi-publish dependency-version: 1.14.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: sigstore/gh-action-sigstore-python dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions - dependency-name: huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml dependency-version: 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169 dependency-type: direct:production dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
|
The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update. |
Automated hardening of the workflow files flagged on #835. > [!WARNING] > **This narrows what the workflow can reach.** Job permissions were declared in `.github/workflows/build_kernel.yaml`, `.github/workflows/build_kernel_cpu.yaml`, `.github/workflows/build_kernel_macos.yaml`, `.github/workflows/build_kernel_rocm.yaml`, `.github/workflows/build_kernel_windows.yaml`, `.github/workflows/build_kernel_xpu.yaml`, `.github/workflows/check_variants.yaml`, `.github/workflows/lint.yml`, `.github/workflows/nix_checks.yml`, `.github/workflows/test_e2e.yaml`, `.github/workflows/test_extra_commands.yaml`, `.github/workflows/update_cache.yaml`. Each job now gets only the scopes its steps were read to need — if one of them does something this could not see, it will fail on the next run. The table below says which step drove each scope. Targets `dependabot/github_actions/actions-2436af7829`. Files changed, and what changed them: - `.github/workflows/build_kernel.yaml` — action pins; job permissions - `.github/workflows/build_kernel_cpu.yaml` — action pins; job permissions - `.github/workflows/build_kernel_macos.yaml` — job permissions - `.github/workflows/build_kernel_rocm.yaml` — action pins; job permissions - `.github/workflows/build_kernel_windows.yaml` — job permissions - `.github/workflows/build_kernel_xpu.yaml` — action pins; job permissions - `.github/workflows/check_variants.yaml` — job permissions - `.github/workflows/lint.yml` — job permissions - `.github/workflows/nix_checks.yml` — action pins; job permissions - `.github/workflows/publish_kernels.yml` — action pins - `.github/workflows/test_e2e.yaml` — action pins; job permissions - `.github/workflows/test_extra_commands.yaml` — action pins; job permissions - `.github/workflows/update_cache.yaml` — action pins; job permissions Fixed by this PR: - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel.yaml:31 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_cpu.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_rocm.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/build_kernel_xpu.yaml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/nix_checks.yml:24 - **HIGH** `unpinned-action` (pinact) — .github/workflows/publish_kernels.yml:251 - **HIGH** `unpinned-action` (pinact) — .github/workflows/publish_kernels.yml:323 - **HIGH** `unpinned-action` (pinact) — .github/workflows/test_e2e.yaml:37 - **HIGH** `unpinned-action` (pinact) — .github/workflows/test_extra_commands.yaml:23 - **HIGH** `unpinned-action` (pinact) — .github/workflows/update_cache.yaml:25 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel.yaml:69 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_cpu.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_cpu.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_macos.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_macos.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_rocm.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_rocm.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_windows.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_windows.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_xpu.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/build_kernel_xpu.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/check_variants.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/check_variants.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:35 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/lint.yml:51 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/nix_checks.yml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/nix_checks.yml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:29 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:111 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_e2e.yaml:155 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_extra_commands.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/test_extra_commands.yaml:18 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/update_cache.yaml:1 - **MEDIUM** `excessive-permissions` (zizmor) — .github/workflows/update_cache.yaml:12 **This does not fix everything.** 10 further finding(s) (2 critical, 1 high, 7 medium) need a decision this bot should not make for you. They are in the security channel with their locations — deliberately not repeated here, since this repository may be public and they are not fixed yet. ### Permissions `.github/workflows/build_documentation.yaml` > `build` was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_main_documentation.yml, whose jobs and steps are not in this file, so the token scopes it requires cannot be determined here. `.github/workflows/build_kernel.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | actions/checkout needs contents: read; the nix-installer, cachix (authenticated via a secret, not the GITHUB_TOKEN) and upload-artifact steps in the same run require no token scopes. | | `test` | `contents: read` | actions/checkout needs contents: read; download-artifact pulls an artifact produced by the build job in the same run, and the docker build/run steps use no GitHub API. | `.github/workflows/build_kernel_cpu.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer, cachix (which uses a secret, not the GITHUB_TOKEN), and the nix build/test steps make no GitHub API writes. | `.github/workflows/build_kernel_macos.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the Nix/Cachix steps and Metal build just compile code and the cachix auth token is a secret, not a token scope. | `.github/workflows/build_kernel_rocm.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix steps authenticate via a secret, not the GITHUB_TOKEN, and the nix build steps use no API access. | `.github/workflows/build_kernel_windows.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the remaining steps are CUDA/Rust/Python toolchain setup, cache actions (which use the cache service, not the token) and local compilation — note the nix-builder\scripts\windows\builder.ps1 build script is not in this file, but its invocation is a plain kernel build with no API usage. | `.github/workflows/build_kernel_xpu.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only `actions/checkout` needs the token (contents: read); the nix-installer, cachix (authenticated via a secret, not the GITHUB_TOKEN) and `nix build` steps make no GitHub API writes. | `.github/workflows/build_pr_documentation.yaml` > `build` was left as it is — This job only calls the external reusable workflow huggingface/doc-builder/.github/workflows/build_pr_documentation.yml, whose job definitions are not in this file, so the required token scopes cannot be read here. `.github/workflows/check_variants.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the remaining steps run nix evaluations, git diff, and a local script (nix-builder/scripts/gen_variants_markdown.py, whose contents aren't in this file but which only regenerates a tracked markdown file for comparison) without any API calls or pushes. | `.github/workflows/lint.yml` | job | granted | why | |---|---|---| | `lint` | `contents: read` | Only actions/checkout plus ruff-action lint/format checks that operate on local files, so contents: read is sufficient. | | `griffe` | `contents: read` | actions/checkout with fetch-depth: 0 and a local uvx griffe API-diff run against the main ref; no API writes, so contents: read. | | `validate-dependencies` | `contents: read` | actions/checkout followed by a local diff of two checked-out files needs only contents: read. | `.github/workflows/nix_checks.yml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix actions authenticate via their own inputs/secrets and the remaining steps just run `nix fmt`/`nix build` locally, so no write scopes are needed. | `.github/workflows/test_e2e.yaml` | job | granted | why | |---|---|---| | `init-build-upload` | `contents: read` | actions/checkout needs contents: read; the nix build/upload steps push artifacts to the Hugging Face Hub using HF_TOKEN, not the GitHub token, so no write scopes are required (cachix and nix-installer actions use their own secrets). | | `download-and-test` | `contents: read` | actions/checkout needs contents: read; setup-uv and dtolnay/rust-toolchain only download public tooling and the test step pulls the kernel from the HF Hub, requiring no GitHub token scopes. | | `cleanup` | `{}` — nothing | No checkout and no GitHub API use — the only step deletes Hugging Face Hub repos via huggingface_hub with HF_TOKEN, so no GITHUB_TOKEN scopes are needed (setup-uv only fetches public release assets). | `.github/workflows/test_extra_commands.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | actions/checkout needs contents: read; the nix-installer and cachix actions only fetch installers/binary caches (cachix uses its own auth token, not GITHUB_TOKEN), and the two nix run steps just build/test locally, so no write scopes are required. | `.github/workflows/test_kernels.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the test, mypy, coverage-rendering and actions/upload-artifact steps all operate on the checked-out tree within the same run, so the workflow's declared packages: write is unnecessary — the PR comment is posted by a separate downstream workflow_run workflow, not here. | `.github/workflows/update_cache.yaml` | job | granted | why | |---|---|---| | `build` | `contents: read` | Only actions/checkout needs the token (contents: read); the nix-installer and cachix steps authenticate to Cachix with a secret, not the GITHUB_TOKEN, and `nix build` just builds locally. | `.github/workflows/upload_pr_documentation.yaml` > `build` was left as it is — This job only declares `uses:` to call an external reusable workflow (huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml) that is not in this file, so its token needs cannot be read here; based on the workflow_run trigger and comment_bot_token input it likely needs at least `actions: read` to fetch the triggering run's artifacts and `pull-requests: write` to post a docs preview comment — verify against the pinned doc-builder workflow. Anything not listed above keeps the permissions it had. To measure a job this could not read, add [`GitHubSecurityLab/actions-permissions/monitor`](https://github.com/GitHubSecurityLab/actions-permissions) to it and run the workflow — it reports the minimum the run actually used. Pinning changes come from `pinact` and are mechanical. Any other change was generated by Claude — read it before merging. <!--slack ts:1789951225.673349 channel:C0AJSP0D53L--> Co-authored-by: hf-security-analysis[bot] <265538906+hf-security-analysis[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 9 updates in the / directory:
7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169222331.11.031.11.12.9.12.9.27ccf6c02dc2e3aea1b07f6668f783b20c3bf407c17ccdf17e0f5e5f88b1ce9f20b3b73fb190171699.0.010.1.01.14.11.14.23.4.03.5.07ccf6c02dc2e3aea1b07f6668f783b20c3bf407c17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169Updates
huggingface/doc-builder/.github/workflows/build_main_documentation.ymlfrom 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169Changelog
Sourced from huggingface/doc-builder/.github/workflows/build_main_documentation.yml's changelog.
Commits
17ccdf1chore: enable Dependabot weekly GitHub Actions bumps (#790)47c6b58fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)cf20b09Revert "Comment out schedule for search engine population (#826)" (#827)9978a41Comment out schedule for search engine population (#826)c2d27f6Fix vectorless Meilisearch document payload (#825)953aa44Add vectorless full-text docs ingestion (#824)1b16dacRemove setup.py in favor of pyproject.toml (#816)bcd143eCheck anchors in links (#820)68667a5fix(kit): accept a lowercase region in language codes (pt-br) (#823)0ab9ea0Ship a pre-commit hook for doc-builder style (#818)Updates
DeterminateSystems/nix-installer-actionfrom 22 to 23Release notes
Sourced from DeterminateSystems/nix-installer-action's releases.
Commits
3138316Merge pull request #293 from detsys-pr-bot/detsys-ts-update-v2.1.33fdd02cUpdatedetsys-tstov2.1.3(99d5b05518240632c090b3c3093be30cac088e8c)042796dMerge pull request #292 from DeterminateSystems/otel-standard-exception-recor...62cd733regena88c0c3telemetry: record an exception the way OpenTelemetry doesa43a456telemetry: put the build counts in the detsys namespace9afbed4telemetry: a caught error is an exception on the spanb073798telemetry: a fact about the run is an attribute, not an eventbded454Merge pull request #291 from DeterminateSystems/grahamc/cleanup-install-events503d68aRegenerateUpdates
cachix/install-nix-actionfrom 31.11.0 to 31.11.1Release notes
Sourced from cachix/install-nix-action's releases.
Commits
13d8dd5fix(ci): skip latest installer on x86_64-darwin875018fMerge pull request #281 from cachix/create-pull-request/patch6624a11nix: 2.35.1 -> 2.35.2Updates
Swatinem/rust-cachefrom 2.9.1 to 2.9.2Release notes
Sourced from Swatinem/rust-cache's releases.
Changelog
Sourced from Swatinem/rust-cache's changelog.
... (truncated)
Commits
6323deb2.9.2b16e8d7bump rollup and rebuild3bf42acinvert target/profile check in cleanup6e5b278correctly sort and dedupe Rust versions5adc05fBump the actions group across 1 directory with 3 updates (#368)66b1e95fix: support Cargo V2 build dir layout (#371)72d126eMerge pull request #367 from Swatinem/dependabot/npm_and_yarn/dev-patch-2b495...48968d2Bump the dev-patch group with 2 updates9f151acupdate dependencies, rebuild0e24e5dBump the actions group across 1 directory with 6 updates (#364)Updates
huggingface/doc-builder/.github/workflows/build_pr_documentation.ymlfrom 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169Changelog
Sourced from huggingface/doc-builder/.github/workflows/build_pr_documentation.yml's changelog.
Commits
17ccdf1chore: enable Dependabot weekly GitHub Actions bumps (#790)47c6b58fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)cf20b09Revert "Comment out schedule for search engine population (#826)" (#827)9978a41Comment out schedule for search engine population (#826)c2d27f6Fix vectorless Meilisearch document payload (#825)953aa44Add vectorless full-text docs ingestion (#824)1b16dacRemove setup.py in favor of pyproject.toml (#816)bcd143eCheck anchors in links (#820)68667a5fix(kit): accept a lowercase region in language codes (pt-br) (#823)0ab9ea0Ship a pre-commit hook for doc-builder style (#818)Updates
astral-sh/setup-uvfrom 9.0.0 to 10.1.0Release notes
Sourced from astral-sh/setup-uv's releases.
... (truncated)
Commits
bec219dchore(deps-dev): roll up Dependabot updates (#1043)b90ec40fix: respect no proxy directive (#1037)421feb6chore: update known checksums for 0.12.12 (#1041)f634bf4Expose a Python "identity" output (#1036)a6772c8chore: update known checksums for 0.12.10/0.12.11 (#1038)e105c8fchore: update known checksums for 0.12.9 (#1035)cd13f92Verify downloads with astral-sh/versions checksums (#1033)3aef7b9chore: update known checksums for 0.12.7/0.12.8 (#1031)d08d816chore: update known checksums for 0.12.6 (#1030)19b4d1eHarden npm install defaults (#1026)Updates
pypa/gh-action-pypi-publishfrom 1.14.1 to 1.14.2Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
... (truncated)
Commits
dc37677Merge pull request #417 from trail-of-forks/ft/bump-deps8b2f234Bumppypi-attestationsandsigstore78b72dbMerge pull request #416 from takluyver/twine-v792f4d2aUpdate twine to v7Updates
sigstore/gh-action-sigstore-pythonfrom 3.4.0 to 3.5.0Release notes
Sourced from sigstore/gh-action-sigstore-python's releases.
Commits
790bc6bbuild(deps): bump github/codeql-action/upload-sarif in the actions group (#445)513a149build(deps): bump platformdirs in the python-dependencies group (#446)74e0040Bump sigstore from 4.4 to 4.5 (#444)52538fdbuild(deps): bump the actions group across 1 directory with 4 updates (#439)cbab91dbuild(deps): bump the python-dependencies group across 1 directory with 9 upd...1d3524cbuild(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 in the acti...a174484build(deps): bump sigstore from 4.3.0 to 4.4.0 in the python-dependencies gro...0b384a6build(deps): bump the actions group with 2 updates (#429)f11d8f8build(deps): bump typing-extensions in the python-dependencies group (#430)258577bbuild(deps): bump the python-dependencies group with 2 updates (#428)Updates
huggingface/doc-builder/.github/workflows/upload_pr_documentation.ymlfrom 7ccf6c02dc2e3aea1b07f6668f783b20c3bf407c to 17ccdf17e0f5e5f88b1ce9f20b3b73fb19017169Changelog
Sourced from huggingface/doc-builder/.github/workflows/upload_pr_documentation.yml's changelog.
Commits
17ccdf1chore: enable Dependabot weekly GitHub Actions bumps (#790)47c6b58fix(ci): pin the doc-builder checkout to the caller's pinned revision (#830)cf20b09Revert "Comment out schedule for search engine population (#826)" (#827)9978a41Comment out schedule for search engine population (#826)c2d27f6Fix vectorless Meilisearch document payload (#825)953aa44Add vectorless full-text docs ingestion (#824)1b16dacRemove setup.py in favor of pyproject.toml (#816)bcd143eCheck anchors in links (#820)68667a5fix(kit): accept a lowercase region in language codes (pt-br) (#823)0ab9ea0Ship a pre-commit hook for doc-builder style (#818)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions