chore(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 - #376
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.2 to 3.0.3. - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@3d0d988...efb3536) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: 3.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
tsforge | 9bb551b | Commit Preview URL Branch Preview URL |
Sep 04 2026, 01:07 AM |
agjs
added a commit
that referenced
this pull request
Sep 25, 2026
Dependency bumps (dependabot #376 #379 #380 #381 #384 #387 #389 #390 #391 #392 #393 #394): wrangler 4.131.2, astro 7.3.2, mermaid 12.0.0, sharp 0.35.4, bun-types 1.4.2, @astrojs/starlight 0.42.0, globals 17.12.0, eslint 10.10.0 + typescript-eslint 8.69.0, @astrojs/react 6.0.5, @astrojs/sitemap 3.7.4, softprops/action-gh-release 3.0.3. - Starlight 0.42 (via @astrojs/mdx 8) needs the @astrojs/markdown-remark ^7.3.0 peer; added to the docs app (the docs build failed without it). - typescript-eslint 8.69 flags `void _drop;` as a meaningless void; removed (the `_` prefix + rest-sibling destructuring already silence unused-var). Security scans - osv: every accepted-risk entry had expired (2026-09-12) and no longer matched; the 8 open advisories were all fixable, so patched versions are pinned via overrides (devalue, js-yaml, lodash-es, smol-toml, svgo, valibot) and the dead allowlist is emptied. osv-scanner: no issues. - gitleaks: allowlist the Chrome extension manifest — its "key" is the extension's PUBLIC key (pins the ID the bridge accepts), not a secret.
agjs
added a commit
that referenced
this pull request
Sep 25, 2026
…eaking into non-code sessions (#395) * docs(spec): chrome research bridge design * feat(browser): research in the user's logged-in Chrome + stop coding-mode leaking into non-code sessions Chrome research bridge - New MV3 extension (packages/chrome-extension) connected to tsforge over a token- and Origin-checked localhost WebSocket (chrome-bridge subsystem). - browser_* tools: tabs, adopt, open, navigate, read (chunked markdown with numbered refs), click, scroll, screenshot, close; agent tabs live in a "tsforge" tab group. Read + navigate only, enforced in the extension: default-deny click policy re-checked on the live element at click time, group-scoped tabs, http(s)-only navigation, private hosts blocked. - note tool: append-only notes/<topic>.md, outside the code write-guard. - TSFORGE_BROWSER / _PORT / _ALLOW_PRIVATE, /browser, /config toggle, docs. Non-code sessions no longer get the TypeScript build machinery - Auto gate stays dormant until the folder has JS/TS code, then wakes; while dormant: assistant prompt, no check/pull_conventions, no gate runs/nudges. - ESLint with nothing to lint passes (--no-error-on-unmatched-pattern). - Research reads count as progress for readonly-spin without a live gate. - task_complete works without a gate (marked not gate-checked). - Folders with no code start in normal mode, not plan-first. - Repetition re-steer, checklist rules and /gate "" follow the gate state. - Assistant prompt no longer opens as a TypeScript engineer. * chore(deps): fold open dependabot bumps; fix security scans Dependency bumps (dependabot #376 #379 #380 #381 #384 #387 #389 #390 #391 #392 #393 #394): wrangler 4.131.2, astro 7.3.2, mermaid 12.0.0, sharp 0.35.4, bun-types 1.4.2, @astrojs/starlight 0.42.0, globals 17.12.0, eslint 10.10.0 + typescript-eslint 8.69.0, @astrojs/react 6.0.5, @astrojs/sitemap 3.7.4, softprops/action-gh-release 3.0.3. - Starlight 0.42 (via @astrojs/mdx 8) needs the @astrojs/markdown-remark ^7.3.0 peer; added to the docs app (the docs build failed without it). - typescript-eslint 8.69 flags `void _drop;` as a meaningless void; removed (the `_` prefix + rest-sibling destructuring already silence unused-var). Security scans - osv: every accepted-risk entry had expired (2026-09-12) and no longer matched; the 8 open advisories were all fixable, so patched versions are pinned via overrides (devalue, js-yaml, lodash-es, smol-toml, svgo, valibot) and the dead allowlist is emptied. osv-scanner: no issues. - gitleaks: allowlist the Chrome extension manifest — its "key" is the extension's PUBLIC key (pins the ID the bridge accepts), not a secret. * test(f19): give the cold write-guard tests a real timeout The write-guard and end-to-end F19 tests each build a fresh TypeScript program + ESLint engine for a new plugin workspace: ~1s locally, 2s under CI=true, and 5s+ on a shared GitHub runner, where they hit bun's default 5s timeout. The late rejection then surfaced as a misleading "expected promise that rejects" — the drift IS detected (all six pass under CI=true with a longer timeout). They are correctness tests, not perf budgets: 30s, matching the explicit timeouts other heavy tests in the suite already use.
Contributor
Author
|
Looks like softprops/action-gh-release is up-to-date now, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/github_actions/softprops/action-gh-release-3.0.3
branch
September 25, 2026 19:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps softprops/action-gh-release from 3.0.2 to 3.0.3.
Release notes
Sourced from softprops/action-gh-release's releases.
Changelog
Sourced from softprops/action-gh-release's changelog.
... (truncated)
Commits
efb3536release 3.0.3 (#840)6441963chore(deps): bump the npm group with 2 updates (#839)e5ee6bcchore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)d1e6617chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)6403751chore(deps): bump the npm group with 2 updates (#835)7c7184bchore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)0f3f0d2chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)77fb938chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)5a6f517chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)a3c91c9chore(deps): bump the github-actions group with 2 updates (#825)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)