Skip to content

chore(deps): bump softprops/action-gh-release from 3.0.2 to 3.0.3 - #376

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3.0.3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3.0.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Bumps softprops/action-gh-release from 3.0.2 to 3.0.3.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates
Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

... (truncated)

Commits
  • efb3536 release 3.0.3 (#840)
  • 6441963 chore(deps): bump the npm group with 2 updates (#839)
  • e5ee6bc chore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)
  • d1e6617 chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)
  • 6403751 chore(deps): bump the npm group with 2 updates (#835)
  • 7c7184b chore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)
  • 0f3f0d2 chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)
  • 77fb938 chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)
  • 5a6f517 chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)
  • a3c91c9 chore(deps): bump the github-actions group with 2 updates (#825)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.2 to 3.0.3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@3d0d988...efb3536)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 4, 2026
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
tsforge 9bb551b Commit Preview URL

Branch Preview URL
Sep 04 2026, 01:07 AM

agjs added a commit that referenced this pull request Sep 25, 2026
Dependency bumps (dependabot #376 #379 #380 #381 #384 #387 #389 #390 #391
#392 #393 #394): wrangler 4.131.2, astro 7.3.2, mermaid 12.0.0, sharp
0.35.4, bun-types 1.4.2, @astrojs/starlight 0.42.0, globals 17.12.0,
eslint 10.10.0 + typescript-eslint 8.69.0, @astrojs/react 6.0.5,
@astrojs/sitemap 3.7.4, softprops/action-gh-release 3.0.3.
- Starlight 0.42 (via @astrojs/mdx 8) needs the @astrojs/markdown-remark
  ^7.3.0 peer; added to the docs app (the docs build failed without it).
- typescript-eslint 8.69 flags `void _drop;` as a meaningless void; removed
  (the `_` prefix + rest-sibling destructuring already silence unused-var).

Security scans
- osv: every accepted-risk entry had expired (2026-09-12) and no longer
  matched; the 8 open advisories were all fixable, so patched versions are
  pinned via overrides (devalue, js-yaml, lodash-es, smol-toml, svgo,
  valibot) and the dead allowlist is emptied. osv-scanner: no issues.
- gitleaks: allowlist the Chrome extension manifest — its "key" is the
  extension's PUBLIC key (pins the ID the bridge accepts), not a secret.
agjs added a commit that referenced this pull request Sep 25, 2026
…eaking into non-code sessions (#395)

* docs(spec): chrome research bridge design

* feat(browser): research in the user's logged-in Chrome + stop coding-mode leaking into non-code sessions

Chrome research bridge
- New MV3 extension (packages/chrome-extension) connected to tsforge over a
  token- and Origin-checked localhost WebSocket (chrome-bridge subsystem).
- browser_* tools: tabs, adopt, open, navigate, read (chunked markdown with
  numbered refs), click, scroll, screenshot, close; agent tabs live in a
  "tsforge" tab group. Read + navigate only, enforced in the extension:
  default-deny click policy re-checked on the live element at click time,
  group-scoped tabs, http(s)-only navigation, private hosts blocked.
- note tool: append-only notes/<topic>.md, outside the code write-guard.
- TSFORGE_BROWSER / _PORT / _ALLOW_PRIVATE, /browser, /config toggle, docs.

Non-code sessions no longer get the TypeScript build machinery
- Auto gate stays dormant until the folder has JS/TS code, then wakes; while
  dormant: assistant prompt, no check/pull_conventions, no gate runs/nudges.
- ESLint with nothing to lint passes (--no-error-on-unmatched-pattern).
- Research reads count as progress for readonly-spin without a live gate.
- task_complete works without a gate (marked not gate-checked).
- Folders with no code start in normal mode, not plan-first.
- Repetition re-steer, checklist rules and /gate "" follow the gate state.
- Assistant prompt no longer opens as a TypeScript engineer.

* chore(deps): fold open dependabot bumps; fix security scans

Dependency bumps (dependabot #376 #379 #380 #381 #384 #387 #389 #390 #391
#392 #393 #394): wrangler 4.131.2, astro 7.3.2, mermaid 12.0.0, sharp
0.35.4, bun-types 1.4.2, @astrojs/starlight 0.42.0, globals 17.12.0,
eslint 10.10.0 + typescript-eslint 8.69.0, @astrojs/react 6.0.5,
@astrojs/sitemap 3.7.4, softprops/action-gh-release 3.0.3.
- Starlight 0.42 (via @astrojs/mdx 8) needs the @astrojs/markdown-remark
  ^7.3.0 peer; added to the docs app (the docs build failed without it).
- typescript-eslint 8.69 flags `void _drop;` as a meaningless void; removed
  (the `_` prefix + rest-sibling destructuring already silence unused-var).

Security scans
- osv: every accepted-risk entry had expired (2026-09-12) and no longer
  matched; the 8 open advisories were all fixable, so patched versions are
  pinned via overrides (devalue, js-yaml, lodash-es, smol-toml, svgo,
  valibot) and the dead allowlist is emptied. osv-scanner: no issues.
- gitleaks: allowlist the Chrome extension manifest — its "key" is the
  extension's PUBLIC key (pins the ID the bridge accepts), not a secret.

* test(f19): give the cold write-guard tests a real timeout

The write-guard and end-to-end F19 tests each build a fresh TypeScript
program + ESLint engine for a new plugin workspace: ~1s locally, 2s under
CI=true, and 5s+ on a shared GitHub runner, where they hit bun's default 5s
timeout. The late rejection then surfaced as a misleading "expected promise
that rejects" — the drift IS detected (all six pass under CI=true with a
longer timeout). They are correctness tests, not perf budgets: 30s, matching
the explicit timeouts other heavy tests in the suite already use.
@dependabot @github

dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

Looks like softprops/action-gh-release is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 25, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/softprops/action-gh-release-3.0.3 branch September 25, 2026 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants