Skip to content

Bump softprops/action-gh-release from 3.0.0 to 3.0.2 - #11

Closed
dependabot[bot] wants to merge 37 commits into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3.0.2
Closed

Bump softprops/action-gh-release from 3.0.0 to 3.0.2#11
dependabot[bot] wants to merge 37 commits into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown

Bumps softprops/action-gh-release from 3.0.0 to 3.0.2.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

v3.0.1

3.0.1

  • maintenance release with updated dependencies
Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. v2.6.2 was the final Node 20-compatible release and is no longer maintained or supported.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; freeze v2 at the final v2.6.2 release

... (truncated)

Commits
  • 3d0d988 release 3.0.2 (#818)
  • 7e13ed4 fix: clarify release creation 404 errors (#817)
  • e6c70a5 fix: replace existing release assets on Gitea (#816)
  • f345337 fix: publish existing draft releases as prereleases (#801)
  • d8a89a2 fix: upload small checksum assets reliably (#815)
  • 45ece40 chore(deps): remove unused TypeScript tooling (#814)
  • f6b913c feat: improve release error reporting and test coverage (#813)
  • 15f193d chore(deps): upgrade TypeScript to 7 (#812)
  • cc8268d chore(deps): bump actions/checkout in the github-actions group (#810)
  • fd0ed1e chore(deps): bump the npm group with 3 updates (#811)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

radhermit added 30 commits June 10, 2026 23:40
So the header subdir used for the `install-headers` target is scallop
otherwise it would overlap with the regular bash package when plugin
support is enabled (which installs the headers).

Also, this changes $PACKAGE_VERSION to the X.Y.Z.DATE format used by scallop.
And rename main() to bash_main() in order to use it externally when
library support is enabled.
Previously when building libraries for scallop, the configure target
would trigger autoconf to be run unnecessarily as the bundled configure
script should up-to-date.
…Level

This makes deferred vs immediate expansion work as expected for other
variables using $(PatchLevel).
That allows external code to register builtins internally instead of
always having to using dynamic loading.
With the builtin being used if it exists instead of the function.
Bash uses an extensive amount of global state and when used as a library
init/reset actions are required for regular operation.
Without this both leak their underlying array data whenever lib_reset()
is called.
Bash uses setjmp/longjmp for error, interrupt, and signal handling cases and
thus initializes jump targets in main() which doesn't get called when
used as a library.

Adding jump targets in the main entry points (sourcing and execution)
allows returning proper error codes during library operation and avoids
issues with unwinding across rust frames (which is currently UB and
generally causes segfaults) when using scallop rust support.

Without this, a segfault occurs if a file with errors is sourced under
library usage and `set -e` enabled since no top level jump target is set
and parse_and_execute() tries to longjmp to a NULL target.

Note that the call stack is tracked from scallop so reentrant calls jump
back to where they entered and not the initial call's entry point.
Instead of always dumping them into stderr.
Used via external library to inject errors into bash across process
boundaries (e.g. erroring out from subshells).
Installing a SIGCHLD handler by default breaks pkgcraft unit tests that
spawn child processes and use wait() or waitpid() to wait for
completion, e.g. tests for builtins such as `econf`.

When enabled by default the tests fail with ECHILD (errno 10) when
trying to wait on child processes since the installed signal handler
gets control instead during child termination.
That allows easily reverting set_var_read_only() settings when toggling
restricted mode.
Without this the process environment isn't inherited and the bash
initialization methods unset everything.
Instead of raising an error. The exit status of the command should be
enough to signify failure.

This avoids the issue where `declare -p UNDEFINED_VAR` is being used to
determine if a variable is defined causing errors when sourcing the
related file or string.
… exec

This allows externally registered special builtins to always override
functions even when bash isn't built with strict posix mode enabled.

This will also have the affect that special builtins native to bash,
e.g. exit and source (see the full list via `enable -s`), won't be able
to be overridden by functions which in our case shouldn't matter and
probably is a good thing anyway.
These should be used externally to build with the options required by
scallop otherwise it's unsupported when used for pkgcraft.
radhermit and others added 7 commits June 10, 2026 23:45
This makes the option name handling match get_minus_o_opts() in the
`set` builtin and is what the the only usage for get_shopt_options() in
pcomplete.c expects as it explicitly doesn't free the list members the
same as it does for the set options list.
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.0 to 3.0.2.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@b430933...3d0d988)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 13, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 8, 2026

Copy link
Copy Markdown
Author

Looks like softprops/action-gh-release is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 8, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/softprops/action-gh-release-3.0.2 branch August 8, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant