chore(deps): update github actions - #4458
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
renovate
Bot
force-pushed
the
renovate/github-actions
branch
3 times, most recently
from
August 25, 2026 13:17
047a56f to
a93f2b8
Compare
gabemontero
approved these changes
Aug 25, 2026
gabemontero
left a comment
Contributor
There was a problem hiding this comment.
approve for the fullsend piece
renovate
Bot
force-pushed
the
renovate/github-actions
branch
13 times, most recently
from
August 27, 2026 21:51
9ba2882 to
433bffa
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate
Bot
force-pushed
the
renovate/github-actions
branch
from
August 27, 2026 22:00
433bffa to
e597135
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR contains the following updates:
v0.32.0→v0.37.0v2.20.0→v2.21.0v1.2.4→v1.4.1Release Notes
fullsend-ai/fullsend (fullsend-ai/fullsend)
v0.37.0Compare Source
Changelog
Features
4f8823e: feat(#1050): implement validation loop feedback_mode (@fullsend-ai-coder[bot])1ad8c27: feat(#3697): add emoji reaction status notifications (@ralphbean)901cc0a: feat(#5110): add native Workers rate limits for CF mint (@fullsend-ai-coder[bot])d21c659: feat(#582): support exit code 78 as neutral pre-script skip (@fullsend-ai-coder[bot])4f42e9d: feat(#5880): add GitHub OAuth2 status auth for GET /v1/status (@fullsend-ai-coder[bot])c202c0b: feat(#5970): add providers and openshell to ForgeConfig (@fullsend-ai-coder[bot])268e876: feat(#5989): add Jira comment create/update support (@ralphbean)45afcdb: feat(#5989): add markdown<->ADF conversion for Jira (@ralphbean)82ecebd: feat(#5989): add tracker.Client implementation backed by Jira (@ralphbean)1f4ccce: feat(#5991): add fullsend issues get/post-comment commands (@fullsend-ai-coder[bot])cbc21c9: feat(#6002): add --signoff flag to github setup command (@fullsend-ai-coder[bot])fb6b942: feat(#6077): split GitLab poller into independent slash and event schedules (@ggallen)5d908d6: feat(#608): diagnose un-normalized tool names in allowlist hook (@waynesun09)71893fb: feat(#6133): add custom domain and managed WAF support for CF mint (@fullsend-ai-coder[bot])33d1e26: feat(#6158): add SkillEntry type for file-level skill overrides (@ggallen)bf9e437: feat(#6176): add fullsend_ref support to GitLab forge infrastructure (@ggallen)8fb75b0: feat(#6188): add effort field for per-agent reasoning effort control (@fullsend-ai-coder[bot])e57c3a9: feat(#6193): add author-fullsend-augmentations skill and BYOA docs (@ascerra)91ebe5c: feat(#6193): add skill for authoring augmentation skills (@fullsend-ai-coder[bot])2be309d: feat(#6198): surface unresolved thread details and add --resolve-threads (@fullsend-ai-coder[bot])e878f40: feat(#6222): add credential mode model (wif/oidc/token) to repos commands (@ggallen)37f9592: feat(#6238): show short SHA with expected ref in repos status (@ggallen)6b1cfd4: feat(#6240): add --forge and --base-url flags to post-review (@ggallen)03e09bc: feat(#6256): default hosted mint URL to mint.fullsend.sh (@fullsend-ai-coder[bot])df491ae: feat(#6257): remove credential mode, add mint_mode to manifest (@ggallen)625b51d: feat(#6269): derive inference project number in repos install (@fullsend-ai-coder[bot])41bcc3f: feat(#6334): add openshell provider and profile for Jira (@fullsend-ai-coder[bot])80a366f: feat(#6339): replace jira-poll HarnessRouter with CEL trigger evaluation (@fullsend-ai-coder[bot])324c7b5: feat(#6346): simplify repos.yaml manifest format (@ggallen)7905677: feat(#6347): add pre-computed matrix input to reusable-dispatch (@ralphbean)1ca0939: feat(#6445): install fullsend CLI at runtime in GitLab CI (@ggallen)7229878: feat(#6464): enable the pi runtime (@waynesun09)4619aa3: feat(#6464): run pi at --thinking high unless the harness sets an effort (@waynesun09)2ee0540: feat(#6464): show the runtime choice on the landing hero (@waynesun09)e63124e: feat(#6487): report component-level detail in dry-run output (@fullsend-ai-coder[bot])6cb77a3: feat(#6522): ship the ORT-enabled scanner in the runner image (@waynesun09)3051a65: feat(#6526): choose the runtime at setup (@waynesun09)1e4abb2: feat(#6526): pass FULLSEND_* run overrides from repository variables into CI runs (@waynesun09)dff4d14: feat(#6526): per-run runtime/model/effort overrides resolved once by the CLI (@waynesun09)72c8121: feat(#6526): pi run env for Gemini on Vertex and a deliberate sub-agent fallback (@waynesun09)6719f4a: feat(#6526): runtime in repos.yaml and fullsend repos install --runtime (@waynesun09)314c667: feat(#6526): surface runtime and model in run plan, status comment, OTel, metrics, and docs (@fullsend-ai-coder[bot])c788f50: feat(#6571): add xai-vertex provider to the pi runtime (@fullsend-ai-coder[bot])eabf15f: feat(config): add SetStatusNotifications setter and behaviourtest reaction support (@fullsend-ai-coder[bot])06cb1ee: feat(eval): add eval measurements and EM-001 trace_fitness scorer (@ascerra)6a3da63: feat(harness): implement CEL-guarded overlays (ADR 0088) (@ralphbean)5c5b322: feat(mint): add --zone-id and --custom-domain CLI flags for CF mint (@fullsend-ai-coder[bot])ab315fd: feat(mint): add opt-in scribe agent role (@ascerra)5625403: feat(security): detect and flag secrets in failed tool calls (@waynesun09)61160a4: feat: add Jira secrets and variables to reusable-dispatch (@ralphbean)ebaa21f: feat: gate agents tag on functional test validation (@maruiz93)05f9eef: feat: keep the GitLab mention to the landing hero (@waynesun09)834dadc: feat: say GitHub and GitLab on the landing page (@waynesun09)Bug Fixes
f8504c3: fix(#1158): zero PEM block and RSA key internals after JWT signing (@fullsend-ai-coder[bot])2137bff: fix(#2682): harden OpenShell SHA update script and doc it in images/README (@ralphbean)7b180e7: fix(#3697): address review feedback on reaction notifications (@ralphbean)0e4f1c4: fix(#3697): target the triggering comment for slash-command reactions (@ralphbean)897dd84: fix(#3697): wire status-comment-id through all reusable workflows (@ralphbean)280af01: fix(#5221): address behaviour artifact redaction security review (@ifireball)fd7ebc3: fix(#5221): always stub binary behaviour artifact files (@ifireball)5e704d1: fix(#5221): harden behaviour artifact redaction per review (@ifireball)ffb6273: fix(#5221): harden literal redaction and workflow log sanitization (@ifireball)2385e35: fix(#5221): redact behaviour debug artifacts before upload (@ifireball)b8b9cf5: fix(#5221): register redaction scripts in vendored defaults manifest (@ifireball)c4d8de3: fix(#5221): widen Bearer/token redaction pattern (@ifireball)f9243e6: fix(#5361): align the span-status cap with the transcript-error precedent (@dhshah13)d00f63c: fix(#5361): bound exception events and sanitize the transcript console line (@dhshah13)4eeb78a: fix(#5361): bound the subtype fallback and cap span attribute values (@dhshah13)3ad7f21: fix(#5361): bound the transcript status within the cap and close the sandbox-status gap (@dhshah13)f9d2d3d: fix(#5361): break colon runs to a fixed point and unify the 8192 bounds (@dhshah13)8ffcdf7: fix(#5361): classify error text under ADR 0050 and make span-limit tests hermetic (@dhshah13)5724f27: fix(#5361): give RecordError the same UTF-8 guarantee as status descriptions (@dhshah13)57e6df0: fix(#5361): honor an explicit unlimited attribute limit and drop the unused wrapper (@dhshah13)2adba57: fix(#5361): mirror the SDK's span-limit env precedence and pin every span finalizer (@dhshah13)3e1ac84: fix(#5361): repair free-text attribute values at the source and state the SDK's units (@dhshah13)de2e5d9: fix(#5361): sanitize transcript status text and validate UTF-8 unconditionally (@dhshah13)f143e56: fix(#5361): set span status from run outcome, not runErr alone (@dhshah13)8691666: fix(#5388): write FULLSEND_REVIEW_CLIENT_ID during per-repo install (@ggallen)1edb4fb: fix(#5536): use is_bot for bot-author detection in fix eligibility (@ggallen)b886e96: fix(#5537): remove duplicate token/cost attributes from root span (@rh-hemartin)dde47ff: fix(#5598): address review round 2 (@shairevivo)28c56c8: fix(#5598): address review — complete mint/repos cross-refs, fix heading (@shairevivo)957c8a7: fix(#5774): document ErrNonFastForward broader use and update log message (@fullsend-ai-coder[bot])0298733: fix(#5774): retry commitFiles on stale tree SHA 422 (@fullsend-ai-coder[bot])efc4820: fix(#582): add deleted-file test and versioning note for exit 78 (@maruiz93)aa8acd4: fix(#582): sanitize stdout-derived skip reasons and update docs (@maruiz93)a0e7a02: fix(#582): truncate stdout reason at rune boundary and update cli-internals (@maruiz93)5331e33: fix(#5989): add jira.ADFToMarkdown and use it for tracker.Body (@ralphbean)22e3027: fix(#5989): address more review feedback on PR #5996 (@ralphbean)e81ff80: fix(#5989): address review feedback on PR #5996 (@fullsend-ai-coder[bot])883e6bd: fix(#5989): attribute edited Jira comments to the editor, not the author (@ralphbean)bd46600: fix(#5989): bound MarkdownToADF recursion depth (@ralphbean)c6168f7: fix(#5989): clarify that tracker.Comment.Author is display-name only (@ralphbean)7e932b2: fix(#5989): dedupe same-type marks in nested emphasis conversion (@ralphbean)898a368: fix(#5989): fail closed on empty or oversized MarkdownToADF output (@ralphbean)63bd8eb: fix(#5989): handle empty codeBlock and escape markdown chars in ADFToMarkdown (@fullsend-ai-coder[bot])b6d361f: fix(#5989): harden MarkdownToADF against DoS, invalid ADF, and unsafe links (@ralphbean)bb25875: fix(#5989): make JiraClient.CreateComment return plain-text Body (@ralphbean)ad81681: fix(#5989): reject credential-bearing Jira base URLs in tracker.JiraClient (@ralphbean)ad8d321: fix(#5989): reject protocol-relative URLs as unsafe link hrefs (@ralphbean)acf9221: fix(#5989): require Updated after Created before trusting UpdateAuthor (@ralphbean)51f9522: fix(#5989): stop link mark from leaking to sibling inline text (@ralphbean)394b193: fix(#5991): address remaining review findings for issues commands (@fullsend-ai-coder[bot])c16d78e: fix(#5991): improve test coverage for issues get/post-comment commands (@fullsend-ai-coder[bot])372f4e6: fix(#5991): require jira email, cap markdown size, add config-default tracker (@ralphbean)3821964: fix(#6002): strip angle brackets from name in FormatSignOffTrailer (@fullsend-ai-coder[bot])34cb1fd: fix(#6052): raise HTTP timeout to 60s and retry on timeouts (@fullsend-ai-coder[bot])b27be69: fix(#6105): retry GetFileContent on 404 in post-install validation (@fullsend-ai-coder[bot])541a406: fix(#6122): write variables and secrets before committing scaffold (@ggallen)689a596: fix(#6125): delete leaked repo-level FULLSEND_MINT_URL in e2e cleanup (@ggallen)9ca45ef: fix(#6165): tighten auth_header redactor pattern to prevent JSON corruption (@fullsend-ai-coder[bot])87848b4: fix(#6178): bump actions/cache to v6.1.0, add actions:write to harness-dispatch (@rh-hemartin)4dd632d: fix(#6180): retry WIF provider operations on HTTP 429 (@fullsend-ai-coder[bot])927cf93: fix(#6185): hardcode canonical mint URL in repos migrate (@ggallen)bb94b82: fix(#6190): use manifest fullsend_ref over binary version (@ggallen)8e148ff: fix(#6196): authenticate lookupAppID with env token when available (@fullsend-ai-coder[bot])7688cb2: fix(#6201): detect merge-queue membership regardless of labels (@fullsend-ai-coder[bot])50ee712: fix(#6204): use PER_REPO_WIF_REPOS=* for GCP public mint mode (@fullsend-ai-coder[bot])e8bb6d0: fix(#6205): strip [bot] suffix from bot-login constants in nextwork.py (@fullsend-ai-coder[bot])44d4605: fix(#6211)!: reject unknown fields in manifest YAML sections (@fullsend-ai-coder[bot])4902c63: fix(#6213): resolve floating refs to SHAs in upgrade path (@ggallen)34fcd26: fix(#6219): address review feedback on upgrade ref resolution (@fullsend-ai-coder[bot])615024f: fix(#6219): address review feedback — DryRun fallback parity and doc update (@fullsend-ai-coder[bot])89e2bd4: fix(#6219): resolve floating refs to SHAs in upgrade path (@fullsend-ai-coder[bot])5412d07: fix(#6246)!: preserve SHA pinning only for already-pinned repos during upgrade (@ggallen)150f0d7: fix(#6266): skip non-source artifacts in lint-mint-embed-sync (@fullsend-ai-coder[bot])8a3d3e4: fix(#6273): add CODE_ALLOWED_TARGET_BRANCHES to GitLab agent template (@fullsend-ai-coder[bot])49a36bc: fix(#6288): fetch forge resources only for the active platform (@fullsend-ai-coder[bot])dba61b0: fix(#6323): skip fullsend_ref drift when symbolic refs match (@fullsend-ai-coder[bot])cc86fb5: fix(#6331): address review feedback on PR #6332 (@fullsend-ai-coder[bot])f23ef74: fix(#6331): merge with existing manifest in repos migrate (@fullsend-ai-coder[bot])0bb84fd: fix(#6334): address review feedback on PR #6335 (@fullsend-ai-coder[bot])ec6fef1: fix(#6337): add SHA ancestry check to upgrade downgrade guard (@fullsend-ai-coder[bot])a75b353: fix(#6341): use manifest fullsend_ref in repos migrate scaffold (@fullsend-ai-coder[bot])346fc6c: fix(#6344): fix GitLab review agent status comments, URL resolution, token source, and prior review (@ggallen)0445dc1: fix(#6347): correct harness-dispatch and harness-run job dependencies (@ralphbean)abef3cf: fix(#6347): validate event_action in harness-dispatch, remove unused route dependency (@ralphbean)9175bf4: fix(#6348): preserve file extension in fetchBaseFile cache paths (@ggallen)574bc1e: fix(#6357): close canary bypasses in the PostToolUse chain (@waynesun09)d2df43f: fix(#6357): drop env-based sanitizer skip and cover Bash object stages (@waynesun09)e3eb507: fix(#6357): make PostToolUse sanitizers honor Claude Code's hook contract (@waynesun09)e75a0d9: fix(#6357): scan all PostToolUse fields and fold canary into the chain (@waynesun09)8cefbfa: fix(#6358): load sandbox hook settings via --settings flag (@waynesun09)e795e0e: fix(#6374): classify needs-breakdown, needs-design, and workflow-blocked issues (@fullsend-ai-coder[bot])072f8df: fix(#6386): pin agent fallback to installed workflow version (@ggallen)6a52f2c: fix(#6387): skip cancelled/skipped artifacts in WaitForHarnessAgent (@fullsend-ai-coder[bot])1b3bfd4: fix(#6397): add missing status comment params to prioritize job (@ggallen)6331d96: fix(#6412): embed agent slug in sandbox name for debuggability (@fullsend-ai-coder[bot])c54ce5c: fix(#6412): limit sandbox name to 19 characters for OpenShell (@fullsend-ai-coder[bot])4c300f2: fix(#6412): update evalmeasure to support new sandbox naming format (@fullsend-ai-coder[bot])1878f39: fix(#6415): add fix-stage environment for GitLab dispatch (@ggallen)25a7009: fix(#6418): pass ORIGINATING_URL and REPO_FULL_NAME in GitLab dispatch (@ggallen)1b57dd4: fix(#6420): make ImportProfile concurrency-safe with hash-based caching (@fullsend-ai-coder[bot])bf570ad: fix(#6435): address review feedback on profile flock PR (@fullsend-ai-coder[bot])e9b41ab: fix(#6435): serialize ImportProfile with flock and retry EnsureProvider (@fullsend-ai-coder[bot])f884711: fix(#6448): add flock serialization to ImportProfiles (@fullsend-ai-coder[bot])226612f: fix(#6448): drop behaviour test that cannot exercise the race (@fullsend-ai-coder[bot])79fd0ae: fix(#6448): extract profileDirTempPath helper and add coverage tests (@fullsend-ai-coder[bot])7c2247b: fix(#6450): install prioritize.yml per-repo and document scheduler (@ggallen)9a497f9: fix(#6455): add defensive guards for matrix evaluation and concurrency key (@ralphbean)f2adaa5: fix(#6455): remove broken harness-dispatch condition to restore backwards compatibility (@ralphbean)b433b82: fix(#6460): export RUNNER_TEMP with /tmp fallback in GitLab agent template (@fullsend-ai-coder[bot])e0d4a20: fix(#6464): align parsePiStream with pi 0.84.2 json wire format (@waynesun09)f6e32d6: fix(#6464): close pi's stdin in the run command; document unattended operation (@waynesun09)2513725: fix(#6464): document parsePiStream result-on-error contract; test read error in 2nd prompt (@waynesun09)280c60b: fix(#6464): fail closed when the pi hook adapter is missing; keep read for skills (@waynesun09)24455c4: fix(#6464): harden parsePiStream against review findings (@waynesun09)801adce: fix(#6464): hold pi ResultEvent until agent_settled and redact before truncating (@waynesun09)02fd6e8: fix(#6464): honour --runtime on per-repo installs; surface pi model errors (@waynesun09)3822019: fix(#6464): honour RunParams.Prompt in the pi runtime (@waynesun09)e6a262e: fix(#6464): keep ANTHROPIC_* out of pi Vertex runs and pin the GCP project (@waynesun09)3778e93: fix(#6464): load the Vertex extension only for the anthropic-vertex provider (@waynesun09)24a224c: fix(#6464): make regen.sh treat an npx failure as an error; correct pi tool list in parser header (@waynesun09)bd1ab38: fix(#6464): pin the pi hook adapter by hash; keep fd redirections out of the allowlist split (@waynesun09)78fd660: fix(#6464): redact pi tool arguments before capping; never surface unknown-tool output (@waynesun09)43bc145: fix(#6464): refuse every env prefix in the pi Bash allowlist; tighten the run gate (@waynesun09)c8eeda0: fix(#6464): run the pi hook guard before .env with command -p; keep indented --- in YAML (@waynesun09)f047ad7: fix([#6Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.