chore(deps): update github-actions - #636
Conversation
Deploying mouseterm with
|
| Latest commit: |
a71dec4
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://571d993e.mouseterm.pages.dev |
| Branch Preview URL: | https://renovate-github-actions.mouseterm.pages.dev |
dormouse-bot
left a comment
There was a problem hiding this comment.
Feedback on a draft — not a merge verdict. Mark ready when you want the full review.
All three SHA pins resolve correctly: chromaui/action@259eda5 is v18.8.1, astral-sh/setup-uv@bec219d is v10.1.0, and anthropics/claude-code-action@9cdae7f is the current v1.
The setup-uv and uv bumps in tend-mention.yaml and tend-notifications.yaml won't survive. Both files are generated — their header reads Do not edit this file directly — it will be overwritten on regeneration — and astral-sh/setup-uv@v10.0.1 / version: "0.12.10" were emitted by tend's generator in d2eda84 (0.1.24 → 0.2.0) and re-emitted unchanged through the 0.2.5 and 0.2.6 regenerations. The next chore: update tend workflows commit rewrites both files from the generator and drops these two lines; Renovate then re-opens the same bump the following Monday, indefinitely. docs/specs/security-ci.rationale.md already records the mechanism for the tend action itself: "a hand-edited SHA is overwritten by the next nightly regen, so pinning locally is not durable."
The durable fix is in .github/renovate.json, not here — a packageRules entry scoping the github-actions manager out of the generated files, alongside the existing "tend manages its own action version" rule:
{
"description": "tend's workflows are generated; a Renovate bump inside them is reverted by the next `uvx tend@latest init` regen. Upstream owns these pins",
"matchManagers": ["github-actions"],
"matchFileNames": [".github/workflows/tend-*.yaml"],
"enabled": false
}That belongs in its own PR. The three remaining bumps here — chromatic.yml, security-audit.yaml, workflow-audit.yaml — are all hand-maintained files and stick fine.
This PR contains the following updates:
9c5ddab→9cdae7fv10.0.1→v10.1.00.12.10→0.12.13v18.7.2→v18.8.1Release Notes
astral-sh/setup-uv (astral-sh/setup-uv)
v10.1.0: 🌈 New outputpython-runtime-idand respect NO_PROXYCompare Source
Changes
This release adds more bheind the scene security improvements and also 2 small improvements.
NO_PROXY
This action now respects
no_proxy/NO_PROXYenvironment variables which were previously ignored.New output
python-runtime-idThe new output
python-runtime-idcan be used to know which python version exactly was installed if you useactivate-environment. See pyca/cryptography#15572 (comment) for details on why this can be useful.🐛 Bug fixes
🚀 Enhancements
🧰 Maintenance
📚 Documentation
⬆️ Dependency updates
astral-sh/uv (astral-sh/uv)
v0.12.13Compare Source
Released on 2026-09-10.
Python
Enhancements
Preview features
tyexclusions whenuv checkautomatically selects members of a virtual workspace (#21555)Performance
Bug fixes
core-metadataover legacy aliases in JSON index responses (#21563)v0.12.12Compare Source
Released on 2026-09-09.
The executables in our macOS and Windows release archives and
uvanduv_buildwheels are now code-signed. macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables verification of the release publisher and binary integrity, supports publisher-based allowlisting, and should reduce security warnings and antivirus false positives.Bug fixes
exclude-newercutoff from lockfiles and generated requirement hashes (#21539)v0.12.11Compare Source
Released on 2026-09-08.
Preview features
pylock.tomlfiles to ensure they conform to PEP 751 (#20146)pylock.tomlartifact hash tables are empty, which will be rejected in a future uv release (#21462)Performance
uv pip install --no-depsfinds the requested packages already installed (#21523)Bug fixes
uv.lockbefore reading their metadata or running their build backends (#21223)===under both--verify-hashesand--require-hashes(#21543).python-versionand.python-versionsfiles (#21529)VIRTUAL_ENVmismatch warnings foruv add --no-sync,uv remove --no-sync, anduv add --frozen(#21496)uv python listcannot query an interpreter (#21498)Documentation
exclude-newerexamples (#21534)chromaui/action (chromaui/action)
v18.8.1Compare Source
🐛 Bug Fix
ENAMETOOLONGerrors #1485 (@codykaup)Authors: 1
v18.8.0Compare Source
🚀 Enhancement
Authors: 1
v18.7.4Compare Source
🐛 Bug Fix
.storybook/*.mdand.storybook/*.txtchanges from TurboSnap v2 #1482 (@codykaup)Authors: 1
v18.7.3Compare Source
🐛 Bug Fix
Authors: 2
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
* * * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.