chore(deps): bump @renovatebot/pep440 from 4.2.2 to 5.0.0 - #907
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump @renovatebot/pep440 from 4.2.2 to 5.0.0#907dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@renovatebot/pep440](https://github.com/renovatebot/pep440) from 4.2.2 to 5.0.0. - [Release notes](https://github.com/renovatebot/pep440/releases) - [Commits](renovatebot/pep440@4.2.2...5.0.0) --- updated-dependencies: - dependency-name: "@renovatebot/pep440" dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
eifinger
added a commit
that referenced
this pull request
Jul 19, 2026
## Summary - update all CodeQL actions from 4.36.2 to 4.37.0 - update `smol-toml` from 1.6.1 to 1.7.0 - update `@types/node` from 25.5.0 to 26.0.1 - update `@vercel/ncc` from 0.44.0 to 0.44.1 - regenerate bundled action artifacts Supersedes #950, #951, #952, #957, #958, and #959. The updates from #905 and #907 are already present on `main`. Refs: pi-session 019f796d-a374-7a76-a8e4-1699b89ec8e6
eifinger
added a commit
that referenced
this pull request
Jul 21, 2026
## Summary Roll up the remaining dependency changes from Dependabot PRs: - #966: update `actions/setup-node` from 6.4.0 to 7.0.0 - #965: update `js-yaml` from 4.1.1 to 5.2.1 - #964: update `@types/node` from 26.0.1 to 26.1.1 - #963: update `esbuild` from 0.28.0 to 0.28.1 PRs #907 and #905 require no net changes because `@renovatebot/pep440` 5.0.0 and Jest 30.4.2 are already on `main`. ## Validation - `npm run all` Refs: pi-session 019f854e-4714-73ad-8de2-e79900f41b4d
eifinger
added a commit
that referenced
this pull request
Aug 11, 2026
## Summary Roll up the remaining net changes from the open Dependabot updates: - release-drafter/release-drafter 7.7.0 (#990) - github/codeql-action 4.37.4 (#987, #988, #989) - zizmorcore/zizmor-action 0.6.1 (#986) - @actions/cache 6.2.0 (#975) - @biomejs/biome 2.5.4 (#974) - undici 8.7.0 (#973) The Jest 30.4.2 (#905) and @renovatebot/pep440 5.0.0 (#907) updates are already present on main and require no additional changes. This also updates the Biome schema, applies the formatter changes from Biome 2.5.4, and regenerates the published bundles. ## Testing - `npm run all` - `actionlint` - `git diff --check` Refs: pi-session 019ff01b-f917-73c1-950e-2966956f263c
eifinger
added a commit
that referenced
this pull request
Aug 11, 2026
## Summary Roll up the remaining dependency changes from Dependabot PRs #997, #998, #999, #1000, #1001, #1002, and #1003: - update `github/codeql-action` to 4.37.6 - update `zizmorcore/zizmor-action` to 0.6.2 - update `undici` to 8.10.0 - update `smol-toml` to 1.7.1 - update `@biomejs/biome` and its schema to 2.5.6 - regenerate the published bundles PRs #905 and #907 were excluded because their requested Jest and pep440 versions are already present on `main`. ## Validation - `npm run all` - `actionlint .github/workflows/codeql-analysis.yml .github/workflows/test.yml` - `uvx zizmor .github/workflows/codeql-analysis.yml .github/workflows/test.yml` - `git diff --check` Refs: pi-session 019ff0c9-8e00-72d3-99ad-d4383a4c57d4
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/renovatebot/pep440-5.0.0
branch
August 11, 2026 13:19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @renovatebot/pep440 from 4.2.2 to 5.0.0.
Release notes
Sourced from @renovatebot/pep440's releases.
... (truncated)
Commits
d84e98cchore(deps): update dependency@types/nodeto v22 (#1411)c503a87feat!: convert to esmd261f99fix!: require node v22+e9c4761chore(deps): update actions/upload-artifact action to v7 (#1410)4a2cc6atest: migrate to vitest (#1412)3b094e1build: add type to package5cac8edbuild: allow pnpm v11d9fb269chore: enable pnpmminimumReleaseAge856cce2chore(deps): update containerbase/internal-tools action to v4.6.15 (#1409)4dac8a9chore(deps): update dependency typescript-eslint to v8.59.1 (#1408)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)