Skip to content

Releases: dependabot/dependabot-core

v0.291.0

19 Dec 13:49
282d52f
Compare
Choose a tag to compare

What's Changed

  • Dotnet ecosystem metric collection by @sachin-sandhu in #11097
  • Fix unsupported PNPM error message by @deivid-rodriguez in #10094
  • Bump poetry version from 1.8.3 to 1.8.5 by @noorul in #11107
  • chore(python): Target latest Python 3.12 version to 3.12.7 by @HrMathematiker in #10831
  • Bump pnpm to 9.15.0 by @jeffwidman in #11114
  • Bump symfony/process from 5.4.40 to 5.4.47 in /composer/helpers/v2 by @dependabot in #11117
  • Bump friendsofphp/php-cs-fixer from 3.54.0 to 3.65.0 in /composer/helpers/v2 in the dev-dependencies group across 1 directory by @dependabot in #11034
  • Bump nock from 13.5.5 to 13.5.6 in /npm_and_yarn/helpers in the npm-dependencies group by @dependabot in #10922
  • Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot in #11078
  • Raise a proper user error when package.json includes just a dummy string by @deivid-rodriguez in #8747
  • Stop checking for Composer 1 dependencies by @jeffwidman in #11120
  • Bump the all-actions group across 1 directory with 5 updates by @dependabot in #11118
  • Add support for NPM V6 deprecation warning and unsupported error by @amazimbe in #11112
  • Bump hashin from 1.0.1 to 1.0.3 in /python/helpers in the poetry group across 1 directory by @dependabot in #11115
  • Bump yarn to 4.5.3 by @jeffwidman in #11123
  • If overridden file exists, then process it and find the missing key values from base file. by @thavaahariharangit in #11137
  • fix(terraform): update less-than/less-than/equals version constraints by @bryan-bar in #8983
  • install .NET SDKs as specified by repo's global.json files by @brettfo in #11090
  • Containerfile is a thing. by @shyouhei in #11141
  • Throw appropriate error when failing to parse project file by @sebasgomez238 in #11139
  • WIP: Set timeout for helper subprocesses to enhance stability by @kbukum1 in #11125
  • To support for "containerFiles" more robust by @randhircs in #11145
  • Increase default timeout for helper subprocess commands from 2 minutes to 15 minutes by @kbukum1 in #11153
  • Improve error handling for missing dependency versions for github actions by @robaiken in #11144
  • v0.291.0 by @dependabot-core-action-automation in #11154

New Contributors

Full Changelog: v0.290.0...v0.291.0

v0.290.0

12 Dec 15:17
b106be3
Compare
Choose a tag to compare

What's Changed

  • allow for differing package and assembly names when finding packages path by @brettfo in #11064
  • download nuget packages to well-known location by @brettfo in #11056
  • remove unnecessary log messages by @brettfo in #11065
  • Add support for terraform ecosystem metrics collection by @amazimbe in #11059
  • Metric collection for Dart ecosystem by @sachin-sandhu in #11070
  • parse and honor ignore-conditions from job file by @brettfo in #11066
  • Add fallback to local package manager when Corepack installation fails by @kbukum1 in #11072
  • detect byte order mark in YAML and report error by @brettfo in #11073
  • patch DotnetSdk::Requirement by @JamieMagee in #11075
  • remove old update checker and stale code by @brettfo in #11076
  • make directory crawling unit-testable by @brettfo in #11071
  • add concrete types to job deserializer by @brettfo in #11088
  • add missing test for scenario by @brettfo in #11087
  • Fix Composer v1 Unsupported Error Handling in Dependabot Core by @kbukum1 in #11091
  • Add argument to parser to allow trailing comma in json. by @sebasgomez238 in #11086
  • Bump nuget/helpers/lib/NuGet.Client from c097388 to 7a84f1e by @dependabot in #11082
  • Bump Microsoft.CodeAnalysis.CSharp from 4.11.0 to 4.12.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11083
  • Add support for swift ecosystem metrics collection by @amazimbe in #11094
  • pass job file path to analyze command by @brettfo in #11089
  • Enable CorePack Installing Package Managers from Private Registries by @kbukum1 in #11077
  • Throwing an appropriate error, when private registry response with 200 status and empty array response by @thavaahariharangit in #11095
  • v0.290.0 by @dependabot-core-action-automation in #11104

Full Changelog: v0.289.0...v0.290.0

v0.289.0

05 Dec 16:18
c62e7c3
Compare
Choose a tag to compare

What's Changed

  • Remove dedup_branch_names ff and existing_branches array by @Nishnha in #10976
  • Add Dependabot configuration for NuGet and git submodule by @JamieMagee in #10984
  • Set Default npm Version to 10 Under enable_corepack_for_npm_and_yarn Feature Flag by @kbukum1 in #10985
  • Bump MSBuildPackageVersion from 17.5.0 to 17.12.6 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10989
  • Bump Microsoft.VisualStudio.Setup.Configuration.Interop from 3.4.2244 to 3.12.2149 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10990
  • Bump Microsoft.Extensions.FileSystemGlobbing from 6.0.0 to 9.0.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10991
  • Bump Microsoft.CodeAnalysis.CSharp from 4.9.2 to 4.11.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10992
  • Bump Newtonsoft.Json from 13.0.1 to 13.0.3 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10993
  • project discovery reports its own imported and additional files by @brettfo in #10994
  • Bump NuGet.Core from 2.14.0-rtm-832 to 2.14.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10996
  • Fix: Ensure Compatibility with npm >= 8 to Prevent Lockfile Downgrades by @kbukum1 in #11001
  • Bump System.ComponentModel.Composition from 7.0.0 to 9.0.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10998
  • Bump System.Security.Cryptography.ProtectedData from 8.0.0 to 9.0.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10999
  • gracefully exit if we can't solve an issue with peer dependencies by @brettfo in #11000
  • Enables python ecosystem metric collection by @sachin-sandhu in #10986
  • Add support for cargo ecosystem metrics collection by @amazimbe in #11009
  • Bump xunit from 2.4.2 to 2.9.2 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #10997
  • Bump Microsoft.CSharp from 4.3.0 to 4.7.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11002
  • Bump Microsoft.Extensions.FileProviders.Abstractions from 6.0.0 to 9.0.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11003
  • Handle paths with multiple case-insenstive matches on disk. by @sebasgomez238 in #10980
  • Bump Microsoft.Web.Xdt from 3.0.0 to 3.1.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11004
  • Add npm_and_yarn package managers' requirements to ecosystem metrics by @kbukum1 in #10977
  • Store Language Name, Version, and Requirements for npm, pnpm, and yarn by @kbukum1 in #11017
  • Bump xunit.runner.visualstudio from 2.4.5 to 2.8.2 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11005
  • Bump DiffPlex from 1.7.1 to 1.7.2 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11014
  • Bump Microsoft.NET.Test.Sdk from 17.5.0 to 17.12.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11015
  • Bump System.Threading.Tasks.Dataflow from 6.0.0 to 9.0.0 in /nuget/helpers/lib/NuGetUpdater by @dependabot in #11016
  • Bump nuget/helpers/lib/NuGet.Client from 1975634 to c097388 by @dependabot in #11007
  • Refactor Composer: Code Cleanup, Constants, and Helper Functions by @kbukum1 in #11021
  • Running yarn install before running the update checkoer by @thavaahariharangit in #11011
  • Python metric collection by @sachin-sandhu in #11013
  • Add support for hex ecosystem metrics collection by @amazimbe in #11023
  • Add support for gradle ecosystem metrics collection by @amazimbe in #11030
  • build(deps): bump terraform from 1.9.1 to 1.10.0 by @HorizonNet in #11029
  • Reorders package managers for python ecosystem metric collection by @sachin-sandhu in #11040
  • Try to find pnpm-lock.yaml file upwards on tree structure by @Yurickh in #10806
  • Update System.Security.Cryptography.Pkcs from 5.0.0 to 9.0.0 by @JamieMagee in #11039
  • Add support for devcontainers ecosystem metrics collection by @amazimbe in #11047
  • use content of discovery JSON to report dependency files by @brettfo in #11026
  • Add Metrics Collection for Composer Ecosystem: Package Manager and Language Details by @kbukum1 in #11025
  • Add Package Manager and Language Version Detection for Elm by @kbukum1 in #11041
  • remove duplicate Directory.Packages.props by @brettfo in #11042
  • align C# log messages with Ruby by @brettfo in #11044
  • filter out invalid requirement strings from array by @brettfo in #11049
  • Adding retries interval to registry client by @robaiken in #11048
  • Add support for git-submodules ecosystem metrics collection by @amazimbe in #11053
  • store discovery files under $HOME so they're not cleaned up by the OS by @brettfo in #11054
  • allow discovery to re-run if files are missing; log errors by @brettfo in #11055
  • Cleaning up lfs environment variable as it is not being used by @thavaahariharangit in #11058
  • v0.289.0 by @dependabot-core-action-automation in #11027

New Contributors

Full Changelog: v0.288.0...v0.289.0

v0.288.0

21 Nov 17:14
e24fe31
Compare
Choose a tag to compare

What's Changed

  • use MSBuild binlog to report dependencies by @brettfo in #10597
  • Store raw installed versions for npm, pnpm, and yarn package managers instead of detected version by @kbukum1 in #10938
  • allow null when parsing job.debug field by @brettfo in #10974
  • Fix Sorbet Typings for npm_and_yarn Ecosystem Package Manager and Helpers by @kbukum1 in #10975
  • Add support for go ecosystem metrics collection by @amazimbe in #10953
  • remove duplicate TFMs when considering updates by @brettfo in #10981
  • v0.288.0 by @dependabot-core-action-automation in #10978

Full Changelog: v0.287.0...v0.288.0

v0.287.0

19 Nov 22:59
3faa946
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.286.0...v0.287.0

v0.286.0

14 Nov 14:46
a7a43ca
Compare
Choose a tag to compare

What's Changed

  • manage C#-only experiments with ExperimentsManager by @brettfo in #10868
  • create interfaces for workers to make testing more direct by @brettfo in #10910
  • clean up warnings from NuGet.Client submodule by @brettfo in #10911
  • Adding support for build-system.requires in pyproject.toml by @gopidesupavan in #10899
  • improve packages directory detection by @brettfo in #10912
  • Send Ecosystem Metrics to Dependabot-API on Update Job Completion by @kbukum1 in #10905
  • Add Ruby Language Requirement Collection for Bundler Ecosystem Metrics by @kbukum1 in #10932
  • Fix bug related to empty package manager name in npm_and_yarn package manager by @kbukum1 in #10936
  • v0.286.0 by @dependabot-core-action-automation in #10933

New Contributors

Full Changelog: v0.285.0...v0.286.0

v0.285.0

07 Nov 14:27
2c549d2
Compare
Choose a tag to compare

What's Changed

  • Add support for centralized package manager abstraction for npm_and_yarn ecosystem by @kbukum1 in #10862
  • Expand Centralized Ecosystem Format with Language Version Information for Bundler by @kbukum1 in #10867
  • Check for packages.config in pure C# updater. by @sebasgomez238 in #10858
  • Expand Centralized Ecosystem Format with Requirements Information for Bundler Package Manager by @kbukum1 in #10897
  • Adds additional logs for Github PR creator by @sachin-sandhu in #10907
  • v0.285.0 by @dependabot-core-action-automation in #10906

Full Changelog: v0.284.0...v0.285.0

v0.284.0

05 Nov 15:27
c71a9d9
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.283.0...v0.284.0

v0.283.0

31 Oct 14:26
353f302
Compare
Choose a tag to compare

What's Changed

  • Add semver ignore-condition range code into python version by @amazimbe in #10844
  • Bump eslint from 9.12.0 to 9.13.0 in /npm_and_yarn/helpers in the dev-dependencies group by @dependabot in #10819
  • v0.283.0 by @dependabot-core-action-automation in #10869

Full Changelog: v0.282.0...v0.283.0

v0.282.0

24 Oct 18:55
2fdc6c1
Compare
Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v0.281.0...v0.282.0