Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: oras-project/setup-oras
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.0.0
Choose a base ref
...
head repository: oras-project/setup-oras
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v2.0.1
Choose a head ref
  • 18 commits
  • 10 files changed
  • 4 contributors

Commits on Apr 13, 2026

  1. chore(deps): Bump @types/node from 25.5.2 to 25.6.0 (#161)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.5.2 to 25.6.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.5.2&new-version=25.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 13, 2026
    Configuration menu
    Copy the full SHA
    0036b2c View commit details
    Browse the repository at this point in the history

Commits on Apr 20, 2026

  1. chore(deps): Bump typescript from 6.0.2 to 6.0.3 (#162)

    Bumps [typescript](https://github.com/microsoft/TypeScript) from 6.0.2
    to 6.0.3.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/microsoft/TypeScript/releases">typescript's
    releases</a>.</em></p>
    <blockquote>
    <h2>TypeScript 6.0.3</h2>
    <p>For release notes, check out the <a
    href="https://devblogs.microsoft.com/typescript/announcing-typescript-6-0/">release
    announcement blog post</a>.</p>
    <ul>
    <li><a
    href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.0%22">fixed
    issues query for TypeScript 6.0.0 (Beta)</a>.</li>
    <li><a
    href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.1%22">fixed
    issues query for TypeScript 6.0.1 (RC)</a>.</li>
    <li><a
    href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.2%22">fixed
    issues query for TypeScript 6.0.2 (Stable)</a>.</li>
    <li><a
    href="https://github.com/Microsoft/TypeScript/issues?utf8=%E2%9C%93&amp;q=milestone%3A%22TypeScript+6.0.3%22">fixed
    issues query for TypeScript 6.0.3 (Stable)</a>.</li>
    </ul>
    <p>Downloads are available on:</p>
    <ul>
    <li><a href="https://www.npmjs.com/package/typescript">npm</a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/microsoft/TypeScript/commit/050880ce59e30b356b686bd3144efe24f875ebc8"><code>050880c</code></a>
    Bump version to 6.0.3 and LKG</li>
    <li><a
    href="https://github.com/microsoft/TypeScript/commit/eeae9dd0f17aa494658e4ec079dc002e02dd625e"><code>eeae9dd</code></a>
    🤖 Pick PR <a
    href="https://redirect.github.com/microsoft/TypeScript/issues/63401">#63401</a>
    (Also check package name validity in...) into release-6.0 (#...</li>
    <li><a
    href="https://github.com/microsoft/TypeScript/commit/ad1c695fada682764bb510dd680e8f175ae54094"><code>ad1c695</code></a>
    🤖 Pick PR <a
    href="https://redirect.github.com/microsoft/TypeScript/issues/63368">#63368</a>
    (Harden ATA package name filtering) into release-6.0 (<a
    href="https://redirect.github.com/microsoft/TypeScript/issues/63372">#63372</a>)</li>
    <li><a
    href="https://github.com/microsoft/TypeScript/commit/0725fb4664a1d5ec94040b6d94db77dc1cc354e4"><code>0725fb4</code></a>
    🤖 Pick PR <a
    href="https://redirect.github.com/microsoft/TypeScript/issues/63310">#63310</a>
    (Mark class property initializers as...) into release-6.0 (#...</li>
    <li>See full diff in <a
    href="https://github.com/microsoft/TypeScript/compare/v6.0.2...v6.0.3">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=typescript&package-manager=npm_and_yarn&previous-version=6.0.2&new-version=6.0.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 20, 2026
    Configuration menu
    Copy the full SHA
    ee85e73 View commit details
    Browse the repository at this point in the history

Commits on Apr 27, 2026

  1. chore(deps): Bump @actions/core from 3.0.0 to 3.0.1 (#165)

    Bumps
    [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core)
    from 3.0.0 to 3.0.1.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md"><code>@​actions/core</code>'s
    changelog</a>.</em></p>
    <blockquote>
    <h2>3.0.1</h2>
    <ul>
    <li>Bump <code>undici</code> from <code>6.23.0</code> to
    <code>6.24.1</code> <a
    href="https://redirect.github.com/actions/toolkit/pull/2348">#2348</a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/actions/toolkit/commits/HEAD/packages/core">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@actions/core&package-manager=npm_and_yarn&previous-version=3.0.0&new-version=3.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Apr 27, 2026
    Configuration menu
    Copy the full SHA
    36a6ade View commit details
    Browse the repository at this point in the history

Commits on May 5, 2026

  1. chore: update releases.json for 1.3.2 (#167)

    Ran into the same issue that #166 is having. Here is a PR for the
    updated `releases.json` file based on checksums found on the release
    page for 1.3.2 https://github.com/oras-project/oras/releases/tag/v1.3.2
    
    Apologize in advance if there are any formatting issues. I edited the
    file through the GitHub web interface.
    
    ---------
    
    Signed-off-by: daniel-s-palmer <114503075+daniel-s-palmer@users.noreply.github.com>
    Signed-off-by: Daniel Palmer <daniel.palmer@defenseunicorns.com>
    daniel-s-palmer authored May 5, 2026
    Configuration menu
    Copy the full SHA
    d98226f View commit details
    Browse the repository at this point in the history

Commits on May 11, 2026

  1. chore(deps): Bump @types/node from 25.6.0 to 25.6.2 (#169)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.6.0 to 25.6.2.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.6.0&new-version=25.6.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored May 11, 2026
    Configuration menu
    Copy the full SHA
    9dd04ea View commit details
    Browse the repository at this point in the history

Commits on May 19, 2026

  1. chore(deps): Bump @types/node from 25.6.2 to 25.8.0 (#170)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.6.2 to 25.8.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.6.2&new-version=25.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored May 19, 2026
    Configuration menu
    Copy the full SHA
    f0d18da View commit details
    Browse the repository at this point in the history

Commits on May 25, 2026

  1. feat: automate releases.json updates via GitHub Actions workflow (#171)

    ## Summary
    
    - Adds `.github/workflows/update-releases.yml` — runs daily at 06:00 UTC
    and on `workflow_dispatch`. Detects new `oras-project/oras` releases
    that aren't yet in `src/lib/data/releases.json`, appends them, rebuilds
    `dist/`, and opens a PR via `peter-evans/create-pull-request`.
    - Adds `.github/scripts/update-releases.mjs` — the underlying Node
    script. Two modes:
    - **Auto** (no args): queries the GitHub releases API and adds only
    versions strictly newer than the current max in `releases.json`, so
    older 0.x releases the project intentionally never tracked are not
    backfilled.
    - **Backfill** (`node .github/scripts/update-releases.mjs 1.3.2 1.3.3`):
    adds the specific versions, useful for catching up if a scheduled run
    was missed. Wired through the `workflow_dispatch` `version` input.
    
    The script downloads the upstream `oras_<version>_checksums.txt`, parses
    the lines, and writes entries that match the existing schema
    (`{platform: {arch: {checksum, url}}}`). Missing/404 checksum files
    cause a non-zero exit before any write, so a partial file is never
    persisted. Auto runs that find nothing exit silently.
    
    The PR opened by the workflow is created with `GITHUB_TOKEN`, which
    means follow-up CI (`Tests`, `Check dist/`) will not auto-trigger on it
    — a maintainer needs to push an empty commit or close/reopen to kick CI.
    If that friction becomes a pain we can swap to a PAT or GitHub App token
    in a follow-up.
    
    Closes #168. Refs #166, #167.
    
    ## Test plan
    
    - [x] `node .github/scripts/update-releases.mjs` — no-op when current
    max (1.3.2) matches upstream
    - [x] `node .github/scripts/update-releases.mjs 1.3.2` — no-op for
    already-present version
    - [x] `node .github/scripts/update-releases.mjs 0.16.0` — successfully
    fetches checksums and inserts entry in semver order (then reverted
    locally)
    - [x] `npm run build` — passes, no dist drift
    - [x] YAML parses cleanly (js-yaml)
    - [ ] After merge, manually trigger the workflow with no input to
    confirm scheduled path
    - [ ] After merge, manually trigger with `version: 1.3.0` (already
    present) to confirm graceful skip
    
    Signed-off-by: Terry Howe <terrylhowe@gmail.com>
    TerryHowe authored May 25, 2026
    Configuration menu
    Copy the full SHA
    930087d View commit details
    Browse the repository at this point in the history
  2. chore(deps): Bump @types/node from 25.8.0 to 25.9.1 (#172)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.8.0 to 25.9.1.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored May 25, 2026
    Configuration menu
    Copy the full SHA
    94695ea View commit details
    Browse the repository at this point in the history

Commits on Jun 1, 2026

  1. chore(deps): Bump peter-evans/create-pull-request from 7 to 8 (#173)

    Bumps
    [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request)
    from 7 to 8.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/peter-evans/create-pull-request/releases">peter-evans/create-pull-request's
    releases</a>.</em></p>
    <blockquote>
    <h2>Create Pull Request v8.0.0</h2>
    <h2>What's new in v8</h2>
    <ul>
    <li>Requires <a
    href="https://github.com/actions/runner/releases/tag/v2.327.1">Actions
    Runner v2.327.1</a> or later if you are using a self-hosted runner for
    Node 24 support.</li>
    </ul>
    <h2>What's Changed</h2>
    <ul>
    <li>chore: Update checkout action version to v6 by <a
    href="https://github.com/yonas"><code>@​yonas</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4258">peter-evans/create-pull-request#4258</a></li>
    <li>Update actions/checkout references to <a
    href="https://github.com/v6"><code>@​v6</code></a> in docs by <a
    href="https://github.com/Copilot"><code>@​Copilot</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4259">peter-evans/create-pull-request#4259</a></li>
    <li>feat: v8 by <a
    href="https://github.com/peter-evans"><code>@​peter-evans</code></a> in
    <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4260">peter-evans/create-pull-request#4260</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yonas"><code>@​yonas</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4258">peter-evans/create-pull-request#4258</a></li>
    <li><a href="https://github.com/Copilot"><code>@​Copilot</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4259">peter-evans/create-pull-request#4259</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/peter-evans/create-pull-request/compare/v7.0.11...v8.0.0">https://github.com/peter-evans/create-pull-request/compare/v7.0.11...v8.0.0</a></p>
    <h2>Create Pull Request v7.0.11</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>fix: restrict remote prune to self-hosted runners by <a
    href="https://github.com/peter-evans"><code>@​peter-evans</code></a> in
    <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4250">peter-evans/create-pull-request#4250</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/peter-evans/create-pull-request/compare/v7.0.10...v7.0.11">https://github.com/peter-evans/create-pull-request/compare/v7.0.10...v7.0.11</a></p>
    <h2>Create Pull Request v7.0.10</h2>
    <p>⚙️ Fixes an issue where updating a pull request failed when targeting
    a forked repository with the same owner as its parent.</p>
    <h2>What's Changed</h2>
    <ul>
    <li>build(deps): bump the github-actions group with 2 updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4235">peter-evans/create-pull-request#4235</a></li>
    <li>build(deps-dev): bump prettier from 3.6.2 to 3.7.3 in the npm group
    by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4240">peter-evans/create-pull-request#4240</a></li>
    <li>fix: provider list pulls fallback for multi fork same owner by <a
    href="https://github.com/peter-evans"><code>@​peter-evans</code></a> in
    <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4245">peter-evans/create-pull-request#4245</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/obnyis"><code>@​obnyis</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4064">peter-evans/create-pull-request#4064</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/peter-evans/create-pull-request/compare/v7.0.9...v7.0.10">https://github.com/peter-evans/create-pull-request/compare/v7.0.9...v7.0.10</a></p>
    <h2>Create Pull Request v7.0.9</h2>
    <p>⚙️ Fixes an <a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4228">incompatibility</a>
    with the recently released <code>actions/checkout@v6</code>.</p>
    <h2>What's Changed</h2>
    <ul>
    <li>~70 dependency updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a></li>
    <li>docs: fix workaround description about <code>ready_for_review</code>
    by <a href="https://github.com/ybiquitous"><code>@​ybiquitous</code></a>
    in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3939">peter-evans/create-pull-request#3939</a></li>
    <li>Docs: <code>add-paths</code> default behavior by <a
    href="https://github.com/joeflack4"><code>@​joeflack4</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3928">peter-evans/create-pull-request#3928</a></li>
    <li>docs: update to create-github-app-token v2 by <a
    href="https://github.com/Goooler"><code>@​Goooler</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4063">peter-evans/create-pull-request#4063</a></li>
    <li>Fix compatibility with actions/checkout@v6 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4230">peter-evans/create-pull-request#4230</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/joeflack4"><code>@​joeflack4</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/3928">peter-evans/create-pull-request#3928</a></li>
    <li><a href="https://github.com/Goooler"><code>@​Goooler</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4063">peter-evans/create-pull-request#4063</a></li>
    <li><a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/peter-evans/create-pull-request/pull/4230">peter-evans/create-pull-request#4230</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/5f6978faf089d4d20b00c7766989d076bb2fc7f1"><code>5f6978f</code></a>
    fix: retry post-creation API calls on 422 eventual consistency errors
    (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4356">#4356</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/d32e88dac789dcc7906e7d26f69f24116fa9c97d"><code>d32e88d</code></a>
    build(deps-dev): bump the npm group with 3 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4349">#4349</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/8170bccad11c0df62542c04dcaefe36d342dfd39"><code>8170bcc</code></a>
    build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4344">#4344</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/00418193b417f888dbf1d993c5c0d31d27fdc7de"><code>0041819</code></a>
    build(deps): bump picomatch (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4339">#4339</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/b993918c8536b6d44706130734d5456879762b27"><code>b993918</code></a>
    build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4334">#4334</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/36d7c8468b48f9c2f8f29e260e82f10d4b90d2bd"><code>36d7c84</code></a>
    build(deps-dev): bump undici from 6.23.0 to 6.24.0 (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4328">#4328</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/a45d1fb447fcaf601166e405fd4f335cde1a8aa8"><code>a45d1fb</code></a>
    build(deps): bump <code>@​tootallnate/once</code> and
    jest-environment-jsdom (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4323">#4323</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/3499eb61835cc0015c0b786e203d74b1e8f55e43"><code>3499eb6</code></a>
    build(deps): bump the github-actions group with 2 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4316">#4316</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/3f3b473b8c148f5a7520efb4d1f9a70eea3d9d1f"><code>3f3b473</code></a>
    build(deps): bump minimatch (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4311">#4311</a>)</li>
    <li><a
    href="https://github.com/peter-evans/create-pull-request/commit/6699836a213cf8b28c4f0408a404a6ac79d4458a"><code>6699836</code></a>
    build(deps-dev): bump the npm group with 2 updates (<a
    href="https://redirect.github.com/peter-evans/create-pull-request/issues/4305">#4305</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/peter-evans/create-pull-request/compare/v7...v8">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=peter-evans/create-pull-request&package-manager=github_actions&previous-version=7&new-version=8)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 1, 2026
    Configuration menu
    Copy the full SHA
    ae76689 View commit details
    Browse the repository at this point in the history

Commits on Jun 8, 2026

  1. chore(deps): Bump @types/node from 25.9.1 to 25.9.2 (#175)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.9.1 to 25.9.2.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.9.1&new-version=25.9.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 8, 2026
    Configuration menu
    Copy the full SHA
    ce8d0d5 View commit details
    Browse the repository at this point in the history

Commits on Jun 13, 2026

  1. chore(deps): Bump esbuild from 0.28.0 to 0.28.1 (#176)

    Bumps [esbuild](https://github.com/evanw/esbuild) from 0.28.0 to 0.28.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/evanw/esbuild/releases">esbuild's
    releases</a>.</em></p>
    <blockquote>
    <h2>v0.28.1</h2>
    <ul>
    <li>
    <p>Disallow <code>\</code> in local development server HTTP requests (<a
    href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr">GHSA-g7r4-m6w7-qqqr</a>)</p>
    <p>This release fixes a security issue where HTTP requests to esbuild's
    local development server could traverse outside of the serve directory
    on Windows using a <code>\</code> backslash character. It happened due
    to the use of Go's <code>path.Clean()</code> function, which only
    handles Unix-style <code>/</code> characters. HTTP requests with paths
    containing <code>\</code> are no longer allowed.</p>
    <p>Thanks to <a
    href="https://github.com/dellalibera"><code>@​dellalibera</code></a> for
    reporting this issue.</p>
    </li>
    <li>
    <p>Add integrity checks to the Deno API (<a
    href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr">GHSA-gv7w-rqvm-qjhr</a>)</p>
    <p>The previous release of esbuild added integrity checks to esbuild's
    npm install script. This release also adds integrity checks to esbuild's
    Deno install script. Now esbuild's Deno API will also fail with an error
    if the downloaded esbuild binary contains something other than the
    expected content.</p>
    <p>Note that esbuild's Deno API installs from
    <code>registry.npmjs.org</code> by default, but allows the
    <code>NPM_CONFIG_REGISTRY</code> environment variable to override this
    with a custom package registry. This change means that the esbuild
    executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the
    expected content.</p>
    <p>Thanks to <a
    href="https://github.com/sondt99"><code>@​sondt99</code></a> for
    reporting this issue.</p>
    </li>
    <li>
    <p>Avoid inlining <code>using</code> and <code>await using</code>
    declarations (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>)</p>
    <p>Previously esbuild's minifier sometimes incorrectly inlined
    <code>using</code> and <code>await using</code> declarations into
    subsequent uses of that declaration, which then fails to dispose of the
    resource correctly. This bug happened because inlining was done for
    <code>let</code> and <code>const</code> declarations by avoiding doing
    it for <code>var</code> declarations, which no longer worked when more
    declaration types were added. Here's an example:</p>
    <pre lang="js"><code>// Original code
    {
      using x = new Resource()
      x.activate()
    }
    <p>// Old output (with --minify)<br />
    new Resource().activate();</p>
    <p>// New output (with --minify)<br />
    {using e=new Resource;e.activate()}<br />
    </code></pre></p>
    </li>
    <li>
    <p>Fix module evaluation when an error is thrown (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>,
    <a
    href="https://redirect.github.com/evanw/esbuild/pull/4467">#4467</a>)</p>
    <p>If an error is thrown during module evaluation, esbuild previously
    didn't preserve the state of the module for subsequent module
    references. This was observable if <code>import()</code> or
    <code>require()</code> is used to import a module multiple times. The
    thrown error is supposed to be thrown by every call to
    <code>import()</code> or <code>require()</code>, not just the first.
    With this release, esbuild will now throw the same error every time you
    call <code>import()</code> or <code>require()</code> on a module that
    throws during its evaluation.</p>
    </li>
    <li>
    <p>Fix some edge cases around the <code>new</code> operator (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4477">#4477</a>)</p>
    <p>Previously esbuild incorrectly printed certain edge cases involving
    complex expressions inside the target of a <code>new</code> expression
    (specifically an optional chain and/or a tagged template literal). The
    generated code for the <code>new</code> target was not correctly wrapped
    with parentheses, and either contained a syntax error or had different
    semantics. These edge cases have been fixed so that they now correctly
    wrap the <code>new</code> target in parentheses. Here is an example of
    some affected code:</p>
    <pre lang="js"><code>// Original code
    new (foo()`bar`)()
    new (foo()?.bar)()
    <p>// Old output<br />
    new foo()<code>bar</code>();<br />
    new (foo())?.bar();</p>
    <p></code></pre></p>
    </li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/evanw/esbuild/blob/main/CHANGELOG.md">esbuild's
    changelog</a>.</em></p>
    <blockquote>
    <h2>0.28.1</h2>
    <ul>
    <li>
    <p>Disallow <code>\</code> in local development server HTTP requests (<a
    href="https://github.com/evanw/esbuild/security/advisories/GHSA-g7r4-m6w7-qqqr">GHSA-g7r4-m6w7-qqqr</a>)</p>
    <p>This release fixes a security issue where HTTP requests to esbuild's
    local development server could traverse outside of the serve directory
    on Windows using a <code>\</code> backslash character. It happened due
    to the use of Go's <code>path.Clean()</code> function, which only
    handles Unix-style <code>/</code> characters. HTTP requests with paths
    containing <code>\</code> are no longer allowed.</p>
    <p>Thanks to <a
    href="https://github.com/dellalibera"><code>@​dellalibera</code></a> for
    reporting this issue.</p>
    </li>
    <li>
    <p>Add integrity checks to the Deno API (<a
    href="https://github.com/evanw/esbuild/security/advisories/GHSA-gv7w-rqvm-qjhr">GHSA-gv7w-rqvm-qjhr</a>)</p>
    <p>The previous release of esbuild added integrity checks to esbuild's
    npm install script. This release also adds integrity checks to esbuild's
    Deno install script. Now esbuild's Deno API will also fail with an error
    if the downloaded esbuild binary contains something other than the
    expected content.</p>
    <p>Note that esbuild's Deno API installs from
    <code>registry.npmjs.org</code> by default, but allows the
    <code>NPM_CONFIG_REGISTRY</code> environment variable to override this
    with a custom package registry. This change means that the esbuild
    executable served by <code>NPM_CONFIG_REGISTRY</code> must now match the
    expected content.</p>
    <p>Thanks to <a
    href="https://github.com/sondt99"><code>@​sondt99</code></a> for
    reporting this issue.</p>
    </li>
    <li>
    <p>Avoid inlining <code>using</code> and <code>await using</code>
    declarations (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>)</p>
    <p>Previously esbuild's minifier sometimes incorrectly inlined
    <code>using</code> and <code>await using</code> declarations into
    subsequent uses of that declaration, which then fails to dispose of the
    resource correctly. This bug happened because inlining was done for
    <code>let</code> and <code>const</code> declarations by avoiding doing
    it for <code>var</code> declarations, which no longer worked when more
    declaration types were added. Here's an example:</p>
    <pre lang="js"><code>// Original code
    {
      using x = new Resource()
      x.activate()
    }
    <p>// Old output (with --minify)<br />
    new Resource().activate();</p>
    <p>// New output (with --minify)<br />
    {using e=new Resource;e.activate()}<br />
    </code></pre></p>
    </li>
    <li>
    <p>Fix module evaluation when an error is thrown (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>,
    <a
    href="https://redirect.github.com/evanw/esbuild/pull/4467">#4467</a>)</p>
    <p>If an error is thrown during module evaluation, esbuild previously
    didn't preserve the state of the module for subsequent module
    references. This was observable if <code>import()</code> or
    <code>require()</code> is used to import a module multiple times. The
    thrown error is supposed to be thrown by every call to
    <code>import()</code> or <code>require()</code>, not just the first.
    With this release, esbuild will now throw the same error every time you
    call <code>import()</code> or <code>require()</code> on a module that
    throws during its evaluation.</p>
    </li>
    <li>
    <p>Fix some edge cases around the <code>new</code> operator (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4477">#4477</a>)</p>
    <p>Previously esbuild incorrectly printed certain edge cases involving
    complex expressions inside the target of a <code>new</code> expression
    (specifically an optional chain and/or a tagged template literal). The
    generated code for the <code>new</code> target was not correctly wrapped
    with parentheses, and either contained a syntax error or had different
    semantics. These edge cases have been fixed so that they now correctly
    wrap the <code>new</code> target in parentheses. Here is an example of
    some affected code:</p>
    <pre lang="js"><code>// Original code
    new (foo()`bar`)()
    new (foo()?.bar)()
    <p>// Old output<br />
    new foo()<code>bar</code>();<br />
    new (foo())?.bar();<br />
    </code></pre></p>
    </li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/evanw/esbuild/commit/bb9db84c02433fbe37b3509f53f9f3e3cc48725e"><code>bb9db84</code></a>
    publish 0.28.1 to npm</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/9ff053e53b8eeb990f59355dbea365277ac45ee2"><code>9ff053e</code></a>
    security: add integrity checks to the Deno API</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/0a9bf2135b67c7e28989a5ba19f0f000805a5ab5"><code>0a9bf21</code></a>
    enforce non-negative size in gzip parser</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/e2a1a7132058ee067fe736eac15f695861b8654e"><code>e2a1a71</code></a>
    security: forbid <code>\\</code> in local dev server requests</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/83a2cbfc35809f4fd5152da59572d7bed7739d78"><code>83a2cbf</code></a>
    fix <a
    href="https://redirect.github.com/evanw/esbuild/issues/4482">#4482</a>:
    don't inline <code>using</code> declarations</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/308ad745d824c77bc607603451b257d0f2fd9a38"><code>308ad74</code></a>
    fix <a
    href="https://redirect.github.com/evanw/esbuild/issues/4471">#4471</a>:
    renaming of nested <code>var</code> declarations</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/f013f5f99a015bce92ec48d49181d4ad3177b29b"><code>f013f5f</code></a>
    fix some typos</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/aafd6e48b1088336a5f5a17e930be7e840d43d8c"><code>aafd6e4</code></a>
    chore: fix some minor issues in comments (<a
    href="https://redirect.github.com/evanw/esbuild/issues/4462">#4462</a>)</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/15300c30b5e22f7cfcbed850c246d35095658386"><code>15300c3</code></a>
    follow up: cjs evaluation fixes</li>
    <li><a
    href="https://github.com/evanw/esbuild/commit/1bda0c31d7697c0af44b3ab39b81e599e559a395"><code>1bda0c3</code></a>
    fix <a
    href="https://redirect.github.com/evanw/esbuild/issues/4461">#4461</a>,
    fix <a
    href="https://redirect.github.com/evanw/esbuild/issues/4467">#4467</a>:
    esm evaluation fixes</li>
    <li>Additional commits viewable in <a
    href="https://github.com/evanw/esbuild/compare/v0.28.0...v0.28.1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=esbuild&package-manager=npm_and_yarn&previous-version=0.28.0&new-version=0.28.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/oras-project/setup-oras/network/alerts).
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Signed-off-by: Terry Howe <terrylhowe@gmail.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Terry Howe <terrylhowe@gmail.com>
    dependabot[bot] and TerryHowe authored Jun 13, 2026
    Configuration menu
    Copy the full SHA
    f8710a5 View commit details
    Browse the repository at this point in the history

Commits on Jun 15, 2026

  1. chore(deps): Bump @types/node from 25.9.2 to 25.9.3 (#177)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.9.2 to 25.9.3.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=25.9.2&new-version=25.9.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 15, 2026
    Configuration menu
    Copy the full SHA
    82faa22 View commit details
    Browse the repository at this point in the history

Commits on Jun 22, 2026

  1. chore(deps): Bump actions/checkout from 6 to 7 (#179)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to
    7.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    <h2>v6.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update changelog by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>Update changelog for v6.0.3 by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
    <h2>v6.0.2</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID
    is set by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2355">actions/checkout#2355</a></li>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.1...v6.0.2">https://github.com/actions/checkout/compare/v6.0.1...v6.0.2</a></p>
    <h2>v6.0.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update all references from v5 and v4 to v6 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2314">actions/checkout#2314</a></li>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    <li>Clarify v6 README by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2328">actions/checkout#2328</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.1">https://github.com/actions/checkout/compare/v6...v6.0.1</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
    update error wording (<a
    href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
    getting ready for checkout v7 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
    Bump the minor-npm-dependencies group across 1 directory with 3 updates
    (<a
    href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
    upgrade module to esm and update dependencies (<a
    href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
    Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
    and Remove uuid (<a
    href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
    Bump js-yaml from 4.1.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
    Bump flatted from 3.3.1 to 3.4.2 (<a
    href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
    Bump actions/publish-immutable-action (<a
    href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
    block checking out fork pr for pull_request_target and workflow_run (<a
    href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
    <li>See full diff in <a
    href="https://github.com/actions/checkout/compare/v6...v7">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/checkout&package-manager=github_actions&previous-version=6&new-version=7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 22, 2026
    Configuration menu
    Copy the full SHA
    0c499ae View commit details
    Browse the repository at this point in the history
  2. chore(deps): Bump @types/node from 25.9.3 to 26.0.0 (#178)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 25.9.3 to 26.0.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 22, 2026
    Configuration menu
    Copy the full SHA
    4aa197c View commit details
    Browse the repository at this point in the history

Commits on Jun 29, 2026

  1. chore(deps): Bump @types/node from 26.0.0 to 26.0.1 (#180)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 26.0.0 to 26.0.1.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=26.0.0&new-version=26.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 29, 2026
    Configuration menu
    Copy the full SHA
    fb503f0 View commit details
    Browse the repository at this point in the history

Commits on Jul 6, 2026

  1. chore(deps): Bump @types/node from 26.0.1 to 26.1.0 (#181)

    Bumps
    [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node)
    from 26.0.1 to 26.1.0.
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@types/node&package-manager=npm_and_yarn&previous-version=26.0.1&new-version=26.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 6, 2026
    Configuration menu
    Copy the full SHA
    6f3b32c View commit details
    Browse the repository at this point in the history

Commits on Jul 11, 2026

  1. ci: sign automated release-update commits (#183)

    ## What
    
    Add `sign-commits: true` to the `peter-evans/create-pull-request` step
    in `.github/workflows/update-releases.yml`.
    
    ## Why
    
    The workflow currently commits via the action's default local-git path,
    which produces **unsigned** commits. Branch protection on `main`
    requires *"commits must have verified signatures"*, so the automated PRs
    it opens (e.g. #182) cannot be merged:
    
    ```
    committer: github-actions[bot]
    verified:  false
    reason:    unsigned
    ```
    
    With `sign-commits: true`, `create-pull-request` builds the commit
    through the GitHub git-data API. Commits created via the API with
    `GITHUB_TOKEN` are signed server-side by GitHub and show as **Verified**
    (attributed to `github-actions[bot]`), satisfying the requirement. No
    key management needed.
    
    ## Notes
    
    - Committer identity on generated commits becomes `github-actions[bot]`
    rather than the local git config — expected with API-created commits.
    - Applies to future runs. The already-open #182 can be regenerated by
    re-dispatching this workflow once merged (fixed branch name +
    `delete-branch: true` updates the PR in place).
    
    Refs #168.
    
    ---------
    
    Signed-off-by: Terry Howe <terrylhowe@gmail.com>
    TerryHowe authored Jul 11, 2026
    Configuration menu
    Copy the full SHA
    b38537d View commit details
    Browse the repository at this point in the history
  2. chore: update releases.json for 1.3.3 (#182)

    Automated update adding ORAS release(s) `1.3.3`
    to `src/lib/data/releases.json`, with `dist/` rebuilt to match.
    
    Generated by `.github/workflows/update-releases.yml` via
    `.github/scripts/update-releases.mjs`.
    
    Review checklist:
    - Checksums match the upstream release(s) at
      https://github.com/oras-project/oras/releases (the one thing not
      covered by CI)
    - `check-dist` is green — confirms `dist/` matches the rebuilt source
    
    Refs #168.
    
    Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
    Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
    github-actions[bot] authored Jul 11, 2026
    Configuration menu
    Copy the full SHA
    1d808f7 View commit details
    Browse the repository at this point in the history
Loading