Skip to content

build(deps): bump sympress/workflows/.github/workflows/javascript-static-analysis.yml from 1.2.2 to 1.2.5 - #81

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sympress/workflows/dot-github/workflows/javascript-static-analysis.yml-1.2.5
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sympress/workflows/dot-github/workflows/javascript-static-analysis.yml-1.2.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps sympress/workflows/.github/workflows/javascript-static-analysis.yml from 1.2.2 to 1.2.5.

Release notes

Sourced from sympress/workflows/.github/workflows/javascript-static-analysis.yml's releases.

v1.2.5

What's Changed

Full Changelog: SymPress/workflows@v1.2.4...v1.2.5

v1.2.4

The Dependencies job now transfers Composer package archives and sanitized Git object caches to the credential-free Build job. Private ZIP and source-only Git packages can be installed again with Composer networking disabled. Authentication, Git remotes and hooks are excluded; the final release does not contain the download caches.

No deployment or install secret is added to Build. Trusted deployment tools remain separate from the uploaded artifact. The deploy example points to a reviewed commit containing the cache fix.

Validated with native workflow/contract/artifact checks, actual private ZIP and Git installation without network, credentials or SSH-agent access, and the release-generator regressions.

v1.2.3

Fix the automatic-release template's Conventional Commits 10 compatibility and its locked installation step. The template now pairs preset 10.4.0 with the published, exactly pinned @semantic-release/release-notes-generator 15.0.0-beta.3 and its Writer 9 dependency. The native preset upgrade no longer fails patch, minor or breaking-change notes with the Writer 8 missing-helper error. No transitive major override is used.

The generator is an upstream prerelease, intentionally pinned rather than followed through a version range. Node must satisfy ^22.22.2 || >=24.15.0; the workflow's Node 24 default is compatible. Consumer custom writer options must migrate from Handlebars partials to Writer 9 rendering functions, and preset type options from hidden/bumpStrict to effect; see release documentation. Default public workflow inputs, outputs and permissions are unchanged.

Also copy the locked local bounded-braces archive into the release-tools directory before npm ci. The regression fixture now runs the shipped install shell rather than reconstructing the installation manually.

Validation: native patch/minor/breaking analysis and rendered links, default Angular rendering, and six actual local Git/semantic-release dry runs for fallback and consumer configurations. Shell/artifact contracts, interface checks, actionlint, documentation checks and moderate npm audits passed. Final PR checks, including CodeQL, passed. The actual Starter DDEV/browser consumer run passed against the production candidate; its final follow-up only strengthens test URL assertions. These fixtures do not publish a real consumer release or exercise npm publishing credentials.

Reviewed and merged through [PR #36](SymPress/workflows#36). The protected v1 alias advances to this release after main checks pass; consumers pinning an immutable commit must update explicitly.

Commits
  • a044303 docs: pin the reviewed immutable audit deployment workflow
  • 2ed4e3b fix: audit immutable dependencies before build and verify releases independently
  • b6ee6d0 docs(deploy): pin the reviewed private-cache implementation
  • 3a5e871 fix(ci): update TOML parser and isolate artifact fixture cache
  • 97a03ad docs(deploy): describe the sanitized bare Composer cache precisely
  • 19540d2 fix: reinstall private Composer packages in credential-free builds
  • 8d06f70 test(release): verify complete generated link targets
  • 22af090 fix(release): render preset 10 notes with supported tooling
  • 4c41a59 chore(deps): bump conventional-changelog-conventionalcommits
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…tic-analysis.yml

Bumps [sympress/workflows/.github/workflows/javascript-static-analysis.yml](https://github.com/sympress/workflows) from 1.2.2 to 1.2.5.
- [Release notes](https://github.com/sympress/workflows/releases)
- [Changelog](https://github.com/SymPress/workflows/blob/main/docs/release.md)
- [Commits](SymPress/workflows@cd809f3...a044303)

---
updated-dependencies:
- dependency-name: sympress/workflows/.github/workflows/javascript-static-analysis.yml
  dependency-version: 1.2.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants