Skip to content

chore(deps): update ci dependencies#349

Merged
stickerdaniel merged 1 commit into
mainfrom
renovate/ci-dependencies
Apr 28, 2026
Merged

chore(deps): update ci dependencies#349
stickerdaniel merged 1 commit into
mainfrom
renovate/ci-dependencies

Conversation

@renovate

@renovate renovate Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
docker/build-push-action (changelog) action digest d08e5c3bcafcac
ghcr.io/astral-sh/uv stage digest 90bbb3c3b7b60a
pypa/gh-action-pypi-publish action minor v1.13.0v1.14.0
softprops/action-gh-release (changelog) action digest 153bb8e3bb1273

Release Notes

pypa/gh-action-pypi-publish (pypa/gh-action-pypi-publish)

v1.14.0

Compare Source

Audit your supply chain regularly!

✨ What's Changed

The main change in this release is that verbose and print-hash inputs are now on by default. This was contributed by @​whitequark💰 in #​397.

📝 Docs

@​woodruffw💰 updated the mentions of PEP 740 to stop implying that it might be experimental (it hasn't been for quite a while!) in #​388 and @​him2him2💰 brushed up some grammar in the README and SECURITY docs via #​395.

🛠️ Internal Updates

@​woodruffw💰 bumped sigstore and pypi-attestations in the lock file (#​391) and @​webknjaz💰 added infra for using type annotations in the project (#​381).

💪 New Contributors

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.13.0...v1.14.0

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​facutuesca💰 and @​woodruffw💰 for helping maintain this project when I can't!

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.

GH Sponsors badge


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@greptile-apps

greptile-apps Bot commented Apr 13, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

Routine CI dependency updates generated by Renovate: digest bumps for docker/build-push-action (v7), softprops/action-gh-release (v2), and the ghcr.io/astral-sh/uv Docker stage, plus a minor version bump for pypa/gh-action-pypi-publish from v1.13.0 to v1.14.0. No logic changes are introduced.

Confidence Score: 5/5

Safe to merge — all changes are pinned digest/version bumps with no logic modifications.

No code logic is changed; only CI action digests and a Docker image digest are updated by Renovate. The pypa/gh-action-pypi-publish minor bump (v1.14.0) only enables verbose and print-hash by default, which are already explicitly set in the workflow.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/release.yml Three action pin digests updated: docker/build-push-action, softprops/action-gh-release (digest-only), and pypa/gh-action-pypi-publish bumped to v1.14.0 — no behavioral changes to the workflow logic.
Dockerfile uv base image digest updated to a newer SHA; no other changes to the build stages.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart TD
    A[Renovate Bot] --> B[Digest bump: docker/build-push-action v7]
    A --> C[Digest bump: softprops/action-gh-release v2]
    A --> D[Minor bump: pypa/gh-action-pypi-publish v1.13→v1.14]
    A --> E[Digest bump: ghcr.io/astral-sh/uv in Dockerfile]
    B --> F[release.yml — no logic change]
    C --> F
    D --> F
    E --> G[Dockerfile — no logic change]
Loading

Reviews (21): Last reviewed commit: "chore(deps): update ci dependencies" | Re-trigger Greptile

@renovate renovate Bot force-pushed the renovate/ci-dependencies branch 15 times, most recently from 23268e7 to 6399612 Compare April 17, 2026 07:01
@stickerdaniel stickerdaniel force-pushed the renovate/ci-dependencies branch from 6399612 to 1789618 Compare April 17, 2026 09:36
@renovate renovate Bot force-pushed the renovate/ci-dependencies branch 3 times, most recently from e11ead4 to 6f38c68 Compare April 22, 2026 15:53
@renovate renovate Bot force-pushed the renovate/ci-dependencies branch from 6f38c68 to bf7c540 Compare April 27, 2026 15:56
@renovate renovate Bot force-pushed the renovate/ci-dependencies branch from bf7c540 to b3b7469 Compare April 28, 2026 21:35
@stickerdaniel stickerdaniel merged commit 9a3f3de into main Apr 28, 2026
6 checks passed
@stickerdaniel stickerdaniel deleted the renovate/ci-dependencies branch April 28, 2026 21:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant