Skip to content

ci: bump softprops/action-gh-release from 2 to 3 - #63

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 13, 2026

Copy link
Copy Markdown
Contributor

Bumps softprops/action-gh-release from 2 to 3.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on v2.6.2.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release

v2.6.2

What's Changed

Other Changes 🔄

Full Changelog: softprops/action-gh-release@v2...v2.6.2

v2.6.1

2.6.1 is a patch release focused on restoring linked discussion thread creation when discussion_category_name is set. It fixes [#764](https://github.com/softprops/action-gh-release/issues/764), where the draft-first publish flow stopped carrying the discussion category through the final publish step.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

Bug fixes 🐛

v2.6.0

2.6.0 is a minor release centered on previous_tag support for generate_release_notes, which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range. It also includes the recent concurrent asset upload recovery fix, a working_directory docs sync, a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

... (truncated)

Changelog

Sourced from softprops/action-gh-release's changelog.

0.1.13

  • fix issue with multiple runs concatenating release bodies #145
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Apr 13, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Verification by execution (backlog check; no branch changes were made).

Diff scope — git show --stat 826990d:

 .github/workflows/release.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Only the softprops/action-gh-release ref on the github-release job changes: @v2 -> @v3.

v3 usage compatibility:

  • v3 action.yml still declares both inputs used here: body and generate_release_notes.
  • v3.0.0's only breaking change is the runtime move Node 20 -> Node 24. This repo's CI already runs Node 24 actions on ubuntu-latest (actions/checkout@v6 and actions/setup-node@v6 both declare using: node24, and their jobs pass).
  • release.yml already sets permissions: contents: write, which creating a release requires.

Local gate reproduction at the PR head (detached worktree of dependabot/github_actions/softprops/action-gh-release-3, commit 826990d):

  • npm test -> 57 tests, 57 pass, 0 fail
  • npm run lint -> 0 errors (1 pre-existing warning)
  • npm run format:check -> clean
  • npm run typecheck -> clean
  • npm run dev -- check . --json -> "ok": true, all scanned areas complete
    Base ref origin/main gives the same test numbers (57/57), so the diff introduces no regression.

The only red check is claude-review. Its check-run annotation on this PR reads:

Action failed with error: Workflow initiated by non-human actor: dependabot (type: Bot).
Add bot to allowed_bots list or use '*' to allow all bots.

That is a bot-actor policy rejection by anthropics/claude-code-action@v1, not a finding about this diff. The same failure reproduces on other dependabot PRs (#68, #69, #70; annotation verified on #70's check run), i.e. it is pre-existing repo-wide. Note also that claude-review was already failing on human-authored PRs on 2026-09-22 with Claude result reported subtype success with is_error:true.

Net: the bump is compatible with the workflow as written and the sole failing check is pre-existing and unrelated to this change. Merge decision remains with the owner.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: head vs base, same gates run in two fresh detached worktrees (head 826990d / origin/main ce7da5b): npm test 57 pass / 0 fail at head vs 57 pass / 0 fail at base; lint 0 errors both; format:check clean both; typecheck clean both; readiness scan "ok": true both. GitHub checks at head: 8 SUCCESS (Check Repository, Lint & Format, Type Check, Validate PR, Scan Agent Readiness, Test Node 20.x, Test Node 22.x, Build) + 1 FAILURE (claude-review). Caveat on literal base re-run: claude-review triggers only on pull_request, so main has no run of it; the failure was instead shown to be actor-caused and pre-existing by identical annotations on other dependabot PRs (#70, #68, #69 all FAILURE). PR is not worse than base on any check.). Independent review: APPROVE.

GROK REVIEW (independent reviewer lane, exit 0, single call, no timeout): "VERDICT: APPROVE / No findings." Grok's stated basis: three-dot diff is the one-line pin change at .github/workflows/release.yml:79; v2 and v3 action.yml differ only in runs.using (node20 -> node24); generate_release_notes and body unchanged and still valid; job runs on ubuntu-latest with contents: write; floating @V3 resolves to v3.0.3; no production code, hence no test surface; no scope creep.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant