Repository navigation
fix(deps): bump @actions/cache to 6.3.0, undici to 6.29.0 and dev-deps - #29
Merged
Merged
Conversation
Combines three Dependabot updates that each rewrite package-lock.json and so would conflict pairwise: - @actions/cache 6.2.0 -> 6.3.0 (#27) - undici 6.28.0 -> 6.29.0, transitively via @actions/http-client (#26) - @types/node 26.6.2 -> 26.6.4 (#28) The first two are bundled into the action, so dist/ is rebuilt here in the same commit. Dependabot cannot do that itself — its PRs run with a read-only token and no access to the Actions secret the rebuild workflow needs — which left both runtime PRs failing the dist-drift gate and blocked. Typecheck clean, 73/73 tests pass, bundle verified byte-identical across two consecutive builds.
This was referenced Oct 5, 2026
chicoxyzzy
pushed a commit
that referenced
this pull request
Oct 5, 2026
🤖 I have created a release *beep* *boop* --- ## [1.0.5](v1.0.4...v1.0.5) (2026-10-05) ### Fixed * **deps:** bump @actions/cache to 6.3.0, undici to 6.29.0 and dev-deps ([#29](#29)) ([0a807f3](0a807f3)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: xyzzylabs-release-bot[bot] <298273869+xyzzylabs-release-bot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Combines three Dependabot PRs that each rewrite
package-lock.jsonand so would conflict pairwise. Supersedes #26, #27, #28.@actions/cache6.2.0 → 6.3.0undici6.28.0 → 6.29.0 (transitive, via@actions/http-client)@types/node26.6.2 → 26.6.4Why these needed combining
#26 and #27 were both
BLOCKED: the first two deps are bundled into the action, sodist/goes stale and the required drift gate (Fail if committed dist/ is out of date) fails. Dependabot cannot fix that itself — its PRs run with a read-only token and no access to the Actions secretrebuild-distneeds to mint its app token.So
dist/is rebuilt here, once, in the same commit.Verification
npm run typecheck— cleannpm test— 73/73 passnpm run buildrun twice: bundle byte-identical both times (dist/main7ced50ff9d198db2,dist/post081a2ae12629e9ca), so the drift gate is reproducible rather than luckundiciconfirmed at 6.29.0 in the lockfile and within the^6.23.0range its parents declare — no direct dependency addedRelease
The bundle genuinely changes here, so the
fix(deps)prefix is correct and release-please should cut a patch release off this.