Skip to content

Bump actions/setup-node from 3.6.0 to 3.7.0#1854

Merged
aj-stein-nist merged 1 commit intodevelopfrom
dependabot/github_actions/develop/actions/setup-node-3.7.0
Aug 8, 2023
Merged

Bump actions/setup-node from 3.6.0 to 3.7.0#1854
aj-stein-nist merged 1 commit intodevelopfrom
dependabot/github_actions/develop/actions/setup-node-3.7.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jul 12, 2023

Bumps actions/setup-node from 3.6.0 to 3.7.0.

Release notes

Sourced from actions/setup-node's releases.

v3.7.0

What's Changed

In scope of this release we added a logic to save an additional cache path for yarn 3 (related pull request and feature request). Moreover, we added functionality to use all the sub directories derived from cache-dependency-path input and add detect all dependencies directories to cache (related pull request and feature request).

Besides, we made such changes as:

New Contributors

Full Changelog: actions/setup-node@v3...v3.7.0

Commits
  • e33196f Do not ivalidate the cache entirely on lock file change (#744)
  • c6722d3 update doc for frozen lock file (#789)
  • 8170e22 Detect cached folders from multiple directories (#735)
  • 698d505 Fix description about ensuring workflow access to private package (#704)
  • 869f4dd Merge pull request #758 from akv-platform/remove-implicit-dependencies
  • 10efafc Update canary version in tests to an existing one
  • 7d16907 Add missing dependency
  • d0d39bd Move eslint-plugin-node to dev dependencies
  • 15a2477 Install eslint-plugin-node
  • 7598dbc Update configuration files
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 12, 2023
@aj-stein-nist
Copy link
Copy Markdown
Contributor

@Arminta-Jenkins-NIST and @JustKuzya, can you review this dependency and approve or reject accordingly given the updated guidance created last sprint? Message the team in nist-team on Gitter/Element or find me if you have any questions, comments, or concerns to address before finalizing a review. Thanks!

Copy link
Copy Markdown
Contributor

@Arminta-Jenkins-NIST Arminta-Jenkins-NIST left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed and Approved.

JustKuzya
JustKuzya previously approved these changes Jul 14, 2023
Copy link
Copy Markdown
Contributor

@JustKuzya JustKuzya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This project changes are minimal and make sense.

The dependent changes range from two letters swap to huge blocks of minified node script with whitespaces messed up, which messes up the diffs as well.

@aj-stein-nist aj-stein-nist changed the title Bump actions/setup-node from 3.6.0 to 3.7.0 [DONOTMERGE] Bump actions/setup-node from 3.6.0 to 3.7.0 Jul 14, 2023
@aj-stein-nist
Copy link
Copy Markdown
Contributor

Thanks for your reviews, everyone. I will ask we do not merge this until the work on #1856 is merged and we can integrate this existing dep update into that branch for a 1.1.0 release branch.

@dependabot dependabot bot dismissed stale reviews from JustKuzya and Arminta-Jenkins-NIST via 746d7b5 July 25, 2023 17:42
@dependabot dependabot bot force-pushed the dependabot/github_actions/develop/actions/setup-node-3.7.0 branch from 531ec7c to 746d7b5 Compare July 25, 2023 17:42
@aj-stein-nist aj-stein-nist changed the title [DONOTMERGE] Bump actions/setup-node from 3.6.0 to 3.7.0 Bump actions/setup-node from 3.6.0 to 3.7.0 Jul 27, 2023
@aj-stein-nist
Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@64ed1c7...e33196f)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/develop/actions/setup-node-3.7.0 branch from 746d7b5 to 4998db5 Compare August 8, 2023 13:20
@aj-stein-nist aj-stein-nist merged commit 2a90880 into develop Aug 8, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/develop/actions/setup-node-3.7.0 branch August 8, 2023 13:40
aj-stein-nist pushed a commit that referenced this pull request Sep 12, 2023
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@64ed1c7...e33196f)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Arminta-Jenkins-NIST pushed a commit that referenced this pull request Sep 12, 2023
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@64ed1c7...e33196f)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants