Bump actions/setup-node from 3.6.0 to 3.7.0#1854
Conversation
|
@Arminta-Jenkins-NIST and @JustKuzya, can you review this dependency and approve or reject accordingly given the updated guidance created last sprint? Message the team in nist-team on Gitter/Element or find me if you have any questions, comments, or concerns to address before finalizing a review. Thanks! |
Arminta-Jenkins-NIST
left a comment
There was a problem hiding this comment.
Reviewed and Approved.
JustKuzya
left a comment
There was a problem hiding this comment.
This project changes are minimal and make sense.
The dependent changes range from two letters swap to huge blocks of minified node script with whitespaces messed up, which messes up the diffs as well.
|
Thanks for your reviews, everyone. I will ask we do not merge this until the work on #1856 is merged and we can integrate this existing dep update into that branch for a 1.1.0 release branch. |
746d7b5
531ec7c to
746d7b5
Compare
|
@dependabot rebase |
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@64ed1c7...e33196f) --- updated-dependencies: - dependency-name: actions/setup-node dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
746d7b5 to
4998db5
Compare
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@64ed1c7...e33196f) --- updated-dependencies: - dependency-name: actions/setup-node dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 3.6.0 to 3.7.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@64ed1c7...e33196f) --- updated-dependencies: - dependency-name: actions/setup-node dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps actions/setup-node from 3.6.0 to 3.7.0.
Release notes
Sourced from actions/setup-node's releases.
Commits
e33196fDo not ivalidate the cache entirely on lock file change (#744)c6722d3update doc for frozen lock file (#789)8170e22Detect cached folders from multiple directories (#735)698d505Fix description about ensuring workflow access to private package (#704)869f4ddMerge pull request #758 from akv-platform/remove-implicit-dependencies10efafcUpdate canary version in tests to an existing one7d16907Add missing dependencyd0d39bdMove eslint-plugin-node to dev dependencies15a2477Install eslint-plugin-node7598dbcUpdate configuration filesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)