Skip to content

deps(deps): bump dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml from 64d705af6e164aac58d507df6fb2f6bdc8a4d22d to e04c7ee5b494b376372023194cb418200761c722 - #348

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dinglebear-ai/workflows/dot-github/workflows/npm-trusted-publish.yml-e04c7ee5b494b376372023194cb418200761c722
Open

deps(deps): bump dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml from 64d705af6e164aac58d507df6fb2f6bdc8a4d22d to e04c7ee5b494b376372023194cb418200761c722#348
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/dinglebear-ai/workflows/dot-github/workflows/npm-trusted-publish.yml-e04c7ee5b494b376372023194cb418200761c722

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml from 64d705af6e164aac58d507df6fb2f6bdc8a4d22d to e04c7ee5b494b376372023194cb418200761c722.

Changelog

Sourced from dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml's changelog.

Changelog

Unreleased

Changed

  • Relicense Dinglebear-owned original work under AGPL-3.0-only and document separate commercial licensing; third-party material retains its original terms.

Documentation

  • document the MinIO-only Kache remote, isolated local L1 stores, and retired NFS architecture

1.0.0 (2026-08-01)

Features

  • complete workflow and bootstrap source of truth (#11) (695d2e5)
  • enforce fleet repository contracts (#13) (4db9c3e)
  • establish canonical workflow library (25be025)
  • support lockfile-free Node launchers (#19) (d7bbe71)

Bug Fixes

  • align actionlint and shellcheck validation (7fd37c0)
  • make hosted validation self-contained (afe0de8)
  • make shared workflow setup cache-safe (#22) (98e4081)
  • prepare marketplace validation tools (#23) (542ea7b)
  • preserve historical documentation trees (#16) (be87fa3)
  • route jobs through scale-set pool selectors (#26) (d1a41a7)
  • safely expand shell validation globs (4307d0b)
  • scope fleet contract to maintained sources (#15) (8ef2adc)
  • support cross-repository workflow contracts (#21) (eb5f36c)
  • support explicit frozen Cargo fixtures (#18) (2650efa)
  • support explicit unsafe FFI lint boundaries (#17) (0a7e39a)
  • update cargo-deny for CVSS 4.0 advisories (#25) (66e64b9)

Performance Improvements

  • batch fleet contract repository scans (#14) (328afd4)

Changelog

All notable changes are managed by Release Please from Conventional Commits.

Commits
  • e04c7ee fix(kache): stop hardcoding the endpoint and align the pin to 0.13.0 (#44)
  • 218eba1 feat(policy): reject gate wiring that lets a required check skip silently (#43)
  • 46c4d89 chore: adopt AGPL commercial dual licensing (#42)
  • 5a01d3b docs(kache): record MinIO-only cache architecture (#39)
  • befa67c fix(mcp): make Registry publication DNS-only (#38)
  • 3302f85 fix(mcp): wait for package propagation (#37)
  • f528830 feat(mcp): standardize Registry publication (#36)
  • 0075252 fix(release): publish MCP metadata with dinglebear.ai
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

…d-publish.yml

Bumps [dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml](https://github.com/dinglebear-ai/workflows) from 64d705af6e164aac58d507df6fb2f6bdc8a4d22d to e04c7ee5b494b376372023194cb418200761c722.
- [Release notes](https://github.com/dinglebear-ai/workflows/releases)
- [Changelog](https://github.com/dinglebear-ai/workflows/blob/main/CHANGELOG.md)
- [Commits](dinglebear-ai/workflows@64d705a...e04c7ee)

---
updated-dependencies:
- dependency-name: dinglebear-ai/workflows/.github/workflows/npm-trusted-publish.yml
  dependency-version: e04c7ee5b494b376372023194cb418200761c722
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants