Skip to content

Bump the actions group across 1 directory with 5 updates - #7

Closed
dependabot[bot] wants to merge 101 commits into
mainfrom
dependabot/github_actions/actions-cba825dc6e
Closed

dependabot[bot] wants to merge 101 commits into
mainfrom
dependabot/github_actions/actions-cba825dc6e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 5 updates in the / directory:

Package From To
actions/checkout 5.1.0 7.0.1
actions/setup-python 6.3.0 7.0.0
actions/upload-artifact 4.6.2 7.0.1
actions/download-artifact 5.0.0 8.0.1
softprops/action-gh-release 2.6.2 3.0.3

Updates actions/checkout from 5.1.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-python from 6.3.0 to 7.0.0

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

Commits

Updates actions/upload-artifact from 4.6.2 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Updates actions/download-artifact from 5.0.0 to 8.0.1

Release notes

Sourced from actions/download-artifact's releases.

v8.0.1

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v7.0.0

v7 - What's new

[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

... (truncated)

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

Updates softprops/action-gh-release from 2.6.2 to 3.0.3

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

v3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

v3.0.1

3.0.1

  • maintenance release with updated dependencies

... (truncated)

Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.3

3.0.3 is a maintenance release with updated dependencies. It also safely classifies malformed GitHub API errors to avoid secondary failures (#822).

What's Changed

Bug fixes 🐛

Other Changes 🔄

  • dependency updates

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

... (truncated)

Commits
  • efb3536 release 3.0.3 (#840)
  • 6441963 chore(deps): bump the npm group with 2 updates (#839)
  • e5ee6bc chore(deps): bump esbuild from 0.28.1 to 0.28.2 in the npm group (#837)
  • d1e6617 chore(deps): bump undici from 6.27.0 to 6.28.0 (#831)
  • 6403751 chore(deps): bump the npm group with 2 updates (#835)
  • 7c7184b chore(deps): bump postcss from 8.5.19 to 8.5.25 (#833)
  • 0f3f0d2 chore(deps): bump brace-expansion from 5.0.8 to 5.0.9 (#832)
  • 77fb938 chore(deps): bump prettier from 3.9.5 to 3.9.6 in the npm group (#830)
  • 5a6f517 chore(deps): bump brace-expansion from 5.0.7 to 5.0.8 (#828)
  • a3c91c9 chore(deps): bump the github-actions group with 2 updates (#825)
  • Additional commits viewable in compare view

Matthew and others added 30 commits September 26, 2026 14:12
…her, PE launcher

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PptP3rK35HdmwGJZSgCFf2
…fetch job

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PptP3rK35HdmwGJZSgCFf2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PptP3rK35HdmwGJZSgCFf2
…annotations

- SourceForge RSS rejects limit=200; drop the parameter
- memtest86+ 8.x ships ISOs on memtest.org: new download_template for GitHub
  sources, verified against the published sha512sum.txt
- clean_tag() turns 'version-1.4.0' / 'v8.10' into plain versions
- version regexes may use several capture groups (ShredOS build + nwipe)
- install.sh: replace A && B || C with explicit if (SC2015)
- CI: one annotation per level (GitHub caps at 10), live fetch job, second
  fetch must be a no-op; drop temporary probe workflow

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PptP3rK35HdmwGJZSgCFf2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PptP3rK35HdmwGJZSgCFf2
Ran Ventoy2Disk.sh 1.1.17 against a loop disk to confirm the flags and
prompts that were guessed from memory. Flags (-I -g -s/-S -r -u) and the
piped "y" answers are right; three problems turned up:

- Ventoy2Disk.sh exits 0 when it stops at a prompt, so a skipped install
  looked like a success. Both scripts now read the disk back with -l and
  check the version.
- -u turns Secure Boot support back on unless -S is passed, so
  refresh.sh --upgrade-ventoy undid --no-secure-boot. It now keeps the
  stick's setting, and skips the upgrade when already current.
- GPT installs need parted; install.sh now says so up front.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
- pe/phoenixpe/CommanderRescue.script: PEBakery script that puts
  CommanderApps.cmd in the PE with desktop and Start menu shortcuts.
- pe/phoenixpe/preset.txt: the recommended options on top of PhoenixPE's
  defaults (Intel RST/VMD driver, Windows network drivers, PowerShell,
  full Task Manager, VC++ 14 runtime for the USB apps; Notepad++ off
  because it comes from USB:\Apps).
- pe/phoenixpe/Apply-CommanderPreset.ps1: installs the add-on into
  Projects\MyApps and flips only the Selected= lines, keeping each file's
  BOM and line endings. Supports -WhatIf; reports renamed scripts.
- pe/README.md: build steps rewritten around the preset.

Tested against PhoenixPE 1.0.11 (master 28d23d0) with PowerShell 7.6:
only the six Selected= lines change, reruns are no-ops, -WhatIf writes
nothing, CRLF and BOM files are preserved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
scripts/common.sh defined head() for section headings, so every
`... | head -n1` in the scripts ran the helper instead: mount_part
returned $'\n-n1' as the stick's mount point (handed straight to
crescue sync), and refresh.sh --upgrade-ventoy looked for disk
"/dev/\n-n1". Rename the helper to section() and add a test that no
helper shadows a command the scripts pipe into.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Creates a Windows 11 VM (UEFI + TPM, SATA disk, e1000e NIC, so setup
needs no extra drivers) in the user's libvirt session, so no root or
libvirt group is needed. A 16 GB FAT32 transfer disk, written with
mtools while the VM is off, carries pe/ into Windows and the built ISO
back: `push` and `pull` (newest .iso in out\ -> pe/out/CommanderPE.iso).
virt-install keeps the install ISO attached for Windows guests, so the
DVD drive doubles as PhoenixPE's source.

Tested here: transfer disk create/push/pull round trip, and the
virt-install command against libvirt's test driver (no KVM in CI, so
the VM itself is untested). pe/README.md rewritten around it; ShellCheck
in CI now covers the script.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
CI's live fetch failed when GitHub's release host answered HTTP 500 for
the Rescuezilla ISO; every other tool downloaded and verified. download()
gave up on the first error, so one transient 5xx failed the whole run.
Retry 5xx, timeouts and connection errors up to three times (2s, 5s,
10s); 4xx still fails at once.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
- theme/: GRUB2 theme (dark navy, amber accent) with its own DejaVu
  fonts at 16/22 px, 9-slice menu and selection boxes, and Ventoy's
  @VTOY_*@ status labels and hotkey line kept.
- theme/build-theme.py regenerates the background, box images and .pf2
  fonts (Pillow + grub-mkfont); the outputs are committed.
- crescue: ventoy.json now lists the theme's fonts, falls back to the
  screen's own mode when 1080p isn't offered (resolution_fit), places
  the Ventoy version text so it fits at 1024 wide, and matches the tip
  colour. The theme folder on the stick is replaced, not merged, so
  removed files don't linger; the generator isn't copied.
- tools.toml turns it on; theme = "" in local.toml turns it off.

Rendered in real Ventoy 1.1.17 under QEMU (BIOS) at 1920x1080 and
1024x768; docs/boot-menu.png is that screenshot.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
…ession-sowfum

Ventoy fixes, Commander PE preset + build VM, boot-menu theme
- Boot Repair: Super GRUB2 Disk (SourceForge, sha256-verified).
- Malware Scan: Kaspersky Rescue Disk and Dr.Web LiveDisk (bootable).
- PE apps: Kaspersky Virus Removal Tool and Microsoft Safety Scanner,
  single-exe scanners that run inside Commander PE / Hiren's.
- Hiren's BootCD PE is now on by default.
- crescue: url sources take an optional `file` for links that don't end
  in a file name (Microsoft's fwlink), and such a URL without one is now
  a clear error instead of an empty filename.

The AV vendors publish no checksums, so those are trust-on-first-use.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
CI's live fetch got HTTP 403 for krd.iso and KVRT.exe. A probe from the
same GitHub runner (country: US) got 403 with both our user agent and a
browser's, so it is Kaspersky's US block, not us. Both stay in the
manifest, off by default, with the local.toml lines to turn them on
outside the US. Drops the temporary probe workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Free, downloaded and verified like the rest:
- HDAT2 (diagnostics, BIOS boot) and DiskGenius Free (PE app), via a new
  `page` source that takes the newest matching link from a download page.
- Boot-Repair-Disk (SourceForge md5). Its file name has no version, so
  SourceForge files now fall back to their upload date, not today's date
  (which made them look new every day).

Bring your own (source = "local", byo = true): menu slots for tools the
project can't download or share: Macrium Reflect, AOMEI Backupper and
Partition Assistant, EaseUS Todo Backup and Data Recovery, Paragon HDM,
Parted Magic, Active@ Data Studio, BootIt Bare Metal, SpinRite, PassMark
MemTest86 (its site blocks automated downloads), Windows 10/11 Setup,
Microsoft DaRT, Jayro's Lockpick. Empty slots are skipped silently; a
removed file drops off the stick on the next sync; paths may use ~.

Menu: new "Windows Install & Recovery" folder; "Linux Rescue" is now
"Rescue Environments" and "Backup & Imaging" is "Backup & Recovery".
Drops the temporary probe workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
CI's upstream check failed when www.hdat2.com timed out while its
download page was being read (the same page answered within seconds in
an earlier run). Downloads already retried transient failures; metadata
requests (release APIs, SourceForge feeds, download pages) didn't. They
now use the same 2/5/10 s retries for 5xx, timeouts and dropped
connections. 4xx answers still fail at once.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
The retry warnings added in the previous commit printed to stdout, so
CI's `crescue check --json > upstream.json` got "! … retrying" lines in
front of the JSON and the summary step failed to parse it. warn() now
writes to stderr like errors do, and stdout is line-buffered so a log
holding both streams keeps its order.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Three runs over 20 minutes, each with four attempts, timed out on
www.hdat2.com (an earlier probe did reach it). Every other new tool
downloaded and verified. HDAT2 stays in the manifest, off by default,
and can be turned on in local.toml where the site answers.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
hdat2.com timed out on every CI attempt, so HDAT2 moves from the
off-by-default page download to a byo/hdat2.iso slot like MemTest86.
byo/README.md says where to get both free ISOs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
…ession-sowfum

More tools, antivirus scanners and bring-your-own slots
sync looked for every app in the download cache, so a local or
bring-your-own app (kind = "app", source = "local") crashed it with
KeyError: 'final'. Apps now come from their own path when they have one,
and an empty bring-your-own app slot is skipped quietly instead of being
reported as "not fetched". byo/README.md shows how to add any ISO or
portable app of your own through local.toml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
…app slots

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
…ession-sowfum

Bring-your-own portable apps, and how to add your own tools
A small tkinter window (and a command line) on the same engine as the
Linux scripts: pick a USB stick, Install (erase, Ventoy, fill) or Update
(refresh in place). Built into one .exe with PyInstaller.

- Disks come from PowerShell Get-Disk. Only USB/SD disks are offered, never
  one holding the running Windows; Install needs the disk number typed
  back, with an extra warning for disks over 300 GB.
- Ventoy is installed with its own CLI (Ventoy2Disk VTOYCLI /I|/U
  /PhyDrive:N [/GPT] [/NoSB], x64 build from altexe), with progress read
  from cli_percent.txt and the result from cli_done.txt (log tail shown
  on failure). Switches and files checked against the 1.1.17 binary.
- crescue: `windows = {...}` tool keys for Windows (Ventoy's
  -windows.zip, same sha256.txt), zip-packaged Ventoy unpacking, volume
  labels via GetVolumeInformationW, shipped files (`assets`) kept apart
  from your folder (local.toml, byo/), output that can't crash a
  non-UTF-8 console, and no Python caches copied into the theme.
- CI (windows.yml): tests on Windows, build, smoke-test the real .exe
  (Get-Disk listing, verified fetch of the Windows Ventoy package, a sync,
  opening the window), upload it, and attach it to releases on v* tags.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
…e test

The first Windows CI run hung in the smoke test for over an hour: the
tests and the build passed, then the real .exe never finished. A
windowless app gave PowerShell no stdin, and PowerShell can block on it.
PowerShell and Ventoy now get stdin=DEVNULL, and a PowerShell call that
takes over 2 minutes becomes a clear error. In CI each .exe call gets 10
minutes before it is killed and its log printed, and the job is capped at
30 minutes instead of the 6-hour default.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nck1u3PcAC35ZBd9zZYHU4
Commanderx-code and others added 16 commits September 29, 2026 06:06
Ventoy's WIMBOOT mode only applies to Windows images, so the marker did
nothing for Dr.Web's Linux ISO. Tested: the ISO boots through Ventoy
1.1.17 in UEFI QEMU; its 2018 kernel (4.13) is what may fail on newer PCs.
Kaspersky's tip now points at Limited graphic mode for black screens.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
StartAllBack reads HKLM\...\AccountPicture\Users\<SID>\Image<size> (or an
.accountpicture-ms that Windows 11 no longer makes for local accounts), not
the ProgramData default pictures PhoenixPE sets. The add-on now writes the
phoenix at each size for SYSTEM, the PE's user.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
… build

PhoenixPE's ConvertImage macro failed (exit 3) when called from the add-on
with a section parameter in its arguments. The ten sizes now come ready-made
in pe/phoenixpe/AccountPictures and the add-on only copies them and writes
the registry values.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
StartAllBack finds the user's picture list through LogonUI's
SessionData\<session>\LoggedOnUserSID, which a PE never writes, so it fell
back to its default picture. The add-on now sets it to SYSTEM for sessions 0-3.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Without --verify, sync compared sizes only, and a rebuilt Lazarus PE was
exactly as big as the last (ISOs round to whole sectors), so the stick kept
the old build. The stick state now records each image's sha256; sticks
synced before this hash a local build once if it changed since that sync.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Deciding by modification time missed a build made before an earlier sync
that still kept size-only state.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
- helix pack also carries Ventoy for Windows and the latest released
  HelixBoot.exe, each verified against its published checksum (and taken
  from the cache when offline).
- Ventoy comes out of a pack for the system it runs on; a Linux-only pack
  says so on Windows before any disk is touched.
- The app: "Tools from: the internet / a pack", a pack beside the .exe (or
  beside its installer folder) is picked up, and --pack / --unpack-to on the
  command line.
- Windows CI makes a pack from its cache and fills a folder from it with the
  real .exe, and checks the window finds a pack beside it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
"installer\HelixBoot.exe" in the pack README and "installer\ folder" in a
docstring made Python print a SyntaxWarning on every start (seen in the
Windows CI log); newer Pythons will refuse them. A test now compiles the
sources with warnings as errors.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
A full-screen launcher (PowerShell + WPF, from the desktop_launcher mockup)
that Lazarus PE opens when its desktop loads, instead of the PortableApps.com
menu, which becomes one of its quick actions.

- Lists the Helix Apps, every PortableApps.com app and the PE's own Start
  menu (read again shortly after startup, as PhoenixPE fills it), each tool
  once, in seven categories by editable rules in launcher.json; search across
  all of them, quick actions, a System Info panel, network and clock.
- Reads appinfo.ini in UTF-8, UTF-16 or ANSI, with junk before the first
  section; friendlier names for folder-named apps; icons from appicon PNGs or
  the programs themselves.
- Scales to any screen, the bottom bar across the full width.
- Lives on the stick in Apps\Lazarus (helix copies pe/lazarus there, packs and
  the Windows app included), so a refresh updates it. apps.txt gains each
  app's description; every app in tools.toml now has one.
- Windows CI (launcher.yml) builds a stand-in stick from a real stick's tool
  list, checks how tools are sorted, and renders screenshots at six sizes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
- Real Ventoy screenshots of the Helix Neon menu (docs/boot-menu*.jpg,
  rendered by booting the stick's ventoy/ folder in a UEFI VM) replace the
  old theme's.
- README: OS Images, the Lazarus PE look and launcher, PortableApps as a quick
  action, Dr.Web/Kaspersky notes, menu keys, stick layout, roadmap, credits.
- PE guide: the startup chain (helper -> Apps\LazarusStartup.cmd -> launcher),
  which Windows to build from (the table contradicted the section below),
  what the add-on installs now.
- byo, theming and contributing notes: Helix Apps, arrow keys, launcher CI,
  PowerShell 5.1 and BOMs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
…ASCII text has one

Windows PowerShell 5.1 reads a .ps1 without a BOM as ANSI; the file's
box-drawing comments would turn into mojibake whose bytes include quote
characters. Found by PSScriptAnalyzer (PSUseBOMForUnicodeEncodedFile).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
- Stick detection (F4, F5): Lazarus PE's startup helper and the Helix Apps menu
  took the first drive with a tag file as the stick, so the PC being repaired
  could plant C:\helix-boot.tag and a script that Lazarus PE ran as SYSTEM.
  New pe/launcher/FindStick.ps1 accepts only a USB/SD/MMC disk whose tag is a
  file and that holds no Windows; without PowerShell, a scan with the same
  checks minus the bus. Helix Apps run from the stick uses its own drive.
- Packs (F1, F2, F3, F8): apps_root, iso_root and member names from a pack are
  validated (_safe_rel: no root, drive, ':' or '..') and every write and delete
  goes through _inside(), which also resolves and requires the path to stay
  on the stick. App and tree names must be tool names.
- Stick state (F7, F8): app names read from .helix-boot/state.json must be
  tool names before anything is deleted, and deletes are contained.
- GitHub token (F6, F9): attached only when the parsed scheme, host and port
  are GitHub's API, as an unredirected header.
- SourceForge (F10): the md5 in sourceforge.net's own feed must agree with a
  download verified by a mirror-served checksum file.

Tests: each finding has a test that failed before the fix (one, on the old
code, deleted a directory outside the stick). Windows CI runs FindStick.ps1
and StartPortableApps.cmd against subst drives with planted decoys.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
…elease job, Dependabot

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 30, 2026
Commanderx-code and others added 4 commits September 29, 2026 20:03
…ers)

Shown by install.sh and refresh.sh (also a pack's copies) once their options are
read; plain one-line header on terminals that aren't UTF-8 or are narrower than
76 columns, and no colour with NO_COLOR or when piped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Like MediCat's Medicat_Installer.sh: download it from Releases, chmod +x, run.
A menu offers Install (new stick), Update and Check; `install`, `refresh` and
`helix` pass straight through. Everything install.sh/refresh.sh need is packed
behind the script (a reproducible gzipped tar of the tracked files), checked
against the checksum in the script before it unpacks into
~/.local/share/helix-boot/app/<version>-<checksum>, so it works offline. As
with the .exe, local.toml and byo/ live beside it, and a pack beside it is used
with no downloads.

- linux/HelixBoot.sh.in + linux/build.sh; helix reads HELIX_USER_DIR.
- CI builds it on every push (artifact) and the release job attaches it.
- tests/test_linux_installer.py: one-file run, your local.toml beside it,
  pass-through, menu, a changed file refused, reproducible build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016y2UtpG4ogxThi7fjNPHQp
Bumps the actions group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `5.1.0` | `7.0.1` |
| [actions/setup-python](https://github.com/actions/setup-python) | `6.3.0` | `7.0.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` |
| [actions/download-artifact](https://github.com/actions/download-artifact) | `5.0.0` | `8.0.1` |
| [softprops/action-gh-release](https://github.com/softprops/action-gh-release) | `2.6.2` | `3.0.3` |



Updates `actions/checkout` from 5.1.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@fbc6f39...3d3c42e)

Updates `actions/setup-python` from 6.3.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@ece7cb0...5fda3b9)

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@ea165f8...043fb46)

Updates `actions/download-artifact` from 5.0.0 to 8.0.1
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@634f93c...3e5f45b)

Updates `softprops/action-gh-release` from 2.6.2 to 3.0.3
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@3bb1273...efb3536)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/setup-python
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the actions group with 5 updates Bump the actions group across 1 directory with 5 updates Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-cba825dc6e branch from bbcbae1 to 0fba3a5 Compare September 30, 2026 01:50
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-cba825dc6e branch September 30, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants