chore(deps): bump actions/github-script from 8 to 9#870
Conversation
Bumps [actions/github-script](https://github.com/actions/github-script) from 8 to 9. - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v8...v9) --- updated-dependencies: - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
@coderabbitai Are there any breaking changes in this dependency update? Is it safe to merge? |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chainLet me check the repository's workflow files for any usage patterns that could be affected by the breaking changes. 🏁 Script executed: Length of output: 1686
|
| Breaking Change | Description |
|---|---|
require('@actions/github') removed |
@actions/github is now ESM-only, so require(...) calls will fail at runtime |
getOctokit is now an injected parameter |
Declaring const getOctokit = ... or let getOctokit = ... in a script will throw a SyntaxError |
@actions/github internals |
Scripts accessing internals beyond the standard github/octokit client may need updates |
✅ Your Workflow is Safe
Inspecting .github/workflows/dependabot-coderabbit-review.yaml, the script only uses:
github.paginate(...)andgithub.rest.issues.*— standardgithubclient ✅context.repo.*andcontext.issue.*— standard context object ✅- No
require('@actions/github')✅ - No
const getOctokit/let getOctokitdeclarations ✅ - No
@actions/githubinternals ✅
✅ New Features in v9 (Bonus)
- A new
getOctokitfactory function is now injected directly into the script context, enabling multi-token workflows without any imports. ACTIONS_ORCHESTRATION_IDis automatically appended to the user-agent for better request tracing.
This PR is safe to merge. 🐇
Bumps actions/github-script from 8 to 9.
Release notes
Sourced from actions/github-script's releases.
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)