chore(deps): bump taiki-e/install-action from 2.87.5 to 2.87.10 - #337
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [taiki-e/install-action](https://github.com/taiki-e/install-action) from 2.87.5 to 2.87.10. - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](taiki-e/install-action@5bf6ce0...fa23953) --- updated-dependencies: - dependency-name: taiki-e/install-action dependency-version: 2.87.10 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1ca1381cb1
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| components: clippy | ||
| - name: Install pinned nextest | ||
| uses: taiki-e/install-action@5bf6ce016fd2e72eefc647cbca1e4213f65955b8 # v2.87.5 | ||
| uses: taiki-e/install-action@fa23953489c080190314742a9b907f8e97c6767c # v2.87.10 |
There was a problem hiding this comment.
Reseal the compatibility surface after changing workflows
This edit changes the bytes of .github/workflows/ci.yml, while docs/tally/compatibility/compatibility-surface.json still records its parent SHA-256 (2d2220d…; the new file hashes to d06b614…); the same stale seal exists for the changed dependency-security.yml. Consequently, the tally-portable job's Enforce exact Tally compatibility claims step invokes gate, whose validate_files returns surface_file_changed, and the required CI check fails deterministically. Rehash and reseal the surface, then repoint the compatibility matrix as part of this update.
Useful? React with 👍 / 👎.
|
Superseded by #386, which consolidates this bump with the other seven Dependabot PRs into a single change. Consolidating means the license regeneration and the compatibility-surface reseal happen once rather than eight times — and each of these PRs would have gone stale the moment any other landed, since they all touch pinned files. The same version bump is carried in #386 with no change to what is being updated. Closing as superseded, not rejected. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps taiki-e/install-action from 2.87.5 to 2.87.10.
Release notes
Sourced from taiki-e/install-action's releases.
... (truncated)
Changelog
Sourced from taiki-e/install-action's changelog.
... (truncated)
Commits
fa23953Release 2.87.104a78383Updatetombi@latestto 1.5.457011ccUpdate protoc-gen-connect-openapi manifest328a425Updatezizmor@latestto 1.30.1b513effUpdateuv@latestto 0.12.11f86c9bbUpdatetombi@latestto 1.5.3b9f14c9Updaterelease-plz@latestto 0.3.16469a8031Updatemise@latestto 2026.9.3ada1005Updatekingfisher@latestto 2.2.0da4edc6Update kache manifestDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)