Bump dependabot-omnibus from 0.217.0 to 0.218.0
Bumps dependabot-omnibus from 0.217.0 to 0.218.0.
Release notes
Sourced from dependabot-omnibus's releases.
v0.218.0
What's Changed
- Cleanup leftover require by
@deivid-rodriguez
in dependabot/dependabot-core#7162- Cleanup duplicated conditions by
@deivid-rodriguez
in dependabot/dependabot-core#7161- Don't run update checker unnecessarily on all javascript packages in a monorepo by
@deivid-rodriguez
in dependabot/dependabot-core#7141- Prepare yarn berry just once by
@deivid-rodriguez
in dependabot/dependabot-core#7160- build(deps): bump Elixir to 1.14.4 by
@yeikel
in dependabot/dependabot-core#7151- Cargo: handle unsupported toolchain versions (part 2) by
@jakecoffman
in dependabot/dependabot-core#7168- It's
bug_tracker_uri
notissue_tracker_uri
by@jeffwidman
in dependabot/dependabot-core#7165- Switch from
Changelog.md
to GitHub releases by@jeffwidman
in dependabot/dependabot-core#7163- No need for
--dry-run
by@jeffwidman
in dependabot/dependabot-core#7164- Update docs with current release process by
@jeffwidman
in dependabot/dependabot-core#7169- build(deps): bump Yarn from 3.4.1 to 3.5.0 by
@yeikel
in dependabot/dependabot-core#7149- Pass the serialized group name when creating a PR for grouped updates by
@Nishnha
in dependabot/dependabot-core#7166- [Updater] Ensure we pass all dependency files into each step in a grouped update by
@brrygrdn
in dependabot/dependabot-core#7170- NPM: fix npmrc generation for v3 package-locks by
@jakecoffman
in dependabot/dependabot-core#7175- docs: add information about where to find Terraform updates and how to validate the release by
@yeikel
in dependabot/dependabot-core#7176- Improve npm instrumentation by
@deivid-rodriguez
in dependabot/dependabot-core#7177- Merge workflows that push images by
@deivid-rodriguez
in dependabot/dependabot-core#6681- Clarify the
images-latest
workflow by@jeffwidman
in dependabot/dependabot-core#7180- Pass exception message directly to peer dependency error handler by
@deivid-rodriguez
in dependabot/dependabot-core#7178- build(deps): bump Terraform to 1.4.6 by
@yeikel
in dependabot/dependabot-core#7181- Remove accidentally committed node_modules folders by
@deivid-rodriguez
in dependabot/dependabot-core#7172- Refactor workspace file fetching in npm by
@deivid-rodriguez
in dependabot/dependabot-core#7183- NPM: handle EBADENGINE better by
@jakecoffman
in dependabot/dependabot-core#7194- Improve naming of a method by
@deivid-rodriguez
in dependabot/dependabot-core#7197- Clarify comments on peer dependency error regexes by
@deivid-rodriguez
in dependabot/dependabot-core#7195- remove unused script by
@jakecoffman
in dependabot/dependabot-core#7205- Fix README.md formatting error by
@JonathanBerkeley
in dependabot/dependabot-core#7193- Remove unused requires by
@deivid-rodriguez
in dependabot/dependabot-core#7200- Catch
bundle lock
failures by@jeffwidman
in dependabot/dependabot-core#7208- Pass required method argument in
GroupUpdateAllVersions
updater operation by@bdragon
in dependabot/dependabot-core#7202- Do not catch the
0
exit code by@jeffwidman
in dependabot/dependabot-core#7209- Remove unused
GH_TOKEN
env var by@jeffwidman
in dependabot/dependabot-core#7207- [Updater] Fix brittle test for grouped updates by
@brrygrdn
in dependabot/dependabot-core#7213- Remove Updater#legacy_run by
@brrygrdn
in dependabot/dependabot-core#7212- [Updater] Implement an Operation capable of refreshing a Grouped Update PR. by
@brrygrdn
in dependabot/dependabot-core#7192- Add PNPM support by
@deivid-rodriguez
in dependabot/dependabot-core#7081- Remove dead code by
@deivid-rodriguez
in dependabot/dependabot-core#7218- Add a placeholder
dependabot-core.gemspec
by@jeffwidman
in dependabot/dependabot-core#7171- Pin docker_registry2 to 1.14.0 to fix CI by
@deivid-rodriguez
in dependabot/dependabot-core#7224- prebuild Python image for faster Codespace startup by
@jakecoffman
in dependabot/dependabot-core#7225- Create version bump PRs using a custom action by
@jeffwidman
in dependabot/dependabot-core#7211- [Updater] The Updater always expects job.dependency_groups to be defined by
@brrygrdn
in dependabot/dependabot-core#7216- [Updater] Add a test for two overlapping groups by
@brrygrdn
in dependabot/dependabot-core#7217- Fix Dependabot failing to create PRs when updates are needed on path gemspecs by
@deivid-rodriguez
in dependabot/dependabot-core#7227- Remove unnecessary usages of VCR by
@deivid-rodriguez
in dependabot/dependabot-core#7233- Don't link to empty releases page in PR body by
@deivid-rodriguez
in dependabot/dependabot-core#7118- Remove references to removed file by
@deivid-rodriguez
in dependabot/dependabot-core#7236- Fix updating GitHub Actions pinned to mixed references by
@deivid-rodriguez
in dependabot/dependabot-core#7215
... (truncated)
Changelog
Sourced from dependabot-omnibus's changelog.
Deprecated in favor of GitHub releases April 24th, 2023
The Dependabot-core Changelog is now available through GitHub Releases.
We switched to GitHub Releases to avoid the race condition between the version bump pull request and another pull request. If the other PR is merged between the time the version bump pull request was created and when it was merged, then the other pull request wasn't getting pulled into our changelog. This also allows a lot more flexibility around automation the creation of the version bump PR.
Commits
-
889ef34
v0.218.0 (#7339) -
eb13f32
Minor format tweak (#7338) -
41b319c
Add App Token to release workflow so CI jobs run (#7324) -
2d23b3c
Ensure we start frommain
even if workflow run from a branch (#7335) -
7e98127
docs: improve documentation (#7328) -
79e5758
Merge pull request #7297 from dependabot/brrygrdn/remove-prototype-from-branc... -
01b510f
Merge branch 'main' into brrygrdn/remove-prototype-from-branch-names -
815856b
CodeQL: ignore purposefully invalid ruby files (#7126) -
7fef65d
Remove prototype from branch names -
5767e8a
Merge pull request #7304 from dependabot/deivid-rodriguez/revert-gradle-fix - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
@dependabot-bot rebase
will rebase this MR. Deprecated, use GitLab's native /rebase instead -
@dependabot-bot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts