Skip to content

🔼(deps): bump provide-io/ci-tooling/actions/setup-python-env from 2872852d6cf693ed3ed3fd14c42b7c214f69fc37 to 6123f4a28a9bff52c666c04ee9bdc8a10054055e - #56

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/provide-io/ci-tooling/actions/setup-python-env-6123f4a28a9bff52c666c04ee9bdc8a10054055e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/provide-io/ci-tooling/actions/setup-python-env-6123f4a28a9bff52c666c04ee9bdc8a10054055e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps provide-io/ci-tooling/actions/setup-python-env from 2872852 to 6123f4a.

Changelog

Sourced from provide-io/ci-tooling/actions/setup-python-env's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

Consumers pin this repository by tag or commit SHA, so a release changes nothing for a repository until that repository moves its uses: pin. Note that callers pin in two places: the uses: line and the ref: of the ci-tooling checkout used by the TestPyPI verification step.

[0.8.6] - 2026-09-06

Fixed

  • Skipped test jobs no longer report their check name with the matrix expression un-interpolated.

    A job gated off by if: has no matrix context, so a name: referencing it was emitted verbatim: every consumer setting run-tests: false, or whose platform-preset excludes an architecture, showed rows reading 🧪 Tests (linux_amd64, py${{ matrix.python-version }}). Both states were visible in one run — provide-io/pyvider run 33991794320 rendered py3.11 on the five running legs and the raw expression on the one skipped.

    The names now carry only the platform. GitHub appends the matrix value to a static name on its own, single entry or several, so a running row still reads 🧪 Tests linux_amd64 (3.11) and a matrix-testing: true consumer keeps four distinguishable rows. Parentheses are left out of the platform because GitHub's suffix supplies them.

    Check names change for every consumer. Nothing is known to depend on them: all fourteen protected repositories require only ci / 📌 No Active Pins. A caller that lists a test job as a required status check must update that name.

[0.8.5] - 2026-09-05

Added

  • ignore-vulnerabilities on python-ci.yml and python-security.yml, a comma-separated list of advisory IDs passed to pip-audit --ignore-vuln.

    A caller can hit an advisory whose fix it cannot take. terraform-provider-pyvider is the case this was written for: cryptography publishes no macOS x86_64 wheel from 49.0.0 on, so the darwin_amd64 package cannot be built above 48.0.1, and three advisories against 48.0.1 are fixed only in 49.0.0 and 50.0.0.

    Without this the choice is to turn fail-on-vulnerability off, which stops the audit gating anything at all. An entry here records that the project examined the finding and established it cannot reach the vulnerable code path; the reason belongs at the call site, beside the IDs. Everything not listed still fails the build, so a fourth advisory against the same package is caught.

[0.8.4] - 2026-09-05

Added

  • scripts/release/attach-release-artifacts.sh and scripts/release/drop-orphan-signatures.sh, previously duplicated byte-for-byte in pyvider and pyvider-components. A pre-release review found four defects in them, and fixing one copy is how the two drift.

    attach-release-artifacts.sh retries gh release upload, which sends each file in turn and gives up on the first rejection with part of the set attached — so one transient 502 can leave a signature beside no artifact. It checks every file before the first upload, because the caller passes globs the workflow shell expands and an unmatched pattern arrives as its literal self; and it stops immediately on the HTTP classes retrying cannot fix rather than spending 75 seconds of backoff on a settled answer.

    drop-orphan-signatures.sh removes any .sigstore.json whose subject is absent. The asset listing uses --paginate: a truncated page would report a present subject as missing, and gh release delete-asset is irreversible and runs unattended.

    Additive only. No workflow in this repository calls them yet, and both consumers keep their local copies until they repin, so v0 callers are unaffected.

[0.8.3] - 2026-09-05

Fixed

  • The dependency audit no longer reports on the scanner. python-ci.yml

... (truncated)

Commits
  • 6123f4a 🔼(deps): bump provide-io/ci-tooling/actions/setup-python-env (#52)
  • b0f6d7d 🔼(deps): bump provide-io/ci-tooling/actions/python-quality (#51)
  • fb8fe4a 🔼(deps): bump provide-io/ci-tooling/actions/github-release (#50)
  • 4e6440e 🔼(deps): bump provide-io/ci-tooling/actions/python-build (#49)
  • 4ca2f59 🔼(deps): bump provide-io/ci-tooling/actions/python-test (#47)
  • 325da97 🔼(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 (#48)
  • 7b17762 🔼(deps): bump codecov/codecov-action from 7.0.0 to 7.1.1 (#53)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [provide-io/ci-tooling/actions/setup-python-env](https://github.com/provide-io/ci-tooling) from 2872852 to 6123f4a.
- [Release notes](https://github.com/provide-io/ci-tooling/releases)
- [Changelog](https://github.com/provide-io/ci-tooling/blob/main/CHANGELOG.md)
- [Commits](2872852...6123f4a)

---
updated-dependencies:
- dependency-name: provide-io/ci-tooling/actions/setup-python-env
  dependency-version: 6123f4a
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants