| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
|
Hello from actions/github-script! (ed2e029) |
Sorry, something went wrong.
|
Before this change: ~/projects/github-script-types
❯ npm i -D @actions/github-script@github:actions/github-script
added 38 packages, and audited 39 packages in 7s
1 critical severity vulnerability
Some issues need review, and may require choosing
a different dependency.
Run `npm audit` for details.
~/projects/github-script-types 7s
❯ npm audit
# npm audit report
github-script *
Severity: critical
Malware in github-script - https://github.com/advisories/GHSA-v9m5-8c6w-p3m5
No fix available
node_modules/@actions/github-script
1 critical severity vulnerability
Some issues need review, and may require choosing
a different dependency.Now: ~/projects/github-script-types
❯ npm i -D @actions/github-script@github:actions/github-script
changed 1 package, and audited 39 packages in 5s
found 0 vulnerabilities
~/projects/github-script-types 6s
❯ npm audit
found 0 vulnerabilities |
Sorry, something went wrong.
sagemathgh-42454: build(deps): bump actions/github-script from 6 to 9 Bumps [actions/github-script](https://github.com/actions/github-script) from 6 to 9. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/github- script/releases">actions/github-script's releases</a>.</em></p> <blockquote> <h2>v9.0.0</h2> <p><strong>New features:</strong></p> <ul> <li><strong><code>getOctokit</code> factory function</strong> — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See <a href="https://github.com/actions/github-script#creating-additional- clients-with-getoctokit">Creating additional clients with <code>getOctokit</code></a> for details and examples.</li> <li><strong>Orchestration ID in user-agent</strong> — The <code>ACTIONS_ORCHESTRATION_ID</code> environment variable is automatically appended to the user-agent string for request tracing.</li> </ul> <p><strong>Breaking changes:</strong></p> <ul> <li><strong><code>require('@actions/github')</code> no longer works in scripts.</strong> The upgrade to <code>@actions/github</code> v9 (ESM- only) means <code>require('@actions/github')</code> will fail at runtime. If you previously used patterns like <code>const { getOctokit } = require('@actions/github')</code> to create secondary clients, use the new injected <code>getOctokit</code> function instead — it's available directly in the script context with no imports needed.</li> <li><code>getOctokit</code> is now an injected function parameter. Scripts that declare <code>const getOctokit = ...</code> or <code>let getOctokit = ...</code> will get a <code>SyntaxError</code> because JavaScript does not allow <code>const</code>/<code>let</code> redeclaration of function parameters. Use the injected <code>getOctokit</code> directly, or use <code>var getOctokit = ...</code> if you need to redeclare it.</li> <li>If your script accesses other <code>@actions/github</code> internals beyond the standard <code>github</code>/<code>octokit</code> client, you may need to update those references for v9 compatibility.</li> </ul> <h2>What's Changed</h2> <ul> <li>Add ACTIONS_ORCHESTRATION_ID to user-agent string by <a href="https://github.com/Copilot"><code>@Copilot</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/695">actions/github-script#695</a></li> <li>ci: use deployment: false for integration test environments by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/712">actions/github-script#712</a></li> <li>feat!: add getOctokit to script context, upgrade <code>@actions/github</code> v9, <code>@octokit/core</code> v7, and related packages by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/700">actions/github-script#700</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Copilot"><code>@Copilot</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github- script/pull/695">actions/github-script#695</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/github- script/compare/v8.0.0...v9.0.0">https://github.com/actions/github- script/compare/v8.0.0...v9.0.0</a></p> <h2>v8.0.0</h2> <h2>What's Changed</h2> <ul> <li>Update Node.js version support to 24.x by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/637">actions/github-script#637</a></li> <li>README for updating actions/github-script from v7 to v8 by <a href="https://github.com/sneha-krip"><code>@sneha-krip</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/653">actions/github-script#653</a></li> </ul> <h2>⚠️ Minimum Compatible Runner Version</h2> <p><strong>v2.327.1</strong><br /> <a href="https://github.com/actions/runner/releases/tag/v2.327.1">Release Notes</a></p> <p>Make sure your runner is updated to this version or newer to use this release.</p> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github- script/pull/637">actions/github-script#637</a></li> <li><a href="https://github.com/sneha-krip"><code>@sneha- krip</code></a> made their first contribution in <a href="https://redirect.github.com/actions/github- script/pull/653">actions/github-script#653</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/github- script/compare/v7.1.0...v8.0.0">https://github.com/actions/github- script/compare/v7.1.0...v8.0.0</a></p> <h2>v7.1.0</h2> <h2>What's Changed</h2> <ul> <li>Upgrade husky to v9 by <a href="https://github.com/benelan"><code>@benelan</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/482">actions/github-script#482</a></li> <li>Add workflow file for publishing releases to immutable action package by <a href="https://github.com/Jcambass"><code>@Jcambass</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/485">actions/github-script#485</a></li> <li>Upgrade IA Publish by <a href="https://github.com/Jcambass"><code>@Jcambass</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/486">actions/github-script#486</a></li> <li>Fix workflow status badges by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/497">actions/github-script#497</a></li> <li>Update usage of <code>actions/upload-artifact</code> by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/512">actions/github-script#512</a></li> <li>Clear up package name confusion by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/514">actions/github-script#514</a></li> <li>Update dependencies with <code>npm audit fix</code> by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/515">actions/github-script#515</a></li> <li>Specify that the used script is JavaScript by <a href="https://github.com/timotk"><code>@timotk</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/478">actions/github-script#478</a></li> <li>chore: Add Dependabot for NPM and Actions by <a href="https://github.com/nschonni"><code>@nschonni</code></a> in <a href="https://redirect.github.com/actions/github- script/pull/472">actions/github-script#472</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="actions/github-script@3a2844b7e9c 422d3c10d287c895573f7108da1b3"><code>3a2844b</code></a> Merge pull request <a href="https://redirect.github.com/actions/github- script/issues/700">sagemath#700</a> from actions/salmanmkc/expose-getoctokit + prepare re...</li> <li><a href="actions/github-script@ca10bbdd1a7 739de09e99a200c7a59f5d73a4079"><code>ca10bbd</code></a> fix: use <code>@octokit/core/</code>types import for v7 compatibility</li> <li><a href="actions/github-script@86e48e20ac8 5c970ed1f96e718fd068173948b7b"><code>86e48e2</code></a> merge: incorporate main branch changes</li> <li><a href="actions/github-script@c1084728b5b 935ec4ddc1e4cee877b01797b3ff9"><code>c108472</code></a> chore: rebuild dist for v9 upgrade and getOctokit factory</li> <li><a href="actions/github-script@afff112e4f8 b57c718168af75b89ce00bc8d091d"><code>afff112</code></a> Merge pull request <a href="https://redirect.github.com/actions/github- script/issues/712">sagemath#712</a> from actions/salmanmkc/deployment-false + fix user-ag...</li> <li><a href="actions/github-script@ff8117e5b78 c415f814f39ad6998f424fee7b817"><code>ff8117e</code></a> ci: fix user- agent test to handle orchestration ID</li> <li><a href="actions/github-script@81c6b787607 9abe10ff715951c9fc7b3e1ab389d"><code>81c6b78</code></a> ci: use deployment: false to suppress deployment noise from integration tests</li> <li><a href="actions/github-script@3953caf8858 d318f37b6cc53a9f5708859b5a7b7"><code>3953caf</code></a> docs: update README examples from <a href="https://github.com/v8"><code>@v8</code></a> to <a href="https://github.com/v9"><code>@v9</code></a>, add getOctokit docs and v9 brea...</li> <li><a href="actions/github-script@c17d55b90dc db3d554d0027a6c180a7adc2daf78"><code>c17d55b</code></a> ci: add getOctokit integration test job</li> <li><a href="actions/github-script@a047196d9a0 2fe92098771cafbb98c2f1814e408"><code>a047196</code></a> test: add getOctokit integration tests via callAsyncFunction</li> <li>Additional commits viewable in <a href="https://github.com/actions/github-script/compare/v6...v9">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing- security-vulnerabilities/about-dependabot-security-updates#about- compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> URL: sagemath#42454 Reported by: dependabot[bot] Reviewer(s):
Bumps [actions/github-script](https://github.com/actions/github-script) from 7.0.1 to 9.0.0. Release notes *Sourced from [actions/github-script's releases](https://github.com/actions/github-script/releases).* > v9.0.0 > ------ > > **New features:** > > * **`getOctokit` factory function** — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See [Creating additional clients with `getOctokit`](https://github.com/actions/github-script#creating-additional-clients-with-getoctokit) for details and examples. > * **Orchestration ID in user-agent** — The `ACTIONS_ORCHESTRATION_ID` environment variable is automatically appended to the user-agent string for request tracing. > > **Breaking changes:** > > * **`require('@actions/github')` no longer works in scripts.** The upgrade to `@actions/github` v9 (ESM-only) means `require('@actions/github')` will fail at runtime. If you previously used patterns like `const { getOctokit } = require('@actions/github')` to create secondary clients, use the new injected `getOctokit` function instead — it's available directly in the script context with no imports needed. > * `getOctokit` is now an injected function parameter. Scripts that declare `const getOctokit = ...` or `let getOctokit = ...` will get a `SyntaxError` because JavaScript does not allow `const`/`let` redeclaration of function parameters. Use the injected `getOctokit` directly, or use `var getOctokit = ...` if you need to redeclare it. > * If your script accesses other `@actions/github` internals beyond the standard `github`/`octokit` client, you may need to update those references for v9 compatibility. > > What's Changed > -------------- > > * Add ACTIONS\_ORCHESTRATION\_ID to user-agent string by [`@Copilot`](https://github.com/Copilot) in [actions/github-script#695](https://redirect.github.com/actions/github-script/pull/695) > * ci: use deployment: false for integration test environments by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/github-script#712](https://redirect.github.com/actions/github-script/pull/712) > * feat!: add getOctokit to script context, upgrade `@actions/github` v9, `@octokit/core` v7, and related packages by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/github-script#700](https://redirect.github.com/actions/github-script/pull/700) > > New Contributors > ---------------- > > * [`@Copilot`](https://github.com/Copilot) made their first contribution in [actions/github-script#695](https://redirect.github.com/actions/github-script/pull/695) > > **Full Changelog**: <actions/github-script@v8.0.0...v9.0.0> > > v8.0.0 > ------ > > What's Changed > -------------- > > * Update Node.js version support to 24.x by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/github-script#637](https://redirect.github.com/actions/github-script/pull/637) > * README for updating actions/github-script from v7 to v8 by [`@sneha-krip`](https://github.com/sneha-krip) in [actions/github-script#653](https://redirect.github.com/actions/github-script/pull/653) > > ⚠️ Minimum Compatible Runner Version > ------------------------------------ > > **v2.327.1** > [Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1) > > Make sure your runner is updated to this version or newer to use this release. > > New Contributors > ---------------- > > * [`@salmanmkc`](https://github.com/salmanmkc) made their first contribution in [actions/github-script#637](https://redirect.github.com/actions/github-script/pull/637) > * [`@sneha-krip`](https://github.com/sneha-krip) made their first contribution in [actions/github-script#653](https://redirect.github.com/actions/github-script/pull/653) > > **Full Changelog**: <actions/github-script@v7.1.0...v8.0.0> > > v7.1.0 > ------ > > What's Changed > -------------- > > * Upgrade husky to v9 by [`@benelan`](https://github.com/benelan) in [actions/github-script#482](https://redirect.github.com/actions/github-script/pull/482) > * Add workflow file for publishing releases to immutable action package by [`@Jcambass`](https://github.com/Jcambass) in [actions/github-script#485](https://redirect.github.com/actions/github-script/pull/485) > * Upgrade IA Publish by [`@Jcambass`](https://github.com/Jcambass) in [actions/github-script#486](https://redirect.github.com/actions/github-script/pull/486) > * Fix workflow status badges by [`@joshmgross`](https://github.com/joshmgross) in [actions/github-script#497](https://redirect.github.com/actions/github-script/pull/497) > * Update usage of `actions/upload-artifact` by [`@joshmgross`](https://github.com/joshmgross) in [actions/github-script#512](https://redirect.github.com/actions/github-script/pull/512) > * Clear up package name confusion by [`@joshmgross`](https://github.com/joshmgross) in [actions/github-script#514](https://redirect.github.com/actions/github-script/pull/514) > * Update dependencies with `npm audit fix` by [`@joshmgross`](https://github.com/joshmgross) in [actions/github-script#515](https://redirect.github.com/actions/github-script/pull/515) > * Specify that the used script is JavaScript by [`@timotk`](https://github.com/timotk) in [actions/github-script#478](https://redirect.github.com/actions/github-script/pull/478) > * chore: Add Dependabot for NPM and Actions by [`@nschonni`](https://github.com/nschonni) in [actions/github-script#472](https://redirect.github.com/actions/github-script/pull/472) ... (truncated) Commits * [`3a2844b`](actions/github-script@3a2844b) Merge pull request [#700](https://redirect.github.com/actions/github-script/issues/700) from actions/salmanmkc/expose-getoctokit + prepare re... * [`ca10bbd`](actions/github-script@ca10bbd) fix: use `@octokit/core/`types import for v7 compatibility * [`86e48e2`](actions/github-script@86e48e2) merge: incorporate main branch changes * [`c108472`](actions/github-script@c108472) chore: rebuild dist for v9 upgrade and getOctokit factory * [`afff112`](actions/github-script@afff112) Merge pull request [#712](https://redirect.github.com/actions/github-script/issues/712) from actions/salmanmkc/deployment-false + fix user-ag... * [`ff8117e`](actions/github-script@ff8117e) ci: fix user-agent test to handle orchestration ID * [`81c6b78`](actions/github-script@81c6b78) ci: use deployment: false to suppress deployment noise from integration tests * [`3953caf`](actions/github-script@3953caf) docs: update README examples from [`@v8`](https://github.com/v8) to [`@v9`](https://github.com/v9), add getOctokit docs and v9 brea... * [`c17d55b`](actions/github-script@c17d55b) ci: add getOctokit integration test job * [`a047196`](actions/github-script@a047196) test: add getOctokit integration tests via callAsyncFunction * Additional commits viewable in [compare view](actions/github-script@v7.0.1...3a2844b) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
| Back | FazBrowse Home | New Git URL |
This repository is not the github-script package that's been identified as malware and it has never been published to the NPM registry.
Installing this repository as a repository package via NPM warns about this vulnerability due to the package.json name github-script. To clear up confusion, I've changed this name to @actions/github-script which is under our controlled Actions NPM scope.