| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
There was a problem hiding this comment.
Adds documentation for publishing npm packages from GitHub Actions using npm Trusted Publishers (OIDC), and links to that guidance from the README.
Changes:
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| docs/advanced-usage.md | Introduces a new section describing npm Trusted Publisher (OIDC) publishing flow and an example workflow snippet. |
| README.md | Adds a table-of-contents link to the new advanced usage section. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Sorry, something went wrong.
#11) This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6.4.0` → `v7.0.0` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) #### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) #### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) #### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Warsaw) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI2MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=--> Reviewed-on: https://git.ajgon.casa/deedee/schemas/pulls/11
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > v7.0.0 > ------ > > What's Changed > -------------- > > ### Enhancements: > > * Add cache-primary-key and cache-matched-key as outputs by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577) > * Migrate to ESM and upgrade dependencies by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574) > > ### Bug fixes: > > * Remove dummy NODE\_AUTH\_TOKEN export by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558) > * Only use `mirrorToken` in `getManifest` if it's provided by [`@deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > > ### Documentation updates: > > * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * docs: Update restore-only cache documentation by [`@priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550) > * docs: Update caching recommendations to mitigate cache poisoning risks by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567) > > ### Dependency update: > > * Upgrade `@actions/cache` to 5.1.0, log cache write denied by [`@jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > New Contributors > ---------------- > > * [`@chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * [`@deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > * [`@jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > **Full Changelog**: <actions/setup-node@v6...v7.0.0> > > v6.5.0 > ------ > > What's Changed > -------------- > > * Update `@actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579) > > **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> Commits * [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574)) * [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577)) * [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567)) * [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0 * [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues * [`4e1a87a`](actions/setup-node@4e1a87a) Update dist * [`360237f`](actions/setup-node@360237f) Strict equality * [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@actions/cache` to 5.1.0, log cache write denied * [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548)) * [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558)) * Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
…roup (#558) Bumps the all-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node). Updates `actions/setup-node` from **6** to **7** ## Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > ## v7.0.0 > > ## What's Changed > > ### Enhancements > - Add `cache-primary-key` and `cache-matched-key` as outputs by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1577](actions/setup-node#1577) > - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1574](actions/setup-node#1574) > > ### Bug fixes > - Remove dummy `NODE_AUTH_TOKEN` export by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1558](actions/setup-node#1558) > - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [actions/setup-node#1548](actions/setup-node#1548) > > ### Documentation updates > - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1536](actions/setup-node#1536) > - Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [actions/setup-node#1550](actions/setup-node#1550) > - Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1567](actions/setup-node#1567) > > ### Dependency update > - Upgrade `@actions/cache` to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [actions/setup-node#1569](actions/setup-node#1569) > > ### New Contributors > - @chiranjib-swain (#1536) > - @deiga (#1548) > - @jasongin (#1569) > > **Full Changelog:** actions/setup-node@v6...v7.0.0 > > ## v6.5.0 > - Update `@actions/cache` to 5.1.0 and add security overrides for `undici` and `fast-xml-parser`. > > **Full Changelog:** actions/setup-node@v6.4.0...v6.5.0 > > ## v6.4.0 > - Upgrade `@actions` dependencies. > - Update Node.js versions in `versions.yml` and bump package to v6.4.0. > > ## v6.3.0 > - Support parsing `devEngines` field. > > ... (remaining release notes truncated exactly as in the original) ## Commits - `8207627` Migrate to ESM and upgrade dependencies (#1574) - `04be95c` Add cache-primary-key and cache-matched-key as outputs (#1577) - `7c2c68d` Update caching recommendations to mitigate cache poisoning risks (#1567) - `6a61c03` Merge pull request #1569 - `30eb73b` Resolve high-severity audit issues - `4e1a87a` Update dist - `360237f` Strict equality - `4f8aac5` Bump `@actions/cache` to 5.1.0 - `f4a67bb` Only use `mirrorToken` in `getManifest` if it's provided (#1548) - `0355742` Remove dummy `NODE_AUTH_TOKEN` export (#1558) - Additional commits viewable in the compare view. --- Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. ## Dependabot commands and options - `@dependabot rebase` - `@dependabot recreate` - `@dependabot show <dependency name> ignore conditions` - `@dependabot ignore <dependency name> major version` - `@dependabot ignore <dependency name> minor version` - `@dependabot ignore <dependency name>` - `@dependabot unignore <dependency name>` - `@dependabot unignore <dependency name> <ignore condition>`
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) #### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) #### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) #### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) #### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) #### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) #### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) #### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) #### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) #### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) #### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/runner/pulls/1094 Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) ##### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) ##### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) ##### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) ##### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) ##### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) ##### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) ##### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) ##### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) #### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/docs/pulls/467 Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-node (actions/setup-node)</summary> ### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0) [Compare Source](actions/setup-node@v7.0.0...v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@​gowridurgad](https://github.com/gowridurgad) in [#​1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@​gowridurgad](https://github.com/gowridurgad) in [#​1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@​gowridurgad](https://github.com/gowridurgad) in [#​1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@​deiga](https://github.com/deiga) in [#​1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@​chiranjib-swain](https://github.com/chiranjib-swain) in [#​1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​1569](actions/setup-node#1569) ##### New Contributors - [@​chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#​1536](actions/setup-node#1536) - [@​deiga](https://github.com/deiga) made their first contribution in [#​1548](actions/setup-node#1548) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ### [`v7`](actions/setup-node@v6.5.0...v7.0.0) [Compare Source](actions/setup-node@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0) [Compare Source](actions/setup-node@v6.4.0...v6.5.0) ##### What's Changed - Update [@​actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​1579](actions/setup-node#1579) **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0) [Compare Source](actions/setup-node@v6.3.0...v6.4.0) ##### What's Changed ##### Dependency updates: - Upgrade [@​actions](https://github.com/actions) dependencies by [@​Copilot](https://github.com/Copilot) in [#​1525](actions/setup-node#1525) - Update Node.js versions in versions.yml and bump package to v6.4.0 by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​1533](actions/setup-node#1533) ##### New Contributors - [@​Copilot](https://github.com/Copilot) made their first contribution in [#​1525](actions/setup-node#1525) **Full Changelog**: <actions/setup-node@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0) [Compare Source](actions/setup-node@v6.2.0...v6.3.0) ##### What's Changed ##### Enhancements: - Support parsing `devEngines` field by [@​susnux](https://github.com/susnux) in [#​1283](actions/setup-node#1283) > When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node. ##### Dependency updates: - Fix npm audit issues by [@​gowridurgad](https://github.com/gowridurgad) in [#​1491](actions/setup-node#1491) - Replace uuid with crypto.randomUUID() by [@​trivikr](https://github.com/trivikr) in [#​1378](actions/setup-node#1378) - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​1498](actions/setup-node#1498) ##### Bug fixes: - Remove hardcoded bearer for mirror-url [@​marco-ippolito](https://github.com/marco-ippolito) in [#​1467](actions/setup-node#1467) - Scope test lockfiles by package manager and update cache tests by [@​gowridurgad](https://github.com/gowridurgad) in [#​1495](actions/setup-node#1495) ##### New Contributors - [@​susnux](https://github.com/susnux) made their first contribution in [#​1283](actions/setup-node#1283) **Full Changelog**: <actions/setup-node@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0) [Compare Source](actions/setup-node@v6.1.0...v6.2.0) ##### What's Changed ##### Documentation - Documentation update related to absence of Lockfile by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​1454](actions/setup-node#1454) - Correct mirror option typos by [@​MikeMcC399](https://github.com/MikeMcC399) in [#​1442](actions/setup-node#1442) - Readme update on checkout version v6 by [@​deining](https://github.com/deining) in [#​1446](actions/setup-node#1446) - Readme typo fixes [@​munyari](https://github.com/munyari) in [#​1226](actions/setup-node#1226) - Advanced document update on checkout version v6 by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1468](actions/setup-node#1468) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5.0.1 by [@​salmanmkc](https://github.com/salmanmkc) in [#​1449](actions/setup-node#1449) ##### New Contributors - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​1454](actions/setup-node#1454) - [@​MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#​1442](actions/setup-node#1442) - [@​deining](https://github.com/deining) made their first contribution in [#​1446](actions/setup-node#1446) - [@​munyari](https://github.com/munyari) made their first contribution in [#​1226](actions/setup-node#1226) **Full Changelog**: <actions/setup-node@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0) [Compare Source](actions/setup-node@v6...v6.1.0) ##### What's Changed ##### Enhancement: - Remove always-auth configuration handling by [@​priyagupta108](https://github.com/priyagupta108) in [#​1436](actions/setup-node#1436) ##### Dependency updates: - Upgrade [@​actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1384](actions/setup-node#1384) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1439](actions/setup-node#1439) - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​1435](actions/setup-node#1435) ##### Documentation update: - Add example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​1419](actions/setup-node#1419) **Full Changelog**: <actions/setup-node@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/blog/pulls/546 Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > v7.0.0 > ------ > > What's Changed > -------------- > > ### Enhancements: > > * Add cache-primary-key and cache-matched-key as outputs by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577) > * Migrate to ESM and upgrade dependencies by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574) > > ### Bug fixes: > > * Remove dummy NODE\_AUTH\_TOKEN export by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558) > * Only use `mirrorToken` in `getManifest` if it's provided by [`@deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > > ### Documentation updates: > > * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * docs: Update restore-only cache documentation by [`@priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550) > * docs: Update caching recommendations to mitigate cache poisoning risks by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567) > > ### Dependency update: > > * Upgrade `@actions/cache` to 5.1.0, log cache write denied by [`@jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > New Contributors > ---------------- > > * [`@chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * [`@deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > * [`@jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > **Full Changelog**: <actions/setup-node@v6...v7.0.0> > > v6.5.0 > ------ > > What's Changed > -------------- > > * Update `@actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579) > > **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> Commits * [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574)) * [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577)) * [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567)) * [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0 * [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues * [`4e1a87a`](actions/setup-node@4e1a87a) Update dist * [`360237f`](actions/setup-node@360237f) Strict equality * [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@actions/cache` to 5.1.0, log cache write denied * [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548)) * [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558)) * Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. Release notes *Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).* > v7.0.0 > ------ > > What's Changed > -------------- > > ### Enhancements: > > * Add cache-primary-key and cache-matched-key as outputs by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577) > * Migrate to ESM and upgrade dependencies by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574) > > ### Bug fixes: > > * Remove dummy NODE\_AUTH\_TOKEN export by [`@gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558) > * Only use `mirrorToken` in `getManifest` if it's provided by [`@deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > > ### Documentation updates: > > * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * docs: Update restore-only cache documentation by [`@priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550) > * docs: Update caching recommendations to mitigate cache poisoning risks by [`@chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567) > > ### Dependency update: > > * Upgrade `@actions/cache` to 5.1.0, log cache write denied by [`@jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > New Contributors > ---------------- > > * [`@chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536) > * [`@deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548) > * [`@jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569) > > **Full Changelog**: <actions/setup-node@v6...v7.0.0> > > v6.5.0 > ------ > > What's Changed > -------------- > > * Update `@actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579) > > **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0> Commits * [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574)) * [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577)) * [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567)) * [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0 * [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues * [`4e1a87a`](actions/setup-node@4e1a87a) Update dist * [`360237f`](actions/setup-node@360237f) Strict equality * [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@actions/cache` to 5.1.0, log cache write denied * [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548)) * [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558)) * Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
##### [vv7.0.0](https://github.com/actions/setup-node/releases/tag/v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@gowridurgad](https://github.com/gowridurgad) in [#1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [#1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@gowridurgad](https://github.com/gowridurgad) in [#1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [#1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [#1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [#1569](actions/setup-node#1569) ##### New Contributors - [@chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#1536](actions/setup-node#1536) - [@deiga](https://github.com/deiga) made their first contribution in [#1548](actions/setup-node#1548) - [@jasongin](https://github.com/jasongin) made their first contribution in [#1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ##### [vv7](actions/setup-node@v6.5.0...v7.0.0)
##### [vv7.0.0](https://github.com/actions/setup-node/releases/tag/v7.0.0) ##### What's Changed ##### Enhancements: - Add cache-primary-key and cache-matched-key as outputs by [@gowridurgad](https://github.com/gowridurgad) in [#1577](actions/setup-node#1577) - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [#1574](actions/setup-node#1574) ##### Bug fixes: - Remove dummy NODE\_AUTH\_TOKEN export by [@gowridurgad](https://github.com/gowridurgad) in [#1558](actions/setup-node#1558) - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [#1548](actions/setup-node#1548) ##### Documentation updates: - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1536](actions/setup-node#1536) - docs: Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [#1550](actions/setup-node#1550) - docs: Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1567](actions/setup-node#1567) ##### Dependency update: - Upgrade [@actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [#1569](actions/setup-node#1569) ##### New Contributors - [@chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#1536](actions/setup-node#1536) - [@deiga](https://github.com/deiga) made their first contribution in [#1548](actions/setup-node#1548) - [@jasongin](https://github.com/jasongin) made their first contribution in [#1569](actions/setup-node#1569) **Full Changelog**: <actions/setup-node@v6...v7.0.0> ##### [vv7](actions/setup-node@v6.5.0...v7.0.0) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Third attempt at getting the v2.1.0 publish through. This one is backed by the maintainers' own fix rather than inference from an error message. ## What was actually wrong `actions/setup-node` exported `NODE_AUTH_TOKEN` as the literal string `XXXXX-XXXXX-XXXXX-XXXXX` in **every major before v7**, whenever `registry-url` was set and the caller supplied no real token. The `.npmrc` it writes references that variable, so npm found a credential, sent garbage, and never attempted the OIDC exchange. [actions/setup-node#1558](actions/setup-node#1558) removed the dummy export; it shipped in v7.0.0. Neither observed error names the real problem: | config | error | what it reads as | what it was | |---|---|---|---| | v4 + `registry-url` | `E404` on the `PUT` | package does not exist | bad credential | | v4 − `registry-url` | `ENEEDAUTH` | not logged in | no exchange attempted | **Provenance signed correctly in both runs** — it takes the OIDC token straight from GitHub and never touches the registry credential. A signed provenance line is not evidence that trusted publishing works, and that is exactly what made the first failure look like a success. ## Why `registry-url` comes back #29 removed it on the theory that any configured credential suppresses the OIDC fallback. The credential was the problem, not the registry line — and the documented recipe ([actions/setup-node#1536](actions/setup-node#1536)) requires `registry-url`, because it writes the userconfig naming the registry the exchange runs against. Removing it is what produced `ENEEDAUTH`. Also moves to `node-version: 24`, which ships an npm already past the 11.5.1 floor. The explicit floor step stays as the guarantee. The comment block is rewritten — it previously said "DO NOT ADD registry-url", which was the wrong lesson drawn from the right evidence, and would have misled the next reader. ## Verification GitHub-side OIDC is confirmed working: run 31735187247 signed and logged a provenance statement to the transparency log, which requires a successfully minted `id-token`. So the remaining variable is npm's credential handling, which is what this changes. Not verifiable before merge — the workflow only runs on a `v*` tag. Tag `v2.1.0` will be moved to the merge commit. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01KjtKNDE8CbYiWjuYR2XsJZ
| Back | FazBrowse Home | New Git URL |
Description:
This pull request updates the documentation to add guidance on publishing npm packages using Trusted Publisher (OIDC), which allows secure publishing from GitHub Actions without long-lived npm tokens. The changes clarify requirements, provide an example workflow, and link to relevant resources.
Documentation updates for npm Trusted Publisher (OIDC):
Related issue:
#1445
Check list: