FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Comparing v0.12.3...v0.12.4 · supabase/ssr · GitHub

/ ssr Public
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: supabase/ssr
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.12.3
Choose a base ref
Could not load branches
Nothing to show
{{ refName }}
...
head repository: supabase/ssr
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.12.4
Choose a head ref
Could not load branches
Nothing to show
{{ refName }}
  • 12 commits
  • 21 files changed
  • 6 contributors

Commits on Jul 15, 2026

  1. chore: update @supabase/supabase-js to v2.110.6 (#265)

    This PR updates `@supabase/supabase-js` to v2.110.6.
    
    **Source**: supabase-js-stable-release
    
    ---
    
    ## Release Notes
    
    ## v2.110.6
    
    ## 2.110.6 (2026-07-15)
    
    ### 🩹 Fixes
    
    - **postgrest:** type hinted self-referencing embeds as arrays
    ([#2520](supabase/supabase-js#2520))
    - **realtime:** forward opts to send() in track()
    ([#2490](supabase/supabase-js#2490))
    - **supabase:** warn instead of throw for unrecognized sb_ API key
    subtypes ([#2526](supabase/supabase-js#2526))
    
    ### ❤️ Thank You
    
    - Franco Kaddour @FrancoKaddour
    - Katerina Skroumpelou @mandarini
    
    This PR was created automatically.
    
    Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
    Configuration menu
    Copy the full SHA
    c6fb1f1 View commit details
    Browse the repository at this point in the history

Commits on Jul 16, 2026

  1. chore: update @supabase/supabase-js to v2.110.7 (#267)

    This PR updates `@supabase/supabase-js` to v2.110.7.
    
    **Source**: supabase-js-stable-release
    
    ---
    
    ## Release Notes
    
    ## v2.110.7
    
    ## 2.110.7 (2026-07-16)
    
    ### 🩹 Fixes
    
    - **postgrest:** correct self-reference inference
    ([#2525](supabase/supabase-js#2525))
    - **realtime:** trigger set auth on INITIAL_SESSION event
    ([#2531](supabase/supabase-js#2531))
    - **realtime:** update phoenix to fix presence issue
    ([#2532](supabase/supabase-js#2532))
    
    ### ❤️ Thank You
    
    - Eduardo Gurgel
    - Filipe Cabaço @filipecabaco
    - Vaibhav @7ttp
    
    This PR was created automatically.
    
    Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
    Configuration menu
    Copy the full SHA
    55a3007 View commit details
    Browse the repository at this point in the history

Commits on Jul 20, 2026

  1. build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#268)

    Bumps [actions/setup-node](https://github.com/actions/setup-node) from
    6.4.0 to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/setup-node/releases">actions/setup-node's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <h3>Enhancements:</h3>
    <ul>
    <li>Add cache-primary-key and cache-matched-key as outputs by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1577">actions/setup-node#1577</a></li>
    <li>Migrate to ESM and upgrade dependencies by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1574">actions/setup-node#1574</a></li>
    </ul>
    <h3>Bug fixes:</h3>
    <ul>
    <li>Remove dummy NODE_AUTH_TOKEN export by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1558">actions/setup-node#1558</a></li>
    <li>Only use <code>mirrorToken</code> in <code>getManifest</code> if
    it's provided by <a
    href="https://github.com/deiga"><code>@​deiga</code></a> in <a
    href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
    </ul>
    <h3>Documentation updates:</h3>
    <ul>
    <li>Add documentation for publishing to npm with Trusted Publisher
    (OIDC) by <a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
    <li>docs: Update restore-only cache documentation by <a
    href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1550">actions/setup-node#1550</a></li>
    <li>docs: Update caching recommendations to mitigate cache poisoning
    risks by <a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1567">actions/setup-node#1567</a></li>
    </ul>
    <h3>Dependency update:</h3>
    <ul>
    <li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
    denied by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
    <li><a href="https://github.com/deiga"><code>@​deiga</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
    <li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-node/compare/v6...v7.0.0">https://github.com/actions/setup-node/compare/v6...v7.0.0</a></p>
    <h2>v6.5.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update <code>@​actions/cache</code> to 5.1.0 and add security
    overrides for undici and fast-xml-parser by <a
    href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1579">actions/setup-node#1579</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0">https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020"><code>8207627</code></a>
    Migrate to ESM and upgrade dependencies (<a
    href="https://redirect.github.com/actions/setup-node/issues/1574">#1574</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4"><code>04be95c</code></a>
    Add cache-primary-key and cache-matched-key as outputs (<a
    href="https://redirect.github.com/actions/setup-node/issues/1577">#1577</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140"><code>7c2c68d</code></a>
    docs: Update caching recommendations to mitigate cache poisoning risks
    (<a
    href="https://redirect.github.com/actions/setup-node/issues/1567">#1567</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d"><code>6a61c03</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/setup-node/issues/1569">#1569</a>
    from jasongin/update-actions-cache-5.1.0</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f"><code>30eb73b</code></a>
    Resolve high-severity audit issues</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f"><code>4e1a87a</code></a>
    Update dist</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574"><code>360237f</code></a>
    Strict equality</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3"><code>4f8aac5</code></a>
    Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980"><code>f4a67bb</code></a>
    Only use <code>mirrorToken</code> in <code>getManifest</code> if it's
    provided (<a
    href="https://redirect.github.com/actions/setup-node/issues/1548">#1548</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75"><code>0355742</code></a>
    Remove dummy NODE_AUTH_TOKEN export (<a
    href="https://redirect.github.com/actions/setup-node/issues/1558">#1558</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-node&package-manager=github_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 20, 2026
    Configuration menu
    Copy the full SHA
    cb961f2 View commit details
    Browse the repository at this point in the history
  2. docs: set up typedoc (#266)

    Sets up TypeDoc for generating API reference documentation. Adds a
    `typedoc.json` config targeting `src/index.ts`, a `docs` script that
    builds HTML output plus a `spec.json`, and a GitHub Actions workflow
    that builds and deploys the docs to GitHub Pages on pushes to `main`.
    
    Also adds `@category` JSDoc tags across public exports (clients, cookie
    helpers, types) so TypeDoc groups them sensibly, and reorders a few
    imports for consistency.
    mandarini authored Jul 20, 2026
    Configuration menu
    Copy the full SHA
    425ac14 View commit details
    Browse the repository at this point in the history

Commits on Jul 22, 2026

  1. chore: update @supabase/supabase-js to v2.110.8 (#269)

    This PR updates `@supabase/supabase-js` to v2.110.8.
    
    **Source**: supabase-js-stable-release
    
    ---
    
    ## Release Notes
    
    ## v2.110.8
    
    ## 2.110.8 (2026-07-21)
    
    ### 🩹 Fixes
    
    - **auth:** downgrade aborted/transient fetch failures from
    console.error to warn
    ([#2544](supabase/supabase-js#2544))
    - **functions:** clean up cross-signal abort listener on invoke() return
    ([#2487](supabase/supabase-js#2487))
    - **functions:** match response Content-Type case-insensitively
    ([#2515](supabase/supabase-js#2515))
    - **storage:** url-encode object key in CDN purge methods
    ([#2545](supabase/supabase-js#2545))
    - **supabase:** skip Node warning in Deno
    ([#2541](supabase/supabase-js#2541))
    
    ### ❤️ Thank You
    
    - Franco Kaddour @FrancoKaddour
    - Katerina Skroumpelou @mandarini
    - Pedro Henrique
    - Vaibhav @7ttp
    
    This PR was created automatically.
    
    Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
    Configuration menu
    Copy the full SHA
    1cf085d View commit details
    Browse the repository at this point in the history

Commits on Jul 24, 2026

  1. build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#272)

    Bumps [actions/setup-node](https://github.com/actions/setup-node) from
    6.4.0 to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/setup-node/releases">actions/setup-node's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <h3>Enhancements:</h3>
    <ul>
    <li>Add cache-primary-key and cache-matched-key as outputs by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1577">actions/setup-node#1577</a></li>
    <li>Migrate to ESM and upgrade dependencies by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1574">actions/setup-node#1574</a></li>
    </ul>
    <h3>Bug fixes:</h3>
    <ul>
    <li>Remove dummy NODE_AUTH_TOKEN export by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-node/pull/1558">actions/setup-node#1558</a></li>
    <li>Only use <code>mirrorToken</code> in <code>getManifest</code> if
    it's provided by <a
    href="https://github.com/deiga"><code>@​deiga</code></a> in <a
    href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
    </ul>
    <h3>Documentation updates:</h3>
    <ul>
    <li>Add documentation for publishing to npm with Trusted Publisher
    (OIDC) by <a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
    <li>docs: Update restore-only cache documentation by <a
    href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1550">actions/setup-node#1550</a></li>
    <li>docs: Update caching recommendations to mitigate cache poisoning
    risks by <a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1567">actions/setup-node#1567</a></li>
    </ul>
    <h3>Dependency update:</h3>
    <ul>
    <li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
    denied by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/chiranjib-swain"><code>@​chiranjib-swain</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1536">actions/setup-node#1536</a></li>
    <li><a href="https://github.com/deiga"><code>@​deiga</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1548">actions/setup-node#1548</a></li>
    <li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-node/pull/1569">actions/setup-node#1569</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-node/compare/v6...v7.0.0">https://github.com/actions/setup-node/compare/v6...v7.0.0</a></p>
    <h2>v6.5.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update <code>@​actions/cache</code> to 5.1.0 and add security
    overrides for undici and fast-xml-parser by <a
    href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-node/pull/1579">actions/setup-node#1579</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0">https://github.com/actions/setup-node/compare/v6.4.0...v6.5.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/setup-node/commit/820762786026740c76f36085b0efc47a31fe5020"><code>8207627</code></a>
    Migrate to ESM and upgrade dependencies (<a
    href="https://redirect.github.com/actions/setup-node/issues/1574">#1574</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/04be95cf3511ea51ebf9f224ddfb99cc7ab87cd4"><code>04be95c</code></a>
    Add cache-primary-key and cache-matched-key as outputs (<a
    href="https://redirect.github.com/actions/setup-node/issues/1577">#1577</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/7c2c68d20d402ed6a201ada70a81341941093140"><code>7c2c68d</code></a>
    docs: Update caching recommendations to mitigate cache poisoning risks
    (<a
    href="https://redirect.github.com/actions/setup-node/issues/1567">#1567</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/6a61c0375d66246de94630495909f12cf8dac84d"><code>6a61c03</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/setup-node/issues/1569">#1569</a>
    from jasongin/update-actions-cache-5.1.0</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/30eb73b41ded577900c1ebf968ef95cdf8f7434f"><code>30eb73b</code></a>
    Resolve high-severity audit issues</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/4e1a87a501d0302f99e30e2748568adcb388d09f"><code>4e1a87a</code></a>
    Update dist</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/360237f0c01778d0c17291f75c56d6feae4f7574"><code>360237f</code></a>
    Strict equality</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/4f8aac5beb2f0854bc79651567a18c67eb0b9de3"><code>4f8aac5</code></a>
    Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/f4a67bbeca970f103397d3d2b9462cf787cd2980"><code>f4a67bb</code></a>
    Only use <code>mirrorToken</code> in <code>getManifest</code> if it's
    provided (<a
    href="https://redirect.github.com/actions/setup-node/issues/1548">#1548</a>)</li>
    <li><a
    href="https://github.com/actions/setup-node/commit/0355742c943ddb13ca8a6b700f824231caa91e75"><code>0355742</code></a>
    Remove dummy NODE_AUTH_TOKEN export (<a
    href="https://redirect.github.com/actions/setup-node/issues/1558">#1558</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/setup-node/compare/v6.4.0...820762786026740c76f36085b0efc47a31fe5020">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-node&package-manager=github_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 24, 2026
    Configuration menu
    Copy the full SHA
    090ee12 View commit details
    Browse the repository at this point in the history
  2. build(deps): bump pnpm/action-setup from 6.0.5 to 6.0.9 (#271)

    Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from
    6.0.5 to 6.0.9.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/pnpm/action-setup/releases">pnpm/action-setup's
    releases</a>.</em></p>
    <blockquote>
    <h2>v6.0.9</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>fix: update pnpm to v11.7.0 by <a
    href="https://github.com/zkochan"><code>@​zkochan</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/267">pnpm/action-setup#267</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/pnpm/action-setup/compare/v6...v6.0.9">https://github.com/pnpm/action-setup/compare/v6...v6.0.9</a></p>
    <h2>v6.0.8</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>docs(README): fix <code>cache_dependency_path</code> type by <a
    href="https://github.com/haines"><code>@​haines</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/257">pnpm/action-setup#257</a></li>
    <li>fix: drop patchPnpmEnv so standalone+self-update works on Windows by
    <a href="https://github.com/zkochan"><code>@​zkochan</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/258">pnpm/action-setup#258</a></li>
    <li>fix: update pnpm to 11.1.1 by <a
    href="https://github.com/mungodewar"><code>@​mungodewar</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/248">pnpm/action-setup#248</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/mungodewar"><code>@​mungodewar</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/248">pnpm/action-setup#248</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8">https://github.com/pnpm/action-setup/compare/v6.0.7...v6.0.8</a></p>
    <h2>v6.0.7</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>fix: honor devEngines.packageManager.onFail=error (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/252">#252</a>)
    by <a href="https://github.com/zkochan"><code>@​zkochan</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/254">pnpm/action-setup#254</a></li>
    <li>fix: restore inputs from state in post by <a
    href="https://github.com/haines"><code>@​haines</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/255">pnpm/action-setup#255</a></li>
    <li>fix: self-update bootstrap to packageManager-pinned version (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/233">#233</a>)
    by <a href="https://github.com/zkochan"><code>@​zkochan</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/256">pnpm/action-setup#256</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/haines"><code>@​haines</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/255">pnpm/action-setup#255</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7">https://github.com/pnpm/action-setup/compare/v6.0.6...v6.0.7</a></p>
    <h2>v6.0.6</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>fix: bin_dest output points to self-updated pnpm, not bootstrap by
    <a href="https://github.com/zkochan"><code>@​zkochan</code></a> in <a
    href="https://redirect.github.com/pnpm/action-setup/pull/249">pnpm/action-setup#249</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6">https://github.com/pnpm/action-setup/compare/v6.0.5...v6.0.6</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/0ebf47130e4866e96fce0953f49152a61190b271"><code>0ebf471</code></a>
    fix: update pnpm to v11.7.0 (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/267">#267</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/0e279bb959325dab635dd2c09392533439d90093"><code>0e279bb</code></a>
    fix: update pnpm to 11.1.1 (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/248">#248</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/3e835812ef01165f4f8ae08ade56da44427ed4e0"><code>3e83581</code></a>
    fix: drop patchPnpmEnv so standalone+self-update works on Windows (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/258">#258</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/551b42e879e37e74d986effdd2a1647d2b02d464"><code>551b42e</code></a>
    docs(README): fix <code>cache_dependency_path</code> type (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/257">#257</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/739bfe42ca9233c5e6aca07c1a25a9d34aca49b0"><code>739bfe4</code></a>
    fix: self-update bootstrap to packageManager-pinned version (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/233">#233</a>)
    (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/256">#256</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/f61705d907761b3b5209e83910fafd1fea50c5a1"><code>f61705d</code></a>
    chore: add CODEOWNERS</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/7a5507b117647ab83e96e9db317ba2234056ebf3"><code>7a5507b</code></a>
    fix: restore inputs from state in post (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/255">#255</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/1155470f3e5fb872accd4d104b8dfcda41f676ce"><code>1155470</code></a>
    fix: honor devEngines.packageManager.onFail=error (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/252">#252</a>)
    (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/254">#254</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/91ab88e2619ed1f46221f0ba42d1492c02baf788"><code>91ab88e</code></a>
    fix: bin_dest output points to self-updated pnpm, not bootstrap (<a
    href="https://redirect.github.com/pnpm/action-setup/issues/249">#249</a>)</li>
    <li><a
    href="https://github.com/pnpm/action-setup/commit/e578e19d19d31b011b841ba2aca34731a5f706a5"><code>e578e19</code></a>
    fix: update pnpm to 11.0.4</li>
    <li>See full diff in <a
    href="https://github.com/pnpm/action-setup/compare/v6.0.5...0ebf47130e4866e96fce0953f49152a61190b271">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pnpm/action-setup&package-manager=github_actions&previous-version=6.0.5&new-version=6.0.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 24, 2026
    Configuration menu
    Copy the full SHA
    f4ffa24 View commit details
    Browse the repository at this point in the history
  3. build(deps): bump actions/checkout from 6.0.2 to 7.0.1 (#270)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2
    to 7.0.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>skip running unsafe pr check if input is default by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
    <li>trim only ascii whitespace for branch by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
    <li>escape values passed to --unset by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
    <li>Various dependency updates</li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    <h2>v6.1.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li><strong>[BREAKING]</strong> backport
    <code>allow-unsafe-pr-checkout</code> to v6 by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2500">actions/checkout#2500</a></li>
    <li>backport fixes to releases-v6 by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2527">actions/checkout#2527</a></li>
    </ul>
    <p><a
    href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a>
    for more details about this breaking change</p>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v6.1.0">https://github.com/actions/checkout/compare/v6.0.3...v6.1.0</a></p>
    <h2>v6.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update changelog by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>Update changelog for v6.0.3 by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.1</h2>
    <ul>
    <li>Skip running unsafe pr check if input is default by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
    <li>Trim only ascii whitespace for branch by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
    <li>Escape values passed to --unset by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
    <li>Various dependency updates</li>
    </ul>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Various dependency updates</li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
    prep v7.0.1 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
    escape values passed to --unset (<a
    href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
    trim only ascii whitespace for branch (<a
    href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
    skip running unsafe pr check if input is default (<a
    href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
    Bump the minor-actions-dependencies group with 2 updates (<a
    href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
    eslint 9 (<a
    href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
    Bump actions/upload-artifact from 4 to 7 (<a
    href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
    Bump actions/checkout from 6 to 7 (<a
    href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
    Bump docker/login-action from 3.3.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
    Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/checkout/compare/v6.0.2...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/checkout&package-manager=github_actions&previous-version=6.0.2&new-version=7.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 24, 2026
    Configuration menu
    Copy the full SHA
    1c561ad View commit details
    Browse the repository at this point in the history

Commits on Jul 27, 2026

  1. chore: update @supabase/supabase-js to v2.110.9 (#273)

    This PR updates `@supabase/supabase-js` to v2.110.9.
    
    **Source**: supabase-js-stable-release
    
    ---
    
    ## Release Notes
    
    ## v2.110.9
    
    ## 2.110.9 (2026-07-27)
    
    ### 🩹 Fixes
    
    - **auth:** downgrade stale refresh token console noise
    ([#2559](supabase/supabase-js#2559))
    - **realtime:** preserve presence refs
    ([#2566](supabase/supabase-js#2566))
    - **repo:** override sharp to >=0.35.0 to clear libvips advisory
    ([#2548](supabase/supabase-js#2548))
    - **repo:** populate symbols in sdk-compliance so capabilities are
    verifiable ([#2547](supabase/supabase-js#2547))
    - **repo:** bump postcss, babel, next to clear audit advisories
    ([#2561](supabase/supabase-js#2561))
    
    ### ❤️ Thank You
    
    - Katerina Skroumpelou @mandarini
    - Vaibhav @7ttp
    
    This PR was created automatically.
    
    Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
    Configuration menu
    Copy the full SHA
    4331f8a View commit details
    Browse the repository at this point in the history

Commits on Jul 28, 2026

  1. fix: flush PKCE verifier slot removals on the server (#275)

    auth-js stores each in-flight PKCE code verifier in its own cookie slot
    (`<storageKey>-flow-<flowId>-code-verifier`), bounded by a ring of five.
    The server storage applies writes to `-code-verifier` keys immediately
    but leaves removals buffered until an `onAuthStateChange` event, and a
    flow start fires no such event: when the ring evicts the oldest slot,
    that removal is discarded while the index write dropping the evicted id
    is applied, orphaning a verifier cookie that nothing references and no
    cleanup path can reach.
    
    This applies the storage on removal for per-flow slot keys only, so the
    fixed `-code-verifier` key and the `-flows-code-verifier` index keep
    their existing buffered behavior and no current code path changes.
    Impact is cookie hygiene rather than credential exposure, since a
    verifier with no matching auth code grants nothing.
    
    `docs/design.md` is the only place documenting when the server applies
    storage to cookies, so the new exception is recorded there. That section
    also never mentioned the existing immediate flush for verifier writes,
    and its event list had drifted from `createServerClient.ts`, so both are
    corrected alongside it.
    mandarini authored Jul 28, 2026
    Configuration menu
    Copy the full SHA
    6df6f03 View commit details
    Browse the repository at this point in the history
  2. chore: update @supabase/supabase-js to v2.111.0 (#277)

    This PR updates `@supabase/supabase-js` to v2.111.0.
    
    **Source**: supabase-js-stable-release
    
    ---
    
    ## Test update included
    
    supabase-js 2.111.0
    ([supabase/supabase-js#2569](supabase/supabase-js#2569))
    stores PKCE verifiers in per-flow slots, so a flow start now writes
    three storage keys instead of one: the per-flow slot, the flow index,
    and the legacy fixed `-code-verifier` key. Our server storage adapter
    flushes each of these immediately (by design — slot keys deliberately
    end in `-code-verifier`), so `setAll` now fires 3 times per flow start
    instead of 1.
    
    The PKCE verifier test asserted that internal flush count and
    snapshotted the exact cookies, so we updated it: expect 3 `setAll`
    calls, normalize the random flow id in slot cookie names, and regenerate
    the snapshots. Test-only change — no source changes needed, the adapter
    was already prepared in #275.
    
    **Why this isn't a breaking change in supabase-js:** the writes are
    purely additive — the legacy key is still written with the same format,
    and `exchangeCodeForSession` without a flow id reads it exactly as
    before. The new slot-only lookup only kicks in when a flow id is
    explicitly passed or the opt-in
    `experimental.appendPkceFlowIdToRedirects` flag is enabled.
    
    ---
    
    ## Release Notes
    
    ## v2.111.0
    
    ## 2.111.0 (2026-07-28)
    
    ### 🚀 Features
    
    - **auth:** store PKCE verifiers in per-flow slots to survive
    overlapping flows
    ([#2569](supabase/supabase-js#2569))
    
    ### ❤️ Thank You
    
    - Katerina Skroumpelou @mandarini
    
    This PR was created automatically.
    
    ---------
    
    Co-authored-by: supabase-workflow-trigger[bot] <266661614+supabase-workflow-trigger[bot]@users.noreply.github.com>
    Co-authored-by: Katerina Skroumpelou <sk.katherine@gmail.com>
    3 people authored Jul 28, 2026
    Configuration menu
    Copy the full SHA
    e17f546 View commit details
    Browse the repository at this point in the history
  3. chore(main): release 0.12.4 (#276)

    🤖 I have created a release *beep* *boop*
    ---
    
    
    ## [0.12.4](v0.12.3...v0.12.4)
    (2026-07-28)
    
    
    ### Bug Fixes
    
    * flush PKCE verifier slot removals on the server
    ([#275](#275))
    ([6df6f03](6df6f03))
    
    ---
    This PR was generated with [Release
    Please](https://github.com/googleapis/release-please). See
    [documentation](https://github.com/googleapis/release-please#release-please).
    
    Co-authored-by: supabase-releaser[bot] <223506987+supabase-releaser[bot]@users.noreply.github.com>
    supabase-releaser[bot] authored Jul 28, 2026
    Configuration menu
    Copy the full SHA
    50e3409 View commit details
    Browse the repository at this point in the history
Loading

Back | FazBrowse Home | New Git URL