chore(deps): bump EndBug/add-and-commit from 10 to 11 - #59
chore(deps): bump EndBug/add-and-commit from 10 to 11#59dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) from 10 to 11. - [Release notes](https://github.com/endbug/add-and-commit/releases) - [Commits](EndBug/add-and-commit@v10...v11) --- updated-dependencies: - dependency-name: EndBug/add-and-commit dependency-version: '11' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Updates the GitHub Actions workflow to use a newer major version of the EndBug/add-and-commit action for the release commit step.
Changes:
- Bump
EndBug/add-and-commitfrom@v10to@v11in the release workflow
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # commit changes to temporary release branch and create a new tag | ||
| - name: Commit changes | ||
| uses: EndBug/add-and-commit@v10 | ||
| uses: EndBug/add-and-commit@v11 |
|
Safe to merge: Major bump EndBug/add-and-commit 10 -> 11; no deterministic risk terms found in Dependabot release notes Changed files: .github/workflows/wp-gh-release-ops.yml. Classification: safe. |
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
udx-github
left a comment
There was a problem hiding this comment.
Approved by Dependabot Actions review automation.
Bumps EndBug/add-and-commit from 10 to 11.
Release notes
Sourced from EndBug/add-and-commit's releases.
Commits
645ecc011.0.006e788ffix: neutralize bidi and control chars in action logs (#763)68ec86aci: pin actions-tagger and restrict release workflow permissions (#762)f1bb0ccfix: do not report committed=true for empty commit SHA (#757)ebc24bffix: refuse unexpected gitlinks staged by git add (#761)75038f8fix: reject unmatched quotes in matchGitArgs to prevent flag injection (#760)d07c930fix: reject -F/--file git args that can exfiltrate runner files (#759)0971289fix: stop logging full git config (credential leak) (#758)c38a33bfix: verify committed lib/ matches source in CI (#756)b4a0134fix: prevent git option injection via new_branch (#755)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)