Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: fengmk2/github-actions
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: master
Choose a base ref
...
head repository: node-modules/github-actions
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: master
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 5 commits
  • 9 files changed
  • 2 contributors

Commits on Sep 8, 2025

  1. Configuration menu
    Copy the full SHA
    818ae17 View commit details
    Browse the repository at this point in the history

Commits on Oct 23, 2025

  1. Make NPM_TOKEN optional in node-release workflow

    Changed NPM_TOKEN requirement from true to false.
    fengmk2 authored Oct 23, 2025
    Configuration menu
    Copy the full SHA
    5aa8776 View commit details
    Browse the repository at this point in the history

Commits on Mar 5, 2026

  1. fix: update semantic-release and @semantic-release/npm to stable vers…

    …ions (#17)
    
    ## Problem
    
    `@semantic-release/npm@13.0.0-alpha.5` depends on
    `npm@github:npm/cli#oidc`, but the `oidc` branch has been deleted from
    the `npm/cli` repo, causing `npm install` to fail:
    
    ```
    npm error command git --no-replace-objects checkout oidc
    npm error error: pathspec 'oidc' did not match any file(s) known to git
    ```
    
    This breaks all downstream release workflows (e.g.
    [cnpm/unpkg-white-list](https://github.com/cnpm/unpkg-white-list/actions/runs/22700918457/job/65844808852)).
    
    ## Fix
    
    - `@semantic-release/npm`: `13.0.0-alpha.5` → `^13.1.5` (stable, uses
    `npm@^11.6.2` from registry)
    - `semantic-release`: `25.0.0-alpha.4` → `^25.0.3` (stable)
    
    <!-- This is an auto-generated comment: release notes by coderabbit.ai
    -->
    
    ## Summary by CodeRabbit
    
    * **Chores**
    * Updated release automation dependencies to stable versions for
    enhanced reliability and compatibility.
    
    <!-- end of auto-generated comment: release notes by coderabbit.ai -->
    fengmk2 authored Mar 5, 2026
    Configuration menu
    Copy the full SHA
    3b7e5e1 View commit details
    Browse the repository at this point in the history
  2. chore: Configure Renovate (#16)

    Welcome to [Renovate](https://redirect.github.com/renovatebot/renovate)!
    This is an onboarding PR to help you understand and configure settings
    before regular Pull Requests begin.
    
    🚦 To activate Renovate, merge this Pull Request. To disable Renovate,
    simply close this Pull Request unmerged.
    
    
    
    ---
    ### Detected Package Files
    
     * `.github/workflows/node-release-no-provenance.yml` (github-actions)
     * `.github/workflows/node-release.yml` (github-actions)
     * `.github/workflows/node-test-mysql.yml` (github-actions)
     * `.github/workflows/node-test-parallel.yml` (github-actions)
     * `.github/workflows/node-test.yml` (github-actions)
     * `.github/workflows/npm-release.yml` (github-actions)
     * `scripts/npm-release/package.json` (npm)
     * `scripts/release/package.json` (npm)
    
    ### Configuration Summary
    
    Based on the default config's presets, Renovate will:
    
      - Start dependency updates only once this onboarding PR is merged
      - Hopefully safe environment variables to allow users to configure.
      - Show all Merge Confidence badges for pull requests.
      - Enable Renovate Dependency Dashboard creation.
    - Use semantic commit type `fix` for dependencies and `chore` for all
    others if semantic commits are in use.
    - Ignore `node_modules`, `bower_components`, `vendor` and various
    test/tests (except for nuget) directories.
      - Group known monorepo packages together.
      - Use curated list of recommended non-monorepo package groupings.
    - Show only the Age and Confidence Merge Confidence badges for pull
    requests.
      - Apply crowd-sourced package replacement rules.
      - Apply crowd-sourced workarounds for known problems with packages.
    - Ensure that every dependency pinned by digest and sourced from
    GitHub.com contains a link to the commit-to-commit diff
      - Correctly link to the source code for golang.org/x packages
      - Link to pkg.go.dev/... for golang.org/x packages' title
    
    🔡 Do you want to change how Renovate upgrades your dependencies? Add
    your custom config to `renovate.json` in this branch. Renovate will
    update the Pull Request description the next time it runs.
    
    ---
    
    ### What to Expect
    
    With your current configuration, Renovate will create 12 Pull Requests:
    
    <details>
    <summary>fix(deps): update semantic-release monorepo</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/semantic-release-monorepo`
      - Merge into: `master`
    - Upgrade
    [@semantic-release/npm](https://redirect.github.com/semantic-release/npm)
    to `13.1.3`
    - Upgrade
    [semantic-release](https://redirect.github.com/semantic-release/semantic-release)
    to `25.0.2`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update actions/checkout action to v6</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/actions-checkout-6.x`
      - Merge into: `master`
    - Upgrade
    [actions/checkout](https://redirect.github.com/actions/checkout) to `v6`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update actions/github-script action to
    v8</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/actions-github-script-8.x`
      - Merge into: `master`
    - Upgrade
    [actions/github-script](https://redirect.github.com/actions/github-script)
    to `v8`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update actions/setup-node action to v6</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/actions-setup-node-6.x`
      - Merge into: `master`
    - Upgrade
    [actions/setup-node](https://redirect.github.com/actions/setup-node) to
    `v6`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update codecov/codecov-action action to
    v5</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/codecov-codecov-action-5.x`
      - Merge into: `master`
    - Upgrade
    [codecov/codecov-action](https://redirect.github.com/codecov/codecov-action)
    to `v5`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update dependency @&#8203;types/node to
    v24</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/node-24.x`
      - Merge into: `master`
    - Upgrade
    [@types/node](https://redirect.github.com/DefinitelyTyped/DefinitelyTyped)
    to `^24.0.0`
    
    
    </details>
    
    <details>
    <summary>chore(deps): update dependency @&#8203;types/semantic-release
    to v21</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/semantic-release-21.x`
      - Merge into: `master`
      - Upgrade @&#8203;types/semantic-release to `^21.0.0`
    
    
    </details>
    
    <details>
    <summary>fix(deps): update dependency @&#8203;actions/core to
    v2</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/actions-core-2.x`
      - Merge into: `master`
    - Upgrade [@actions/core](https://redirect.github.com/actions/toolkit)
    to `^2.0.0`
    
    
    </details>
    
    <details>
    <summary>fix(deps): update dependency @&#8203;actions/exec to
    v2</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/actions-exec-2.x`
      - Merge into: `master`
    - Upgrade [@actions/exec](https://redirect.github.com/actions/toolkit)
    to `^2.0.0`
    
    
    </details>
    
    <details>
    <summary>fix(deps): update dependency
    conventional-changelog-conventionalcommits to v9</summary>
    
      - Schedule: ["at any time"]
    - Branch name: `renovate/conventional-changelog-conventionalcommits-9.x`
      - Merge into: `master`
    - Upgrade
    [conventional-changelog-conventionalcommits](https://redirect.github.com/conventional-changelog/conventional-changelog)
    to `^9.0.0`
    
    
    </details>
    
    <details>
    <summary>fix(deps): update dependency undici to v7</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/undici-7.x`
      - Merge into: `master`
    - Upgrade [undici](https://redirect.github.com/nodejs/undici) to
    `^7.0.0`
    
    
    </details>
    
    <details>
    <summary>fix(deps): update semantic-release monorepo (major)</summary>
    
      - Schedule: ["at any time"]
      - Branch name: `renovate/major-semantic-release-monorepo`
      - Merge into: `master`
    - Upgrade
    [@semantic-release/exec](https://redirect.github.com/semantic-release/exec)
    to `^7.0.0`
    - Upgrade
    [@semantic-release/github](https://redirect.github.com/semantic-release/github)
    to `^12.0.0`
    - Upgrade
    [semantic-release](https://redirect.github.com/semantic-release/semantic-release)
    to `^25.0.0`
    
    
    </details>
    
    
    
    🚸 Branch creation will be limited to maximum 2 per hour, so it doesn't
    swamp any CI resources or overwhelm the project. See docs for
    `prhourlylimit` for details.
    
    
    ---
    
    ❓ Got questions? Check out Renovate's
    [Docs](https://docs.renovatebot.com/), particularly the Getting Started
    section.
    If you need any further assistance then you can also [request help
    here](https://redirect.github.com/renovatebot/renovate/discussions).
    
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/node-modules/github-actions).
    
    
    <!--renovate-config-hash:e80b4e42a3043bc12fa0640db4bac392d2bf770acf841360d7c8ceeeac2ec1a9-->
    
    Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
    renovate[bot] authored Mar 5, 2026
    Configuration menu
    Copy the full SHA
    c0c86f6 View commit details
    Browse the repository at this point in the history

Commits on Aug 16, 2026

  1. chore: bump actions to node24 runtime (#36)

    Every run of these reusable workflows now emits:
    
    > Node.js 20 is deprecated. The following actions target Node.js 20 but
    are being forced to run on Node.js 24: actions/checkout@v4,
    actions/setup-node@v4.
    
    See the [runner
    changelog](https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/).
    
    Bumps:
    
    - `actions/checkout` v4 -> v7
    - `actions/setup-node` v4 -> v7
    - `actions/github-script` v7 -> v9
    - `codecov/codecov-action` v3 -> v7 (v3 still targets node16)
    
    `github-script` is only used for a pure-JS architecture calculation with
    no octokit calls, so the v8 Octokit change does not apply.
    `codecov-action` is only passed `token`, which v7 still accepts.
    
    One behaviour guard: setup-node v5 started enabling npm caching
    automatically when `package.json` has a `packageManager` field, and v6
    narrowed that to npm. These workflows install with `npm i
    --no-package-lock`, so auto-caching would fail on repos with no
    lockfile. Every `setup-node` step now passes `package-manager-cache:
    false` to keep the v4 behaviour.
    
    Caveat for downstream: checkout v7 refuses to check out fork PR code
    when the *caller* workflow is triggered by `pull_request_target` or
    `workflow_run`, unless it sets `allow-unsafe-pr-checkout: true`
    ([actions/checkout#2454](actions/checkout#2454)).
    Repos calling these workflows from a plain `pull_request` trigger are
    unaffected.
    
    Found while clearing the same warning on
    [cnpm/cnpmcore](https://github.com/cnpm/cnpmcore/actions/runs/31931686405),
    which consumes `npm-release.yml` through the `cnpm/github-actions` fork.
    fengmk2 authored Aug 16, 2026
    Configuration menu
    Copy the full SHA
    9deffd2 View commit details
    Browse the repository at this point in the history
Loading