Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: astral-sh/setup-uv
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v8.2.0
Choose a base ref
...
head repository: astral-sh/setup-uv
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v8.3.0
Choose a head ref
  • 18 commits
  • 32 files changed
  • 8 contributors

Commits on Jun 4, 2026

  1. chore: update known checksums for 0.11.19 (#909)

    chore: update known checksums for 0.11.19
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 4, 2026
    Configuration menu
    Copy the full SHA
    21d5da3 View commit details
    Browse the repository at this point in the history

Commits on Jun 9, 2026

  1. fix: use BUILD_ID as backup for determining os version (#912)

    On Arch Linux based runners, the setup fails with because
    `/etc/os-release` does not contain `VERSION_ID` or `VERSION_CODENAME`.
    It does contain a `BUILD_ID` which is set to `rolling`:
    
    ```sh
    $ cat /etc/os-release
    NAME="Arch Linux"
    PRETTY_NAME="Arch Linux"
    ID=arch
    BUILD_ID=rolling
    ANSI_COLOR="38;2;23;147;209"
    HOME_URL="https://archlinux.org/"
    DOCUMENTATION_URL="https://wiki.archlinux.org/"
    SUPPORT_URL="https://bbs.archlinux.org/"
    BUG_REPORT_URL="https://gitlab.archlinux.org/groups/archlinux/-/issues"
    PRIVACY_POLICY_URL="https://terms.archlinux.org/docs/privacy-policy/"
    LOGO=archlinux-logo
    ```
    
    This PR makes `getLinuxOSNameVersion` return `arch-rolling`.
    
    There is no update from arch that would change the returned value, so
    the same cache will always be used. Is this an issue? I'm not sure. At
    least it's better than crashing because `os-release` does not contain
    the expected values :).
    hgaiser authored Jun 9, 2026
    Configuration menu
    Copy the full SHA
    ed73b5d View commit details
    Browse the repository at this point in the history

Commits on Jun 11, 2026

  1. chore: update known checksums for 0.11.20 (#915)

    chore: update known checksums for 0.11.20
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 11, 2026
    Configuration menu
    Copy the full SHA
    e2f6a92 View commit details
    Browse the repository at this point in the history

Commits on Jun 12, 2026

  1. chore: update known checksums for 0.11.21 (#917)

    chore: update known checksums for 0.11.21
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 12, 2026
    Configuration menu
    Copy the full SHA
    ca5ddd0 View commit details
    Browse the repository at this point in the history

Commits on Jun 19, 2026

  1. feat: support uv.lock as a version-file source (#918)

    Adds `uv.lock` as a supported `version-file` source. When `uv` is locked
    as a
    dependency in `uv.lock`, the action now installs the exact pinned
    version,
    closing the gap reported in #682.
    
    This is useful for deterministic CI: the same uv version is used until
    the
    lockfile is updated, which avoids "CI worked yesterday, fails today"
    drift and
    reduces supply-chain exposure from auto-installing the latest release.
    
    The implementation mirrors the existing `version-file` parsers — a new
    `uv.lock`
    entry in the parser registry reads the `[[package]]` whose `name = "uv"`
    and
    returns its locked `version`. Scoped to explicit `version-file:
    uv.lock`;
    workspace auto-detection is left as a possible follow-up to avoid
    precedence
    ambiguity with `uv.toml` / `pyproject.toml`.
    
    Validation (local, Node 23; dist build is esbuild-deterministic):
    - `npm run all` → build clean, biome clean, package clean, jest 77/77
    - New tests: 3 unit (`uv-lock-file.test.ts`) + 1 integration — exact pin
    resolves
      through the full pipeline (`uv.lock` → `0.8.17`)
    - dist rebuilt + committed (single bundle, no spurious churn)
    
    related: #682
    somaz94 authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    3faa317 View commit details
    Browse the repository at this point in the history
  2. chore: update known checksums for 0.11.22 (#921)

    chore: update known checksums for 0.11.22
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    a9b33f0 View commit details
    Browse the repository at this point in the history

Commits on Jun 23, 2026

  1. chore: update known checksums for 0.11.23 (#922)

    chore: update known checksums for 0.11.23
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 23, 2026
    Configuration menu
    Copy the full SHA
    e53da17 View commit details
    Browse the repository at this point in the history

Commits on Jun 24, 2026

  1. chore: update known checksums for 0.11.24 (#925)

    chore: update known checksums for 0.11.24
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 24, 2026
    Configuration menu
    Copy the full SHA
    b173788 View commit details
    Browse the repository at this point in the history

Commits on Jun 27, 2026

  1. chore: update known checksums for 0.11.25 (#929)

    chore: update known checksums for 0.11.25
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jun 27, 2026
    Configuration menu
    Copy the full SHA
    224c887 View commit details
    Browse the repository at this point in the history
  2. Add a threat model for setup-uv (#923)

    This adds a threat model for `setup-uv` so security scanners can use it
    as a baseline in terms of what's in-, and out of scope.
    
    The TM covers credential recipients, executable and cache boundaries,
    and release authority. It treats checkout-selected interpreters, paths,
    virtual environments, symlinks, and helpers as delegated project
    authority unless they override an explicit workflow choice or cross an
    independent cache, runner, remote, or publication boundary.
    zsol authored Jun 27, 2026
    Configuration menu
    Copy the full SHA
    c86fe4e View commit details
    Browse the repository at this point in the history

Commits on Jul 1, 2026

  1. chore: update known checksums for 0.11.26 (#930)

    chore: update known checksums for 0.11.26
    
    Co-authored-by: eifinger <[email protected]>
    github-actions[bot] and eifinger authored Jul 1, 2026
    Configuration menu
    Copy the full SHA
    c5680ec View commit details
    Browse the repository at this point in the history

Commits on Jul 2, 2026

  1. docs: update version references to v8.2.0 (#932)

    ## Summary
    - update README and docs `uses: astral-sh/setup-uv@...` examples to the
    v8.2.0 commit SHA
    - replace stale `v8.1.0` comments with `v8.2.0`
    
    Fixes #931
    
    ## Validation
    - npm ci --ignore-scripts
    - npm run all
    KRRT7 authored Jul 2, 2026
    Configuration menu
    Copy the full SHA
    a5e9cbf View commit details
    Browse the repository at this point in the history
  2. ci: call docs update workflow from release (#933)

    - replace the docs update tag-push trigger with manual and reusable
    workflow entrypoints
    - call the docs update reusable workflow after publishing a release
    - keep manual docs updates available by selecting the latest semver tag
    
    Refs: pi-session 019f2352-565c-7f60-b96b-f2546fb1690f
    eifinger authored Jul 2, 2026
    Configuration menu
    Copy the full SHA
    a1a7345 View commit details
    Browse the repository at this point in the history
  3. chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#926)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2
    to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    <h2>v6.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update changelog by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>Update changelog for v6.0.3 by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
    update error wording (<a
    href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
    getting ready for checkout v7 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
    Bump the minor-npm-dependencies group across 1 directory with 3 updates
    (<a
    href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
    upgrade module to esm and update dependencies (<a
    href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
    Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
    and Remove uuid (<a
    href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
    Bump js-yaml from 4.1.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
    Bump flatted from 3.3.1 to 3.4.2 (<a
    href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
    Bump actions/publish-immutable-action (<a
    href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
    block checking out fork pr for pull_request_target and workflow_run (<a
    href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/df4cb1c069e1874edd31b4311f1884172cec0e10"><code>df4cb1c</code></a>
    Update changelog for v6.0.3 (<a
    href="https://redirect.github.com/actions/checkout/issues/2446">#2446</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 2, 2026
    Configuration menu
    Copy the full SHA
    fc16fa3 View commit details
    Browse the repository at this point in the history
  4. chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 (

    …#924)
    
    Bumps
    [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter)
    from 7.3.1 to 7.4.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/release-drafter/release-drafter/releases">release-drafter/release-drafter's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.4.0</h2>
    <h1>What's Changed</h1>
    <h2>New</h2>
    <ul>
    <li>feat: unify category config around change classification (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1558">#1558</a>)
    <a href="https://github.com/cchanche"><code>@​cchanche</code></a></li>
    </ul>
    <h2>Maintenance</h2>
    <ul>
    <li>chore: update generated GraphQL types (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1629">#1629</a>)
    @<a
    href="https://github.com/apps/github-actions">github-actions[bot]</a></li>
    </ul>
    <h2>Documentation</h2>
    <ul>
    <li>docs: document github enterprise server support (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1627">#1627</a>)
    <a href="https://github.com/cchanche"><code>@​cchanche</code></a></li>
    </ul>
    <h2>Dependency Updates</h2>
    <ul>
    <li>build(deps-dev): bump vite from 8.0.13 to 8.0.16 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1634">#1634</a>)
    @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
    <li>build(deps-dev): bump js-yaml from 4.1.1 to 4.2.0 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1633">#1633</a>)
    @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
    <li>build(deps-dev): bump shell-quote from 1.8.3 to 1.8.4 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1632">#1632</a>)
    @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/release-drafter/release-drafter/compare/v7.3.1...v7.4.0">https://github.com/release-drafter/release-drafter/compare/v7.3.1...v7.4.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/ed4bc48ec97379be2258e7b7ac2624a3e26ab809"><code>ed4bc48</code></a>
    chore: release v7.4.0</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/0cc23b4878edb4924aae8c9ce2b39766cef66033"><code>0cc23b4</code></a>
    chore: update generated GraphQL types (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1629">#1629</a>)</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/091a8c83088ce6d694d28ad1024aff1235127ee5"><code>091a8c8</code></a>
    build(deps-dev): bump vite from 8.0.13 to 8.0.16 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1634">#1634</a>)</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/5e296d69e2244af2f2ddf8a50c4ae8313f5c210b"><code>5e296d6</code></a>
    build(deps-dev): bump js-yaml from 4.1.1 to 4.2.0 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1633">#1633</a>)</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/86a47c9c8e6620a64feb3a362f3ffd9f6f808f6a"><code>86a47c9</code></a>
    build(deps-dev): bump shell-quote from 1.8.3 to 1.8.4 (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1632">#1632</a>)</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/bf75d71215edb5f1fff8c68bcfafc338f5e61056"><code>bf75d71</code></a>
    docs: document github enterprise server support (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1627">#1627</a>)</li>
    <li><a
    href="https://github.com/release-drafter/release-drafter/commit/cff71867e24849ec3c235e40896fe71a8a0895bf"><code>cff7186</code></a>
    feat: unify category config around change classification (<a
    href="https://redirect.github.com/release-drafter/release-drafter/issues/1558">#1558</a>)</li>
    <li>See full diff in <a
    href="https://github.com/release-drafter/release-drafter/compare/693d20e7c1ce1a81d3a41962f85914253b518449...ed4bc48ec97379be2258e7b7ac2624a3e26ab809">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=release-drafter/release-drafter&package-manager=github_actions&previous-version=7.3.1&new-version=7.4.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 2, 2026
    Configuration menu
    Copy the full SHA
    9225f84 View commit details
    Browse the repository at this point in the history

Commits on Jul 5, 2026

  1. chore(deps): roll up Dependabot updates (#936)

    ## Summary
    - Roll up open Dependabot npm and GitHub Actions updates
    - Update Biome schema to 2.4.16
    - Regenerate bundled dist artifacts
    
    ## Validation
    - npm run all
    
    Refs: pi-session 019f3160-c4af-7606-b4be-648e0abff131
    eifinger authored Jul 5, 2026
    Configuration menu
    Copy the full SHA
    3cc3c11 View commit details
    Browse the repository at this point in the history
  2. Fix cache keys for Python version ranges (#937)

    ## Summary
    - URL-encode the Python version component before adding it to the cache
    key
    - URL-encode the user-provided cache suffix for the same reason
    - Add cache key tests for Python ranges, comma-containing suffixes, and
    unchanged simple inputs
    
    Fixes #914
    
    Refs: pi-session 019f3164-85e7-7817-bffd-501d89b3a1fd
    
    ## Tests
    - npm run all
    eifinger authored Jul 5, 2026
    Configuration menu
    Copy the full SHA
    17c3989 View commit details
    Browse the repository at this point in the history
  3. Strip environment markers from detected uv dependency pins (#938)

    ## Summary
    - strip PEP 508 environment markers before extracting uv versions from
    dependency entries
    - cover dependency-group pins with and without whitespace before the
    marker
    - cover requirements-style pins with markers
    
    Fixes #920
    
    ## Validation
    - npm ci --ignore-scripts
    - npm run all
    
    Refs: pi-session 019f316a-4108-7975-892f-ee5bf8abc7c3
    eifinger authored Jul 5, 2026
    Configuration menu
    Copy the full SHA
    d31148d View commit details
    Browse the repository at this point in the history
Loading