Repository navigation
chore(ci)(deps): Bump peter-evans/dockerhub-description from 4 to 5 - #432
Merged
navneetkumar-pim-webkul merged 1 commit intoMay 27, 2026
Conversation
Bumps [peter-evans/dockerhub-description](https://github.com/peter-evans/dockerhub-description) from 4 to 5. - [Release notes](https://github.com/peter-evans/dockerhub-description/releases) - [Commits](peter-evans/dockerhub-description@v4...v5) --- updated-dependencies: - dependency-name: peter-evans/dockerhub-description dependency-version: '5' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>
Contributor
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
navneetkumar-pim-webkul
deleted the
dependabot/github_actions/peter-evans/dockerhub-description-5
branch
May 27, 2026 10:52
abhishekverma-webkul
pushed a commit
to abhishekverma-webkul/unopim
that referenced
this pull request
Jun 25, 2026
* fix: prevent saving descendant or self as parent category Adds validation in the category update flow to block assigning a descendant or the category itself as its parent. Previously this caused a raw PHP exception from the nested-set library. Now a clear UI error message is shown and the save is rejected. * fix: disable current category in parent tree radio selector * fix: resolve attribute history tab not showing columns (unopim#703) - Rename v-datagrid-table to v-history-table in history/table.blade.php to avoid Vue component registration conflict with the regular datagrid table (both shared the same template ID, causing visibleColumns to be undefined) - Remove unconditional slot forwarding from v-history-datagrid that was overriding v-history-table's default slot content with empty content - Add AttributeHistoryPresenter to translate raw field names and values into human-readable labels in the history detail modal * fix: accept snake_case params in AjaxOptionsController to fix select attribute filter options loading * fix: add purpose field to text_generation prompts in seeder so both text and image prompts are seeded on fresh install * fix: reject root category assignment on products (unopim#731) * fix: make product edit page header sticky so save button is always visible * fix: unify add-option modal layout for image swatch attributes * fix: return 403 instead of 401 for authenticated users without permission * fix: hide edit and delete actions in platform datagrid for users without permission * fix: align ACL sort values with menu order for data_transfer and ai-agent * fix: bulk edit attribute list now scoped to the selected products' attribute families * fix: update ACL tests to assert 403 Forbidden instead of 401 Unauthorized for permission-denied access * fix: remove dead code accessing non-existent data column and fix parameter name typo in TrackerController * fix: guard prompt and system-prompt datagrid actions with ACL permission checks * fix: update security test to assert 403 Forbidden instead of 401 for unauthorized access * fix: correct undefined variable in ProductValuesValidator channel codes lookup * fix: update product update test to use non-root category to match category assignment restriction * fix: fix parameter name typo in ImportController normalizeSummary method * fix: replace missing translation key with correct tracker datagrid view key and add view translation across all locales * fix: redirect reset-password route without token to forget-password page instead of 500 * fix: hide AI agent chat widget on anonymous and error pages * fix: honor server-side default AI platform when session cache holds a stale selection * fix: prevent marking a disabled AI platform as default with server-side validation * fix: strip leading tilde from fetched and submitted AI model names to pass validation * fix: hide Magic AI button in TinyMCE toolbar when text generation is disabled * fix: render datetime attribute with datetime-local picker in bulk edit and validate on input * fix: validate numeric attribute values on bulk edit save to reject non-numeric prices * fix: persist uploaded media file path into product attribute values after upload * fix: accept both configurable-products and legacy configrable-products URL prefixes for the configurable product API * feat: add DELETE endpoint for configurable products via REST API * test: add regression coverage asserting limit query parameter is respected on configurable products endpoint * test: add regression coverage asserting PATCH and DELETE are rejected on the products listing endpoint * fix: reject attribute create POST when body is a list of multiple objects * fix: reject unknown option codes when updating category field options instead of silently creating them * fix: reject API update requests that include immutable fields for attributes and category fields * fix: return parent category code when fetching a category by code in REST API * fix: use clearer page titles for attribute families, Magic AI prompts, and system prompts listing pages * fix: ignore trailing empty header columns when validating spreadsheet imports * fix: raise Agentic AI chat CSV/XLSX upload limit from 20MB to 100MB for bulk product imports * fix: hide edit and delete icons on magic AI platform grid when permission is missing * fix: forbid deletion of the default magic AI platform regardless of the count of other platforms * fix: hide Add Platform button for users without ai-agent.platform.create permission * fix: persist empty value when a core-config field is explicitly cleared so deselected multiselects are saved * fix: resolve ambiguous name column in attribute search and default suggestion query to empty string * fix: hide attribute code in manage columns list so only the translated name is shown * fix: make bulk edit column resize handle larger, persistent, and visible on hover * fix: place Magic AI before Data Transfer in sidebar and role hierarchy by setting ai-agent sort to 7 * fix: guarantee selected models are posted in Magic AI platform form regardless of DOM binding timing * fix: revoke Passport tokens on password change and API key secret regeneration * fix: reject invalid parent filter on products API with 422 instead of silently returning data * fix: verify Magic AI platform credentials with test-connection before save to block invalid API keys * fix: auto-fetch Magic AI models on api_key input with a 500ms debounce * test: align attribute and category field API tests with the immutable-fields 422 policy * fix: source platform save payload from Vue state so custom multiselect values (provider) reach the server * chore: pin laravel/pint to 1.29.1 and apply resulting format fixes CI installs latest pint via aglipanci/laravel-pint-action while lockfile had v1.29.0; v1.29.1 (PR unopim#432) tightened fixer detection causing CI-only style failures. Pin exact version to align local + CI, reformat the three affected controllers. * ci: run pint via project vendor instead of global install aglipanci/[email protected] does composer global require and pulls the latest pint, bypassing composer.lock. Swap to setup-php + ramsey/composer-install so the lockfile-pinned version is used, keeping CI and local in lockstep. * test: fix Magic AI default-requires-enabled spec CSRF handling Admin layouts don't render a meta[name="csrf-token"] tag, so the old adminPage.request.post path sent an empty X-CSRF-TOKEN and the request was rejected (419 locally, 500 in CI shard 2). Switch to the same in-page fetch pattern as webhook-delivery.spec.js: read the XSRF-TOKEN cookie and send it as X-XSRF-TOKEN, which the session-backed request context accepts. * fix: address Copilot review feedback - ProductBulkEditController::validateNumericAttributeValues: replace break 2 with break so a single bad scalar no longer aborts validation of the remaining numeric attributes on the same product. - ApiResponse::storeExceptionLog: map UnprocessableEntityHttpException to 422 instead of 404; keep ModelNotFoundException on 404. - Tighten API tests: ApiProductInvalidFilterTest asserts 422 exactly, ApiProductMethodNotAllowedTest asserts 405 and presence of Allow header instead of accepting a loose status set. * chore: drop accidentally-committed playwright test-results artifact * refactor: address remaining Copilot review feedback - MediaFileController::assignMediaToProductAttribute: use the injected $attributeRepository instead of an ad-hoc app() lookup. - tree/radio.blade.php: bind cursor-pointer/cursor-not-allowed on icon and label text to isCurrentCategory so the disabled state is reflected consistently. - CoreConfigRepositoryClearValueTest: drop source-string matching and replace with behavioral tests that exercise CoreConfigRepository against the DB for null-cleared and default-valued fields. - ImporterEmptyHeadersTest: exercise AbstractImporter::validateData via a minimal concrete subclass with a stub source so regressions in the trailing-empty-header trim are caught against production code. - ProductCategoriesValidator: replace the per-validate root-code pluck with a closure that does a single indexed whereNull lookup per submitted code. * fix: guard CoreConfigRepository field-type access when field definition is missing The previous null-to-empty-string change made the code fall through to a password-type check that assumed $field was an array. Tests that exercise legacy configuration payloads hit a "Trying to access array offset on null" error. Use null-coalesce on $field['type'] so the password path is skipped when the config field is not registered.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps peter-evans/dockerhub-description from 4 to 5.
Release notes
Sourced from peter-evans/dockerhub-description's releases.
... (truncated)
Commits
1b9a80cfeat: v5 (#327)ef9b19abuild(deps-dev): bump@vercel/nccfrom 0.38.3 to 0.38.4 (#326)a48612bbuild(deps): bump actions/setup-node from 4 to 5 (#325)08eafd1build(deps): bump actions/checkout from 4 to 5 (#324)a0bee1bbuild(deps-dev): bump eslint-plugin-prettier from 5.5.3 to 5.5.4 (#323)2877192build(deps): bump actions/download-artifact from 4 to 5 (#322)444ccd3build(deps): bump form-data from 3.0.1 to 3.0.4 (#321)aca792bbuild(deps-dev): bump eslint-plugin-prettier from 5.5.1 to 5.5.3 (#320)940963abuild(deps-dev): bump eslint-plugin-prettier from 5.5.0 to 5.5.1 (#318)0b249a1build(deps-dev): bump prettier from 3.5.3 to 3.6.2 (#317)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)