GutenTAG
GutenTAG copied to clipboard
chore(deps): bump pypa/gh-action-pypi-publish from 1.8.14 to 1.10.1
Bumps pypa/gh-action-pypi-publish from 1.8.14 to 1.10.1.
Release notes
Sourced from pypa/gh-action-pypi-publish's releases.
v1.10.1
🚑🔏 Oopsie... We missed a tiny bug in the attestations feature the other day
The problem was that the distribution file validity check was failing on any valid distribution being present and ready to be signed. What a silly mistake! It's now been fixed via https://github.com/pypa/gh-action-pypi-publish/commit/0ab0b79, though. So everything's good!
--
@webknjaz
💰[!IMPORTANT] ✨ Despite this minor hiccup, we invite you to still opt into trying this feature out early. It can be enabled like this:
with: attestations: true
Leave feedback in the v1.10.0 release discussion or the PR.
🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.10.0...v1.10.1
🧔♂️ Release Manager:
@webknjaz 🇺🇦
🙏 Special Thanks to
@hugovk
💰 for promptly validating the bug fix, mere minutes after I pushed it — I even haven't finished writing this text by then!v1.10.0
🔏 Anything fancy, eh?
This time,
@woodruffw
💰 implemented support for PEP 740 attestations functionality in #236 and #245. This is a big deal, as it is a huge step forward to replacing what the deprecated GPG signatures used to provide in a more meaningful way.[!IMPORTANT] ✨ Please, do opt into trying this feature out early. It can be enabled as follows:
with: attestations: true
Leave any feedback on this in this release discussion or the PR.
🙏 And please, thank William for working on this amazing improvement for the ecosystem! The overall effort is tracked @ pypi/warehouse#15871, by the way.
🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.9.0...v1.10.0
🧔♂️ Release Manager:
@webknjaz 🇺🇦
v1.9.0
💅 Cosmetic Output Improvements
@woodruffw
💰 updated the tense on password nudge in #234@shenxianpeng
💰 helped us disable the progress bar that was being produced by thetwine upload
command via #231@woodruffw
💰 also linked the PyPI status dashboard in the trusted publishing error message via pypa/gh-action-pypi-publish#243🛠️ Internal Dependencies
- pre-commit linters got auto-updated @ #225
... (truncated)
Commits
0ab0b79
🚑 Invert the dists-to-attest validity check8a08d61
Expose PEP 740 attestations functionalityfb9fc6a
Merge pull request #245 from trail-of-forks/ww/bump-twine4d020ff
requirements: re-compile requirements with latest twineec4db0b
Merge PR #243 into unstable/v1e790844
oidc-exchange: link to status dashboard87b624f
💅Update homepage @ Dockerfile to GH Marketplaceda2f9bb
Merge pull request #241 from br3ndonland/ghcr-labelabbea2d
Add Docker label for GHCR2734d07
build(deps): bump requests from 2.31.0 to 2.32.0 in /requirements (#240)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)