Skip to content

chore(deps): update mathieudutour/github-tag-action action to v7 - #5

Merged
JFWenisch merged 1 commit into
mainfrom
renovate/mathieudutour-github-tag-action-7.x
Oct 5, 2026
Merged

JFWenisch merged 1 commit into
mainfrom
renovate/mathieudutour-github-tag-action-7.x

Conversation

@renovate-wenisch-tech

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
mathieudutour/github-tag-action action major v6.2 → v7.0.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

mathieudutour/github-tag-action (mathieudutour/github-tag-action)

v7.0.0

Compare Source

v7 upgrades the action to Node 24 and introduces breaking changes to version calculation and branch handling. Review the migration guide before upgrading from v6.

  • Run on Node 24 and ship a self-contained dist/ bundle with both supported commit presets, templates, dependencies, and license notices. Refresh the lockfile, remove the old Octokit dependency chain, and retain proxy support.
  • Align analysis and changelogs on Conventional Commits, including feat!. Angular remains selectable.
  • Match whole branch names; an empty prerelease list now means no prerelease branches. Never publish from PR events or recursively process tag events. Preview versions include a commit SHA suffix.
  • Fetch all tags and all compare-commit pages. Explicitly restricted tag fetching fails when results might be incomplete. Read initial commit history instead of comparing against a fabricated HEAD baseline.
  • Skip version creation when no eligible commits remain, unless custom or forced versioning was explicitly requested.
  • Keep stable release baselines separate from unrelated prereleases; match prerelease identifiers exactly, honor the first prerelease default, increment existing RCs, and allow higher-level changes to advance the RC base.
  • Add path/scope/ignore filters, opt-in squash-bullet parsing, tag-stream filtering, explicit bump/version inputs, local/moving/rolling tags, repository/ref/directory overrides, and release metadata outputs.
  • Retry transient API reads and fall back to complete local Git history for compare failures. No history means no guessed release. Optional soft failure clears release outputs.

Migration

See Migrating from v6 to v7 for changed defaults, workflow examples, prerelease behavior, and a dry-run validation procedure.

New inputs are opt-in unless explicitly described above and require v7. See the README for the full input contract.

v7

Compare Source

v7 upgrades the action to Node 24 and introduces breaking changes to version calculation and branch handling. Review the migration guide before upgrading from v6.

  • Run on Node 24 and ship a self-contained dist/ bundle with both supported commit presets, templates, dependencies, and license notices. Refresh the lockfile, remove the old Octokit dependency chain, and retain proxy support.
  • Align analysis and changelogs on Conventional Commits, including feat!. Angular remains selectable.
  • Match whole branch names; an empty prerelease list now means no prerelease branches. Never publish from PR events or recursively process tag events. Preview versions include a commit SHA suffix.
  • Fetch all tags and all compare-commit pages. Explicitly restricted tag fetching fails when results might be incomplete. Read initial commit history instead of comparing against a fabricated HEAD baseline.
  • Skip version creation when no eligible commits remain, unless custom or forced versioning was explicitly requested.
  • Keep stable release baselines separate from unrelated prereleases; match prerelease identifiers exactly, honor the first prerelease default, increment existing RCs, and allow higher-level changes to advance the RC base.
  • Add path/scope/ignore filters, opt-in squash-bullet parsing, tag-stream filtering, explicit bump/version inputs, local/moving/rolling tags, repository/ref/directory overrides, and release metadata outputs.
  • Retry transient API reads and fall back to complete local Git history for compare failures. No history means no guessed release. Optional soft failure clears release outputs.

Migration

See Migrating from v6 to v7 for changed defaults, workflow examples, prerelease behavior, and a dry-run validation procedure.

New inputs are opt-in unless explicitly described above and require v7. See the README for the full input contract.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@github-actions

Copy link
Copy Markdown
Contributor

Trivy vulnerability report


Report Summary

┌────────────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                               Target                               │ Type  │ Vulnerabilities │
├────────────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/smtp2x:0.1.3-89db7d8-pr.5.16 (wolfi 20230201) │ wolfi │        0        │
├────────────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                        │  jar  │        2        │
└────────────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.74/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


Java (jar)
==========
Total: 2 (MEDIUM: 0, HIGH: 2, CRITICAL: 0)

┌───────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────────┐
│                    Library                    │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                           Title                           │
├───────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────────┤
│ tools.jackson.core:jackson-databind (app.jar) │ CVE-2026-91776 │ HIGH     │ fixed  │ 3.1.6             │ 3.1.7, 3.2.3  │ TypeDeserializerBase._findDeserializer() in FasterXML     │
│                                               │                │          │        │                   │               │ jackson-databind ...                                      │
│                                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-91776                │
│                                               ├────────────────┤          │        │                   │               ├───────────────────────────────────────────────────────────┤
│                                               │ CVE-2026-91777 │          │        │                   │               │ Forward-reference completion for @JsonIdentityInfo object │
│                                               │                │          │        │                   │               │ IDs in Faste ...                                          │
│                                               │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-91777                │
└───────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────────┘

@JFWenisch
JFWenisch merged commit 18953bc into main Oct 5, 2026
10 checks passed
@renovate-wenisch-tech
renovate-wenisch-tech Bot deleted the renovate/mathieudutour-github-tag-action-7.x branch October 5, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant