Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Aug 4, 2025

Bumps @octokit/action from 6.1.0 to 8.0.2.

Release notes

Sourced from @​octokit/action's releases.

v8.0.2

8.0.2 (2025-05-26)

Bug Fixes

  • deps: update dependency @​octokit/plugin-rest-endpoint-methods to v16 (#703) (25f537f)

v8.0.1

8.0.1 (2025-05-21)

Bug Fixes

  • deps: update octokit monorepo (major) (#702) (76679e4)

v8.0.0

8.0.0 (2025-05-20)

Continuous Integration

BREAKING CHANGES

  • Drop support for NodeJS v18

  • build: set minimal node version in build script to v20

  • ci: stop testing against NodeJS v18

v7.0.2

7.0.2 (2025-04-10)

Bug Fixes

  • deps: update octokit monorepo (major) (#694) (82d96c1)

v7.0.1

7.0.1 (2025-02-15)

Bug Fixes

  • deps: update Octokit dependencies to mitigate ReDos vulnerabilities [security] (#682) (715671e)

v7.0.0

... (truncated)

Commits
  • 25f537f fix(deps): update dependency @​octokit/plugin-rest-endpoint-methods to v16 (#703)
  • 76679e4 fix(deps): update octokit monorepo (major) (#702)
  • b6a290e ci: stop testing against NodeJS v18 (#700)
  • 249ff46 build(deps): lock file maintenance (#701)
  • d36e0ef build(deps-dev): bump vite from 6.3.2 to 6.3.5 (#699)
  • 74128c3 build(deps): lock file maintenance (#697)
  • a3b34c9 build(deps): lock file maintenance (#696)
  • de907e7 build(deps-dev): bump vite from 6.2.5 to 6.2.6 (#695)
  • 82d96c1 fix(deps): update octokit monorepo (major) (#694)
  • ab658ce build(deps-dev): bump vite from 6.2.0 to 6.2.5 (#693)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
### Summary by AIGNE

Release Notes:

  • Chore: Updated @octokit/action to v8.0.2 to enhance security and maintainability
  • Breaking Change: Node.js v20 is now required (previously v18)
  • Security: Fixed ReDos vulnerabilities in dependencies

Impact: This update improves the overall security and stability of the GitHub Actions integration. Users must ensure their workflows use Node.js v20 or later. No functional changes or user-visible features are included in this maintenance release.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2025
Bumps [@octokit/action](https://github.com/octokit/action.js) from 6.1.0 to 8.0.2.
- [Release notes](https://github.com/octokit/action.js/releases)
- [Commits](octokit/action.js@v6.1.0...v8.0.2)

---
updated-dependencies:
- dependency-name: "@octokit/action"
  dependency-version: 8.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/octokit/action-8.0.2 branch from 937bbcf to f130538 Compare August 27, 2025 04:00
@github-actions
Copy link

github-actions bot commented Aug 27, 2025

Image description AIGNE CodeSmith

Walkthrough

This update focuses on upgrading the @octokit/action dependency from v6.1.0 to v8.0.2, which includes critical security improvements addressing ReDos vulnerabilities. The upgrade requires Node.js v20 as the minimum version, dropping support for Node.js v18. The change synchronizes dependencies across package files to maintain consistency.

Changes

Files Summary
package.json
pnpm-lock.yaml
- Upgrades @octokit/action from 6.1.0 to 8.0.2
- Updates core Octokit dependencies (@octokit/core: 5.2.1 → 7.0.3)
- Updates related plugins (auth-token, paginate-rest, rest-endpoint-methods)
- Synchronizes versions between package files

Copy link

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image description AIGNE CodeSmith

Commits Files that changed from the base of the PR and between 4c6103e and f130538 commits.
Files selected (2)
  • package.json (1)
  • pnpm-lock.yaml (17)
Review comments generated (4)
  • Review: 3
  • LGTM: 1

提示

Image description AIGNE CodeSmith (@codesmith) 聊天

  • 回复此机器人留下的审查评论以提出后续问题。审查评论是对差异或文件的评论。
  • 通过在回复中标记 @codesmith 邀请机器人加入审查评论链。

代码建议

  • 机器人可能会提出代码建议,但在提交前请仔细审查它们,因为行号范围可能会不对齐。
  • 你可以编辑机器人做出的评论,并在建议稍有偏差时手动调整。

暂停增量审查

  • 在 PR 描述中的任何位置添加 @codesmith: ignore 以暂停机器人的进一步审查。

engines: {node: '>= 18'}
'@octokit/action@8.0.2':
resolution: {integrity: sha512-th1WWnL5BCFirTni7v4cnqjGBNqSbTjac+EodnYqpsOUmMuimHA0reiZJsSm6yOD5zQ750igdWXSKOCiq0eaRA==}
engines: {node: '>= 20'}

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image description AIGNE CodeSmith

The minimum Node.js version requirement has increased significantly from v18 to v20. This is a critical change that needs to be reflected in the project's engine requirements.

-    engines: {node: '>= 18'}
+    engines: {node: '>= 20'}

Comment on lines +4306 to +4314
'@octokit/[email protected](@octokit/core@7.0.3)':
dependencies:
'@octokit/core': 3.6.0([email protected])
'@octokit/core': 7.0.3
'@octokit/types': 9.3.2
bottleneck: 2.19.5

'@octokit/[email protected](@octokit/core@3.6.0([email protected]))':
'@octokit/[email protected](@octokit/core@7.0.3)':
dependencies:
'@octokit/core': 3.6.0([email protected])
'@octokit/core': 7.0.3

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image description AIGNE CodeSmith

The plugin-retry and plugin-throttling dependencies are now using different core versions which could lead to compatibility issues. They should be aligned to use the same core version.

[email protected]([email protected])([email protected])([email protected]):
dependencies:
'@types/node': 18.19.121
'@types/node': 18.19.123

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image description AIGNE CodeSmith

The @types/node version used by OpenAI SDK should be updated to match the new minimum Node.js requirement:

-      '@types/node': 18.19.123
+      '@types/node': 20.19.11

The rest of the changes look good and maintain proper dependency alignment. The updates to the Octokit packages and their dependencies appear to be consistent with the version bumps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant