Commit graph

  • 8d2567b22e
    Merge 4d67388a51 into c86fe4ef1f dependabot[bot] 2026-06-27 18:48:02 -04:00
  • 930e2520ca
    Merge d51e4923d7 into c86fe4ef1f dependabot[bot] 2026-06-27 18:48:00 -04:00
  • 4011bcd2ae
    Merge 9c2a51d787 into c86fe4ef1f dependabot[bot] 2026-06-27 18:48:00 -04:00
  • 2ee07cce0a
    Merge 7570463c3f into c86fe4ef1f dependabot[bot] 2026-06-27 18:48:00 -04:00
  • 432fd944a3
    Merge 5ab5a28da9 into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:58 -04:00
  • 985bdfea1b
    Merge 96eb13bb91 into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:57 -04:00
  • 1ccbf3101e
    Merge 4da9a5feeb into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:57 -04:00
  • 3a6f0c66de
    Merge ff91e456ae into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:57 -04:00
  • 5c4bb243d0
    Merge 61418d0281 into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:57 -04:00
  • 46a6991c06
    Merge b7c3ddc196 into c86fe4ef1f dependabot[bot] 2026-06-27 18:47:57 -04:00
  • c86fe4ef1f
    Add a threat model for setup-uv (#923) main Zsolt Dollenstein 2026-06-27 20:01:45 +01:00
  • 224c887d48
    chore: update known checksums for 0.11.25 (#929) github-actions[bot] 2026-06-27 09:33:56 +02:00
  • 9924429f8d chore: update known checksums for 0.11.25 eifinger 2026-06-27 05:20:06 +00:00
  • 4d67388a51
    chore(deps): bump github/codeql-action/init from 4.36.0 to 4.36.2 dependabot/github_actions/github/codeql-action/init-4.36.2 dependabot[bot] 2026-06-26 10:55:31 +00:00
  • 7570463c3f
    chore(deps): bump github/codeql-action/autobuild from 4.36.0 to 4.36.2 dependabot/github_actions/github/codeql-action/autobuild-4.36.2 dependabot[bot] 2026-06-26 10:54:07 +00:00
  • 9c2a51d787
    chore(deps): bump actions/checkout from 6.0.2 to 7.0.0 dependabot/github_actions/actions/checkout-7.0.0 dependabot[bot] 2026-06-24 10:52:52 +00:00
  • b173788282
    chore: update known checksums for 0.11.24 (#925) github-actions[bot] 2026-06-24 09:18:23 +02:00
  • dbce8806bf chore: update known checksums for 0.11.24 eifinger 2026-06-24 05:23:33 +00:00
  • 1de985f1b7
    docs: address threat model review feedback Zsolt Dollenstein 2026-06-23 12:58:48 +01:00
  • d51e4923d7
    chore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0 dependabot/github_actions/release-drafter/release-drafter-7.4.0 dependabot[bot] 2026-06-23 10:52:40 +00:00
  • e53da17296
    chore: update known checksums for 0.11.23 (#922) github-actions[bot] 2026-06-23 08:54:47 +02:00
  • 9d6f9ef13b chore: update known checksums for 0.11.23 eifinger 2026-06-20 05:32:31 +00:00
  • 81e0b4e357
    docs: clarify threat model authority boundary Zsolt Dollenstein 2026-06-19 16:23:27 +01:00
  • a9b33f0240
    chore: update known checksums for 0.11.22 (#921) github-actions[bot] 2026-06-19 08:02:13 +02:00
  • 8a82d6843a chore: update known checksums for 0.11.22 eifinger 2026-06-19 05:46:12 +00:00
  • 3faa3174e6
    feat: support uv.lock as a version-file source (#918) somaz 2026-06-19 14:08:57 +09:00
  • c2f220d627
    simplify Zsolt Dollenstein 2026-06-17 15:03:39 +01:00
  • 38ae580275
    docs: add repository threat model Zsolt Dollenstein 2026-06-17 11:53:07 +01:00
  • 4c810afe20 feat: support uv.lock as a version-file source somaz 2026-06-12 15:25:07 +09:00
  • ca5ddd015e
    chore: update known checksums for 0.11.21 (#917) github-actions[bot] 2026-06-12 07:54:16 +02:00
  • 8857f1b704 chore: update known checksums for 0.11.21 eifinger 2026-06-12 05:37:29 +00:00
  • 5ab5a28da9
    chore(deps): bump github/codeql-action from 4.36.0 to 4.36.2 dependabot/github_actions/github/codeql-action-4.36.2 dependabot[bot] 2026-06-11 10:55:03 +00:00
  • e2f6a928de
    chore: update known checksums for 0.11.20 (#915) github-actions[bot] 2026-06-11 08:28:31 +02:00
  • 73961b4a45 chore: update known checksums for 0.11.20 eifinger 2026-06-11 05:37:44 +00:00
  • ed73b5df24
    fix: use BUILD_ID as backup for determining os version (#912) Hans Gaiser 2026-06-09 13:12:37 +02:00
  • 35e6a0d571
    chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 dependabot[bot] 2026-06-09 10:54:42 +00:00
  • 3eaa254213
    chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1 dependabot[bot] 2026-06-09 10:54:18 +00:00
  • c13b534803 fix: use BUILD_ID as backup for determining os version Hans Gaiser 2026-06-09 12:47:34 +02:00
  • 21d5da3bc3
    chore: update known checksums for 0.11.19 (#909) github-actions[bot] 2026-06-04 07:53:58 +02:00
  • 0ba3acb29e chore: update known checksums for 0.11.19 eifinger 2026-06-04 05:39:29 +00:00
  • b7c3ddc196
    chore(deps-dev): bump typescript from 5.9.3 to 6.0.3 dependabot/npm_and_yarn/typescript-6.0.3 dependabot[bot] 2026-06-03 23:56:11 +00:00
  • 61418d0281
    chore(deps): bump @renovatebot/pep440 from 4.2.2 to 5.0.0 dependabot/npm_and_yarn/renovatebot/pep440-5.0.0 dependabot[bot] 2026-06-03 23:56:04 +00:00
  • ff91e456ae
    chore(deps-dev): bump @biomejs/biome from 2.4.15 to 2.4.16 dependabot/npm_and_yarn/biomejs/biome-2.4.16 dependabot[bot] 2026-06-03 23:55:59 +00:00
  • 4da9a5feeb
    chore(deps-dev): bump jest from 30.3.0 to 30.4.2 dependabot/npm_and_yarn/jest-30.4.2 dependabot[bot] 2026-06-03 23:55:53 +00:00
  • 96eb13bb91
    chore(deps): bump @actions/cache from 6.0.0 to 6.0.1 dependabot/npm_and_yarn/actions/cache-6.0.1 dependabot[bot] 2026-06-03 23:55:45 +00:00
  • fac544c07d
    chore(deps): roll up dependabot updates (#903) v8.2.0 Kevin Stillhammer 2026-06-03 10:21:55 +02:00
  • 371603de84
    chore(deps): roll up dependabot updates Kevin Stillhammer 2026-06-03 10:16:08 +02:00
  • a7252cec24
    chore(deps-dev): bump @biomejs/biome from 2.4.10 to 2.4.15 dependabot[bot] 2026-06-03 08:05:37 +00:00
  • e70ac24396
    chore(deps-dev): bump ts-jest from 29.4.9 to 29.4.11 dependabot[bot] 2026-06-03 08:05:16 +00:00
  • 327aca098c
    chore(deps): bump undici from 8.0.0 to 8.3.0 dependabot[bot] 2026-06-03 08:05:03 +00:00
  • 979e48f94b
    chore(deps-dev): bump esbuild from 0.27.5 to 0.28.0 dependabot[bot] 2026-06-03 07:55:37 +00:00
  • 7390f777b0
    docs: update dependabot rollup biome guidance (#902) Kevin Stillhammer 2026-06-03 09:50:08 +02:00
  • 363c64a728
    chore(deps): roll up dependabot updates (#901) Kevin Stillhammer 2026-06-03 09:49:40 +02:00
  • 512c644c93
    docs: update dependabot rollup biome guidance Kevin Stillhammer 2026-06-03 09:46:48 +02:00
  • e808723e51
    chore(deps): roll up dependabot updates Kevin Stillhammer 2026-06-03 09:43:47 +02:00
  • c4fcbafce4
    chore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.3.1 (#900) dependabot[bot] 2026-06-03 09:37:40 +02:00
  • 58e8c6db13
    chore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.3.1 dependabot[bot] 2026-06-02 07:39:12 +00:00
  • 8e642c5e62
    chore: update known checksums for 0.11.18 (#899) github-actions[bot] 2026-06-02 08:33:00 +02:00
  • 6ebde47161 chore: update known checksums for 0.11.18 eifinger 2026-06-02 05:37:08 +00:00
  • a92cb43098
    Add quiet input to suppress info-level log output (#898) Kevin Stillhammer 2026-05-31 21:13:30 +02:00
  • e07f2ac4b7
    chore(deps): bump eifinger/actionlint-action from 1.10.1 to 1.10.2 (#842) dependabot[bot] 2026-05-31 21:09:12 +02:00
  • bc4034eedf
    chore(deps): bump github/codeql-action from 4.35.4 to 4.36.0 (#893) dependabot[bot] 2026-05-31 21:08:54 +02:00
  • fd1049be7f
    Wire all source files through logging module for quiet mode Kevin Stillhammer 2026-05-31 12:37:17 +02:00
  • c2514a526e
    Add quiet input to suppress info-level log output Kevin Stillhammer 2026-05-31 12:37:01 +02:00
  • df42d4f6ba
    chore(deps): bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6 (#891) dependabot[bot] 2026-05-31 12:17:39 +02:00
  • b9c8c4c7ba
    feat: add download-from-astral-mirror input (#897) Kevin Stillhammer 2026-05-31 11:47:01 +02:00
  • 4fa8fca033
    feat: add download-from-astral-mirror input Kevin Stillhammer 2026-05-31 11:40:47 +02:00
  • 80cc27528e
    chore(deps): bump release-drafter/release-drafter from 7.2.0 to 7.3.0 (#884) dependabot[bot] 2026-05-31 11:26:42 +02:00
  • 818affc359
    fix: report unexpected cache save failures (#896) Kevin Stillhammer 2026-05-31 11:25:35 +02:00
  • ddb93f091f
    fix: report unexpected cache save failures Kevin Stillhammer 2026-05-31 11:21:30 +02:00
  • feda7fc6a9
    fix: report unexpected setup failures (#895) Kevin Stillhammer 2026-05-31 11:17:46 +02:00
  • d532b42787
    fix: report unexpected setup failures Kevin Stillhammer 2026-05-31 11:11:40 +02:00
  • 8dc20b2aca
    fix: add timeout to fetch to prevent silent hangs (#883) eifinger-bot 2026-05-31 09:37:59 +02:00
  • a465253b89
    fix: add timeout to fetch to prevent silent hangs eifinger-bot 2026-05-14 18:53:01 +00:00
  • edc4037b1b
    fix: add timeout to fetch to prevent silent hangs fix/fetch-timeout eifinger-bot 2026-05-14 18:53:01 +00:00
  • e964836ece
    chore(deps): bump github/codeql-action from 4.35.4 to 4.36.0 dependabot[bot] 2026-05-29 11:39:18 +00:00
  • e7108c6ccc
    chore: update known checksums for 0.11.17 (#892) github-actions[bot] 2026-05-29 11:10:08 +02:00
  • 773d23e00f chore: update known checksums for 0.11.17 eifinger 2026-05-29 05:30:06 +00:00
  • 525924c72d
    chore(deps): bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6 dependabot[bot] 2026-05-25 16:35:38 +00:00
  • 7b2a9532e0
    chore(deps): bump github/codeql-action from 4.35.4 to 4.35.5 dependabot[bot] 2026-05-22 10:55:22 +00:00
  • 12d13f90bc
    chore: update known checksums for 0.11.16 (#889) github-actions[bot] 2026-05-22 07:56:51 +02:00
  • a05da5d0dc chore: update known checksums for 0.11.16 eifinger 2026-05-22 05:24:08 +00:00
  • 7470949a2c
    chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5 (#888) dependabot[bot] 2026-05-21 14:29:19 +02:00
  • 6c83c18e13
    chore(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.5 dependabot[bot] 2026-05-21 11:26:17 +00:00
  • e34e4524ab
    Add clone command for top-pypi-packages repository Pathum 2026-05-20 12:50:02 +08:00
  • 7c0f98a37b
    Update README.md Pathum 2026-05-20 12:42:06 +08:00
  • ed07c76224
    chore: update known checksums for 0.11.15 (#885) github-actions[bot] 2026-05-19 07:42:01 +02:00
  • 7f9f82d24f chore: update known checksums for 0.11.15 eifinger 2026-05-19 05:23:53 +00:00
  • 21f0e753a6
    chore(deps): bump release-drafter/release-drafter from 7.2.0 to 7.3.0 dependabot[bot] 2026-05-15 10:55:03 +00:00
  • ba17a16c0a
    chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 (#881) dependabot[bot] 2026-05-14 15:10:36 +02:00
  • 44bd605ce8
    chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 dependabot[bot] 2026-05-14 10:55:35 +00:00
  • 853401723d
    Limit GitHub tokens to github.com download URLs (#878) Zsolt Dollenstein 2026-05-13 12:26:05 +01:00
  • ccabf26f97
    Inline GitHub token gating for download URLs Zsolt Dollenstein 2026-05-13 12:16:45 +01:00
  • 7568f55a9a
    increase libuv-workaround timeout to 100ms (#880) Kevin Stillhammer 2026-05-13 08:28:39 +02:00
  • 32e0005318
    increase libuv-workaround timeout to 100ms Kevin Stillhammer 2026-05-13 08:21:36 +02:00
  • a81585cbb0
    chore: update known checksums for 0.11.14 (#879) github-actions[bot] 2026-05-13 07:37:30 +02:00
  • 0743ae2011 chore: update known checksums for 0.11.14 eifinger 2026-05-13 05:19:58 +00:00
  • 2f9f369997
    Limit GitHub tokens to github.com download URLs Zsolt Dollenstein 2026-05-11 17:52:04 +01:00
  • 88aa608651
    chore: update known checksums for 0.11.13 (#877) github-actions[bot] 2026-05-11 08:14:58 +02:00
  • db5a014c3e chore: update known checksums for 0.11.13 eifinger 2026-05-11 05:22:12 +00:00