Skip to content

github-actions: bump softprops/action-gh-release from 2 to 3.0.0#579

Merged
bgentry merged 1 commit into
masterfrom
dependabot/github_actions/softprops/action-gh-release-3
Jun 23, 2026
Merged

github-actions: bump softprops/action-gh-release from 2 to 3.0.0#579
bgentry merged 1 commit into
masterfrom
dependabot/github_actions/softprops/action-gh-release-3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor

Bumps softprops/action-gh-release from 2 to 3.0.0.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on v2.6.2.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release

v2.6.2

What's Changed

Other Changes 🔄

Full Changelog: softprops/action-gh-release@v2...v2.6.2

v2.6.1

2.6.1 is a patch release focused on restoring linked discussion thread creation when discussion_category_name is set. It fixes [#764](https://github.com/softprops/action-gh-release/issues/764), where the draft-first publish flow stopped carrying the discussion category through the final publish step.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

Bug fixes 🐛

v2.6.0

2.6.0 is a minor release centered on previous_tag support for generate_release_notes, which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range. It also includes the recent concurrent asset upload recovery fix, a working_directory docs sync, a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

... (truncated)

Changelog

Sourced from softprops/action-gh-release's changelog.

0.1.13

  • fix issue with multiple runs concatenating release bodies #145
Commits
  • 718ea10 release 3.0.1
  • f1a938b chore(deps): bump esbuild from 0.28.0 to 0.28.1 (#802)
  • 0066ead chore(deps): bump vite from 8.0.14 to 8.0.16 (#806)
  • dc643ca chore(deps): bump the npm group with 3 updates (#805)
  • 85ee99b chore(deps): bump actions/checkout in the github-actions group (#804)
  • 9ed3cf9 chore(deps): bump the npm group with 2 updates (#800)
  • 3efcac8 chore(deps): bump the npm group with 3 updates (#798)
  • 05d6b91 chore(deps): bump brace-expansion from 5.0.5 to 5.0.6 (#797)
  • 403a524 chore(deps): bump @​types/node from 24.12.2 to 24.12.3 in the npm group (#796)
  • 437e073 chore(deps): bump the npm group with 4 updates (#792)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: github-actions. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label May 17, 2026
@bgentry

bgentry commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.0.0.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title github-actions: bump softprops/action-gh-release from 2 to 3 github-actions: bump softprops/action-gh-release from 2 to 3.0.0 Jun 23, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/softprops/action-gh-release-3 branch from 50313f1 to e34a84d Compare June 23, 2026 12:47

@bgentry bgentry left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Security review looks good to me.

I reviewed this as a dependency-upgrade supply-chain/security pass for the softprops/action-gh-release update from v2 to the v3 line at PR head e34a84ddbaee1f8479366d75d9e983673b04bfa1. Although Dependabot's title names 3.0.0, the workflow uses the floating @v3 major tag, so I reviewed the current v3 tag target as well.

Scope reviewed:

  • Confirmed the rebased PR only updates the release workflow's softprops/action-gh-release reference.
  • Resolved the current upstream v3 annotated tag and peeled commit, and compared upstream action metadata/source for the Node 24 runtime move and small release upload changes.
  • Checked the action's token usage: it still uses the configured/default GitHub token to create releases and upload the listed assets, only under the existing startsWith(github.ref, 'refs/tags/') condition.
  • Looked for unexpected credential sources, new network destinations beyond GitHub release APIs, dynamic code execution, install hooks, or expanded file upload behavior.

Local validation completed on the rebased head:

  • npm run lint
  • npm run test:once
  • npm run build
  • make lint
  • make test

No blocking findings. Residual risk is that this release job intentionally has contents: write behavior on tag refs, and the workflow still trusts a moving major-version action reference rather than a pinned commit SHA.

@bgentry bgentry merged commit 8d5c8ab into master Jun 23, 2026
16 of 18 checks passed
@bgentry bgentry deleted the dependabot/github_actions/softprops/action-gh-release-3 branch June 23, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant