-
Notifications
You must be signed in to change notification settings - Fork 738
Comparing changes
Open a pull request
base repository: actions/setup-python
base: releases/v6
head repository: actions/setup-python
compare: main
- 17 commits
- 85 files changed
- 13 contributors
Commits on Jul 10, 2026
-
Bump certifi from 2020.6.20 to 2024.7.4 in /__tests__/data (#1328)
Bumps [certifi](https://github.com/certifi/python-certifi) from 2020.6.20 to 2024.7.4. - [Commits](certifi/python-certifi@2020.06.20...2024.07.04) --- updated-dependencies: - dependency-name: certifi dependency-version: 2024.7.4 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0903b46 - Browse repository at this point
Copy the full SHA 0903b46View commit details
Commits on Jul 13, 2026
-
remove EOL Python versions and Bumps numpy text fixture (#1333)
* remove EOL Python versions * Fix typo in comments for executable suffix removal in test-pypy.yml
Configuration menu - View commit details
-
Copy full SHA for 6849080 - Browse repository at this point
Copy the full SHA 6849080View commit details -
Co-authored-by: lmvysakh <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for c709277 - Browse repository at this point
Copy the full SHA c709277View commit details
Commits on Jul 14, 2026
-
Validate and retry manifest fetch to prevent silent failures (#1332)
* validate and retry manifest fetch * Refactor error handling in isRateLimitError function for improved clarity
Configuration menu - View commit details
-
Copy full SHA for 54baeea - Browse repository at this point
Copy the full SHA 54baeeaView commit details
Commits on Jul 15, 2026
-
Migrate to ESM and upgrade dependencies (#1330)
* Migrate to ESM and upgrade dependencies * Add ESM migration note to README for V7 * Remove unnecessary devDependencies: ts-node, @types/jest * npm audit fix * Upgrade @types/node to version 26.0.0 * Clarify ESM migration details in README for V7 * Update README and dependencies * Fix lint issue
Configuration menu - View commit details
-
Copy full SHA for f8cf429 - Browse repository at this point
Copy the full SHA f8cf429View commit details
Commits on Jul 16, 2026
-
Remove the pip-install input (#1336)
* Remove the pip-install input * Resloves merge conflicts --------- Co-authored-by: gowridurgad <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 0f3a009 - Browse repository at this point
Copy the full SHA 0f3a009View commit details -
Merge pull request #1337 from actions/philip-gai/bump-actions-cache-6…
…-2-0 chore(deps): bump @actions/cache to 6.2.0
Configuration menu - View commit details
-
Copy full SHA for 4ab7e95 - Browse repository at this point
Copy the full SHA 4ab7e95View commit details
Commits on Jul 20, 2026
-
Pin SHA commits and update docs with latest versions (#1338)
* Update GitHub Actions to use checkout and setup-python actions version 7 * Fix formatting in publish-immutable-actions.yml
Configuration menu - View commit details
-
Copy full SHA for 5fda3b9 - Browse repository at this point
Copy the full SHA 5fda3b9View commit details
Commits on Aug 3, 2026
-
fix: resolve npm audit high severity vulnerabilities (#1347)
- Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q) - Add package.json override to force brace-expansion >=5.0.8 across all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without downgrading jest/ts-jest - Refresh .licenses/npm cache to match updated dependency tree - Rebuild dist/setup and dist/cache-save npm audit now reports 0 vulnerabilities. Pre-existing test suite failures (7 suites, ESM/jest teardown issue) verified unrelated to this change - identical on unmodified main with node 24. Co-authored-by: Copilot <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 8549b9f - Browse repository at this point
Copy the full SHA 8549b9fView commit details
Commits on Aug 18, 2026
-
fix: resolve npm audit high severity vulnerabilities (#1350)
Bumps transitive dependencies to patched versions: - brace-expansion 5.0.8 -> 5.0.9 (GHSA-rgw5-rvv9-x895) - js-yaml 3.15.0 -> 3.15.1 (GHSA-5p4m-2wfm-xmqj) - undici 6.27.0 -> 6.28.0 (GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5, GHSA-v3r7-h72x-cjcm) Refreshes .licenses/ cache for the updated packages and rebuilds dist/. Co-authored-by: Copilot <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9191ea1 - Browse repository at this point
Copy the full SHA 9191ea1View commit details
Commits on Aug 19, 2026
-
Bump actions/checkout from 7.0.0 to 7.0.1 (#1345)
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@9c091bb...3d3c42e) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 66fcabf - Browse repository at this point
Copy the full SHA 66fcabfView commit details
Commits on Aug 20, 2026
-
Co-authored-by: lmvysakh <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 751276e - Browse repository at this point
Copy the full SHA 751276eView commit details
Commits on Sep 8, 2026
-
feat: Add
mirrorandmirror-tokeninputs for custom Python distri……bution sources (#1302) * feat: Add `mirror` and `mirror-token` inputs for custom Python distribution sources Users who need custom CPython builds (internal mirrors, GHES-hosted forks, special build configurations, compliance builds, air-gapped runners) could not previously point setup-python at anything other than actions/python-versions. Adds two new inputs: - `mirror`: base URL hosting versions-manifest.json and the Python distributions it references. Defaults to the existing https://raw.githubusercontent.com/actions/python-versions/main. - `mirror-token`: optional token used to authenticate requests to the mirror. If `mirror` is a raw.githubusercontent.com/{owner}/{repo}/{branch} URL, the manifest is fetched via the GitHub REST API (authenticated rate limit applies); otherwise the action falls back to a direct GET of {mirror}/versions-manifest.json. Token interaction ----------------- `token` is never forwarded to arbitrary hosts. Auth resolution is per-URL: 1. if mirror-token is set, use mirror-token 2. else if token is set AND the target host is github.com, *.github.com, or *.githubusercontent.com, use token 3. else send no auth Cases: Default (no inputs set) mirror = default raw.githubusercontent.com URL, mirror-token empty, token = github.token. → manifest API call and tarball downloads use `token`. Identical to prior behavior. Custom raw.githubusercontent.com mirror (e.g. personal fork) mirror-token empty, token = github.token. → manifest API call and tarball downloads use `token` (target hosts are GitHub-owned). Custom non-GitHub mirror, no mirror-token mirror-token empty, token = github.token. → manifest fetched via direct URL (no auth attached), tarball downloads use no auth. `token` is NOT forwarded to the custom host — this is the leak-prevention case. Custom non-GitHub mirror with mirror-token mirror-token set, token may be set. → manifest fetch and tarball downloads use `mirror-token`. Custom GitHub mirror with both tokens set mirror-token wins. Used for both the manifest API call and tarball downloads. * fix: address mirror review feedback - scope mirror-token to the mirror host and send it verbatim - route non-repo mirrors straight to the URL fetch instead of throwing - authenticate the manifest fetch - warn on slash branches, and on mirror with PyPy/GraalPy - memoize mirror validation - exercise the direct-URL path in the E2E job Addresses #1302 (comment) Co-Authored-By: Claude Opus 4.8 <[email protected]> * fix: correct mirror warnings, auth scoping, and integration coverage - only warn about PyPy/GraalPy mirror when a custom mirror is set; the action.yml default made the warning fire on every run - accept the refs/heads/{branch} raw URL form so it routes via the REST API instead of tripping the slash-branch warning - scope mirror-token to the full mirror origin (scheme+host+port) so it can't leak to a same-host http download_url - make an invalid mirror fatal on the auth path, matching getManifestUrl - fix warning/docs that wrongly claimed the raw fallback is anonymous - force a manifest fetch in the mirror integration job (check-latest) so it actually contacts the mirror instead of using the preinstalled cache --------- Co-authored-by: Claude Opus 4.8 <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 337b072 - Browse repository at this point
Copy the full SHA 337b072View commit details
Commits on Sep 9, 2026
-
Bump browserslist from 4.28.2 to 4.28.9 (#1353)
* Bump browserslist from 4.28.2 to 4.28.9 Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.2 to 4.28.9. - [Release notes](https://github.com/browserslist/browserslist/releases) - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md) - [Commits](browserslist/browserslist@4.28.2...4.28.9) --- updated-dependencies: - dependency-name: browserslist dependency-version: 4.28.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <[email protected]> * chore: remove mirror-token test, bump js-yaml --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: priyagupta108 <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ad3497a - Browse repository at this point
Copy the full SHA ad3497aView commit details
Commits on Sep 21, 2026
-
Bump @typescript-eslint/parser from 8.62.0 to 8.70.0 (#1343)
Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.62.0 to 8.70.0. - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases) - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md) - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser) --- updated-dependencies: - dependency-name: "@typescript-eslint/parser" dependency-version: 8.64.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7aeabeb - Browse repository at this point
Copy the full SHA 7aeabebView commit details -
Bump eslint-plugin-jest from 29.15.2 to 29.16.6 (#1342)
Bumps [eslint-plugin-jest](https://github.com/jest-community/eslint-plugin-jest) from 29.15.2 to 29.16.6. - [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases) - [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md) - [Commits](jest-community/eslint-plugin-jest@v29.15.2...v29.16.6) --- updated-dependencies: - dependency-name: eslint-plugin-jest dependency-version: 29.15.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for af9bcc7 - Browse repository at this point
Copy the full SHA af9bcc7View commit details
Commits on Sep 24, 2026
-
Bump @vercel/ncc from 0.44.0 to 0.45.0 (#1357)
* Bump @vercel/ncc from 0.44.0 to 0.45.0 Bumps [@vercel/ncc](https://github.com/vercel/ncc) from 0.44.0 to 0.45.0. - [Release notes](https://github.com/vercel/ncc/releases) - [Commits](vercel/ncc@0.44.0...0.45.0) --- updated-dependencies: - dependency-name: "@vercel/ncc" dependency-version: 0.45.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]> * fix: update asset-relocator-loader for compatibility with webpack runtime --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: HarithaVattikuti <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 06da627 - Browse repository at this point
Copy the full SHA 06da627View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff releases/v6...main