Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: actions/setup-python
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: releases/v6
Choose a base ref
...
head repository: actions/setup-python
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 17 commits
  • 85 files changed
  • 13 contributors

Commits on Jul 10, 2026

  1. Bump certifi from 2020.6.20 to 2024.7.4 in /__tests__/data (#1328)

    Bumps [certifi](https://github.com/certifi/python-certifi) from 2020.6.20 to 2024.7.4.
    - [Commits](certifi/python-certifi@2020.06.20...2024.07.04)
    
    ---
    updated-dependencies:
    - dependency-name: certifi
      dependency-version: 2024.7.4
      dependency-type: direct:production
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jul 10, 2026
    Configuration menu
    Copy the full SHA
    0903b46 View commit details
    Browse the repository at this point in the history

Commits on Jul 13, 2026

  1. remove EOL Python versions and Bumps numpy text fixture (#1333)

    * remove EOL Python versions
    
    * Fix typo in comments for executable suffix removal in test-pypy.yml
    v-priya-kinthali authored Jul 13, 2026
    Configuration menu
    Copy the full SHA
    6849080 View commit details
    Browse the repository at this point in the history
  2. Annotation code fix (#1335)

    Co-authored-by: lmvysakh <[email protected]>
    v-lmvysakh and lmvysakh authored Jul 13, 2026
    Configuration menu
    Copy the full SHA
    c709277 View commit details
    Browse the repository at this point in the history

Commits on Jul 14, 2026

  1. Validate and retry manifest fetch to prevent silent failures (#1332)

    * validate and retry manifest fetch
    
    * Refactor error handling in isRateLimitError function for improved clarity
    v-priyagupta108 authored Jul 14, 2026
    Configuration menu
    Copy the full SHA
    54baeea View commit details
    Browse the repository at this point in the history

Commits on Jul 15, 2026

  1. Migrate to ESM and upgrade dependencies (#1330)

    * Migrate to ESM and upgrade dependencies
    
    * Add ESM migration note to README for V7
    
    * Remove unnecessary devDependencies: ts-node, @types/jest
    
    * npm audit fix
    
    * Upgrade @types/node to version 26.0.0
    
    * Clarify ESM migration details in README for V7
    
    * Update README and dependencies
    
    * Fix lint issue
    v-priyagupta108 authored Jul 15, 2026
    Configuration menu
    Copy the full SHA
    f8cf429 View commit details
    Browse the repository at this point in the history

Commits on Jul 16, 2026

  1. Remove the pip-install input (#1336)

    * Remove the pip-install input
    
    * Resloves merge conflicts
    
    ---------
    
    Co-authored-by: gowridurgad <[email protected]>
    v-gowridurgad and gowridurgad authored Jul 16, 2026
    Configuration menu
    Copy the full SHA
    0f3a009 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #1337 from actions/philip-gai/bump-actions-cache-6…

    …-2-0
    
    chore(deps): bump @actions/cache to 6.2.0
    philip-gai authored Jul 16, 2026
    Configuration menu
    Copy the full SHA
    4ab7e95 View commit details
    Browse the repository at this point in the history

Commits on Jul 20, 2026

  1. Pin SHA commits and update docs with latest versions (#1338)

    * Update GitHub Actions to use checkout and setup-python actions version 7
    
    * Fix formatting in publish-immutable-actions.yml
    v-HarithaVattikuti authored Jul 20, 2026
    Configuration menu
    Copy the full SHA
    5fda3b9 View commit details
    Browse the repository at this point in the history

Commits on Aug 3, 2026

  1. fix: resolve npm audit high severity vulnerabilities (#1347)

    - Upgrade fast-xml-parser to 5.10.1 (fixes GHSA-8r6m-32jq-jx6q)
    - Add package.json override to force brace-expansion >=5.0.8 across
      all transitive dependencies (fixes GHSA-mh99-v99m-4gvg) without
      downgrading jest/ts-jest
    - Refresh .licenses/npm cache to match updated dependency tree
    - Rebuild dist/setup and dist/cache-save
    
    npm audit now reports 0 vulnerabilities. Pre-existing test suite
    failures (7 suites, ESM/jest teardown issue) verified unrelated to
    this change - identical on unmodified main with node 24.
    
    Co-authored-by: Copilot <[email protected]>
    v-HarithaVattikuti and Copilot authored Aug 3, 2026
    Configuration menu
    Copy the full SHA
    8549b9f View commit details
    Browse the repository at this point in the history

Commits on Aug 18, 2026

  1. fix: resolve npm audit high severity vulnerabilities (#1350)

    Bumps transitive dependencies to patched versions:
    - brace-expansion 5.0.8 -> 5.0.9 (GHSA-rgw5-rvv9-x895)
    - js-yaml 3.15.0 -> 3.15.1 (GHSA-5p4m-2wfm-xmqj)
    - undici 6.27.0 -> 6.28.0 (GHSA-8xcm-r25x-g524, GHSA-m8rv-5g2x-5cg5, GHSA-v3r7-h72x-cjcm)
    
    Refreshes .licenses/ cache for the updated packages and rebuilds dist/.
    
    Co-authored-by: Copilot <[email protected]>
    v-HarithaVattikuti and Copilot authored Aug 18, 2026
    Configuration menu
    Copy the full SHA
    9191ea1 View commit details
    Browse the repository at this point in the history

Commits on Aug 19, 2026

  1. Bump actions/checkout from 7.0.0 to 7.0.1 (#1345)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
    - [Release notes](https://github.com/actions/checkout/releases)
    - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
    - [Commits](actions/checkout@9c091bb...3d3c42e)
    
    ---
    updated-dependencies:
    - dependency-name: actions/checkout
      dependency-version: 7.0.1
      dependency-type: direct:production
      update-type: version-update:semver-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Aug 19, 2026
    Configuration menu
    Copy the full SHA
    66fcabf View commit details
    Browse the repository at this point in the history

Commits on Aug 20, 2026

  1. Updated error message (#1351)

    Co-authored-by: lmvysakh <[email protected]>
    v-lmvysakh and lmvysakh authored Aug 20, 2026
    Configuration menu
    Copy the full SHA
    751276e View commit details
    Browse the repository at this point in the history

Commits on Sep 8, 2026

  1. feat: Add mirror and mirror-token inputs for custom Python distri…

    …bution sources (#1302)
    
    * feat: Add `mirror` and `mirror-token` inputs for custom Python distribution sources
    
    Users who need custom CPython builds (internal mirrors, GHES-hosted forks,
    special build configurations, compliance builds, air-gapped runners) could not
    previously point setup-python at anything other than actions/python-versions.
    
    Adds two new inputs:
    - `mirror`: base URL hosting versions-manifest.json and the Python
      distributions it references. Defaults to the existing
      https://raw.githubusercontent.com/actions/python-versions/main.
    - `mirror-token`: optional token used to authenticate requests to the mirror.
    
    If `mirror` is a raw.githubusercontent.com/{owner}/{repo}/{branch} URL, the
    manifest is fetched via the GitHub REST API (authenticated rate limit applies);
    otherwise the action falls back to a direct GET of {mirror}/versions-manifest.json.
    
    Token interaction
    -----------------
    
    `token` is never forwarded to arbitrary hosts. Auth resolution is per-URL:
    
      1. if mirror-token is set, use mirror-token
      2. else if token is set AND the target host is github.com,
         *.github.com, or *.githubusercontent.com, use token
      3. else send no auth
    
    Cases:
    
      Default (no inputs set)
        mirror = default raw.githubusercontent.com URL, mirror-token empty,
        token = github.token.
        → manifest API call and tarball downloads use `token`.
        Identical to prior behavior.
    
      Custom raw.githubusercontent.com mirror (e.g. personal fork)
        mirror-token empty, token = github.token.
        → manifest API call and tarball downloads use `token`
          (target hosts are GitHub-owned).
    
      Custom non-GitHub mirror, no mirror-token
        mirror-token empty, token = github.token.
        → manifest fetched via direct URL (no auth attached),
          tarball downloads use no auth.
        `token` is NOT forwarded to the custom host — this is the
        leak-prevention case.
    
      Custom non-GitHub mirror with mirror-token
        mirror-token set, token may be set.
        → manifest fetch and tarball downloads use `mirror-token`.
    
      Custom GitHub mirror with both tokens set
        mirror-token wins. Used for both the manifest API call and
        tarball downloads.
    
    * fix: address mirror review feedback
    
    - scope mirror-token to the mirror host and send it verbatim
    - route non-repo mirrors straight to the URL fetch instead of throwing
    - authenticate the manifest fetch
    - warn on slash branches, and on mirror with PyPy/GraalPy
    - memoize mirror validation
    - exercise the direct-URL path in the E2E job
    
    Addresses #1302 (comment)
    
    Co-Authored-By: Claude Opus 4.8 <[email protected]>
    
    * fix: correct mirror warnings, auth scoping, and integration coverage
    
    - only warn about PyPy/GraalPy mirror when a custom mirror is set; the
      action.yml default made the warning fire on every run
    - accept the refs/heads/{branch} raw URL form so it routes via the REST
      API instead of tripping the slash-branch warning
    - scope mirror-token to the full mirror origin (scheme+host+port) so it
      can't leak to a same-host http download_url
    - make an invalid mirror fatal on the auth path, matching getManifestUrl
    - fix warning/docs that wrongly claimed the raw fallback is anonymous
    - force a manifest fetch in the mirror integration job (check-latest) so
      it actually contacts the mirror instead of using the preinstalled cache
    
    ---------
    
    Co-authored-by: Claude Opus 4.8 <[email protected]>
    luhenry and claude authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    337b072 View commit details
    Browse the repository at this point in the history

Commits on Sep 9, 2026

  1. Bump browserslist from 4.28.2 to 4.28.9 (#1353)

    * Bump browserslist from 4.28.2 to 4.28.9
    
    Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.2 to 4.28.9.
    - [Release notes](https://github.com/browserslist/browserslist/releases)
    - [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
    - [Commits](browserslist/browserslist@4.28.2...4.28.9)
    
    ---
    updated-dependencies:
    - dependency-name: browserslist
      dependency-version: 4.28.8
      dependency-type: indirect
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * chore: remove mirror-token test, bump js-yaml
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: priyagupta108 <[email protected]>
    dependabot[bot] and v-priyagupta108 authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    ad3497a View commit details
    Browse the repository at this point in the history

Commits on Sep 21, 2026

  1. Bump @typescript-eslint/parser from 8.62.0 to 8.70.0 (#1343)

    Bumps [@typescript-eslint/parser](https://github.com/typescript-eslint/typescript-eslint/tree/HEAD/packages/parser) from 8.62.0 to 8.70.0.
    - [Release notes](https://github.com/typescript-eslint/typescript-eslint/releases)
    - [Changelog](https://github.com/typescript-eslint/typescript-eslint/blob/main/packages/parser/CHANGELOG.md)
    - [Commits](https://github.com/typescript-eslint/typescript-eslint/commits/v8.70.0/packages/parser)
    
    ---
    updated-dependencies:
    - dependency-name: "@typescript-eslint/parser"
      dependency-version: 8.64.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 21, 2026
    Configuration menu
    Copy the full SHA
    7aeabeb View commit details
    Browse the repository at this point in the history
  2. Bump eslint-plugin-jest from 29.15.2 to 29.16.6 (#1342)

    Bumps [eslint-plugin-jest](https://github.com/jest-community/eslint-plugin-jest) from 29.15.2 to 29.16.6.
    - [Release notes](https://github.com/jest-community/eslint-plugin-jest/releases)
    - [Changelog](https://github.com/jest-community/eslint-plugin-jest/blob/main/CHANGELOG.md)
    - [Commits](jest-community/eslint-plugin-jest@v29.15.2...v29.16.6)
    
    ---
    updated-dependencies:
    - dependency-name: eslint-plugin-jest
      dependency-version: 29.15.4
      dependency-type: direct:development
      update-type: version-update:semver-patch
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Sep 21, 2026
    Configuration menu
    Copy the full SHA
    af9bcc7 View commit details
    Browse the repository at this point in the history

Commits on Sep 24, 2026

  1. Bump @vercel/ncc from 0.44.0 to 0.45.0 (#1357)

    * Bump @vercel/ncc from 0.44.0 to 0.45.0
    
    Bumps [@vercel/ncc](https://github.com/vercel/ncc) from 0.44.0 to 0.45.0.
    - [Release notes](https://github.com/vercel/ncc/releases)
    - [Commits](vercel/ncc@0.44.0...0.45.0)
    
    ---
    updated-dependencies:
    - dependency-name: "@vercel/ncc"
      dependency-version: 0.45.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    
    * fix: update asset-relocator-loader for compatibility with webpack runtime
    
    ---------
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: HarithaVattikuti <[email protected]>
    dependabot[bot] and v-HarithaVattikuti authored Sep 24, 2026
    Configuration menu
    Copy the full SHA
    06da627 View commit details
    Browse the repository at this point in the history
Loading