From 11403dfb40fbc5340fb9209d06056374d6f74058 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Fri, 6 Dec 2024 15:35:33 -0500
Subject: [PATCH] Bump tj-actions/changed-files from 36.0.10 to 41.0.0 in
/.github/workflows (#5620)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps
[tj-actions/changed-files](https://github.com/tj-actions/changed-files)
from 36.0.10 to 41.0.0.
Sourced from tj-actions/changed-files's
releases. A new [!NOTE]
This can be disabled by setting the ...
Release notes
v41.0.0
🔥 🔥 BREAKING CHANGE 🔥 🔥
safe_output
input is now available to prevent
outputting unsafe filename characters (Enabled by default). This would
escape characters in the filename that could be used for command
injection.
safe_output
to false
this comes with a recommendation to store all outputs generated in an
environment variable first before using them.Example
...
- name: Get changed files
id: changed-files
uses: tj-actions/changed-files@v40
with:
safe_output: false # set to false because we are using an environment
variable to store the output and avoid command injection.
- name: List all added files
env:
ADDED_FILES: ${{ steps.changed-files.outputs.added_files }}
run: |
for file in "$ADDED_FILES"; do
echo "$file was added"
done
@renovate
in tj-actions/changed-files#1801@tj-actions-bot
in tj-actions/changed-files#1800@renovate
in tj-actions/changed-files#1802@renovate
in tj-actions/changed-files#1803@renovate
in tj-actions/changed-files#1804@tj-actions-bot
in tj-actions/changed-files#1805@jackton1
in tj-actions/changed-files#1806@jackton1
in tj-actions/changed-files#1808@renovate
in tj-actions/changed-files#1809@tj-actions-bot
in tj-actions/changed-files#1810Full Changelog: https://github.com/tj-actions/changed-files/compare/v40...v41.0.0
@tj-actions-bot
in tj-actions/changed-files#1811@renovate
in tj-actions/changed-files#1813@jackton1
in tj-actions/changed-files#1815... (truncated)
Sourced from tj-actions/changed-files's changelog.
41.0.0 - (2023-12-23)
🐛 Bug Fixes
⏪ Reverts
- Revert "chore(deps): update actions/download-artifact action to v4" (#1806)
(4f573fe) - (Tonye Jack)
🔄 Update
- Update README.md (6e79d6e) - (Tonye Jack)
- Update README.md (d13ac19) - (Tonye Jack)
- Update README.md (bb89f97) - (Tonye Jack)
- Updated README.md (#1810)
Co-authored-by: renovate[bot] (1864078) - (tj-actions[bot])
- Update README.md (#1808)
(47371c5) - (Tonye Jack)
📝 Other
- Merge pull request from GHSA-mcph-m25j-8j63
feat: add
safe_output
input enabled by defaultfix: migrate README to safe uses of interpolation
fix: README
uses
typofix: README examples to account for newlines
fix: README examples missing
safe_output
fix: remove sanitization of
'
fix: also sanitize
|&;
(0102c07) - (Jorge)⚙️ Miscellaneous Tasks
- deps: Lock file maintenance (f495a03) - (renovate[bot])
- deps: Update dependency eslint-plugin-prettier to v5.1.1 (089842a) - (renovate[bot])
- deps: Lock file maintenance (787db06) - (renovate[bot])
- deps: Update dependency eslint-plugin-prettier to v5.1.0 (4ef6b56) - (renovate[bot])
- deps: Update typescript-eslint monorepo to v6.15.0 (c9ae347) - (renovate[bot])
... (truncated)
6e79d6e
Update README.mdd13ac19
Update README.mdbb89f97
Update README.md1864078
Updated README.md (#1810)f495a03
chore(deps): lock file maintenance47371c5
Update README.md (#1808)4f573fe
Revert "chore(deps): update actions/download-artifact action to
v4" (#1806)ff2f6e6
fix: update safe output regex and the docs (#1805)0102c07
Merge pull request from GHSA-mcph-m25j-8j63089842a
chore(deps): update dependency eslint-plugin-prettier to v5.1.1