Skip to content

chore(deps): update pypa/gh-action-pypi-publish digest to dc37677 - #363

Draft
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypa-gh-action-pypi-publish-digest
Draft

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypa-gh-action-pypi-publish-digest

Conversation

@renovate

@renovate renovate Bot commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
pypa/gh-action-pypi-publish (changelog) action digest ed0c539 → dc37677

Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • "before 9am on Monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Apr 13, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 8db9ff5a-44a8-4b0c-81b4-ddee2d66dbbf

📥 Commits

Reviewing files that changed from the base of the PR and between 44e9c98 and d0684ca.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: a19c66f7-9dc1-47c0-ab82-0e46d0dc5b87

📥 Commits

Reviewing files that changed from the base of the PR and between d4d3d7d and 817ee04.

📒 Files selected for processing (1)
  • .github/workflows/cd-pypi-cli.yml
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/cd-pypi-cli.yml

Included review availability: Your plan provides up to 8 included reviews per hour; 4 remain after this review.


📝 Walkthrough

Walkthrough

Updated the pinned commit SHA for the PyPI publishing action in the CD workflow. The release/v1 reference and packages-dir: dist configuration remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: dinohamzic

Merge Risk: ⚪ Minimal · up to 817ee

The change only retargets the pinned PyPI publishing action commit, with no evidenced configuration or behavior regression. It is ready to merge after normal workflow validation.

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating the pinned digest for the PyPI publishing GitHub Action.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Updates Docs ✅ Passed PASS: The pull request changes only the pinned commit digest for pypa/gh-action-pypi-publish in .github/workflows/cd-pypi-cli.yml. It does not implement a feature or change user-facing behavior th…

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Apr 13, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 90.00%. Comparing base (505ea44) to head (d0684ca).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #363   +/-   ##
=======================================
  Coverage   90.00%   90.00%           
=======================================
  Files         211      211           
  Lines       12451    12451           
  Branches     3482     3482           
=======================================
  Hits        11206    11206           
  Misses       1242     1242           
  Partials        3        3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from 676a24a to 8f64b4d Compare April 22, 2026 07:20
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from cc9f68d to f9f6d24 Compare April 30, 2026 13:24
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 3 times, most recently from 3f74138 to 5b53809 Compare May 14, 2026 07:18
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from 99991d4 to decb330 Compare May 15, 2026 10:23
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from decb330 to 1579836 Compare May 21, 2026 18:10
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 9 times, most recently from dec790e to d434058 Compare June 4, 2026 12:05

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/cd-pypi-cli.yml:
- Line 46: The Setup Bun action step (uses:
oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is incorrectly
attempting to use a non-existent `cache` input; change the step to pass the
correct input by adding `with: no-cache: true` to the "Setup Bun" step so Bun
caching is disabled (use the `no-cache` input rather than `cache`).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: a23aa126-1262-4adf-8a61-1c8e4f17c8f1

📥 Commits

Reviewing files that changed from the base of the PR and between ddef09f and d434058.

📒 Files selected for processing (1)
  • .github/workflows/cd-pypi-cli.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/cd-pypi-cli.yml:
- Line 46: The Setup Bun action step (uses:
oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is incorrectly
attempting to use a non-existent `cache` input; change the step to pass the
correct input by adding `with: no-cache: true` to the "Setup Bun" step so Bun
caching is disabled (use the `no-cache` input rather than `cache`).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: a23aa126-1262-4adf-8a61-1c8e4f17c8f1

📥 Commits

Reviewing files that changed from the base of the PR and between ddef09f and d434058.

📒 Files selected for processing (1)
  • .github/workflows/cd-pypi-cli.yml
🛑 Comments failed to post (1)
.github/workflows/cd-pypi-cli.yml (1)

46-46: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify setup-bun supports cache input and its default in the pinned commit.
set -euo pipefail

curl -fsSL https://raw.githubusercontent.com/oven-sh/setup-bun/0c5077e51419868618aeaa5fe8019c62421857d6/action.yml \
  | sed -n '1,220p'

# Find all setup-bun uses and whether cache is explicitly configured.
rg -n -C3 'uses:\s*oven-sh/setup-bun@' .github/workflows

Repository: deepnote/deepnote

Length of output: 3070


Disable Bun caching at Line 46 using no-cache (not cache)

oven-sh/setup-bun@... (pinned v2) exposes no-cache (default: false); there is no cache input. Set with: no-cache: true on the Setup Bun step.

Suggested fix
      - name: Setup Bun
        uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
        with:
          no-cache: true
🧰 Tools
🪛 zizmor (1.25.2)

[error] 46-46: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default

(cache-poisoning)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/cd-pypi-cli.yml at line 46, The Setup Bun action step
(uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6) is
incorrectly attempting to use a non-existent `cache` input; change the step to
pass the correct input by adding `with: no-cache: true` to the "Setup Bun" step
so Bun caching is disabled (use the `no-cache` input rather than `cache`).

@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from d434058 to ca71123 Compare June 4, 2026 13:05
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 2 times, most recently from 440b998 to b78b457 Compare July 29, 2026 17:55
@renovate renovate Bot changed the title chore(deps): update pypa/gh-action-pypi-publish digest to ba38be9 chore(deps): update pypa/gh-action-pypi-publish digest to dc37677 Jul 29, 2026
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 5 times, most recently from 8576a30 to cc47d4b Compare August 5, 2026 17:31
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from cc47d4b to e4dd168 Compare August 6, 2026 16:21
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch from e4dd168 to 7dcf2ab Compare August 7, 2026 08:03
@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 9 times, most recently from be8333c to e51ca79 Compare August 13, 2026 12:35
@renovate
renovate Bot force-pushed the renovate/pypa-gh-action-pypi-publish-digest branch 7 times, most recently from abeda3a to 800583a Compare August 20, 2026 19:11

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants