Skip to content

chore(deps): Bump peter-evans/create-pull-request from 6 to 8 - #9

Merged
DeepDiver1975 merged 1 commit into
mainfrom
dependabot/github_actions/peter-evans/create-pull-request-8
Jun 22, 2026
Merged

chore(deps): Bump peter-evans/create-pull-request from 6 to 8#9
DeepDiver1975 merged 1 commit into
mainfrom
dependabot/github_actions/peter-evans/create-pull-request-8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps peter-evans/create-pull-request from 6 to 8.

Release notes

Sourced from peter-evans/create-pull-request's releases.

Create Pull Request v8.0.0

What's new in v8

What's Changed

New Contributors

Full Changelog: peter-evans/create-pull-request@v7.0.11...v8.0.0

Create Pull Request v7.0.11

What's Changed

Full Changelog: peter-evans/create-pull-request@v7.0.10...v7.0.11

Create Pull Request v7.0.10

⚙️ Fixes an issue where updating a pull request failed when targeting a forked repository with the same owner as its parent.

What's Changed

New Contributors

Full Changelog: peter-evans/create-pull-request@v7.0.9...v7.0.10

Create Pull Request v7.0.9

⚙️ Fixes an incompatibility with the recently released actions/checkout@v6.

What's Changed

New Contributors

... (truncated)

Commits
  • 5f6978f fix: retry post-creation API calls on 422 eventual consistency errors (#4356)
  • d32e88d build(deps-dev): bump the npm group with 3 updates (#4349)
  • 8170bcc build(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (#4344)
  • 0041819 build(deps): bump picomatch (#4339)
  • b993918 build(deps-dev): bump flatted from 3.3.1 to 3.4.2 (#4334)
  • 36d7c84 build(deps-dev): bump undici from 6.23.0 to 6.24.0 (#4328)
  • a45d1fb build(deps): bump @​tootallnate/once and jest-environment-jsdom (#4323)
  • 3499eb6 build(deps): bump the github-actions group with 2 updates (#4316)
  • 3f3b473 build(deps): bump minimatch (#4311)
  • 6699836 build(deps-dev): bump the npm group with 2 updates (#4305)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) from 6 to 8.
- [Release notes](https://github.com/peter-evans/create-pull-request/releases)
- [Commits](peter-evans/create-pull-request@v6...v8)

---
updated-dependencies:
- dependency-name: peter-evans/create-pull-request
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 18, 2026
@DeepDiver1975
DeepDiver1975 merged commit 67ce1a5 into main Jun 22, 2026
2 checks passed
@DeepDiver1975
DeepDiver1975 deleted the dependabot/github_actions/peter-evans/create-pull-request-8 branch June 22, 2026 16:35
DeepDiver1975 added a commit that referenced this pull request Aug 21, 2026
…1) (#99)

Three open alerts all concern the same transitive js-yaml 4.x copies, which
Antora nests under three of its packages:

- js-yaml 4.1.1 -> 4.3.1 in @antora/content-aggregator,
  @antora/playbook-builder and @antora/ui-loader
  - #10 high   — quadratic CPU consumption in !!omap resolution
                 (CVE-2026-59870 not backported), needs >= 4.3.1
  - #9  high   — YAML merge-key chains force quadratic CPU, needs >= 4.3.0
  - #8  medium — quadratic-complexity DoS in merge key handling via
                 repeated aliases, needs >= 4.2.0

The direct js-yaml dependency is already 5.3.0 and is not in any vulnerable
range, so a blanket override is wrong here: it would downgrade the safe 5.x
direct dependency to the 4.x legacy line. Two major lines are live at once,
so the pin is applied per parent instead, leaving the root dependency at
5.3.0.

The three Antora packages declare "js-yaml": "~4.1", which cannot reach
4.3.1, and Antora's latest stable release (3.1.15) is already in use — only
3.2.0 pre-releases exist upstream. Overrides are therefore the only route to
the patched version without moving to a pre-release Antora.

Verified under Node 22 (the version CI uses; the local default is 18):
npm ci, npm run antora (exit 0), npm test (17/17 pass), npm run pagefind.
The 29 xref errors in the Antora log are pre-existing content issues on main
(stale "next@ocis:ROOT:" targets) and are non-fatal — no failure_level is
configured in site.yml.

All three alerts are fixable and fixed; none are left without a fix. They
remain open until this lands on the default branch.

Signed-off-by: Thomas Müller <1005065+DeepDiver1975@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant