Skip to content

build(deps): bump the github-actions group across 1 directory with 2 updates - #136

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-70e908e652
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-70e908e652

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 2 updates in the / directory: CodSpeedHQ/action and changesets/action.

Updates CodSpeedHQ/action from 5.2.1 to 5.4.0

Release notes

Sourced from CodSpeedHQ/action's releases.

v5.4.0

Bumps the CodSpeed runner to v5.4.0, including v5.3.0 and v5.3.1.

The Memory instrument now tracks physical (resident) memory and captures allocation call stacks to build memory flamegraphs. Both are enabled by default and can be turned off with the new disable-memory-track-physical and disable-memory-capture-stack inputs. Serialization is also faster on large memory benchmarks.

The action now exposes the id of the CodSpeed run as a run-id output, and CodSpeed now works on non-Ubuntu/Debian distributions such as Arch Linux.

🚀 Features

  • Track physical memory and capture allocation call stacks for memory flamegraphs, both enabled by default by @​not-matthias in #529, #522 and #553
  • Expose the run id as a GitHub Actions step output by @​moha-bekh in #551
  • Add an --experimental-disable-pythonmalloc-override flag (CODSPEED_EXPERIMENTAL_DISABLE_PYTHONMALLOC_OVERRIDE) to stop overriding the Python allocator, which can break free-threaded Python in simulation mode, by @​not-matthias in #539
  • Apply kernel memory tunables before memory-mode runs, and fail early when the kernel has no BTF by @​not-matthias in #507 and #524
  • Pause producers under ring buffer pressure in memory mode, and log process stops per reason by @​not-matthias in #543
  • Log which authentication method the run uses by @​fargito in #521

🐛 Bug Fixes

  • Support distributions CodSpeed publishes no valgrind package for (Arch, rolling releases) by @​moha-bekh in #525
  • Error out when the profile archive exceeds the upload size limit by @​lvaroqui in #557
  • Detect free-threaded Python from venv and uv before setting PYTHONMALLOC by @​not-matthias in #539
  • Honor deprecated experimental flags, including their falsey values, instead of ignoring them by @​not-matthias in #532 and #553
  • Fix memory tracking edge cases: reused pids, stack-ring overflow, BPF links held by forked processes, and allocator symbols aliased at an attached offset by @​not-matthias in #522 and #543
  • Attach memory tracking hooks without perf_event_open by @​GuillaumeLagrange in #536
  • Restore profiling sysctls in walltime mode by @​not-matthias in #507

⚡ Performance

⚙️ Internals

Full Runner Changelog: https://github.com/CodSpeedHQ/codspeed/blob/main/CHANGELOG.md

What's Changed

New Contributors

... (truncated)

Commits
  • c4fd08a Release v5.4.0 🚀
  • 759ae97 feat: add disable-memory-capture-stack and disable-memory-track-physical inputs
  • fe42bc0 chore: bump runner version to 5.4.0 (#244)
  • c205870 feat: add a run-id output (#243)
  • 48820ec chore: bump runner version to 5.3.1 (#240)
  • 0fc899a feat: add experimental-memory-track-physical input
  • 2d26491 chore: bump runner version to 5.3.0 (#239)
  • See full diff in compare view

Updates changesets/action from 2.1.1 to 2.1.2

Release notes

Sourced from changesets/action's releases.

v2.1.2

Patch Changes

Changelog

Sourced from changesets/action's changelog.

@​changesets/action

2.1.2

Patch Changes

2.1.1

Patch Changes

2.1.0

Minor Changes

  • #718 3b7c71c Thanks @​bluwy! - Add a cwd input to the root action, /select-mode, /version, /pack, and /publish sub-actions to set the current working directory to execute Changesets in. This input existed in v1 but was incorrectly removed.

Patch Changes

2.0.0

Major Changes

  • #692 cb3f011 Thanks @​Andarist! - Release commits and tags are now pushed using the GitHub API by default.

    Replace the commit-mode input with the boolean push-with-git-cli input. Set push-with-git-cli: true to continue using the Git CLI.

    Regardless of the push mode, custom GitHub tokens must be passed explicitly through the github-token input. The GITHUB_TOKEN environment variable and credentials configured by actions/checkout or embedded in remote URLs are not substitutes for this input. When the Git CLI is enabled, github-token takes precedence over those repository credentials.

  • #680 ca57073 Thanks @​bluwy! - Add a new push-git-tags option that complements create-github-releases to control specifically if git tags should be created but not GitHub releases.

    If create-github-releases was previously set to false, which also indirectly disabled git tag creation, git tags will now be created instead by default. If this is not desired, set push-git-tags to false explicitly.

  • #657 4f718b5 Thanks @​Andarist! - Removed compatibility support for old Changesets v1.

  • #681 7359107 Thanks @​bluwy! - Rename the root action inputs and outputs to better match the sub-actions' conventions.

    Inputs:

... (truncated)

Commits
  • ae32849 v2.1.2
  • 0138f45 Version Packages (#726)
  • 8833883 Handle error when pushing git tags with the git CLI (#735)
  • e08fde7 Improve log messages (#730)
  • 371fd77 Bump human-id in the production-dependencies group across 1 directory (#732)
  • 85efcaf Bump actions/checkout in the github-actions group across 1 directory (#734)
  • 5bb9d5c Bump the development-dependencies group across 1 directory with 7 updates (#733)
  • ca85897 Always prepare branch for version (#729)
  • 36f529f Fix root action double error logs (#724)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the github-actions group with 2 updates in the / directory: [CodSpeedHQ/action](https://github.com/codspeedhq/action) and [changesets/action](https://github.com/changesets/action).


Updates `CodSpeedHQ/action` from 5.2.1 to 5.4.0
- [Release notes](https://github.com/codspeedhq/action/releases)
- [Changelog](https://github.com/CodSpeedHQ/action/blob/main/CHANGELOG.md)
- [Commits](CodSpeedHQ/action@373d686...c4fd08a)

Updates `changesets/action` from 2.1.1 to 2.1.2
- [Release notes](https://github.com/changesets/action/releases)
- [Changelog](https://github.com/changesets/action/blob/main/CHANGELOG.md)
- [Commits](changesets/action@8488615...ae32849)

---
updated-dependencies:
- dependency-name: CodSpeedHQ/action
  dependency-version: 5.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: changesets/action
  dependency-version: 2.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 6, 2026
@bombshell-cooper

Copy link
Copy Markdown

No changeset needed

This pull request is classified as no_release_impact: no published package

@pkg-pr-new

pkg-pr-new Bot commented Oct 6, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@bomb.sh/tty@136

commit: ae3f2f2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changeset: not-needed dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants