Skip to content

chore(deps): bump softprops/action-gh-release from 2 to 3 - #2

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/softprops/action-gh-release-3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown

Bumps softprops/action-gh-release from 2 to 3.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on v2.6.2.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release

v2.6.2

What's Changed

Other Changes 🔄

Full Changelog: softprops/action-gh-release@v2...v2.6.2

v2.6.1

2.6.1 is a patch release focused on restoring linked discussion thread creation when discussion_category_name is set. It fixes [#764](https://github.com/softprops/action-gh-release/issues/764), where the draft-first publish flow stopped carrying the discussion category through the final publish step.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

Bug fixes 🐛

v2.6.0

2.6.0 is a minor release centered on previous_tag support for generate_release_notes, which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range. It also includes the recent concurrent asset upload recovery fix, a working_directory docs sync, a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

... (truncated)

Changelog

Sourced from softprops/action-gh-release's changelog.

0.1.13

  • fix issue with multiple runs concatenating release bodies #145
Commits
  • 3d0d988 release 3.0.2 (#818)
  • 7e13ed4 fix: clarify release creation 404 errors (#817)
  • e6c70a5 fix: replace existing release assets on Gitea (#816)
  • f345337 fix: publish existing draft releases as prereleases (#801)
  • d8a89a2 fix: upload small checksum assets reliably (#815)
  • 45ece40 chore(deps): remove unused TypeScript tooling (#814)
  • f6b913c feat: improve release error reporting and test coverage (#813)
  • 15f193d chore(deps): upgrade TypeScript to 7 (#812)
  • cc8268d chore(deps): bump actions/checkout in the github-actions group (#810)
  • fd0ed1e chore(deps): bump the npm group with 3 updates (#811)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 17, 2026
@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: 81625d6b-be60-45e1-b08f-58cd5ff887b1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@dependabot dependabot Bot changed the title build(deps): Bump softprops/action-gh-release from 2 to 3 chore(deps): bump softprops/action-gh-release from 2 to 3 Jul 17, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/softprops/action-gh-release-3 branch from 5e44bb0 to 1ee6743 Compare July 17, 2026 18:12
@dependabot
dependabot Bot requested a review from DevVig as a code owner July 17, 2026 18:12
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/softprops/action-gh-release-3 branch from 1ee6743 to b41e036 Compare July 17, 2026 18:13
@DevVig

DevVig commented Jul 17, 2026

Copy link
Copy Markdown
Owner

Superseded by #15 (batched GitHub Actions bumps).

@DevVig DevVig closed this Jul 17, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/softprops/action-gh-release-3 branch July 17, 2026 18:40
DevVig added a commit that referenced this pull request Jul 18, 2026
## What

Adds a **Tauri in-app self-updater** alongside the existing Homebrew
path — and makes it **channel-aware** so the two can't drift.

### The drift problem this avoids
A brew-installed `.app` that silently self-updates diverges from the
formula version, and the next `brew upgrade` fights it. So the updater
checks how the app was installed:

- **Homebrew installs** (formula drops a `.microbridge-brew` marker at
the bundle root) → "Check for Updates…" points the user at `brew upgrade
microbridge`. Never self-replaced.
- **Direct / DMG installs** → full Tauri flow: `check()` → confirm →
`downloadAndInstall()` → `relaunch()`.

### Staying honest with principle #2 ("Zero network, no update pings")
- The **daemon stays 100% network-free** — the updater lives entirely in
the UI app.
- **User-initiated by default.** No background polling, no timers.
- An **opt-in** "check once at launch" toggle exists (off by default);
when on, it checks silently and only speaks up if an update is ready.

## Changes
- `tauri-plugin-updater` / `-process` / `-dialog` wired into the menu
bar app (Rust + JS + capabilities).
- `update_channel` + `app_version` commands (`src-tauri/src/lib.rs`).
- **"Check for Updates…"** tray menu item → emits
`menu://check-updates`; the always-loaded popover runs the flow.
- New **Updates** settings tab: version, install channel, opt-in
launch-check toggle, manual check button.
- `plugins.updater` config with the committed public key + the stable
GitHub `releases/latest/download/latest.json` endpoint.

## Not in this PR (follow-up)
Release plumbing — `bundle.createUpdaterArtifacts`, signing the updater
tarball in CI, and generating/uploading `latest.json`. Until that ships
with `v0.2.0`, `check()` simply finds no manifest and no-ops gracefully.
The updater signing keypair + GitHub secrets are already in place.

## Verification
- `npm run build` (tsc + vite) ✅
- `cargo build` on the tauri crate ✅ — compiles, and tauri's build
script validates the new `plugins.updater` config and capability
permissions.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
DevVig added a commit that referenced this pull request Jul 18, 2026
## What

Completes the in-app self-updater (follow-up to #41) by producing the
artifacts it consumes at release time.

### Release plumbing
- **`bundle.createUpdaterArtifacts: true`** → `tauri build` emits the
signed `Microbridge.app.tar.gz` + `.sig` updater bundle alongside the
`.app`/DMG.
- **Signing secrets** (`TAURI_SIGNING_PRIVATE_KEY` + `_PASSWORD`)
exported into the UI build. Already set on the repo. Forks without the
key still build — updater artifacts auto-disable via a `--config`
override, so releases never hard-fail.
- **Per-arch packing**: the updater tarball is renamed
`Microbridge-<target>.app.tar.gz` so the two matrix legs don't collide
as release assets.
- **`latest.json`** generated in the publish job (via `jq`, from the
`.sig` contents) with `darwin-aarch64` + `darwin-x86_64` entries, and
uploaded as a release asset. The app's endpoint
`releases/latest/download/latest.json` always resolves to the newest
release.

### Docs
- README principle #2 reworded: the **daemon stays zero-network**; the
app's *only* network call is the **opt-in, user-triggered** update
check. No background pings.
- INSTALL.md documents the in-app update path for direct installs and
the brew-managed behavior.

## Channel safety (recap from #41)
Brew installs carry a `.microbridge-brew` marker; the app routes those
to `brew upgrade` and never self-replaces, so the formula version and
the on-disk bundle can't drift. Direct/DMG installs self-update.

## How it's exercised
This runs on the next `v*` tag (targeting `v0.2.0`). Merge order matters
only in that both this and #41 must be on `main` before tagging — no
release is cut before then.

## Verification
- `release.yml` validated as YAML; `tauri.conf.json` valid JSON with
`createUpdaterArtifacts: true`.
- `cargo build` on the tauri crate passes with the config change.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant