Skip to content

build(deps): bump getplumber/plumber from 0.4.26 to 0.4.34 - #79

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/getplumber/plumber-0.4.34
Closed

build(deps): bump getplumber/plumber from 0.4.26 to 0.4.34#79
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/getplumber/plumber-0.4.34

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps getplumber/plumber from 0.4.26 to 0.4.34.

Release notes

Sourced from getplumber/plumber's releases.

v0.4.34

0.4.34 (2026-08-07)

✨ Features

  • identity: expose the finding-identity recipe and make job mean a job (e7af327), closes #403

👷 CI/CD

  • release: pin v0.4.33 refs [skip ci] (4a0c59d)

v0.4.33

0.4.33 (2026-08-07)

🐛 Bug Fixes

  • github: normalize SHA case and peel nested tag objects (fbfacde)
  • github: resolve action pins that name an annotated tag object (4016170), closes #401

⚡ Performance

  • github: skip the tag object probe for refs that cannot be one (eb9c669)

🔧 Chores

  • drop a stray worktree entry committed by mistake (82c947f)

📚 Documentation

  • github: record that the fork blind spot now covers tag objects (4eeee96)

✅ Tests

  • github: lock the collector-to-IR metadata handoff (ccfc59b)
  • github: lock the zero-cost happy path for the tag object fallback (fae517e)

👷 CI/CD

  • release: pin v0.4.32 refs [skip ci] (e84e2c0)

v0.4.32

0.4.32 (2026-08-06)

... (truncated)

Changelog

Sourced from getplumber/plumber's changelog.

0.4.35 (2026-08-08)

🐛 Bug Fixes

  • config: embed the shipped default in place (a27b4a5), closes #405

👷 CI/CD

  • release: pin v0.4.34 refs [skip ci] (d4bf27b)

0.4.34 (2026-08-07)

✨ Features

  • identity: expose the finding-identity recipe and make job mean a job (e7af327), closes #403

👷 CI/CD

  • release: pin v0.4.33 refs [skip ci] (4a0c59d)

0.4.33 (2026-08-07)

🐛 Bug Fixes

  • github: normalize SHA case and peel nested tag objects (fbfacde)
  • github: resolve action pins that name an annotated tag object (4016170), closes #401

⚡ Performance

  • github: skip the tag object probe for refs that cannot be one (eb9c669)

🔧 Chores

  • drop a stray worktree entry committed by mistake (82c947f)

📚 Documentation

  • github: record that the fork blind spot now covers tag objects (4eeee96)

✅ Tests

... (truncated)

Commits
  • e0ba76a chore(release): 0.4.34 [skip ci]
  • e7af327 feat(identity): expose the finding-identity recipe and make job mean a job
  • 4a0c59d ci(release): pin v0.4.33 refs [skip ci]
  • 8a58d65 chore(release): 0.4.33 [skip ci]
  • 4eeee96 docs(github): record that the fork blind spot now covers tag objects
  • ccfc59b test(github): lock the collector-to-IR metadata handoff
  • 82c947f chore: drop a stray worktree entry committed by mistake
  • fae517e test(github): lock the zero-cost happy path for the tag object fallback
  • fbfacde fix(github): normalize SHA case and peel nested tag objects
  • eb9c669 perf(github): skip the tag object probe for refs that cannot be one
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [getplumber/plumber](https://github.com/getplumber/plumber) from 0.4.26 to 0.4.34.
- [Release notes](https://github.com/getplumber/plumber/releases)
- [Changelog](https://github.com/getplumber/plumber/blob/main/CHANGELOG.md)
- [Commits](getplumber/plumber@7ad9d26...e0ba76a)

---
updated-dependencies:
- dependency-name: getplumber/plumber
  dependency-version: 0.4.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 10, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #81.

@dependabot dependabot Bot closed this Aug 17, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/getplumber/plumber-0.4.34 branch August 17, 2026 02:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants