)]}'
{
  "log": [
    {
      "commit": "e6eb5b02190608ba5bbae8639e98792e41d88179",
      "tree": "2900c1d56953b13121476569143a9667cc48bcc7",
      "parents": [
        "6d7bf90c34939a2fe6379be00d34e3b887988bb6"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jul 21 13:10:42 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jul 21 13:10:42 2026"
      },
      "message": "release 21.7.0"
    },
    {
      "commit": "6d7bf90c34939a2fe6379be00d34e3b887988bb6",
      "tree": "35b62c5dc26b3951e14e663c98dac19d12b39775",
      "parents": [
        "482c7f91d10b75b0f51e78aaf371a5dd05361f1a"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jul 21 13:10:17 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jul 21 13:10:17 2026"
      },
      "message": "Add changelog fragment for Python 3.15 support\n"
    },
    {
      "commit": "482c7f91d10b75b0f51e78aaf371a5dd05361f1a",
      "tree": "841f76cb3fe5d0993c7eb48ab07bfc815eb3a26a",
      "parents": [
        "a190228c76349ed8cf26db43aa4789a1f084cbb7"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jul 21 06:07:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 06:07:35 2026"
      },
      "message": "👷 ci: test against Python 3.15 beta (#3192)"
    },
    {
      "commit": "a190228c76349ed8cf26db43aa4789a1f084cbb7",
      "tree": "72220c78a9ce8fe110df13c75cbb844be33075c7",
      "parents": [
        "b54bc80c0f055fbc64cda453545486d589af0347"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 05:42:06 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 05:42:06 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3191)\n\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "b54bc80c0f055fbc64cda453545486d589af0347",
      "tree": "0d0446465e2bdad868a62998ccb69908a5691974",
      "parents": [
        "c5dff1d4defbd2f16ff0ead54de0354b2398fead"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Jul 16 01:00:33 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 01:00:33 2026"
      },
      "message": "Replace prettier with mdformat and yamlfmt (#3190)\n\nCommitted via https://github.com/asottile/all-repos"
    },
    {
      "commit": "c5dff1d4defbd2f16ff0ead54de0354b2398fead",
      "tree": "0ed71dee4482515d2c5e3c340c95aa3fb75e28a9",
      "parents": [
        "cab4a0af798849839dfeaa814257e1c8e84ef01e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 15 07:30:51 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 15 07:30:51 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 8.3.1 to 8.3.2 (#3189)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n8.3.1 to 8.3.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/11f9893b081a58869d3b5fccaea48c9e9e46f990\"\u003e\u003ccode\u003e11f9893\u003c/code\u003e\u003c/a\u003e\nchore: roll up Dependabot updates (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/948\"\u003e#948\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/f79855603231e1609d02bec6956bd0e05cbc46b5\"\u003e\u003ccode\u003ef798556\u003c/code\u003e\u003c/a\u003e\ndocs: update version references to v8.3.1 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/946\"\u003e#946\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/e80544d808267c93733c3fd1e2c8c65e0c8707d6\"\u003e\u003ccode\u003ee80544d\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.28 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/947\"\u003e#947\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/f98e06938123ccabd21905ea5d0069192241f9f1...11f9893b081a58869d3b5fccaea48c9e9e46f990\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.3.1\u0026new-version\u003d8.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "cab4a0af798849839dfeaa814257e1c8e84ef01e",
      "tree": "88190d65e8b5d78efcc9496baf1c914751d6a2ae",
      "parents": [
        "c53b5b198abbc5ff7de38eb823bf15c9f618a9a3"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 00:38:31 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 00:38:31 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.1 (#3188)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n8.3.0 to 8.3.1.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/f98e06938123ccabd21905ea5d0069192241f9f1\"\u003e\u003ccode\u003ef98e069\u003c/code\u003e\u003c/a\u003e\nChange update-docs PR labels from \u0027update-docs\u0027 to \u0027documentation\u0027 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/945\"\u003e#945\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/cd462639a967553a16241af35461402a96978d48\"\u003e\u003ccode\u003ecd46263\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.27 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/944\"\u003e#944\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/11245c7e122cd1c2297e8115d1e43fe1570f6270\"\u003e\u003ccode\u003e11245c7\u003c/code\u003e\u003c/a\u003e\ndocs: update version references to v8.3.0 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/939\"\u003e#939\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/d31148d669074a8d0a63714ba94f3201e7020bc3...f98e06938123ccabd21905ea5d0069192241f9f1\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.3.0\u0026new-version\u003d8.3.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c53b5b198abbc5ff7de38eb823bf15c9f618a9a3",
      "tree": "b0e40777c09b6bf21a0da96fe6e7e9ef848dace3",
      "parents": [
        "20b70f30e8f712c099905454b100d68cc677ef53"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 20:47:49 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 20:47:49 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3187)"
    },
    {
      "commit": "20b70f30e8f712c099905454b100d68cc677ef53",
      "tree": "d0731ebebca09770be6cd5b5599db85e8bda8182",
      "parents": [
        "544ca3d8b08188e8329570c88b362956496aaeec"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 04:10:06 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 04:10:06 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.0 (#3186)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n8.2.0 to 8.3.0.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/d31148d669074a8d0a63714ba94f3201e7020bc3\"\u003e\u003ccode\u003ed31148d\u003c/code\u003e\u003c/a\u003e\nStrip environment markers from detected uv dependency pins (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/938\"\u003e#938\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/17c398959b4611a88929fabb5c563a8e43a0ff60\"\u003e\u003ccode\u003e17c3989\u003c/code\u003e\u003c/a\u003e\nFix cache keys for Python version ranges (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/937\"\u003e#937\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/3cc3c11fdf511cab39136b7c946d973d4ad0df20\"\u003e\u003ccode\u003e3cc3c11\u003c/code\u003e\u003c/a\u003e\nchore(deps): roll up Dependabot updates (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/936\"\u003e#936\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/9225f843d7a9f80a757cf25ef48901fda69ba4bc\"\u003e\u003ccode\u003e9225f84\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump release-drafter/release-drafter from 7.3.1 to 7.4.0\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/924\"\u003e#924\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/fc16fa3bbf37d2816834f76a1fe25d33564eaa34\"\u003e\u003ccode\u003efc16fa3\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump actions/checkout from 6.0.2 to 7.0.0 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/926\"\u003e#926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/a1a7345c8ef5d6d3b18c6f1c247244c19f1d878c\"\u003e\u003ccode\u003ea1a7345\u003c/code\u003e\u003c/a\u003e\nci: call docs update workflow from release (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/933\"\u003e#933\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/a5e9cbfd5f946647f478460490fa497b0a732e63\"\u003e\u003ccode\u003ea5e9cbf\u003c/code\u003e\u003c/a\u003e\ndocs: update version references to v8.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/932\"\u003e#932\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/c5680ec91f7b9b91406fab4ded5d45245abf7b67\"\u003e\u003ccode\u003ec5680ec\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.26 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/c86fe4ef1f4a79845e6d465628d733650f6c41d8\"\u003e\u003ccode\u003ec86fe4e\u003c/code\u003e\u003c/a\u003e\nAdd a threat model for setup-uv (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/923\"\u003e#923\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/224c887d488ab24d8a1b49f10416d6ad6b6ca71d\"\u003e\u003ccode\u003e224c887\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.25 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/929\"\u003e#929\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/fac544c07dec837d0ccb6301d7b5580bf5edae39...d31148d669074a8d0a63714ba94f3201e7020bc3\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.2.0\u0026new-version\u003d8.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "544ca3d8b08188e8329570c88b362956496aaeec",
      "tree": "ea697b1db52c990b0c2286f296488087212e88df",
      "parents": [
        "3abee98f928981c19240f506401e92a15960e20c"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Fri Jul 10 19:32:42 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Fri Jul 10 19:32:42 2026"
      },
      "message": "release 21.6.1"
    },
    {
      "commit": "3abee98f928981c19240f506401e92a15960e20c",
      "tree": "3858e334e7d2696bc8e36cece3a2d7466e24a73f",
      "parents": [
        "57c8dc69a9080c3cd5741355aa756ce5a3b8ab15"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Fri Jul 10 19:31:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 19:31:35 2026"
      },
      "message": "🐛 fix(fish): harden prompt against shadowed builtins (#3185)"
    },
    {
      "commit": "57c8dc69a9080c3cd5741355aa756ce5a3b8ab15",
      "tree": "2d47494a9355c7efab61cd56685d45495c597c76",
      "parents": [
        "04ff7560669642b2861d1c83df0e2daa05da99d3"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Jul 06 22:48:33 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Jul 06 22:48:33 2026"
      },
      "message": "release 21.6.0"
    },
    {
      "commit": "04ff7560669642b2861d1c83df0e2daa05da99d3",
      "tree": "ae0ff692d684d413fb04c25cb01950178c748f74",
      "parents": [
        "7c3506546ba1b5f848d784202165be093773fe10"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Mon Jul 06 22:47:34 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 22:47:34 2026"
      },
      "message": "✨ feat(create): skip distutils hook on Python 3.10+ (#3184)\n\nvirtualenv installs a `_virtualenv.{py,pth}` import hook into every\nenvironment to stop distutils install config keys (`prefix`,\n`install_purelib`, and friends from `~/.pydistutils.cfg` or a project\n`setup.cfg`) from redirecting package installs outside the environment.\nAs #3181 tracks, that guard no longer earns its keep on modern Python.\nSince 3.10 pip ignores those keys by default, and both setuptools and\nCPython\u0027s vendored distutils drop them too. What survives is cost. The\n`.pth` runs `import _virtualenv` on every interpreter startup, which\nimports `contextlib` and adds about 2ms (measured in the issue).\n\nThis gates hook installation on the target interpreter version, so\nenvironments for Python 3.10 and later skip the hook and its startup\nimport. The cutoff avoids a blanket removal for one reason: the last pip\nrelease supporting Python 3.9 still needs the workaround below 3.10, so\n3.9 environments keep the hook. Once virtualenv drops 3.9,\n`install_patch` and `_virtualenv.py` can go for good.\n\nNothing changes for 3.9 or for the escape-prevention guarantee itself,\nsince pip on 3.10+ keeps installs inside the environment without our\nhook. Closes #3181.\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7c3506546ba1b5f848d784202165be093773fe10",
      "tree": "427a21124f68654f7597bdfa0367052e91fc70da",
      "parents": [
        "ca5eefaa86e5b9a3f431f9b9f6a11ed5be439642"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jul 06 21:08:39 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 21:08:39 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3183)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/python-jsonschema/check-jsonschema: 0.37.3 →\n0.37.4](https://github.com/python-jsonschema/check-jsonschema/compare/0.37.3...0.37.4)\n- [github.com/rbubley/mirrors-prettier: v3.9.1 →\nv3.9.4](https://github.com/rbubley/mirrors-prettier/compare/v3.9.1...v3.9.4)\n\u003c!--pre-commit.ci end--\u003e\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ca5eefaa86e5b9a3f431f9b9f6a11ed5be439642",
      "tree": "34fabf2d1f52c7dbce4ecbef5b14c88a02516517",
      "parents": [
        "84d652f15a7616079de77775fbb3d38e49474cda"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Jul 06 15:19:52 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Jul 06 15:19:52 2026"
      },
      "message": "release 21.5.2"
    },
    {
      "commit": "84d652f15a7616079de77775fbb3d38e49474cda",
      "tree": "bc1dccd4ae060194adbd9a6ed74d3df29d5487cf",
      "parents": [
        "1fa46f509496f9526fbe333ee5c955f7e158e0a9"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Jul 06 15:18:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 15:18:54 2026"
      },
      "message": "Upgrade embedded pip/setuptools/wheel (#3180)\n\nAutomated upgrade of embedded pip, setuptools, and wheel dependencies.\n\nThis PR was created automatically by the [upgrade\nworkflow](https://github.com/pypa/virtualenv/actions/workflows/upgrade.yaml).\n\n---------\n\nCo-authored-by: gaborbernat \u003c690238+gaborbernat@users.noreply.github.com\u003e\nCo-authored-by: github-actions[bot] \u003c41898282+github-actions[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernat Gabor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "1fa46f509496f9526fbe333ee5c955f7e158e0a9",
      "tree": "28ede9b3ee24b7e60b7a184106a0ab553a3264ab",
      "parents": [
        "0a2e25ca9a1f3fb45becb66ed8443760c3d7b4d1"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Mon Jul 06 15:18:37 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 15:18:37 2026"
      },
      "message": "fix(upgrade): emit dash bullets in changelog (#3182)\n\n`_write_changelog` in `tasks/upgrade_wheels.py` rendered upgrade list\nitems with `*`, but the repo\u0027s `docstrfmt` pre-commit hook normalizes\nbullet lists to `-`. Every auto-generated upgrade PR failed docstrfmt\nuntil the bullet was fixed by hand (e.g. #3180).\n\nEmit `-` so the generated fragment is clean on the first try.\n\nTask-script-only change, so no changelog fragment (matches #3143)."
    },
    {
      "commit": "0a2e25ca9a1f3fb45becb66ed8443760c3d7b4d1",
      "tree": "732cef8b2bcfc92af3e30b55ddcf2416629f8b1e",
      "parents": [
        "5fcb71d1a9b2aace511704fb520371f5216d5b5c"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Fri Jul 03 15:17:25 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Fri Jul 03 15:17:25 2026"
      },
      "message": ":moneybag: Surface GitHub Sponsors + thanks.dev"
    },
    {
      "commit": "5fcb71d1a9b2aace511704fb520371f5216d5b5c",
      "tree": "7a321dd4fed5c63b4580f39bde70ddb0ca8a718d",
      "parents": [
        "44a0f9a0e3fdef5850531ea7c81bfd48005ecaa8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 30 04:04:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 04:04:54 2026"
      },
      "message": "chore(deps): bump actions/setup-python from 6.2.0 to 6.3.0 (#3179)\n\nBumps [actions/setup-python](https://github.com/actions/setup-python)\nfrom 6.2.0 to 6.3.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/setup-python/releases\"\u003eactions/setup-python\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.3.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancement\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd RHEL support and include Linux distro in cache keys by \u003ca\nhref\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e@​priyagupta108\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1323\"\u003eactions/setup-python#1323\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix pip cache error handling on Windows by \u003ca\nhref\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e@​priyagupta108\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1040\"\u003eactions/setup-python#1040\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency update\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade minimatch from 3.1.2 to 3.1.5 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1281\"\u003eactions/setup-python#1281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade actions dependencies by \u003ca\nhref\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e\nwith \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1303\"\u003eactions/setup-python#1303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@​actions/cache\u003c/code\u003e to 5.1.0, log cache write\ndenied by \u003ca\nhref\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e@​jasongin\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1324\"\u003eactions/setup-python#1324\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade dependency versions and test workflow configuration by \u003ca\nhref\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e@​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1322\"\u003eactions/setup-python#1322\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate advanced-usage.md by \u003ca\nhref\u003d\"https://github.com/Dunky-Z\"\u003e\u003ccode\u003e@​Dunky-Z\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/811\"\u003eactions/setup-python#811\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e\nwith \u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1303\"\u003eactions/setup-python#1303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/jasongin\"\u003e\u003ccode\u003e@​jasongin\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1324\"\u003eactions/setup-python#1324\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Dunky-Z\"\u003e\u003ccode\u003e@​Dunky-Z\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/811\"\u003eactions/setup-python#811\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/setup-python/compare/v6...v6.3.0\"\u003ehttps://github.com/actions/setup-python/compare/v6...v6.3.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/ece7cb06caefa5fff74198d8649806c4678c61a1\"\u003e\u003ccode\u003eece7cb0\u003c/code\u003e\u003c/a\u003e\nFix pip cache error handling on Windows. (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1040\"\u003e#1040\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/1d18d7af5f767c1259ede05a0a5bcc30f3dcf1cf\"\u003e\u003ccode\u003e1d18d7a\u003c/code\u003e\u003c/a\u003e\nUpdate advanced-usage.md (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/d2b357a6a3a3687dd6781a416c0d24fcfd68660e\"\u003e\u003ccode\u003ed2b357a\u003c/code\u003e\u003c/a\u003e\nUpdate dependency versions and test workflow configuration (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1322\"\u003e#1322\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/8f639b1e75c1048640734b2bb46e22cecf136982\"\u003e\u003ccode\u003e8f639b1\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1324\"\u003e#1324\u003c/a\u003e\nfrom jasongin/update-actions-cache-5.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/6731c2ba87f530c26324d128c8fdd53499a4d4b0\"\u003e\u003ccode\u003e6731c2b\u003c/code\u003e\u003c/a\u003e\nResolve high-severity audit issues\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/0cb1a84326b90186fcd211036c65b42819794c87\"\u003e\u003ccode\u003e0cb1a84\u003c/code\u003e\u003c/a\u003e\nAdd RHEL support and include Linux distro in cache keys (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1323\"\u003e#1323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/dc6eab6194394e0119523369788b507096f923e2\"\u003e\u003ccode\u003edc6eab6\u003c/code\u003e\u003c/a\u003e\nUpdate dist\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/6f4b74bfa2f520a380a620de3615c0dac427f4d3\"\u003e\u003ccode\u003e6f4b74b\u003c/code\u003e\u003c/a\u003e\nStrict equality\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/fa8bde1a9cc6347d06948d66bcd68c598b79eaea\"\u003e\u003ccode\u003efa8bde1\u003c/code\u003e\u003c/a\u003e\nBump \u003ccode\u003e@​actions/cache\u003c/code\u003e to 5.1.0, log cache write denied\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/c8813ba1bc76ebf779b911ad8ffccbf2e449cb48\"\u003e\u003ccode\u003ec8813ba\u003c/code\u003e\u003c/a\u003e\nUpgrade \u003ca href\u003d\"https://github.com/actions\"\u003e\u003ccode\u003e@​actions\u003c/code\u003e\u003c/a\u003e\ndependencies and update licenses (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1303\"\u003e#1303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/setup-python\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6.2.0\u0026new-version\u003d6.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "44a0f9a0e3fdef5850531ea7c81bfd48005ecaa8",
      "tree": "c76b2827c951806c40f4accf878f2d1bfad9b2b7",
      "parents": [
        "8681256d0a532b88117ce068435dd61b86d7f56d"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jun 29 19:13:46 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 19:13:46 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3178)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/tox-dev/pyproject-fmt: v2.25.0 →\nv2.25.1](https://github.com/tox-dev/pyproject-fmt/compare/v2.25.0...v2.25.1)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.18 →\nv0.15.20](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.18...v0.15.20)\n- [github.com/rbubley/mirrors-prettier: v3.8.4 →\nv3.9.1](https://github.com/rbubley/mirrors-prettier/compare/v3.8.4...v3.9.1)\n\u003c!--pre-commit.ci end--\u003e\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8681256d0a532b88117ce068435dd61b86d7f56d",
      "tree": "c7cb5c03d8010c96b08f70f0b48063f25ec4ec0e",
      "parents": [
        "0b42ffe9e0a0ab87189bc716eba3a2ffb5699eda"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Wed Jun 24 07:37:15 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 07:37:15 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3176)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/tox-dev/pyproject-fmt: v2.24.1 →\nv2.25.0](https://github.com/tox-dev/pyproject-fmt/compare/v2.24.1...v2.25.0)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.17 →\nv0.15.18](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.17...v0.15.18)\n- [github.com/LilSpazJoekp/docstrfmt: v2.1.1 →\nv2.2.0](https://github.com/LilSpazJoekp/docstrfmt/compare/v2.1.1...v2.2.0)\n- [github.com/zizmorcore/zizmor-pre-commit: v1.25.2 →\nv1.26.1](https://github.com/zizmorcore/zizmor-pre-commit/compare/v1.25.2...v1.26.1)\n\u003c!--pre-commit.ci end--\u003e\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "0b42ffe9e0a0ab87189bc716eba3a2ffb5699eda",
      "tree": "3dc8f1781bbde499047f573da53123b7ed0aa94b",
      "parents": [
        "736220190fbe6a5161f37c9a51df98ebb4837ea0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 24 01:52:59 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 01:52:59 2026"
      },
      "message": "chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 (#3177)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3\nto 7.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/releases\"\u003eactions/checkout\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eblock checking out fork pr for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the\nminor-actions-dependencies group across 1 directory by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and\n\u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3\nupdates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003egetting ready for checkout v7 release by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2464\"\u003eactions/checkout#2464\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate error wording by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2467\"\u003eactions/checkout#2467\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/v6.0.3...v7.0.0\"\u003ehttps://github.com/actions/checkout/compare/v6.0.3...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/blob/main/CHANGELOG.md\"\u003eactions/checkout\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock checking out fork PR for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the\nminor-actions-dependencies group across 1 directory by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2458\"\u003eactions/checkout#2458\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump flatted from 3.3.1 to 3.4.2 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2460\"\u003eactions/checkout#2460\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump js-yaml from 4.1.0 to 4.2.0 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2461\"\u003eactions/checkout#2461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump \u003ccode\u003e@​actions/core\u003c/code\u003e and\n\u003ccode\u003e@​actions/tool-cache\u003c/code\u003e and Remove uuid by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2459\"\u003eactions/checkout#2459\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupgrade module to esm and update dependencies by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2463\"\u003eactions/checkout#2463\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 3\nupdates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2462\"\u003eactions/checkout#2462\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePersist creds to a separate file by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2286\"\u003eactions/checkout#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README to include Node.js 24 support details and requirements\nby \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2248\"\u003eactions/checkout#2248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v5 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2301\"\u003eactions/checkout#2301\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions checkout to use node 24 by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2226\"\u003eactions/checkout#2226\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v4 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2305\"\u003eactions/checkout#2305\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README.md by \u003ca\nhref\u003d\"https://github.com/motss\"\u003e\u003ccode\u003e@​motss\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1971\"\u003eactions/checkout#1971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd internal repos for checking out multiple repositories by \u003ca\nhref\u003d\"https://github.com/mouismail\"\u003e\u003ccode\u003e@​mouismail\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1977\"\u003eactions/checkout#1977\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation update - add recommended permissions to Readme by \u003ca\nhref\u003d\"https://github.com/benwells\"\u003e\u003ccode\u003e@​benwells\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2043\"\u003eactions/checkout#2043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdjust positioning of user email note and permissions heading by \u003ca\nhref\u003d\"https://github.com/joshmgross\"\u003e\u003ccode\u003e@​joshmgross\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2044\"\u003eactions/checkout#2044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca\nhref\u003d\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2194\"\u003eactions/checkout#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate CODEOWNERS for actions by \u003ca\nhref\u003d\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2224\"\u003eactions/checkout#2224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate package dependencies by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2236\"\u003eactions/checkout#2236\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eurl-helper.ts\u003c/code\u003e now leverages well-known environment\nvariables by \u003ca href\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1941\"\u003eactions/checkout#1941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand unit test coverage for \u003ccode\u003eisGhes\u003c/code\u003e by \u003ca\nhref\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1946\"\u003eactions/checkout#1946\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCheck out other refs/* by commit if provided, fall back to ref by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1924\"\u003eactions/checkout#1924\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\"\u003e\u003ccode\u003e9c091bb\u003c/code\u003e\u003c/a\u003e\nupdate error wording (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2467\"\u003e#2467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a\"\u003e\u003ccode\u003e1044a6d\u003c/code\u003e\u003c/a\u003e\ngetting ready for checkout v7 release (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2464\"\u003e#2464\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f\"\u003e\u003ccode\u003ef028218\u003c/code\u003e\u003c/a\u003e\nBump the minor-npm-dependencies group across 1 directory with 3 updates\n(\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2462\"\u003e#2462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d\"\u003e\u003ccode\u003ed914b26\u003c/code\u003e\u003c/a\u003e\nupgrade module to esm and update dependencies (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2463\"\u003e#2463\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d\"\u003e\u003ccode\u003e537c7ef\u003c/code\u003e\u003c/a\u003e\nBump \u003ccode\u003e@​actions/core\u003c/code\u003e and \u003ccode\u003e@​actions/tool-cache\u003c/code\u003e\nand Remove uuid (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2459\"\u003e#2459\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6\"\u003e\u003ccode\u003e130a169\u003c/code\u003e\u003c/a\u003e\nBump js-yaml from 4.1.0 to 4.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2461\"\u003e#2461\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3\"\u003e\u003ccode\u003e7d09575\u003c/code\u003e\u003c/a\u003e\nBump flatted from 3.3.1 to 3.4.2 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2460\"\u003e#2460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e\"\u003e\u003ccode\u003e0f9f3aa\u003c/code\u003e\u003c/a\u003e\nBump actions/publish-immutable-action (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2458\"\u003e#2458\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7\"\u003e\u003ccode\u003ef9e715a\u003c/code\u003e\u003c/a\u003e\nblock checking out fork pr for pull_request_target and workflow_run (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2454\"\u003e#2454\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/checkout\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6.0.3\u0026new-version\u003d7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "736220190fbe6a5161f37c9a51df98ebb4837ea0",
      "tree": "8e35e8e17ec57dba975e542d9c6838c5e0c5cce4",
      "parents": [
        "e1db75c64ff11daa1574df5d1bf565b46ae6ec6e"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Wed Jun 17 16:14:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 16:14:54 2026"
      },
      "message": "🐛 fix(seed): sync wheel regen script with seeder guard (#3175)"
    },
    {
      "commit": "e1db75c64ff11daa1574df5d1bf565b46ae6ec6e",
      "tree": "6051b69a37b31851a55eebd0d1aaf232e1e802c9",
      "parents": [
        "2bbb35c704dac0c816464da56da239cf2eeaf3a1"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Jun 16 16:21:16 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Jun 16 16:21:16 2026"
      },
      "message": "release 21.5.1"
    },
    {
      "commit": "2bbb35c704dac0c816464da56da239cf2eeaf3a1",
      "tree": "ec21332e7ae0ffcf090cd259aa21a6e70c2753cd",
      "parents": [
        "7042705b5f4eddbcace0830fcfd3bcfbddc25635"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Jun 16 16:20:02 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 16 16:20:02 2026"
      },
      "message": "🐛 fix(seed): refuse to seed unsupported Python versions (#3173)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7042705b5f4eddbcace0830fcfd3bcfbddc25635",
      "tree": "c895f61c1e8357b996030c4bfd929806d6808d51",
      "parents": [
        "90735e08d69325adc25765ef3498df5fac334c07"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 21:57:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 21:57:29 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3172)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/python-jsonschema/check-jsonschema: 0.37.2 →\n0.37.3](https://github.com/python-jsonschema/check-jsonschema/compare/0.37.2...0.37.3)\n- [github.com/tox-dev/pyproject-fmt: v2.23.0 →\nv2.24.1](https://github.com/tox-dev/pyproject-fmt/compare/v2.23.0...v2.24.1)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.16 →\nv0.15.17](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.16...v0.15.17)\n- [github.com/rbubley/mirrors-prettier: v3.8.3 →\nv3.8.4](https://github.com/rbubley/mirrors-prettier/compare/v3.8.3...v3.8.4)\n- [github.com/LilSpazJoekp/docstrfmt: v2.1.0 →\nv2.1.1](https://github.com/LilSpazJoekp/docstrfmt/compare/v2.1.0...v2.1.1)\n\u003c!--pre-commit.ci end--\u003e\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "90735e08d69325adc25765ef3498df5fac334c07",
      "tree": "4c72775cdcc1333fb5378d93da2e4525ce4fa8e7",
      "parents": [
        "79ce906a2378e24c81a7b27ac506c73d5cc262d9"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Sat Jun 13 20:35:28 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Sat Jun 13 20:35:28 2026"
      },
      "message": "release 21.5.0"
    },
    {
      "commit": "79ce906a2378e24c81a7b27ac506c73d5cc262d9",
      "tree": "f4229f00335d8359ece4bbf758df1fd9a30387be",
      "parents": [
        "f1f4d687b12caac079d81ffc5ee50a16d1fabc1a"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Sat Jun 13 20:34:30 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 13 20:34:30 2026"
      },
      "message": "✨ feat: drop Python 3.8 support (#3170)\n\nCPython 3.8 reached end of life on 2024-10-07, more than 18 months ago,\nwhich meets the project policy for dropping a version. 🐍 virtualenv now\nrequires Python 3.9 or later, both to run and to create environments, so\nthis raises `requires-python` to `\u003e\u003d3.9` and clears the 3.8 entries out\nof the packaging metadata, CI matrix, and tox environments.\n\nvirtualenv bundled the embedded `wheel` seed package only for Python\n3.8, so dropping 3.8 lets me remove it outright: the `wheel` files, the\n`3.8` bundle entry (which also orphaned `pip-25.0.1` and\n`setuptools-75.3.4`), and the wheel handling in\n`tasks/upgrade_wheels.py`. Removing the only 3.8-specific creator code,\nthe macOS `__PYVENV_LAUNCHER__` patch that applied to CPython 3.8.0\nthrough 3.8.2, falls out of the same cleanup.\n\n`#3168` removed the orphaned `wheel-0.47.0` on its own; this supersedes\nit, so close that one once this merges. PR `#2884` restored\n`--wheel`/`--no-wheel` after an earlier removal broke Fedora and other\ndownstream callers, so I kept both flags as no-ops rather than repeat\nthat breakage. They now warn louder: the message states that virtualenv\nwill remove them in a release after 2026-12, giving downstream tooling a\ndeadline to stop passing them.\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f1f4d687b12caac079d81ffc5ee50a16d1fabc1a",
      "tree": "55b17b08bd87b26421caa6082fdf048144600fe3",
      "parents": [
        "78df6f0873a89f8cc4ecb9378562e5eb74576e9f"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Sat Jun 13 15:28:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 13 15:28:12 2026"
      },
      "message": "Upgrade embedded pip/setuptools/wheel (#3168)\n\nAutomated upgrade of embedded pip, setuptools, and wheel dependencies.\n\nThis PR was created automatically by the [upgrade\nworkflow](https://github.com/pypa/virtualenv/actions/workflows/upgrade.yaml).\n\nCo-authored-by: gaborbernat \u003c690238+gaborbernat@users.noreply.github.com\u003e"
    },
    {
      "commit": "78df6f0873a89f8cc4ecb9378562e5eb74576e9f",
      "tree": "a4dfe778d7db85a1e941b3a19ae10be63b2530e8",
      "parents": [
        "134b080fae08c8eac719750d21c3449d3aa02aaa"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Sat Jun 13 15:28:00 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 13 15:28:00 2026"
      },
      "message": "Set git identity in upgrade changelog rename step (#3169)\n\nThe scheduled `Upgrade embedded dependencies` workflow failed in its\n\"Rename changelog with PR number\" step with:\n\n```\nfatal: empty ident name (for \u003crunner@...\u003e) not allowed\n```\n\nThe `peter-evans/create-pull-request` action configures its own\ncommitter identity, but the follow-up step runs a bare `git commit` with\nno identity set on the runner, so it exits 128 (see [run\n27464646715](https://github.com/pypa/virtualenv/actions/runs/27464646715)).\n\nConfigure the `github-actions[bot]` identity (the same one\n`create-pull-request` uses) before committing the renamed changelog\nfragment."
    },
    {
      "commit": "134b080fae08c8eac719750d21c3449d3aa02aaa",
      "tree": "8ec929fb8c876cc449b728a72bf2a46bf3960139",
      "parents": [
        "2a36128bef8914ad006b49e5f1e2ca431dafa1cf"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu Jun 11 16:45:40 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu Jun 11 16:45:40 2026"
      },
      "message": "release 21.4.3"
    },
    {
      "commit": "2a36128bef8914ad006b49e5f1e2ca431dafa1cf",
      "tree": "ba6861b736ee925a56d8881b767f9ba752206bc9",
      "parents": [
        "5389c25cf4a1ee11ea55183d6daf4c8055dc3060"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Jun 11 16:43:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 16:43:54 2026"
      },
      "message": "🐛 fix(discovery): resolve base interpreter executable-only symlinks (#3166)\n\nCreating an environment with `-p` pointing at a symlink to just the\ninterpreter binary recorded the symlink in `pyvenv.cfg`: `home` ended up\nas the symlink\u0027s directory, which contains no `lib/`, and\n`base-executable` kept the unresolved link. 🐛 Standard CPython survives\nbecause `getpath` re-resolves the link when reading `home`, but layouts\nwhere `home` must directly locate the base stdlib, such as\npython-build-standalone, produce a broken environment (#3157).\n\nThe resolution lives in python-discovery (tox-dev/python-discovery#85,\nrefined by tox-dev/python-discovery#87): `system_executable` follows the\nsymlink chain of the executable\u0027s final path component only, stopping as\nsoon as the stdlib landmark is reachable and never touching macOS\nframework builds, the same semantics CPython\u0027s `getpath` uses and its\n`venv` adopts in python/cpython#115237. A barren-directory symlink\nresolves to the real interpreter while stable aliases like Homebrew\u0027s\n`opt` paths, Debian\u0027s `/usr/bin/python3`, or a fully symlinked\ninterpreter tree keep their recorded form. This PR raises the dependency\nfloor to `python-discovery\u003e\u003d1.4.2` and bumps the app-data `py_info`\ncache key from `4` to `5` so interpreter records probed by older\nvirtualenv versions are not shared with the corrected ones.\n\nCI needs python-discovery `1.4.2` on PyPI (tox-dev/python-discovery#87\nmerge + release) to go green.\n\nFixes #3157."
    },
    {
      "commit": "5389c25cf4a1ee11ea55183d6daf4c8055dc3060",
      "tree": "15dec230d5fec01035a544ca29de06f16f840472",
      "parents": [
        "0134feeec7ba0bd1a6193dc6245934ee5e800774"
      ],
      "author": {
        "name": "Patrick Kleindienst",
        "email": "12052783+apophizzz@users.noreply.github.com",
        "time": "Thu Jun 11 14:47:17 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 14:47:17 2026"
      },
      "message": "Add wheel-0.47.0 to seed packages as mitigation of CVE-2026-24049 (#3167)\n\nHi!\n\nMe and my team ran into the issue that even with the latest version of\n`virtualenv` each venv gets seeded with `wheel 0.45.1`, which is\nvulnerable in terms of\n[CVE-2026-24049](https://nvd.nist.gov/vuln/detail/CVE-2026-24049).\nThis PR adds the most current version of the `wheel` package to the list\nof seeding packages at the time this PR was authored.\n\n---------\n\nCo-authored-by: Patrick Kleindienst \u003cPatrick.Kleindienst@ibm.com\u003e"
    },
    {
      "commit": "0134feeec7ba0bd1a6193dc6245934ee5e800774",
      "tree": "04c05114e84fc95d913afb20ec3c043c40c1ab4e",
      "parents": [
        "af1ed9fd10b67adbcfd9f9e542fdc5bfcdd6ea5b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 10 14:52:32 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 14:52:32 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#3165)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n8.1.0 to 8.2.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/releases\"\u003eastral-sh/setup-uv\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.2.0 🌈 New inputs \u003ccode\u003equiet\u003c/code\u003e and\n\u003ccode\u003edownload-from-astral-mirror\u003c/code\u003e\u003c/h2\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cp\u003eThis release brings two new inputs and a few bug fixes.\u003c/p\u003e\n\u003ch3\u003eNew inputs\u003c/h3\u003e\n\u003cp\u003eLets talk about the new inputs first.\u003c/p\u003e\n\u003ch4\u003equiet\u003c/h4\u003e\n\u003cp\u003ePretty simple. It turns of all \u003ccode\u003einfo\u003c/code\u003e loggings. Useful if\nyou use this in a composite action and are not interested in all the\ndetails.\nIn the upcoming releases we will add log groups to fully implement\nsupport for \u0026quot;less noise\u0026quot;\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!NOTE]\u003cbr /\u003e\nWarnings and errors are always logged.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch4\u003edownload-from-astral-mirror\u003c/h4\u003e\n\u003cp\u003eIn some cases you may want to directly use the fallback of checking\nfor available versions and downloading releases from GitHub instead of\nusing the astral.sh mirror. Setting \u003ccode\u003edownload-from-astral-mirror:\nfalse\u003c/code\u003e allows you to do that.\u003c/p\u003e\n\u003ch3\u003eBugfixes\u003c/h3\u003e\n\u003cp\u003eWhen using the astral.sh mirror to query available versions and\ndownload releases (done by default) we now stop sending the GitHub token\nin the header. The mirror never looked at it but we shouldn\u0027t be handing\nout that data even if it is just a short lived token.\nAll other bugfixes try to limit the impact of failed GitHub queries due\nto retries and other faults.\u003c/p\u003e\n\u003cp\u003eWe couldn\u0027t pinpoint all rootcauses yet but added more logging for\nerror cases to track them down.\u003c/p\u003e\n\u003ch2\u003e🐛 Bug fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: report unexpected cache save failures \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/896\"\u003e#896\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: report unexpected setup failures \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/895\"\u003e#895\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix: add timeout to fetch to prevent silent hangs \u003ca\nhref\u003d\"https://github.com/eifinger-bot\"\u003e\u003ccode\u003e@​eifinger-bot\u003c/code\u003e\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/883\"\u003e#883\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLimit GitHub tokens to github.com download URLs \u003ca\nhref\u003d\"https://github.com/zsol\"\u003e\u003ccode\u003e@​zsol\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/878\"\u003e#878\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eincrease libuv-workaround timeout to 100ms \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/880\"\u003e#880\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚀 Enhancements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd quiet input to suppress info-level log output \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/898\"\u003e#898\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat: add \u003ccode\u003edownload-from-astral-mirror\u003c/code\u003e input \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/897\"\u003e#897\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🧰 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update dependabot rollup biome guidance \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/902\"\u003e#902\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.18 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/899\"\u003e#899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.17 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/892\"\u003e#892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.16 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/889\"\u003e#889\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.15 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/885\"\u003e#885\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.14 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/879\"\u003e#879\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.13 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/877\"\u003e#877\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/fac544c07dec837d0ccb6301d7b5580bf5edae39\"\u003e\u003ccode\u003efac544c\u003c/code\u003e\u003c/a\u003e\nchore(deps): roll up dependabot updates (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/903\"\u003e#903\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/7390f777b051d6c47c9cb905ff80e7d5d85a7068\"\u003e\u003ccode\u003e7390f77\u003c/code\u003e\u003c/a\u003e\ndocs: update dependabot rollup biome guidance (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/902\"\u003e#902\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/363c64a728451954156ddb9e3f368b879eeee5da\"\u003e\u003ccode\u003e363c64a\u003c/code\u003e\u003c/a\u003e\nchore(deps): roll up dependabot updates (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/901\"\u003e#901\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/c4fcbafce4f941a09e04c45c42db7a2e3ba5cd91\"\u003e\u003ccode\u003ec4fcbaf\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump release-drafter/release-drafter from 7.3.0 to 7.3.1\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/900\"\u003e#900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/8e642c5e623b521f8b6b15bbc2ba54bae583fe45\"\u003e\u003ccode\u003e8e642c5\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.18 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/899\"\u003e#899\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/a92cb430984b4b2b34c9c47e020cf035089958fa\"\u003e\u003ccode\u003ea92cb43\u003c/code\u003e\u003c/a\u003e\nAdd quiet input to suppress info-level log output (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/898\"\u003e#898\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/e07f2ac4b796a5fa8dc51ebf0a5187d0463eb4d6\"\u003e\u003ccode\u003ee07f2ac\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump eifinger/actionlint-action from 1.10.1 to 1.10.2 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/842\"\u003e#842\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/bc4034eedf3a6f77238660a28089c6b201eae39f\"\u003e\u003ccode\u003ebc4034e\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump github/codeql-action from 4.35.4 to 4.36.0 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/893\"\u003e#893\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/df42d4f6ba41cdcf6eda832c32439db37cc28b39\"\u003e\u003ccode\u003edf42d4f\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump zizmorcore/zizmor-action from 0.5.5 to 0.5.6 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/891\"\u003e#891\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/b9c8c4c7baf912cbda30843477d08b3f63b0f660\"\u003e\u003ccode\u003eb9c8c4c\u003c/code\u003e\u003c/a\u003e\nfeat: add \u003ccode\u003edownload-from-astral-mirror\u003c/code\u003e input (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/897\"\u003e#897\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/08807647e7069bb48b6ef5acd8ec9567f424441b...fac544c07dec837d0ccb6301d7b5580bf5edae39\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.1.0\u0026new-version\u003d8.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "af1ed9fd10b67adbcfd9f9e542fdc5bfcdd6ea5b",
      "tree": "6dcd7e8ebc18f1943763a1d4f6bddbefe8425d28",
      "parents": [
        "1b00ec8d284752f893e63fc752535cd7dc14b0c8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 09 00:30:39 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 00:30:39 2026"
      },
      "message": "chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#3164)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2\nto 6.0.3.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/releases\"\u003eactions/checkout\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate changelog by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2357\"\u003eactions/checkout#2357\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate changelog for v6.0.3 by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2446\"\u003eactions/checkout#2446\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/v6...v6.0.3\"\u003ehttps://github.com/actions/checkout/compare/v6...v6.0.3\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/blob/main/CHANGELOG.md\"\u003eactions/checkout\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePersist creds to a separate file by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2286\"\u003eactions/checkout#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README to include Node.js 24 support details and requirements\nby \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2248\"\u003eactions/checkout#2248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v5 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2301\"\u003eactions/checkout#2301\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions checkout to use node 24 by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2226\"\u003eactions/checkout#2226\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v4 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2305\"\u003eactions/checkout#2305\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README.md by \u003ca\nhref\u003d\"https://github.com/motss\"\u003e\u003ccode\u003e@​motss\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1971\"\u003eactions/checkout#1971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd internal repos for checking out multiple repositories by \u003ca\nhref\u003d\"https://github.com/mouismail\"\u003e\u003ccode\u003e@​mouismail\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1977\"\u003eactions/checkout#1977\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation update - add recommended permissions to Readme by \u003ca\nhref\u003d\"https://github.com/benwells\"\u003e\u003ccode\u003e@​benwells\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2043\"\u003eactions/checkout#2043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdjust positioning of user email note and permissions heading by \u003ca\nhref\u003d\"https://github.com/joshmgross\"\u003e\u003ccode\u003e@​joshmgross\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2044\"\u003eactions/checkout#2044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca\nhref\u003d\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2194\"\u003eactions/checkout#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate CODEOWNERS for actions by \u003ca\nhref\u003d\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2224\"\u003eactions/checkout#2224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate package dependencies by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2236\"\u003eactions/checkout#2236\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eurl-helper.ts\u003c/code\u003e now leverages well-known environment\nvariables by \u003ca href\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1941\"\u003eactions/checkout#1941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand unit test coverage for \u003ccode\u003eisGhes\u003c/code\u003e by \u003ca\nhref\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1946\"\u003eactions/checkout#1946\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCheck out other refs/* by commit if provided, fall back to ref by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1924\"\u003eactions/checkout#1924\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Ref and Commit outputs by \u003ca\nhref\u003d\"https://github.com/lucacome\"\u003e\u003ccode\u003e@​lucacome\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1180\"\u003eactions/checkout#1180\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDependency updates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e- \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1777\"\u003eactions/checkout#1777\u003c/a\u003e,\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1872\"\u003eactions/checkout#1872\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.1.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump the minor-npm-dependencies group across 1 directory with 4\nupdates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1739\"\u003eactions/checkout#1739\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 3 to 4 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1697\"\u003eactions/checkout#1697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCheck out other refs/* by commit by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1774\"\u003eactions/checkout#1774\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/df4cb1c069e1874edd31b4311f1884172cec0e10\"\u003e\u003ccode\u003edf4cb1c\u003c/code\u003e\u003c/a\u003e\nUpdate changelog for v6.0.3 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2446\"\u003e#2446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/1cce3390c2bfda521930d01229c073c7ff920824\"\u003e\u003ccode\u003e1cce339\u003c/code\u003e\u003c/a\u003e\nFix checkout init for SHA-256 repositories (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2439\"\u003e#2439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/900f2210b1d28bbbd0bd22d17926b9e224e8f231\"\u003e\u003ccode\u003e900f221\u003c/code\u003e\u003c/a\u003e\nfix: expand merge commit SHA regex and add SHA-256 test cases (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2414\"\u003e#2414\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/0c366fd6a839edf440554fa01a7085ccba70ac98\"\u003e\u003ccode\u003e0c366fd\u003c/code\u003e\u003c/a\u003e\nUpdate changelog (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2357\"\u003e#2357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/de0fac2e4500dabe0009e67214ff5f5447ce83dd...df4cb1c069e1874edd31b4311f1884172cec0e10\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/checkout\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6.0.2\u0026new-version\u003d6.0.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1b00ec8d284752f893e63fc752535cd7dc14b0c8",
      "tree": "4c22c852306332c2754def76fe6fa0696454901f",
      "parents": [
        "ce9729edbfc5b2f5fa2800def1ccc8e7c2d0f0be"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jun 08 22:46:18 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 22:46:18 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3163)"
    },
    {
      "commit": "ce9729edbfc5b2f5fa2800def1ccc8e7c2d0f0be",
      "tree": "ca0c4ecad8a0650ec6c34bb2ba026364b503f782",
      "parents": [
        "9e6f59fb2fbd96aba220f5858ae7114aeb353c65"
      ],
      "author": {
        "name": "Karl Hill",
        "email": "karlhillx@gmail.com",
        "time": "Mon Jun 08 17:40:50 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 17:40:50 2026"
      },
      "message": "Stop exporting PS1 in bash activator (#3162)\n\nCloses #3158.\n\n`PS1` is shell-local prompt state. The bash activator now updates it\nwithout exporting it, so child processes do not inherit prompt text\nduring activation or after deactivation.\n\nTests:\n- `.tox/3.14/bin/python -m pytest tests/unit/activation/test_bash.py -q`"
    },
    {
      "commit": "9e6f59fb2fbd96aba220f5858ae7114aeb353c65",
      "tree": "ffc781ede79b7140a73985093602896aef8f5b9b",
      "parents": [
        "a423028aa00bccb071efb72469f4dc0f05b27cfa"
      ],
      "author": {
        "name": "LuNoX",
        "email": "maillunox@gmail.com",
        "time": "Mon Jun 08 17:40:45 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 17:40:45 2026"
      },
      "message": "Fish activator passes VIRTUAL_ENV through cygpath (#3161)\n\nCloses #3160. Sourcing activate.fish from fish run inside MSYS2 (or\nsimilar) breaks the PATH because of a path style mismatch. This PR\napplies the changes from #1970 as well as the change to using uname from\n#3036 to the fish template as well.\n\n### Thanks for contributing, make sure you address all the checklists\n(for details on how see [development\ndocumentation](https://virtualenv.pypa.io/en/latest/development.html#development))\n\n- [ ] ran the linter to address style issues (`tox -e fix`)\n- [x] wrote descriptive pull request text\n- [ ] ensured there are test(s) validating the fix\n- [x] added news fragment in `docs/changelog` folder\n- [ ] updated/extended the documentation\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a423028aa00bccb071efb72469f4dc0f05b27cfa",
      "tree": "309c4e84a153ab18cb9d6b1fefadb5d80f5bc382",
      "parents": [
        "f838c2120a0399dd2e2dec1ff38218672c7c8af8"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 19:26:09 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 19:26:09 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3156)"
    },
    {
      "commit": "f838c2120a0399dd2e2dec1ff38218672c7c8af8",
      "tree": "7043b5305fb237e9654db6e2c7c2d7adde7a9f6d",
      "parents": [
        "7c1d328e9bd9ead9a9e9dfa0bfba76ff90808e2e"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 17:16:47 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 17:16:47 2026"
      },
      "message": "Upgrade embedded pip/setuptools/wheel (#3155)\n\nAutomated upgrade of embedded pip, setuptools, and wheel dependencies.\n\nThis PR was created automatically by the [upgrade\nworkflow](https://github.com/pypa/virtualenv/actions/workflows/upgrade.yaml).\n\n---------\n\nCo-authored-by: gaborbernat \u003c690238+gaborbernat@users.noreply.github.com\u003e\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7c1d328e9bd9ead9a9e9dfa0bfba76ff90808e2e",
      "tree": "62513948f424adecd0a97b31567d0ecaae7b158a",
      "parents": [
        "3cf1a29a24ad7f93ecd2db8c7fbbf454a3607694"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Mon Jun 01 04:18:08 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 04:18:08 2026"
      },
      "message": "ci: silence avoidable check workflow notices (#3154)\n\nCleans up the avoidable warnings/notices on the `🧪 check` workflow.\n\n- **Windows redirect notice** — opt into `windows-2025-vs2026` (the\nimage GitHub is migrating `windows-2025` to by 2026-06-15), silencing\nthe per-job redirect notice.\n- **pip version-check notice** — promote\n`PIP_DISABLE_PIP_VERSION_CHECK\u003d1` to job-level `env` so the setup step\n(which installs via pip) and test subprocesses inherit it, not just the\nrun-test step.\n- **brew already-installed notice** — `brew list --versions … || brew\ninstall …` instead of `install || upgrade`, so it no-ops silently when\nthe runner already ships that Python.\n\nLeft as-is:\n- **`Cache entry deserialization failed`** — a spurious warning from pip\n26.1.1, the wheel virtualenv bundles and seeds. It\u0027s an upstream pip\nregression (fixed in https://github.com/pypa/pip/pull/14012, not yet\nreleased); harmless and clears itself once the bundled pip is upgraded.\n- **`Failed to resolve action download info` / DNS errors** — transient\nrunner network blips, not controllable here.\n\nNo changelog entry — CI-only change."
    },
    {
      "commit": "3cf1a29a24ad7f93ecd2db8c7fbbf454a3607694",
      "tree": "1c3b3b27347f5f3c9c47f706c16b7ae31c166823",
      "parents": [
        "b724203e38ca810dc682126435c3ba756a8bd943"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Sun May 31 17:00:05 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Sun May 31 17:00:05 2026"
      },
      "message": "release 21.4.2"
    },
    {
      "commit": "b724203e38ca810dc682126435c3ba756a8bd943",
      "tree": "bc8afbdf131e517bf33aece6fc71b8bec6a2cee5",
      "parents": [
        "e88f194c574fba787a9f44a0568042974d45a539"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Sun May 31 16:46:04 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 31 16:46:04 2026"
      },
      "message": "🐛 fix(activation): silence deactivate hash -r under set -e (#3152)\n\nSourcing the bash/zsh activation script and later running `deactivate`\ncould abort the shell when strict mode is on. 🐚 Under `set -euo\npipefail` with shell command hashing disabled (`set +h`), the `hash -r`\ncall inside `deactivate()` returns non-zero, and `2\u003e/dev/null` only\nhides its stderr, not its exit status, so the failing command tears down\nthe session.\n\nThe `deactivate()` call now appends `|| true`, the same guard the\ntrailing activation-time `hash -r` already carried. This brings the two\n`hash -r` sites into line and mirrors the equivalent CPython `venv`\nchange in gh-149701.\n\nThe fix is confined to the bash/zsh activator; behavior under non-strict\nshells is unchanged since `hash -r` already succeeded there.\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "e88f194c574fba787a9f44a0568042974d45a539",
      "tree": "67a2f5b619f7e780ba538cf7a590c03cd0eb54c2",
      "parents": [
        "6a2d79cd8077035a8a9d08b8501975eead13b496"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu May 28 04:11:34 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu May 28 04:11:34 2026"
      },
      "message": "release 21.4.1"
    },
    {
      "commit": "6a2d79cd8077035a8a9d08b8501975eead13b496",
      "tree": "502b9229178b476697e546a955fd68a0ed040c42",
      "parents": [
        "30bcf62a65d262b85f3272a7f9b91397f712a13b"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu May 28 04:10:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 04:10:29 2026"
      },
      "message": "🐛 fix(create): debug build venvlauncher lookup on Windows 3.13+ (#3151)"
    },
    {
      "commit": "30bcf62a65d262b85f3272a7f9b91397f712a13b",
      "tree": "a5e0ae5f492f196d74924ac29512da94c53393af",
      "parents": [
        "61434984154e4474c478301e433071efd880ad8c"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu May 28 01:23:58 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Thu May 28 01:23:58 2026"
      },
      "message": "release 21.4.0"
    },
    {
      "commit": "61434984154e4474c478301e433071efd880ad8c",
      "tree": "5bb274dd37591a8288e7782e1abdd8d155178906",
      "parents": [
        "ceaf88f8736c253ca71d155bb08b8475deebda02"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu May 28 01:22:59 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 01:22:59 2026"
      },
      "message": "✨ feat(create): support Windows debug builds and remove dead code (#3150)"
    },
    {
      "commit": "ceaf88f8736c253ca71d155bb08b8475deebda02",
      "tree": "2cb65e6c4a2d0e0c422c9ddb922f7f074ed382bd",
      "parents": [
        "d423ddcce98ad1c5b4529d2c9e947a7ccf09a968"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Wed May 27 21:52:52 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 21:52:52 2026"
      },
      "message": "♻️ refactor(create): remove dead code and document droppable paths (#3149)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d423ddcce98ad1c5b4529d2c9e947a7ccf09a968",
      "tree": "66c61e61425964389147008a26415323086e6713",
      "parents": [
        "f4a793600df5a660190fb55c57b9eed84fb09d68"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Wed May 27 18:05:50 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 18:05:50 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3148)\n\nCo-authored-by: Bernát Gábor \u003cbgabor8@bloomberg.net\u003e"
    },
    {
      "commit": "f4a793600df5a660190fb55c57b9eed84fb09d68",
      "tree": "d4f615de3c807bc717bdc76397b04da80ffeec09",
      "parents": [
        "7189e8e018f3390f6ce217f2fe21a55af26f441e"
      ],
      "author": {
        "name": "Tian Teng",
        "email": "tengtianmoemoe@gmail.com",
        "time": "Wed May 27 15:56:27 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 15:56:27 2026"
      },
      "message": "Fix Mermaid flowchart rendering (#3147)"
    },
    {
      "commit": "7189e8e018f3390f6ce217f2fe21a55af26f441e",
      "tree": "1d052442cd9e82f60f4b1cbe306ec24052fef442",
      "parents": [
        "e6dba2a503560c1561258770ade4d15529c4db3d"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Tue May 19 03:27:29 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 19 03:27:29 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3145)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/astral-sh/ruff-pre-commit: v0.15.12 →\nv0.15.13](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.12...v0.15.13)\n- [github.com/zizmorcore/zizmor-pre-commit: v1.24.1 →\nv1.25.2](https://github.com/zizmorcore/zizmor-pre-commit/compare/v1.24.1...v1.25.2)\n\u003c!--pre-commit.ci end--\u003e\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "e6dba2a503560c1561258770ade4d15529c4db3d",
      "tree": "166cc6eb0b75cfc38df0c56d3d8b9e9f1a3e4eb7",
      "parents": [
        "e7517c0e56c159946374c2fed8fb874fd3bde94f"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Wed May 13 17:59:43 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Wed May 13 17:59:43 2026"
      },
      "message": "release 21.3.3"
    },
    {
      "commit": "e7517c0e56c159946374c2fed8fb874fd3bde94f",
      "tree": "61a37890edf2c55d1b81af68e8c6cc89607eaf2e",
      "parents": [
        "8531d47ff3e78492d0c1eb7d1159750e91176b67"
      ],
      "author": {
        "name": "Tim Felgentreff",
        "email": "tim.felgentreff@oracle.com",
        "time": "Wed May 13 17:58:42 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 13 17:58:42 2026"
      },
      "message": "Accept GraalPy implementation name. (#3144)\n\nWith the latest python-discover release, GraalPy names are normalized to\nGraalPy, instead of GraalVM, so virtualenv needs to be adapted.\n\n### Thanks for contributing, make sure you address all the checklists\n(for details on how see [development\ndocumentation](https://virtualenv.pypa.io/en/latest/development.html#development))\n\n- [x] ran the linter to address style issues (`tox -e fix`)\n- [x] wrote descriptive pull request text\n- [x] ensured there are test(s) validating the fix\n- [x] added news fragment in `docs/changelog` folder \n- [x] updated/extended the documentation (not needed)"
    },
    {
      "commit": "8531d47ff3e78492d0c1eb7d1159750e91176b67",
      "tree": "103ae4be01756be945d0fc18fffba23ba2c82a61",
      "parents": [
        "afefada9505d4fe67805244c31c5761e4c6c2622"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue May 12 14:42:32 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue May 12 14:42:32 2026"
      },
      "message": "release 21.3.2"
    },
    {
      "commit": "afefada9505d4fe67805244c31c5761e4c6c2622",
      "tree": "d6677ad4d0a8c996d0db4890429912aba91e15d9",
      "parents": [
        "7e270411ebf5739dfc63998a9084dc2bfd2d467b"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue May 12 14:41:18 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 12 14:41:18 2026"
      },
      "message": "🐛 fix(upgrade): regen embedded init with correct MAX and 3.16 (#3143)\n\nThe daily `Upgrade embedded dependencies` workflow keeps regenerating\n`src/virtualenv/seed/wheels/embed/__init__.py` with `MAX \u003d \"3.8\"` and\ndropping the `3.16` entry — both of which had to be hand-patched in\n#3140 on top of the auto-PR. The script is the source of the regression,\nso patching the generated file alone leaves the next cron run free to\nundo the fix again. 🔁\n\nThe `MAX` substitution in `render_init` was reading the first key of the\nordered support table, which is always the lowest Python version, so it\nbaked `MAX \u003d \u00273.8\u0027` into the rendered module on every regen. Emit the\nruntime expression `next(reversed(BUNDLE_SUPPORT))` as literal text in\nthe template instead, so the rendered module evaluates it at import time\nand always points at the highest supported version regardless of what\nthe table contains.\n\nThe `SUPPORT` range stopped at `3.15`, which is why each regen also\ndropped the `3.16` entry. Extend the range through `3.16` so the\ngenerated table covers the versions we already ship wheels for.\n\nNo runtime behavior changes for users — this only affects what the regen\ntask writes, so no changelog fragment is needed."
    },
    {
      "commit": "7e270411ebf5739dfc63998a9084dc2bfd2d467b",
      "tree": "90ea2194f2b346604c4e012b99a5ccaa81eeb8f4",
      "parents": [
        "214934c9606ef792e42580109cbdff940a62f034"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon May 11 19:56:46 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 19:56:46 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3141)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/tox-dev/tox-toml-fmt: v1.9.2 →\nv1.9.3](https://github.com/tox-dev/tox-toml-fmt/compare/v1.9.2...v1.9.3)\n- [github.com/tox-dev/pyproject-fmt: v2.21.1 →\nv2.21.2](https://github.com/tox-dev/pyproject-fmt/compare/v2.21.1...v2.21.2)\n\u003c!--pre-commit.ci end--\u003e\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "214934c9606ef792e42580109cbdff940a62f034",
      "tree": "0daac1de329dcb967fc82e583234772ea22b4d0d",
      "parents": [
        "12ab4957289c1963849bf04a5f35982c928c0a35"
      ],
      "author": {
        "name": "anthony sottile",
        "email": "asottile@umich.edu",
        "time": "Mon May 11 18:19:11 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 18:19:11 2026"
      },
      "message": "add 3.16 to embedded wheel versions (#3140)"
    },
    {
      "commit": "12ab4957289c1963849bf04a5f35982c928c0a35",
      "tree": "7fab6ed4e32137e64eeaf2d4f7fca64c8c4efc3f",
      "parents": [
        "22eadc4d2738af7e96d744369a7f40df34935c94"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue May 05 01:32:57 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue May 05 01:32:57 2026"
      },
      "message": "release 21.3.1"
    },
    {
      "commit": "22eadc4d2738af7e96d744369a7f40df34935c94",
      "tree": "fa564bebf9757d9c180e7b0b19271fabb58d7cff",
      "parents": [
        "6651dafd919c745adca1e29e31e1d96a1c9e9e52"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Tue May 05 01:32:02 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 01:32:02 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3137)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "6651dafd919c745adca1e29e31e1d96a1c9e9e52",
      "tree": "74c37a8d7c355727cbfd71dac4bb18c2bb7dde9c",
      "parents": [
        "936a36ae63eb8c68123cf9e23824f68aa9ac51b1"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue May 05 01:31:48 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 01:31:48 2026"
      },
      "message": "🐛 fix(seed): bump embedded pip to 26.1.1 (#3138)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "936a36ae63eb8c68123cf9e23824f68aa9ac51b1",
      "tree": "de3fe3290ceca4214e006b936d6fdf55c558d2d0",
      "parents": [
        "cb5a7d1820871cf26e370c6a954e48326ddd6c57"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue May 05 01:31:37 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 01:31:37 2026"
      },
      "message": "👷 ci: retry transient apt failures on Linux (#3139)"
    },
    {
      "commit": "cb5a7d1820871cf26e370c6a954e48326ddd6c57",
      "tree": "a62de4aad959c732e09490a3046eac2cf1caab4a",
      "parents": [
        "e917cc244e659160607c890de2cbad3a7bc2a28c"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Wed Apr 29 08:03:58 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 29 08:03:58 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3133)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "e917cc244e659160607c890de2cbad3a7bc2a28c",
      "tree": "54e8707542afb1a822c6b65768ba286d665059f7",
      "parents": [
        "21152f1b88c49cdefda2743cddc2cf36d50e2e57"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Apr 27 17:04:32 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Apr 27 17:04:32 2026"
      },
      "message": "release 21.3.0"
    },
    {
      "commit": "21152f1b88c49cdefda2743cddc2cf36d50e2e57",
      "tree": "ab551e9d790f88919071f0c8ae8890a54886c92b",
      "parents": [
        "096bdcd72d7a6c92dcb9dee97fd429fe3e0231a5"
      ],
      "author": {
        "name": "github-actions[bot]",
        "email": "41898282+github-actions[bot]@users.noreply.github.com",
        "time": "Mon Apr 27 17:03:20 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 17:03:20 2026"
      },
      "message": "Upgrade embedded pip/setuptools/wheel (#3132)\n\nAutomated upgrade of embedded pip, setuptools, and wheel dependencies.\n\nThis PR was created automatically by the [upgrade\nworkflow](https://github.com/pypa/virtualenv/actions/workflows/upgrade.yaml).\n\n---------\n\nCo-authored-by: gaborbernat \u003c690238+gaborbernat@users.noreply.github.com\u003e\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "096bdcd72d7a6c92dcb9dee97fd429fe3e0231a5",
      "tree": "64c5e0fb78939546583b3874c501a2112f3b94ee",
      "parents": [
        "01610dc7a8ef08158c815f43dc22ceadb98b85c0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Apr 23 13:47:08 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 23 13:47:08 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 8.0.0 to 8.1.0 (#3131)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n8.0.0 to 8.1.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/releases\"\u003eastral-sh/setup-uv\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.1.0 🌈 New input \u003ccode\u003eno-project\u003c/code\u003e\u003c/h2\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cp\u003eThis add the a new boolean input \u003ccode\u003eno-project\u003c/code\u003e.\nIt only makes sense to use in combination with\n\u003ccode\u003eactivate-environment: true\u003c/code\u003e and will append \u003ccode\u003e--no\nproject\u003c/code\u003e to the \u003ccode\u003euv venv\u003c/code\u003e call. This is for example\nuseful \u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/854\"\u003eif you\nhave a pyproject.toml file with parts unparseable by uv\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e🚀 Enhancements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd input no-project in combination with activate-environment \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🧰 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: grant contents:write to validate-release job \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/860\"\u003e#860\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a release-gate step to the release workflow \u003ca\nhref\u003d\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/859\"\u003e#859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDraft commitish releases \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd action-types.yml to instructions \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/857\"\u003e#857\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.7 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/853\"\u003e#853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRefactor version resolving \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/852\"\u003e#852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.6 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/850\"\u003e#850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.5 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/845\"\u003e#845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.4 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/843\"\u003e#843\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a release workflow \u003ca\nhref\u003d\"https://github.com/zanieb\"\u003e\u003ccode\u003e@​zanieb\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/839\"\u003e#839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.3 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/836\"\u003e#836\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📚 Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate ignore-nothing-to-cache documentation \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/833\"\u003e#833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePin setup-uv docs to v8 \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/829\"\u003e#829\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⬆️ Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(deps): bump release-drafter/release-drafter from 7.1.1 to\n7.2.0 @\u003ca href\u003d\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/855\"\u003e#855\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/08807647e7069bb48b6ef5acd8ec9567f424441b\"\u003e\u003ccode\u003e0880764\u003c/code\u003e\u003c/a\u003e\nfix: grant contents:write to validate-release job (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/860\"\u003e#860\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/717d6aba0f15312f509f5c4999e34d71ecbab8a9\"\u003e\u003ccode\u003e717d6ab\u003c/code\u003e\u003c/a\u003e\nAdd a release-gate step to the release workflow (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/859\"\u003e#859\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/5a911eb3a3983b5e650f2dad95c1ce698ca94378\"\u003e\u003ccode\u003e5a911eb\u003c/code\u003e\u003c/a\u003e\nDraft commitish releases (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/858\"\u003e#858\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/080c31e04cd7155b0ca676d08c7bc260a4476a23\"\u003e\u003ccode\u003e080c31e\u003c/code\u003e\u003c/a\u003e\nAdd action-types.yml to instructions (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/857\"\u003e#857\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/b3e97d2ba1a1eed7e9d1f8456dd06c3b725bc3a6\"\u003e\u003ccode\u003eb3e97d2\u003c/code\u003e\u003c/a\u003e\nAdd input no-project in combination with activate-environment (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/856\"\u003e#856\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/7dd591db9557f680290587fcc578372813b9ff64\"\u003e\u003ccode\u003e7dd591d\u003c/code\u003e\u003c/a\u003e\nchore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/855\"\u003e#855\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/1541b7762698877904805605192ecd63d0e4787a\"\u003e\u003ccode\u003e1541b77\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.7 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/853\"\u003e#853\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/cdfb2ee6dde255817c739680168ad81e184c4bfb\"\u003e\u003ccode\u003ecdfb2ee\u003c/code\u003e\u003c/a\u003e\nRefactor version resolving (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/852\"\u003e#852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/cb84d12dc6a0d495b82fcae14fa4559b90698660\"\u003e\u003ccode\u003ecb84d12\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.6 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/850\"\u003e#850\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/1912cc65f2e839707d7a16f2372f30b57d35fd80\"\u003e\u003ccode\u003e1912cc6\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.5 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/845\"\u003e#845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/cec208311dfd045dd5311c1add060b2062131d57...08807647e7069bb48b6ef5acd8ec9567f424441b\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.0.0\u0026new-version\u003d8.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "01610dc7a8ef08158c815f43dc22ceadb98b85c0",
      "tree": "b3ded373f90170954ac5b1dd954168c113f92a8e",
      "parents": [
        "fb6ec7c461db2b0ccfabe7ec6255368e86cfaed3"
      ],
      "author": {
        "name": "Andy Kipp",
        "email": "anki-code@users.noreply.github.com",
        "time": "Tue Apr 21 17:23:44 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 17:23:44 2026"
      },
      "message": "docs: Add usage instruction for Xonsh activation (#3130)\n\nContinue https://github.com/pypa/virtualenv/pull/3125\nSorry I missed this in original PR.\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "fb6ec7c461db2b0ccfabe7ec6255368e86cfaed3",
      "tree": "a3ff86f47a42cd7dba4e5ef0d245181782d7ffa6",
      "parents": [
        "60956799efa82adac0c3d5e70d9ca1fdd63125f8"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 21 17:23:18 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 17:23:18 2026"
      },
      "message": "🐛 fix(test): prevent PowerShell activation test from crashing xdist workers on Windows (#3128)"
    },
    {
      "commit": "60956799efa82adac0c3d5e70d9ca1fdd63125f8",
      "tree": "a3a1909f999e9de00c6229c38bb4c3ae62bfe4c1",
      "parents": [
        "8d3179cf42332501240e9ee3ddca7e376a790752"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Tue Apr 21 15:17:38 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 21 15:17:38 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3129)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8d3179cf42332501240e9ee3ddca7e376a790752",
      "tree": "59e681e6c1adb3591d87d3bb4a7bfabadcdec75d",
      "parents": [
        "a159c50a400d4e18aca3bfde5224f09e71d2eb17"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Apr 19 02:22:40 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 19 02:22:40 2026"
      },
      "message": "chore(deps): bump peter-evans/create-pull-request from 8.1.0 to 8.1.1 (#3127)\n\nBumps\n[peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request)\nfrom 8.1.0 to 8.1.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/releases\"\u003epeter-evans/create-pull-request\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eCreate Pull Request v8.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps-dev): bump the npm group with 2 updates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4305\"\u003epeter-evans/create-pull-request#4305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump minimatch by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4311\"\u003epeter-evans/create-pull-request#4311\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump the github-actions group with 2 updates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4316\"\u003epeter-evans/create-pull-request#4316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump \u003ccode\u003e@​tootallnate/once\u003c/code\u003e and\njest-environment-jsdom by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4323\"\u003epeter-evans/create-pull-request#4323\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump undici from 6.23.0 to 6.24.0 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4328\"\u003epeter-evans/create-pull-request#4328\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump flatted from 3.3.1 to 3.4.2 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4334\"\u003epeter-evans/create-pull-request#4334\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump picomatch by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4339\"\u003epeter-evans/create-pull-request#4339\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump handlebars from 4.7.8 to 4.7.9 by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4344\"\u003epeter-evans/create-pull-request#4344\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps-dev): bump the npm group with 3 updates by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot]\nin \u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4349\"\u003epeter-evans/create-pull-request#4349\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: retry post-creation API calls on 422 eventual consistency\nerrors by \u003ca\nhref\u003d\"https://github.com/peter-evans\"\u003e\u003ccode\u003e@​peter-evans\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/pull/4356\"\u003epeter-evans/create-pull-request#4356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/compare/v8.1.0...v8.1.1\"\u003ehttps://github.com/peter-evans/create-pull-request/compare/v8.1.0...v8.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/5f6978faf089d4d20b00c7766989d076bb2fc7f1\"\u003e\u003ccode\u003e5f6978f\u003c/code\u003e\u003c/a\u003e\nfix: retry post-creation API calls on 422 eventual consistency errors\n(\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4356\"\u003e#4356\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/d32e88dac789dcc7906e7d26f69f24116fa9c97d\"\u003e\u003ccode\u003ed32e88d\u003c/code\u003e\u003c/a\u003e\nbuild(deps-dev): bump the npm group with 3 updates (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4349\"\u003e#4349\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/8170bccad11c0df62542c04dcaefe36d342dfd39\"\u003e\u003ccode\u003e8170bcc\u003c/code\u003e\u003c/a\u003e\nbuild(deps-dev): bump handlebars from 4.7.8 to 4.7.9 (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4344\"\u003e#4344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/00418193b417f888dbf1d993c5c0d31d27fdc7de\"\u003e\u003ccode\u003e0041819\u003c/code\u003e\u003c/a\u003e\nbuild(deps): bump picomatch (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4339\"\u003e#4339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/b993918c8536b6d44706130734d5456879762b27\"\u003e\u003ccode\u003eb993918\u003c/code\u003e\u003c/a\u003e\nbuild(deps-dev): bump flatted from 3.3.1 to 3.4.2 (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4334\"\u003e#4334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/36d7c8468b48f9c2f8f29e260e82f10d4b90d2bd\"\u003e\u003ccode\u003e36d7c84\u003c/code\u003e\u003c/a\u003e\nbuild(deps-dev): bump undici from 6.23.0 to 6.24.0 (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4328\"\u003e#4328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/a45d1fb447fcaf601166e405fd4f335cde1a8aa8\"\u003e\u003ccode\u003ea45d1fb\u003c/code\u003e\u003c/a\u003e\nbuild(deps): bump \u003ccode\u003e@​tootallnate/once\u003c/code\u003e and\njest-environment-jsdom (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4323\"\u003e#4323\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/3499eb61835cc0015c0b786e203d74b1e8f55e43\"\u003e\u003ccode\u003e3499eb6\u003c/code\u003e\u003c/a\u003e\nbuild(deps): bump the github-actions group with 2 updates (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4316\"\u003e#4316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/3f3b473b8c148f5a7520efb4d1f9a70eea3d9d1f\"\u003e\u003ccode\u003e3f3b473\u003c/code\u003e\u003c/a\u003e\nbuild(deps): bump minimatch (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4311\"\u003e#4311\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/commit/6699836a213cf8b28c4f0408a404a6ac79d4458a\"\u003e\u003ccode\u003e6699836\u003c/code\u003e\u003c/a\u003e\nbuild(deps-dev): bump the npm group with 2 updates (\u003ca\nhref\u003d\"https://redirect.github.com/peter-evans/create-pull-request/issues/4305\"\u003e#4305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/peter-evans/create-pull-request/compare/c0f553fe549906ede9cf27b5156039d195d2ece0...5f6978faf089d4d20b00c7766989d076bb2fc7f1\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dpeter-evans/create-pull-request\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.1.0\u0026new-version\u003d8.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a159c50a400d4e18aca3bfde5224f09e71d2eb17",
      "tree": "094576347dbb108c55b8a2e7f34fd2955500c132",
      "parents": [
        "9ba729bbbbec89c121c3ce4ef205fdd403e33e26"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Apr 19 02:22:36 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 19 02:22:36 2026"
      },
      "message": "chore(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#3126)\n\nBumps\n[actions/upload-artifact](https://github.com/actions/upload-artifact)\nfrom 7.0.0 to 7.0.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/releases\"\u003eactions/upload-artifact\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the readme with direct upload details by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/795\"\u003eactions/upload-artifact#795\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReadme: bump all the example versions to v7 by \u003ca\nhref\u003d\"https://github.com/danwkennedy\"\u003e\u003ccode\u003e@​danwkennedy\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/796\"\u003eactions/upload-artifact#796\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInclude changes in typespec/ts-http-runtime 0.3.5 by \u003ca\nhref\u003d\"https://github.com/yacaovsnc\"\u003e\u003ccode\u003e@​yacaovsnc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/pull/797\"\u003eactions/upload-artifact#797\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/upload-artifact/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003e\u003ccode\u003e043fb46\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/797\"\u003e#797\u003c/a\u003e\nfrom actions/yacaovsnc/update-dependency\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/634250c1388765ea7ed0f053e636f1f399000b94\"\u003e\u003ccode\u003e634250c\u003c/code\u003e\u003c/a\u003e\nInclude changes in typespec/ts-http-runtime 0.3.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/e454baaac2be505c9450e11b8f3215c6fc023ce8\"\u003e\u003ccode\u003ee454baa\u003c/code\u003e\u003c/a\u003e\nReadme: bump all the example versions to v7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/796\"\u003e#796\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/commit/74fad66b98a6d799dc004d3353ccd0e6f6b2530e\"\u003e\u003ccode\u003e74fad66\u003c/code\u003e\u003c/a\u003e\nUpdate the readme with direct upload details (\u003ca\nhref\u003d\"https://redirect.github.com/actions/upload-artifact/issues/795\"\u003e#795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/upload-artifact/compare/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f...043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/upload-artifact\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d7.0.0\u0026new-version\u003d7.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "9ba729bbbbec89c121c3ce4ef205fdd403e33e26",
      "tree": "12623001bdc9d5fc416ea15716db59173c3974fa",
      "parents": [
        "d42ea5cd19a116dbdbb9852becace188d5b3a225"
      ],
      "author": {
        "name": "Andy Kipp",
        "email": "anki-code@users.noreply.github.com",
        "time": "Sun Apr 19 02:22:31 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Apr 19 02:22:31 2026"
      },
      "message": "feat: Reintroduce xonsh shell support (#3125)\n\nHello @gaborbernat! In the Xonsh shell project, we’ve done a significant\namount of groundwork ([*](https://github.com/xonsh/xonsh/pull/6152)) and\nare now on the verge of releasing version 0.23.0, which is expected to\nbe the most stable release in the project’s history. While working on\nthis version, we took your previous\n[feedback](https://github.com/xonsh/xonsh/issues/3689#issuecomment-748621587)\ninto account and implemented additional improvements.\n\nIn light of this, and given the recurring requests for virtualenv\nsupport, I’d like to introduce an updated version of Xonsh support for\nvirtualenv.\n\nPlease take a look. Thanks!\n\n------\n\n- [x] ran the linter to address style issues (`tox -e fix`)\n- [x] wrote descriptive pull request text\n- [x] ensured there are test(s) validating the fix\n- [x] added news fragment in `docs/changelog` folder\n- [x] updated/extended the documentation\n\n------\n\n* cc https://github.com/xonsh/xonsh/issues/6025\n* сс https://github.com/xonsh/xonsh/pull/4466\n* cc https://github.com/pypa/virtualenv/pull/2160\n* cc https://github.com/pypa/virtualenv/pull/1206\n\n---------\n\nCo-authored-by: 1 \u003c1@1.1\u003e\nCo-authored-by: anki-code \u003c1@1.com\u003e\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e"
    },
    {
      "commit": "d42ea5cd19a116dbdbb9852becace188d5b3a225",
      "tree": "d06b53dae3fa5fd9b60cbc0bb5eb0f55d3442fcd",
      "parents": [
        "15063c10b3afae1d3fa3234e99f956434051f7b5"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Wed Apr 15 22:12:56 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 15 22:12:56 2026"
      },
      "message": "🐛 fix(type): stop ty flagging default_source on Action (#3124)"
    },
    {
      "commit": "15063c10b3afae1d3fa3234e99f956434051f7b5",
      "tree": "509fa5c5ec91542c5e66714b8c56291a53c5efa0",
      "parents": [
        "754602d6f07d262f4f352cc590bd3f9ef3b157fe"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Apr 14 22:14:15 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Apr 14 22:14:15 2026"
      },
      "message": "release 21.2.4"
    },
    {
      "commit": "754602d6f07d262f4f352cc590bd3f9ef3b157fe",
      "tree": "22b24817604866bc72b312656b78e1f1a70f62b8",
      "parents": [
        "43deabf249c10896d09a282aa254a837fdcef9b5"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 14 20:26:56 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 20:26:56 2026"
      },
      "message": "🐛 fix(seed): validate wheel zip entries before extraction (#3118)\n\nSecurity hardening. The app-data seeder extracts seed wheels with\n`zipfile.ZipFile.extractall` without validating entry names first.\nWheels are not a strongly trusted input — they live on disk, they can be\nreplaced by anyone with write access to the app-data cache, and in the\n``--download`` path they come from pip\u0027s cache — so a tampered wheel\nwith an entry named `../evil.py` or an absolute path would land outside\nthe image directory. 🔒\n\nThe fix wraps extraction in a helper that refuses any entry whose name\nis absolute or resolves outside the target image directory, then\ndelegates to `extractall` for the happy path. Absolute-path checks cover\nboth POSIX and Windows forms so the same guard is effective on any\nplatform.\n\nNothing changes for well-formed wheels; only malformed archives are\nrejected, with a clear `RuntimeError` that names the offending entry."
    },
    {
      "commit": "43deabf249c10896d09a282aa254a837fdcef9b5",
      "tree": "def5e9f29019eeab9fce84865050f85d8e3e84a5",
      "parents": [
        "4e412b0ba38284487267f481026ea218689fa9bd"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 14 20:26:26 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 20:26:26 2026"
      },
      "message": "🐛 fix(seed): verify sha256 of bundled wheels on load (#3119)\n\nSecurity hardening. Bundled seed wheels were loaded straight off disk\nand handed to pip without any integrity check. A corrupted or tampered\nwheel sitting next to `embed/__init__.py` — whether from a botched\nupgrade, a filesystem error, or a supply-chain compromise — would have\nbeen silently installed into every new environment. 🔒\n\nThe fix records the SHA-256 of every bundled wheel alongside\n`BUNDLE_SUPPORT` in the generated `embed/__init__.py`, and verifies each\nwheel the first time it is requested. Hashes are cached per wheel name\nso the happy path keeps a single file read per interpreter run, and a\nmismatch aborts with a clear `RuntimeError`. When virtualenv runs from a\nzipapp the bytes are read straight from the archive entry, so the check\napplies to both on-disk and zipapp layouts.\n\nThe hash table is produced by `tasks/upgrade_wheels.py` so future wheel\nbumps stay in sync without manual bookkeeping. A new `--regen` mode lets\nthe generator rewrite the module from the wheels currently on disk\nwithout re-downloading anything, which is how this PR produced the\ninitial table."
    },
    {
      "commit": "4e412b0ba38284487267f481026ea218689fa9bd",
      "tree": "f8092edd1e3282a9b2bd9eefc17319d60f2073e7",
      "parents": [
        "130981834946a828174e37ecdd250f530f09832f"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 14 20:23:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 20:23:12 2026"
      },
      "message": "🐛 fix(seed): validate distribution and version before pip download (#3120)\n\nSecurity hardening. The distribution name and version specifier handed\nto `pip download` in `download_wheel` were interpolated straight into\nthe subprocess argument list with an f-string. Internal callers always\npass sensible values today, but the function is a small function call\naway from turning a distribution string like `pip\n--index-url\u003dhttp://evil` or `pip[extra]` into extra pip flags or a\ndifferent package entirely. 🔒 Defense in depth is cheap here and the\ncheck runs before the subprocess is ever spawned.\n\nThe fix rejects any distribution name that does not match the PEP 503\nnormalised form, and any non-empty version spec that does not match what\n`Version.as_version_spec` can emit. The regexes are written in verbose\nmode with named groups so the allow-list is readable at a glance.\nAnything outside those shapes raises a `ValueError` with the offending\nstring quoted for debugging. Happy-path callers see no behavioural\nchange.\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "130981834946a828174e37ecdd250f530f09832f",
      "tree": "e5a0068fd7530732d1fd04c3e615cc267fd38cb2",
      "parents": [
        "48f6fdcc14b8654236f9081adbff10a32f536940"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 14 20:21:23 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 20:21:23 2026"
      },
      "message": "🐛 fix(zipapp): enforce ROOT containment with Path.relative_to (#3121)\n\nSecurity hardening. When running from a zipapp,\n`virtualenv.util.zipapp._get_path_within_zip` guards against paths that\nresolve outside the archive. The previous implementation called\n`os.path.realpath`, then decided containment by building a\nseparator-prefixed string and comparing with `startswith`. That is\nfragile on Windows path separators, brittle around the trailing\nseparator, and hard to reason about when symlinks are involved. 🔒\n\nThe fix resolves both the candidate path and `ROOT` through `pathlib`\nand uses `Path.relative_to` to decide containment — anything that does\nnot resolve inside `ROOT` is rejected with a `RuntimeError` before any\nzipfile work happens. The returned entry name is always forward-slashed\nvia `as_posix`, so the Windows-specific replacement is no longer needed.\n\nBehaviour is unchanged for well-formed paths; only previously-accepted\nescape attempts become errors."
    },
    {
      "commit": "48f6fdcc14b8654236f9081adbff10a32f536940",
      "tree": "c2efe464abf396b21614a896820405dd1955958a",
      "parents": [
        "a5fb4a290d60776e2b3f81696bd7291913aa25d4"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Apr 14 20:20:04 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 14 20:20:04 2026"
      },
      "message": "🐛 fix(periodic-update): refuse unverified HTTPS to PyPI by default (#3122)\n\nSecurity hardening. When the verified HTTPS request to\n`https://pypi.org/pypi/\u003cdist\u003e/json` failed, the periodic update retried\nthe request with an unverified SSL context and used whatever came back.\nThe original comment justified this with \u0027the information we request is\nnot sensitive\u0027, but the metadata drives the decision about which wheel\nversion virtualenv considers \u0027up to date\u0027. 🔒 A network-level attacker\nthat can break the handshake can then pin virtualenv to an older seed\nwheel and silently suppress security updates.\n\nThe fallback is now skipped by default. A failed verified request logs\nthe error and returns `None`, which the periodic update path already\nhandles gracefully — no wheel bump happens and the run continues. Hosts\nwith genuinely broken trust stores can opt back in by setting\n`VIRTUALENV_PERIODIC_UPDATE_INSECURE\u003d1`, which is logged at WARNING so\nit shows up in CI output. The env var is documented in\n`docs/how-to/usage.rst` next to the existing override knobs."
    },
    {
      "commit": "a5fb4a290d60776e2b3f81696bd7291913aa25d4",
      "tree": "0cd3b3da9e44bee485a7688ea2d53553a0ed0f0e",
      "parents": [
        "7f91a9a0bfbc549fc10274164135cf02c8ca8167"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Apr 14 01:09:23 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Tue Apr 14 01:09:23 2026"
      },
      "message": "release 21.2.3"
    },
    {
      "commit": "7f91a9a0bfbc549fc10274164135cf02c8ca8167",
      "tree": "be06416af1d6a77b964c539ee80accebfe00b316",
      "parents": [
        "33348d69426ef49ea26dcab7f12b474706968813"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Apr 13 23:32:56 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "690238+gaborbernat@users.noreply.github.com",
        "time": "Mon Apr 13 23:32:56 2026"
      },
      "message": "release 21.2.2"
    },
    {
      "commit": "33348d69426ef49ea26dcab7f12b474706968813",
      "tree": "5b7408c20dc5d874dc0c80821283e10eee1f94d6",
      "parents": [
        "d73ff7c2dccd6a60223b5c4ed673d7f3e7df9a43"
      ],
      "author": {
        "name": "Rahul Devikar",
        "email": "rahuldevikar5512@gmail.com",
        "time": "Mon Apr 13 23:32:05 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 13 23:32:05 2026"
      },
      "message": "bump python-discovery minimum to 1.2.2 (#3117)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d73ff7c2dccd6a60223b5c4ed673d7f3e7df9a43",
      "tree": "073016604ec7dd2ca50ea0bdb5d5df5a58b7f894",
      "parents": [
        "d1fc6e68678da49932707bb09a10464aff2f30cc"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Apr 13 21:57:32 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 13 21:57:32 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3116)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d1fc6e68678da49932707bb09a10464aff2f30cc",
      "tree": "8dff92a1f7c06a8557084ac6a8669872c37c2108",
      "parents": [
        "4136b51af53ba50354c6727cae3b79c6be2b2a3b"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 19:29:32 2026"
      },
      "committer": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 19:29:32 2026"
      },
      "message": "Release 21.2.1\n"
    },
    {
      "commit": "4136b51af53ba50354c6727cae3b79c6be2b2a3b",
      "tree": "6b92053cf9bb7bc94ed967c8ef28bdcff1920147",
      "parents": [
        "d1deceacb19edde2c91a40e20894b7863d2a02ab"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 19:22:52 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 19:22:52 2026"
      },
      "message": "fix(ci): check out repo in publish job for gh release notes (#3115)\n\n`gh release create --generate-notes` runs git to locate the previous tag\nwhen building auto-generated release notes. The publish job had no\ncheckout, so it failed with `fatal: not a git repository`. This broke\nthe 21.2.1 release after PyPI publish had already succeeded.\n\nA minimal `fetch-depth: 0` checkout is added before the artifact\ndownloads. `persist-credentials: false` is set since the publish job\nonly reads the repo — it does not push."
    },
    {
      "commit": "d1deceacb19edde2c91a40e20894b7863d2a02ab",
      "tree": "075d6d56427bcfc81b45bc45c1b75a651f32b365",
      "parents": [
        "48e21104c939b6fb582dc4c56349860264d00062"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 18:44:54 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 18:44:54 2026"
      },
      "message": "fix(ci): persist git credentials in pre-release workflow (#3114)\n\n`pre-release.yaml` had `persist-credentials: false` on the checkout step\nthat uses `GH_RELEASE_TOKEN`. The release script (via gitpython) pushes\nthe changelog commit and tag to main after building — but by then the\ntoken credentials had been discarded, causing git to fail with `fatal:\ncould not read Username for \u0027https://github.com\u0027: No such device or\naddress`.\n\nCommit 235b124e removed `persist-credentials: false` from jobs that need\npush access but missed `pre-release.yaml`. This aligns it with\n`release.yaml`\u0027s rollback job, which already omits the flag and carries\nthe `zizmor: ignore[artipacked]` annotation."
    },
    {
      "commit": "48e21104c939b6fb582dc4c56349860264d00062",
      "tree": "109c031b6a7b4fd281b7ca3480df0153112f565f",
      "parents": [
        "d00c465448230b7d964b2fbf646fa9602c7aa816"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 18:05:35 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 18:05:35 2026"
      },
      "message": "👷 ci: fix setup-uv warnings and drop brew@3.9 (#3113)\n\nEvery CI job emitted \"Empty workdir detected\" and \"No file matched to\n[...]. The cache will never get invalidated.\" because\n`astral-sh/setup-uv` ran before `actions/checkout`. With 50+ parallel\njobs sharing the same cache key, jobs also raced to save the cache\nsimultaneously, producing \"Unable to reserve cache\" warnings on every\nrun.\n\nCheckout now runs first in both jobs so `setup-uv` can find\n`pyproject.toml` for cache keying. A `cache-suffix` derived from the\nmatrix variable (`matrix.py` / `matrix.tox_env`) gives each job its own\ncache slot, eliminating the write race entirely. 🔧\n`PIP_DISABLE_PIP_VERSION_CHECK\u003d1` suppresses the pip upgrade notice that\nappeared for Python 3.8, which ships with a stale pip. `brew@3.9` is\ndropped because Python 3.9 reached EOL in October 2024 and Homebrew\nemits a deprecation warning when installing it."
    },
    {
      "commit": "d00c465448230b7d964b2fbf646fa9602c7aa816",
      "tree": "2bb3b797b5936d4091a85ea13b5e141331fee761",
      "parents": [
        "0a8c46a5436d1d31487b88d0e72be1b48cf9b02e"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Apr 09 13:15:20 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Apr 09 13:15:20 2026"
      },
      "message": "🐛 fix(nushell): surface actionable hint in deactivate error output (#3112)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0a8c46a5436d1d31487b88d0e72be1b48cf9b02e",
      "tree": "21d1d84f2d13cde9655a4173511481bd50833edc",
      "parents": [
        "f0bbe174e2c241f9a7fbeaac7446cf200c14a851"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Apr 08 15:56:33 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Apr 08 15:56:33 2026"
      },
      "message": "chore(deps): bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 (#3111)\n\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f0bbe174e2c241f9a7fbeaac7446cf200c14a851",
      "tree": "872f67af3d8f019c6e17cb0a8059073a6f382de7",
      "parents": [
        "dfaa73826dad5e9c2cdc2b5873a14eb80c37480b"
      ],
      "author": {
        "name": "bahtyar",
        "email": "34988899+Bahtya@users.noreply.github.com",
        "time": "Tue Apr 07 15:05:22 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Apr 07 15:05:22 2026"
      },
      "message": "fix: use terminal width for help formatting instead of hardcoded 240 (#3110)\n\nFixes #3105\n\n## Problem\n\n`virtualenv --help` ignores terminal width and always formats output for\n240 characters, making it hard to read on standard terminal widths.\n\nRoot cause: `HelpFormatter.__init__` hardcodes `width\u003d240` instead of\nusing the actual terminal size.\n\n## Fix\n\nReplace hardcoded `width\u003d240` with `shutil.get_terminal_size().columns`\nto respect the user\u0027s terminal width.\n\n## Before\n\n```bash\n# Terminal is 80 columns wide, but help text runs to 240:\nvirtualenv --help  # text overflows, hard to read\n```\n\n## After\n\n```bash\n# Help text wraps at terminal width:\nvirtualenv --help  # clean, readable formatting\n```\n\n## Testing\n\n- Verified `HelpFormatter._width` now matches\n`shutil.get_terminal_size().columns`\n- All existing unit tests pass (43 passed)\n\n## Changes\n\n- `src/virtualenv/config/cli/parser.py`: 4 lines added, 1 removed"
    },
    {
      "commit": "dfaa73826dad5e9c2cdc2b5873a14eb80c37480b",
      "tree": "8630066f746a5cedf3004effab776514cd7ba360",
      "parents": [
        "cc658da7f137776813f3304cdd772eb52f8ed36e"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Apr 06 20:59:03 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 06 20:59:03 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3109)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/tox-dev/pyproject-fmt: v2.20.0 →\nv2.21.0](https://github.com/tox-dev/pyproject-fmt/compare/v2.20.0...v2.21.0)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.8 →\nv0.15.9](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.8...v0.15.9)\n\u003c!--pre-commit.ci end--\u003e\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "cc658da7f137776813f3304cdd772eb52f8ed36e",
      "tree": "99ce1fb7b5c86274757d5c3eb8a893147a1f49dd",
      "parents": [
        "f235373eee6e3e98e556408fa71e67adb4d4685b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 06 14:40:32 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 06 14:40:32 2026"
      },
      "message": "chore(deps): bump astral-sh/setup-uv from 7.6.0 to 8.0.0 (#3107)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from\n7.6.0 to 8.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/releases\"\u003eastral-sh/setup-uv\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev8.0.0 🌈 Immutable releases and secure tags\u003c/h2\u003e\n\u003ch1\u003eThis is the first immutable release of \u003ccode\u003esetup-uv\u003c/code\u003e 🥳\u003c/h1\u003e\n\u003cp\u003eAll future releases are also immutable, if you want to know more\nabout what this means checkout \u003ca\nhref\u003d\"https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases\"\u003ethe\ndocs\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release also has two breaking changes\u003c/p\u003e\n\u003ch2\u003eNew format for \u003ccode\u003emanifest-file\u003c/code\u003e\u003c/h2\u003e\n\u003cp\u003eThe previously deprecated way of defining a custom version manifest\nto control which \u003ccode\u003euv\u003c/code\u003e versions are available and where to\ndownload them from got removed. The functionality is still there but you\nhave to use the \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format\"\u003enew\nformat\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNo more major and minor tags\u003c/h2\u003e\n\u003cp\u003eTo increase \u003cstrong\u003esecurity\u003c/strong\u003e even more we will \u003cstrong\u003estop\npublishing minor tags\u003c/strong\u003e. You won\u0027t be able to use\n\u003ccode\u003e@v8\u003c/code\u003e or \u003ccode\u003e@v8.0\u003c/code\u003e any longer. We do this because\npinning to major releases opens up users to supply chain attacks like\nwhat happened to \u003ca\nhref\u003d\"https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/\"\u003etj-actions\u003c/a\u003e.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!TIP]\nUse the immutable tag as a version\n\u003ccode\u003eastral-sh/setup-uv@v8.0.0\u003c/code\u003e\nOr even better the githash\n\u003ccode\u003eastral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57\u003c/code\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove update-major-minor-tags workflow \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/826\"\u003e#826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove deprecrated custom manifest \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/813\"\u003e#813\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🧰 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eShortcircuit latest version from manifest \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/828\"\u003e#828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSimplify inputs.ts \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/827\"\u003e#827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump release-drafter to v7.1.1 \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/825\"\u003e#825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRefactor inputs \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/823\"\u003e#823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplace inline compile args with tsconfig \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/824\"\u003e#824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.2 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/821\"\u003e#821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.1 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/817\"\u003e#817\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.11.0 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/815\"\u003e#815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix latest-version workflow check \u003ca\nhref\u003d\"https://github.com/eifinger\"\u003e\u003ccode\u003e@​eifinger\u003c/code\u003e\u003c/a\u003e (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/812\"\u003e#812\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: update known checksums for 0.10.11/0.10.12 @\u003ca\nhref\u003d\"https://github.com/apps/github-actions\"\u003egithub-actions[bot]\u003c/a\u003e\n(\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/cec208311dfd045dd5311c1add060b2062131d57\"\u003e\u003ccode\u003ecec2083\u003c/code\u003e\u003c/a\u003e\nShortcircuit latest version from manifest (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/828\"\u003e#828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/4dd8ab45206a76f8c1dfe399fa88df10a7264f27\"\u003e\u003ccode\u003e4dd8ab4\u003c/code\u003e\u003c/a\u003e\nSimplify inputs.ts (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/827\"\u003e#827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/7fdbe7cf0c8ef50cfd0878eed7b5180abc6b53c7\"\u003e\u003ccode\u003e7fdbe7c\u003c/code\u003e\u003c/a\u003e\nRemove update-major-minor-tags workflow (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/826\"\u003e#826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/485abd05e5c74a247f0a309e333d2433ab9a353a\"\u003e\u003ccode\u003e485abd0\u003c/code\u003e\u003c/a\u003e\nBump release-drafter to v7.1.1 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/825\"\u003e#825\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/f82eb19c06057c455674b2602e0139fd906f1428\"\u003e\u003ccode\u003ef82eb19\u003c/code\u003e\u003c/a\u003e\nRefactor inputs (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/823\"\u003e#823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/868d1f74d9d862d7b40219546bfe35299c6dd452\"\u003e\u003ccode\u003e868d1f7\u003c/code\u003e\u003c/a\u003e\nReplace inline compile args with tsconfig (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/824\"\u003e#824\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/447e6d02b15d65b3247cce2d6019f11957285d11\"\u003e\u003ccode\u003e447e6d0\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.2 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/821\"\u003e#821\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/5c62c5926145985eec91f09e2e0a75f40daed929\"\u003e\u003ccode\u003e5c62c59\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.1 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/817\"\u003e#817\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/e1a7373adb857afd2a70b971e8ebdacc64ed27d0\"\u003e\u003ccode\u003ee1a7373\u003c/code\u003e\u003c/a\u003e\nchore: update known checksums for 0.11.0 (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/815\"\u003e#815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/commit/89709315bb3bd4bf0f4b1db4b710e99009087ab5\"\u003e\u003ccode\u003e8970931\u003c/code\u003e\u003c/a\u003e\nRemove deprecrated custom manifest (\u003ca\nhref\u003d\"https://redirect.github.com/astral-sh/setup-uv/issues/813\"\u003e#813\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/astral-sh/setup-uv/compare/37802adc94f370d6bfd71619e3f0bf239e1f3b78...cec208311dfd045dd5311c1add060b2062131d57\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dastral-sh/setup-uv\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d7.6.0\u0026new-version\u003d8.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\n---------\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cgaborjbernat@gmail.com\u003e\nCo-authored-by: Claude Opus 4.6 (1M context) \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "f235373eee6e3e98e556408fa71e67adb4d4685b",
      "tree": "1394b524c98396761926775692bf8258ad6a956a",
      "parents": [
        "235b124e4400d4784dbb37f19f9a2e5afbe97378"
      ],
      "author": {
        "name": "bahtyar",
        "email": "34988899+Bahtya@users.noreply.github.com",
        "time": "Sat Apr 04 18:31:13 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Apr 04 18:31:13 2026"
      },
      "message": "Fix broken Installation link in README (#3106)"
    },
    {
      "commit": "235b124e4400d4784dbb37f19f9a2e5afbe97378",
      "tree": "3f56f435be0c8d3059c7d5b2d9beb689db90e36b",
      "parents": [
        "0f63b3d07f5e319c4d672b7d6f38747b660f2937"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Mar 31 21:10:07 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 31 21:10:07 2026"
      },
      "message": "Remove persist-credentials: false from jobs needing push access (#3102)"
    },
    {
      "commit": "0f63b3d07f5e319c4d672b7d6f38747b660f2937",
      "tree": "81b69baa118db1ce0661523787398266d7bbf7dd",
      "parents": [
        "5b9b17048ad0e6ead4ed9bc5e2ae60d77cd24894"
      ],
      "author": {
        "name": "Rahul Devikar",
        "email": "rahuldevikar5512@gmail.com",
        "time": "Mon Mar 30 21:13:52 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 30 21:13:52 2026"
      },
      "message": "Add current and previous maintainers (#3101)"
    },
    {
      "commit": "5b9b17048ad0e6ead4ed9bc5e2ae60d77cd24894",
      "tree": "1a39028508db2350d98ef147fe6108bc31f76c36",
      "parents": [
        "1bbeb9045b7075ba55684f9f601f64d8844fbf12"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Mar 30 18:57:04 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 30 18:57:04 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3100)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/python-jsonschema/check-jsonschema: 0.37.0 →\n0.37.1](https://github.com/python-jsonschema/check-jsonschema/compare/0.37.0...0.37.1)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.7 →\nv0.15.8](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.7...v0.15.8)\n\u003c!--pre-commit.ci end--\u003e\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1bbeb9045b7075ba55684f9f601f64d8844fbf12",
      "tree": "85deb27034d7eb1966254a914c8a4d6c4f230be0",
      "parents": [
        "3925ac83b3ea8659581c291e42e939fd5da05834"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Thu Mar 26 05:55:19 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 26 05:55:19 2026"
      },
      "message": "🔒 ci(workflows): add zizmor security auditing (#3099)\n\nGitHub Actions workflows were vulnerable to several security issues\nincluding template injection, credential exposure, and permission\nover-scoping. These vulnerabilities could allow attackers to execute\narbitrary code or access sensitive tokens.\n\nThis change adds `zizmor` as a pre-commit hook to continuously audit\nworkflow security and fixes all existing vulnerabilities. The fixes\ninclude pinning actions to commit hashes, moving secrets to dedicated\nenvironments, isolating GitHub context from shell execution, and\nrestricting permissions to the minimum required scope.\n\nAll workflows now pass security audit with zero findings. Future\nworkflow changes will be automatically checked before commit.\n\n---------\n\nSigned-off-by: Bernát Gábor \u003cbgabor8@bloomberg.net\u003e\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "3925ac83b3ea8659581c291e42e939fd5da05834",
      "tree": "84528ec4a73f3178e8a38b3c2e6e66e1d792d658",
      "parents": [
        "5b5e2813dc6afcb9cea007c2ddb917ec79a3d451"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Mon Mar 23 22:31:12 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Mar 23 22:31:12 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3098)\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5b5e2813dc6afcb9cea007c2ddb917ec79a3d451",
      "tree": "7430e0bb087387287037d541a30a53b4d582b71b",
      "parents": [
        "dc10a343c91d9b3306a553342e90d6bbe919cc03"
      ],
      "author": {
        "name": "pre-commit-ci[bot]",
        "email": "66853113+pre-commit-ci[bot]@users.noreply.github.com",
        "time": "Tue Mar 17 00:32:57 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 17 00:32:57 2026"
      },
      "message": "[pre-commit.ci] pre-commit autoupdate (#3096)\n\n\u003c!--pre-commit.ci start--\u003e\nupdates:\n- [github.com/tox-dev/pyproject-fmt: v2.16.2 →\nv2.19.0](https://github.com/tox-dev/pyproject-fmt/compare/v2.16.2...v2.19.0)\n- [github.com/astral-sh/ruff-pre-commit: v0.15.5 →\nv0.15.6](https://github.com/astral-sh/ruff-pre-commit/compare/v0.15.5...v0.15.6)\n\u003c!--pre-commit.ci end--\u003e\n\n---------\n\nCo-authored-by: pre-commit-ci[bot] \u003c66853113+pre-commit-ci[bot]@users.noreply.github.com\u003e\nCo-authored-by: Bernát Gábor \u003cbgabor8@bloomberg.net\u003e"
    },
    {
      "commit": "dc10a343c91d9b3306a553342e90d6bbe919cc03",
      "tree": "86562060ea51a31dcf461c64808dac1bc9746982",
      "parents": [
        "080a1bd20eb9c4b55363506f16964164cd46941d"
      ],
      "author": {
        "name": "Bernát Gábor",
        "email": "gaborjbernat@gmail.com",
        "time": "Tue Mar 17 00:12:00 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Mar 17 00:12:00 2026"
      },
      "message": "🐛 fix(create): use commonpath for correct path validation (#3097)"
    },
    {
      "commit": "080a1bd20eb9c4b55363506f16964164cd46941d",
      "tree": "2c52cb4400aa6eec5868eaceff9ccf17d552e38e",
      "parents": [
        "1a838b278263aeab2a379b5c938c8fcd95150ef6"
      ],
      "author": {
        "name": "Rahul Devikar",
        "email": "rahuldevikar5512@gmail.com",
        "time": "Thu Mar 12 21:20:34 2026"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 12 21:20:34 2026"
      },
      "message": "Enhance upgrade workflow: age check, dedup, issue tracking (#3094)"
    }
  ],
  "next": "1a838b278263aeab2a379b5c938c8fcd95150ef6"
}
