Skip to content

Bump softprops/action-gh-release from 2 to 3#853

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/softprops/action-gh-release-3
Open

Bump softprops/action-gh-release from 2 to 3#853
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/softprops/action-gh-release-3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 13, 2026

Bumps softprops/action-gh-release from 2 to 3.

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on v2.6.2.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release

v2.6.2

What's Changed

Other Changes 🔄

Full Changelog: softprops/action-gh-release@v2...v2.6.2

v2.6.1

2.6.1 is a patch release focused on restoring linked discussion thread creation when discussion_category_name is set. It fixes [#764](https://github.com/softprops/action-gh-release/issues/764), where the draft-first publish flow stopped carrying the discussion category through the final publish step.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

Bug fixes 🐛

v2.6.0

2.6.0 is a minor release centered on previous_tag support for generate_release_notes, which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range. It also includes the recent concurrent asset upload recovery fix, a working_directory docs sync, a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.

If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.

What's Changed

... (truncated)

Changelog

Sourced from softprops/action-gh-release's changelog.

0.1.13

  • fix issue with multiple runs concatenating release bodies #145
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 13, 2026
@dependabot dependabot Bot requested a review from a team as a code owner April 13, 2026 08:01
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 13, 2026
@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented Apr 13, 2026

⚠️ No Changeset found

Latest commit: 6b74d97

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@dependabot dependabot Bot force-pushed the dependabot/github_actions/softprops/action-gh-release-3 branch 6 times, most recently from ba2fdb5 to 72b65a4 Compare May 1, 2026 13:19
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/softprops/action-gh-release-3 branch from 72b65a4 to 6b74d97 Compare May 1, 2026 14:02
Copy link
Copy Markdown
Contributor

Review summary — safe to merge ✅

Usage in this repo

softprops/action-gh-release is used in exactly two places, both with the same minimal pattern:

  • .github/workflows/npm-publish.yml:117
  • .github/workflows/publish-static-bundle.yml:291
- uses: softprops/action-gh-release@v2
  with:
    body: ${{ steps.release-content.outputs.content }}
    tag_name: ${{ inputs.tag_name }}

Only body (changelog snippet) and tag_name are passed. No files, draft, prerelease, discussion_category_name, make_latest, target_commitish, repository, token, or generate_release_notes are used. The default github.token is used; both jobs grant contents: write. Both run on ubuntu-latest and are wrapped in continue-on-error: true.

v2 → v3 diff

Diffing action.yml between the v2 and v3 tags, the only change is:

-  using: "node20"
+  using: "node24"

The v3.0.0 release notes confirm this is a runtime-only bump (Node 20 → Node 24). Inputs and outputs are unchanged. v2.6.2 is documented as the last Node 20-compatible line for environments that don't support Node 24.

Runner compatibility

ubuntu-latest has supported the node24 Actions runtime since actions/runner v2.327.0 (released July 2024), so both invocations will execute correctly. The rest of this repo is already on modern actions (actions/checkout@v6, actions/setup-node@v6, actions/download-artifact@v8), all of which are node24-ready.

Security / supply chain

  • Tag-pinning (@v3) is consistent with the rest of the repo's pinning style.
  • v3 introduces no new permissions, network calls, or behavioral changes.
  • No other workflow files reference this action.

Build verification

This PR only touches GitHub Actions workflow YAML — no source code, no pnpm build impact. The action only runs during release workflows, not regular CI.

Changes pushed

None. The two @v2 → @v3 updates are sufficient as-is; no compensating code changes are needed.

Conclusion: Safe to merge.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Development

Successfully merging this pull request may close these issues.

1 participant