From 1fad41ff479174a854fa1b9fc4a969f85587b113 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Mon, 25 Dec 2023 11:16:37 +0000
Subject: [PATCH] chore(deps): Bump tj-actions/changed-files from 40.2.2 to
41.0.1 (#28487)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Bumps [tj-actions/changed-files](https://github.com/tj-actions/changed-files) from 40.2.2 to 41.0.1.
Sourced from tj-actions/changed-files's releases. Full Changelog: https://github.com/tj-actions/changed-files/compare/v41...v41.0.1 A new [!NOTE]
This can be disabled by setting the ...
Release notes
v41.0.1
What's Changed
@tj-actions-bot
in tj-actions/changed-files#1811@renovate
in tj-actions/changed-files#1813@jackton1
in tj-actions/changed-files#1815v41.0.0
🔥 🔥 BREAKING CHANGE 🔥 🔥
safe_output
input is now available to prevent outputting unsafe filename characters (Enabled by default). This would escape characters in the filename that could be used for command injection.
safe_output
to false this comes with a recommendation to store all outputs generated in an environment variable first before using them.Example
...
- name: Get changed files
id: changed-files
uses: tj-actions/changed-files@v40
with:
safe_output: false # set to false because we are using an environment variable to store the output and avoid command injection.
- name: List all added files
env:
ADDED_FILES: ${{ steps.changed-files.outputs.added_files }}
run: |
for file in "$ADDED_FILES"; do
echo "$file was added"
done
@renovate
in tj-actions/changed-files#1801@tj-actions-bot
in tj-actions/changed-files#1800@renovate
in tj-actions/changed-files#1802@renovate
in tj-actions/changed-files#1803@renovate
in tj-actions/changed-files#1804@tj-actions-bot
in tj-actions/changed-files#1805@jackton1
in tj-actions/changed-files#1806@jackton1
in tj-actions/changed-files#1808@renovate
in tj-actions/changed-files#1809@tj-actions-bot
in tj-actions/changed-files#1810... (truncated)
Sourced from tj-actions/changed-files's changelog.
Changelog
41.0.1 - (2023-12-24)
🐛 Bug Fixes
⚙️ Miscellaneous Tasks
- deps: Update dependency eslint-plugin-prettier to v5.1.2 (7aaf10d) - (renovate[bot])
⬆️ Upgrades
- Upgraded to v41 (#1811)
Co-authored-by: jackton1 jackton1@users.noreply.github.com (cc08e17) - (tj-actions[bot])
41.0.0 - (2023-12-23)
🐛 Bug Fixes
⏪ Reverts
- Revert "chore(deps): update actions/download-artifact action to v4" (#1806)
(4f573fe) - (Tonye Jack)
🔄 Update
- Update README.md (6e79d6e) - (Tonye Jack)
- Update README.md (d13ac19) - (Tonye Jack)
- Update README.md (bb89f97) - (Tonye Jack)
- Updated README.md (#1810)
Co-authored-by: renovate[bot] (1864078) - (tj-actions[bot])
- Update README.md (#1808)
(47371c5) - (Tonye Jack)
📝 Other
- Merge pull request from GHSA-mcph-m25j-8j63
feat: add
safe_output
input enabled by defaultfix: migrate README to safe uses of interpolation
... (truncated)
716b1e1
fix: update characters escaped by safe output (#1815)7aaf10d
chore(deps): update dependency eslint-plugin-prettier to v5.1.2cc08e17
Upgraded to v41 (#1811)6e79d6e
Update README.mdd13ac19
Update README.mdbb89f97
Update README.md1864078
Updated README.md (#1810)f495a03
chore(deps): lock file maintenance47371c5
Update README.md (#1808)4f573fe
Revert "chore(deps): update actions/download-artifact action to v4" (#1806)