| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-08-10 | 4.9 kB | |
| v0.391.0 source code.tar.gz | 2026-08-10 | 25.4 MB | |
| v0.391.0 source code.zip | 2026-08-10 | 30.1 MB | |
| Totals: 3 Items | 55.5 MB | 2 | |
What's Changed
- Add typed requirement metadata readers by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15740
- Type common requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15741
- gracefully handle exceptions generated during package detail fetch by @brettfo in https://github.com/dependabot/dependabot-core/pull/15762
- Bump the dev-dependencies group across 2 directories with 7 updates by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15563
- Upgrade uv to 0.11.31 by @ABruihler in https://github.com/dependabot/dependabot-core/pull/15424
- Bump ip-address from 10.2.0 to 10.4.0 in /bun/helpers by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15768
- Bump brace-expansion from 1.1.13 to 1.1.18 in /npm_and_yarn/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15769
- Bump brace-expansion from 1.1.11 to 1.1.18 in /bun/helpers/test/npm6/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15765
- Bump brace-expansion from 1.1.16 to 1.1.18 in /npm_and_yarn/helpers/test/yarn/fixtures/conflicting-dependency-parser/deeply-nested by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15743
- Bump ip-address from 10.2.0 to 10.4.0 in /npm_and_yarn/helpers by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15767
- Bump brace-expansion in /npm_and_yarn/helpers by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15763
- Keep GitHub Actions ref precision when cooldown filters out the latest tag by @v-robaiken in https://github.com/dependabot/dependabot-core/pull/15760
- Gradle: fall back to the running JVM when a Java toolchain is unavailable by @saefty in https://github.com/dependabot/dependabot-core/pull/15722
- Bump the all-actions group across 1 directory with 22 updates by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15688
- only call package restore targets on transitive projects by @brettfo in https://github.com/dependabot/dependabot-core/pull/15717
- fix(uv): use env var auth for all matching pyproject.toml indexes, not just explicit ones by @benjaminaltieri in https://github.com/dependabot/dependabot-core/pull/14382
- uv: regression test for versionless back-references not producing false-positive alerts (#15259) by @kbukum1 in https://github.com/dependabot/dependabot-core/pull/15778
- Type shared container requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15780
- Type Docker requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15781
- Type Helm requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15782
- Type shared JVM requirement readers by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15794
- Bump the dev-dependencies group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15748
- Type Maven requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15795
- Fix Maven fetcher treating .xml directories as pom files by @v-HaripriyaC in https://github.com/dependabot/dependabot-core/pull/15787
- Add dependency group subgroup naming helpers by @thavaahariharangit in https://github.com/dependabot/dependabot-core/pull/15826
- Type Gradle requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15796
- Fix Corepack signature verification against replaces-base private registries (#15567) by @opswithranjan in https://github.com/dependabot/dependabot-core/pull/15568
- Don't omit the
Release notessection if the release name includes more periods than the release version by @jeffwidman in https://github.com/dependabot/dependabot-core/pull/15801 - Type SBT requirement access by @JamieMagee in https://github.com/dependabot/dependabot-core/pull/15797
- Bump brace-expansion in /bun/helpers by @dependabot[bot] in https://github.com/dependabot/dependabot-core/pull/15788
- v0.391.0 by @dependabot-core-action-automation[bot] in https://github.com/dependabot/dependabot-core/pull/15835
New Contributors
- @ABruihler made their first contribution in https://github.com/dependabot/dependabot-core/pull/15424
- @saefty made their first contribution in https://github.com/dependabot/dependabot-core/pull/15722
- @benjaminaltieri made their first contribution in https://github.com/dependabot/dependabot-core/pull/14382
- @opswithranjan made their first contribution in https://github.com/dependabot/dependabot-core/pull/15568
Full Changelog: https://github.com/dependabot/dependabot-core/compare/v0.390.0...v0.391.0