Sourced from actions/checkout's releases.
v7.0.1
What's Changed
- skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
Full Changelog: https://github.com/actions/checkout/compare/v7...v7.0.1
Sourced from actions/checkout's changelog.
Changelog
v7.0.1
- Skip running unsafe pr check if input is default by
@aiqiaoyin actions/checkout#2518- Trim only ascii whitespace for branch by
@aiqiaoyin actions/checkout#2521- Escape values passed to --unset by
@aiqiaoyin actions/checkout#2530- Various dependency updates
v7.0.0
- Block checking out fork PR for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Various dependency updates
v6.0.3
- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414v6.0.2
- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356v6.0.1
- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327v6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248v5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301v5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226v4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305v4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924
... (truncated)
3d3c42e
prep v7.0.1 release (#2531)2880268
escape values passed to --unset (#2530)12cd223
trim only ascii whitespace for branch (#2521)62661c4
skip running unsafe pr check if input is default (#2518)e8d4307
Bump the minor-actions-dependencies group with 2 updates (#2499)631c942
eslint 9 (#2474)4f1f4ae
Bump actions/upload-artifact from 4 to 7 (#2476)ba09753
Bump actions/checkout from 6 to 7 (#2488)b9e0990
Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398
Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Sourced from pypa/gh-action-pypi-publish's releases.
v1.14.2
🛠️ Urgh… Another release!? Again? Explain yourself!
Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.
[!tip] So what most people will find useful is
@takluyver💰's update of Twine to v7 that we use internally (#416). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.🧐 Tell me why..
TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like aio-libs/aiohttp#13226 around July 23. On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.
I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.
Over the course of investigation,
@facutuesca💰 found and fixed a related underlying cache invalidation bug in sigstore/sigstore-python#1838, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: https://publishing-five-minute-timeout.tiiny.site.
🫶 New Contributors
@davidbrochartmade their first contribution in #415@takluyvermade their first contribution in #416🪞 Full Diff: https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2
🧔♂️ Release Manager:
@webknjaz🇺🇦🙏 Special Thanks to
@davidbrochart💰 and@Dreamsorcerer💰 for turning my attention (in #415 and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware.@bdraco💰 came up with a DIY sharding workaround for aiohttp that served as a demo for other projects.@miketheman💰 confirmed the Warehouse-side details. Also,@jku💰 and@woodruffw💰 helped work through, review and release the Sigstore ecosystem upstream libs.💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and [on GitHub][release discussion].
[![GH Sponsors badge]][GH Sponsors URL]
... (truncated)
dc37677
Merge pull request #417
from trail-of-forks/ft/bump-deps8b2f234
Bump pypi-attestations and sigstore78b72db
Merge pull request #416
from takluyver/twine-v792f4d2a
Update twine to v7ba38be9
Merge pull request #408
from adisivaprasad/bump-setup-python-v6a6c5088
Bump actions/setup-python from v5.6.0 to v6.2.0Sourced from aws-actions/configure-aws-credentials's releases.
v6.2.3
6.2.3 (2026-07-22)
Bug Fixes
- attach git credentials before Tag Major Version push (#1877) (9ae780b)
- PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)
v6.2.2
6.2.2 (2026-07-07)
Miscellaneous Chores
- release 6.2.2 (d01d678)
Sourced from aws-actions/configure-aws-credentials's changelog.
Changelog
All notable changes to this project will be documented in this file. See standard-version for commit guidelines.
6.2.3 (2026-07-22)
Bug Fixes
- attach git credentials before Tag Major Version push (#1877) (9ae780b)
- PackedPolicyTooLarge detection in STS tags (#1899) (fa8d6a5)
6.2.2 (2026-07-07)
Miscellaneous Chores
- release 6.2.2 (d01d678)
6.2.1 (2026-06-26)
Bug Fixes
6.2.0 (2026-06-01)
Features
- add additional session tags by default (#1775) (e0ba768)
- add more retry logic and better logging (#1764) (540d0c1)
- add regex validation to role-session-name (#1765) (e354499)
- Allow custom session tags to be passed when assuming a role (#1759) (61f50f6)
- expose run id in STS client user-agent (#1774) (29d1be3)
- support custom STS endpoints (#1762) (8d52d05)
Bug Fixes
- skip credential check on output-env-credentials: false (#1778) (58e7c47)
- assumeRole failing from session tag size too large (#1808) (d6f5dc3)
6.1.3 (2026-05-28)
Bug Fixes
- fix: allow kubelet token symlink in #1805
6.1.2 (2026-05-26)
... (truncated)
e6de054
chore(main): release 6.2.3 (#1878)ab3b2ba
chore: Update distfa8d6a5
fix: PackedPolicyTooLarge detection in STS tags (#1899)42e118a
chore(deps-dev): bump markdownlint-cli from 0.49.0 to 0.49.1 (#1896)d86ddfc
chore: Update dist874aaac
chore(deps): bump @aws-sdk/client-sts from 3.1086.0 to
3.1091.0 (#1892)d4341b6
chore: Update distfe51823
chore(deps-dev): bump @aws-sdk/credential-provider-env (#1894)a8be382
chore(deps-dev): bump @biomejs/biome from 2.5.3 to 2.5.4
(#1893)e000376
chore: Update dist