dependabot[bot]
d01847ad16
Bump actions/create-github-app-token from 3.1.1 to 3.2.0
...
Bumps [actions/create-github-app-token](https://github.com/actions/create-github-app-token ) from 3.1.1 to 3.2.0.
- [Release notes](https://github.com/actions/create-github-app-token/releases )
- [Changelog](https://github.com/actions/create-github-app-token/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/create-github-app-token/compare/1b10c78c7865c340bc4f6099eb2f838309f1e8c3...bcd2ba49218906704ab6c1aa796996da409d3eb1 )
---
updated-dependencies:
- dependency-name: actions/create-github-app-token
dependency-version: 3.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-01 17:56:39 +00:00
Jens Ulferts
a15d5b10eb
Merge pull request #23420 from opf/dependabot/github_actions/dev/runs-on/cache-5.0.7
...
Bump runs-on/cache from 5.0.5 to 5.0.7
2026-06-01 11:12:00 +02:00
Jens Ulferts
8eca394df1
Merge pull request #23417 from opf/dependabot/github_actions/dev/zizmorcore/zizmor-action-0.5.6
...
Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6
2026-06-01 11:10:50 +02:00
Ivan Kuchin
bbdaa41b61
Merge pull request #23402 from opf/cleanup-determining-latest-release-branches
...
Cleanup determining latest release branches
2026-05-29 13:43:13 +02:00
dependabot[bot]
5de5f3fb77
Bump ruby/setup-ruby from 1.306.0 to 1.310.0 ( #23418 )
...
Bumps [ruby/setup-ruby](https://github.com/ruby/setup-ruby ) from 1.306.0 to 1.310.0.
- [Release notes](https://github.com/ruby/setup-ruby/releases )
- [Changelog](https://github.com/ruby/setup-ruby/blob/master/release.rb )
- [Commits](https://github.com/ruby/setup-ruby/compare/c4e5b1316158f92e3d49443a9d58b31d25ac0f8f...afeafc3d1ab54a631816aba4c914a0081c12ff2f )
---
updated-dependencies:
- dependency-name: ruby/setup-ruby
dependency-version: 1.310.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-05-28 20:26:36 +02:00
dependabot[bot]
918a0ebfe1
Bump runs-on/cache from 5.0.5 to 5.0.7
...
Bumps [runs-on/cache](https://github.com/runs-on/cache ) from 5.0.5 to 5.0.7.
- [Release notes](https://github.com/runs-on/cache/releases )
- [Changelog](https://github.com/runs-on/cache/blob/v5/RELEASES.md )
- [Commits](https://github.com/runs-on/cache/compare/bd330c5a5f6cbb837823ee25864f3c71a211c2e3...88d90644011a3a9957fd141a106f5a94f9794203 )
---
updated-dependencies:
- dependency-name: runs-on/cache
dependency-version: 5.0.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-28 10:00:13 +00:00
dependabot[bot]
c5cdf285d0
Bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6
...
Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action ) from 0.5.3 to 0.5.6.
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases )
- [Commits](https://github.com/zizmorcore/zizmor-action/compare/b1d7e1fb5de872772f31590499237e7cce841e8e...5f14fd08f7cf1cb1609c1e344975f152c7ee938d )
---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
dependency-version: 0.5.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-28 09:59:08 +00:00
Ivan Kuchin
e4a3b37037
combine steps to find previous and latest release branches
2026-05-27 18:45:01 +02:00
Ivan Kuchin
f26f55559a
fetch all branches using gh
2026-05-27 18:01:38 +02:00
Alexander Brandon Coles
fb21b7d7bf
Add dependabot group for vitest
2026-05-27 15:45:20 +02:00
Alexander Brandon Coles
208c82aefd
Add dependabot group for uirouter
2026-05-27 15:45:20 +02:00
Alexander Brandon Coles
19c6ccc95c
Add dependabot group for typescript-eslint
2026-05-27 15:45:20 +02:00
Alexander Brandon Coles
d4290bc5e2
Add dependabot group for testing-library
2026-05-27 15:45:19 +02:00
Alexander Brandon Coles
53e58f8c37
Add dependabot group for mantine
2026-05-27 15:45:19 +02:00
Alexander Brandon Coles
0ad1675919
Add dependabot group for jquery
2026-05-27 15:45:19 +02:00
Alexander Brandon Coles
a644554545
Add dependabot group for hotwired
...
Excludes @hotwired/stimulus which is versioned independently from Turbo.
2026-05-27 15:45:14 +02:00
Alexander Brandon Coles
bb6652ba5d
Add dependabot group for eslint
2026-05-27 15:45:13 +02:00
Alexander Brandon Coles
a8a4dfe54d
Add dependabot groups for Angular ecosystem
...
Splits the broad `@angular*` pattern into specific groups: `@angular/*`,
`@angular-devkit/*`, and `@angular-builders/*` for core Angular, plus a
new `angular-eslint` group for `@angular-eslint/*` and `angular-eslint`.
Adds major-version ignore rules for each new pattern.
2026-05-27 15:45:02 +02:00
Ivan Kuchin
2e6a5e846f
yamllint workflow
2026-05-26 16:33:15 +02:00
Dombi Attila
300573c271
Merge pull request #23031 from opf/dependabot/github_actions/dev/dawidd6/action-send-mail-17
...
Bump dawidd6/action-send-mail from 16 to 17
2026-05-26 14:02:23 +03:00
dependabot[bot]
9f7af7608a
Bump benc-uk/workflow-dispatch from 1.3.1 to 1.3.2
...
Bumps [benc-uk/workflow-dispatch](https://github.com/benc-uk/workflow-dispatch ) from 1.3.1 to 1.3.2.
- [Release notes](https://github.com/benc-uk/workflow-dispatch/releases )
- [Commits](https://github.com/benc-uk/workflow-dispatch/compare/7a027648b88c2413826b6ddd6c76114894dc5ec4...31e2b3319479a63f0ab15bf800eff9e913504e26 )
---
updated-dependencies:
- dependency-name: benc-uk/workflow-dispatch
dependency-version: 1.3.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-25 07:21:30 +00:00
Oliver Günther
3ed10956c2
Update hocuspocus-docker.yml from release/17.4 to release/17.5
2026-05-21 06:55:14 +02:00
Oliver Günther
a720efaa4f
Update docker-scheduled.yml from release/17.4 to release/17.5
2026-05-21 06:55:13 +02:00
Oliver Günther
23dc28bde6
Fix image output after zizmor changes
2026-05-19 12:21:08 +02:00
dependabot[bot]
36e93df6eb
Bump runs-on/action from 2.1.0 to 2.1.2
...
Bumps [runs-on/action](https://github.com/runs-on/action ) from 2.1.0 to 2.1.2.
- [Release notes](https://github.com/runs-on/action/releases )
- [Commits](https://github.com/runs-on/action/compare/742bf56072eb4845a0f94b3394673e4903c90ff0...d141ef83eb66d096ce8afc767e09115a65c63b60 )
---
updated-dependencies:
- dependency-name: runs-on/action
dependency-version: 2.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-18 11:08:43 +00:00
Cyril Rohr
6ab474fae8
Improve CI families and update volume size ( #22951 )
2026-05-18 13:06:14 +02:00
Alexander Brandon Coles
8316197e96
Use npm ci in GitHub Actions workflows
...
Replaces `npm i` with `npm ci` for deterministic, lockfile-exact
installs in CI. Avoids accidental dependency drift from transitive
resolution.
2026-05-13 13:59:36 +02:00
Alexander Brandon Coles
bab5bfc738
Merge branch 'dev' into code-maintenance/66563-migrate-to-vitest-playwright-chromium
2026-05-13 13:57:13 +02:00
dependabot[bot]
9a2d874d7c
Bump dawidd6/action-send-mail from 16 to 17
...
Bumps [dawidd6/action-send-mail](https://github.com/dawidd6/action-send-mail ) from 16 to 17.
- [Release notes](https://github.com/dawidd6/action-send-mail/releases )
- [Commits](https://github.com/dawidd6/action-send-mail/compare/d38f3f7cd391cdebfe0d38efc3998b935e951c4f...42942bc2f8fba4e611b459a018967a6a7c78c68c )
---
updated-dependencies:
- dependency-name: dawidd6/action-send-mail
dependency-version: '17'
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-13 11:04:17 +00:00
Oliver Günther
30954cf766
Merge branch 'dev' into fix/github-actions-zizmor
2026-05-13 11:52:07 +02:00
Alexander Brandon Coles
109db3f53c
Merge remote-tracking branch 'opf/dev' into HEAD
...
# Conflicts:
# lib/open_project/version.rb
# modules/backlogs/config/locales/crowdin/de.yml
# modules/wikis/config/locales/crowdin/de.yml
2026-05-13 11:04:03 +02:00
Oliver Günther
b67a37868d
Only build hocuspocus in the core
2026-05-13 08:19:54 +02:00
Oliver Günther
6b6da0ca76
Merge remote-tracking branch 'origin/release/17.3' into release/17.4
2026-05-13 07:51:33 +02:00
Markus Kahl
feded1608a
add major and minor floating tags for hocuspocus docker build
2026-05-13 07:51:03 +02:00
Oliver Günther
d98bc94617
Force higher volume for builds
2026-05-13 07:34:55 +02:00
Alexander Brandon Coles
c1bbbfe9b1
[ #66563 ] Split Playwright setup steps
...
Split the CI setup into separate Playwright dependency and browser
install steps. This shows whether apt or the browser download is slow
when a matrix job stalls.
Add short step timeouts so a stalled install fails quickly instead of
holding the browser matrix open indefinitely.
https://community.openproject.org/wp/66563
2026-05-12 21:05:01 +02:00
Alexander Brandon Coles
7a594ed11f
[ #66563 ] Config Units job to use Actions reporter
...
https://community.openproject.org/wp/66563
2026-05-12 20:23:40 +02:00
Alexander Brandon Coles
94cf7d0c6d
[ #66563 ] Run Units job across browser matrix
...
Runs frontend unit tests against chromium, firefox, and webkit
in parallel. Each job installs only its own browser via
Playwright and runs `npm test -- --browsers <browser>`. Uses
`fail-fast: false` so all browsers report results.
https://community.openproject.org/wp/66563
2026-05-12 20:23:36 +02:00
dependabot[bot]
65473e3d9f
Bump actions/dependency-review-action from 4 to 4.9.0
...
Bumps [actions/dependency-review-action](https://github.com/actions/dependency-review-action ) from 4 to 4.9.0.
- [Release notes](https://github.com/actions/dependency-review-action/releases )
- [Commits](https://github.com/actions/dependency-review-action/compare/v4...v4.9.0 )
---
updated-dependencies:
- dependency-name: actions/dependency-review-action
dependency-version: 4.9.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-05-11 08:39:42 +00:00
Alexander Brandon Coles
88632e0122
[ #66563 ] Remove Karma
...
Drop the Karma config and browser test bootstrap now that the frontend
unit suite runs through Vitest.
https://community.openproject.org/wp/66563
2026-05-08 09:53:21 +02:00
Oliver Günther
e378301f3c
Add new contributors to CLA workflow
2026-05-07 08:40:55 +02:00
Oliver Günther
c8f6c18c9a
Ignore unpinned-use in docker-scheduled
2026-05-06 11:07:12 +02:00
Oliver Günther
fa9d54a3d3
Address remaining findings
2026-05-06 11:04:47 +02:00
Oliver Günther
2a0bd7f60a
Remove semver of cooldown for actions
2026-05-06 10:47:04 +02:00
Oliver Günther
7bb8250a84
Add ignore to CLA workflow
2026-05-06 10:38:47 +02:00
Oliver Günther
99e6e3fdf4
Add ignore rule
2026-05-06 10:37:54 +02:00
Oliver Günther
38ac69ca28
Remove explicit npm caching
2026-05-06 10:37:54 +02:00
Oliver Günther
febd9d0fe6
Explicity selt package-manager-cache: false
2026-05-06 10:37:54 +02:00
Oliver Günther
c147194440
Add scan workflow
2026-05-06 10:26:43 +02:00
Oliver Günther
63426f037e
Run zizmor on github actions, pinning all actions
2026-05-06 10:26:43 +02:00