Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: pydata/pydata-sphinx-theme
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v0.19.0
Choose a base ref
...
head repository: pydata/pydata-sphinx-theme
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v0.20.0
Choose a head ref
  • 18 commits
  • 29 files changed
  • 7 contributors

Commits on Jun 15, 2026

  1. Drop Sphinx <= 8.1, Python <= 3.10 (#2412)

    Sphinx 8.0 and 8.1 are from 2024,
    https://www.sphinx-doc.org/en/master/changes/index.html
    
    Keeping 8.2 for now conservatively even though it is more than 1 year
    old
    
    EDIT: dropping Sphinx 8.1 means dropping Python 3.10, because [Sphinx
    8.2 dropped
    3.10](https://www.sphinx-doc.org/en/master/changes/8.2.html#dependencies)...
    should we wait for Python 3.10 to reach end of life later this year to
    merge this?
    
    WARNING: follow-up needed after merging: bumping all internal pins,
    #2383 - or Github
    actions will fail during next release.
    Yann-P authored Jun 15, 2026
    Configuration menu
    Copy the full SHA
    562617b View commit details
    Browse the repository at this point in the history
  2. Bump internal actions ; Bump pyupgrade options to 3.7+ -> 3.11+ (#2416)

    8196a14 is follow-up of
    #2412 (see also
    #2383)
    
    bumping pyupgrade options in .pre-commit-config.yaml that I missed in
    the above PR, automatic code changes ensued
    Yann-P authored Jun 15, 2026
    Configuration menu
    Copy the full SHA
    9530b79 View commit details
    Browse the repository at this point in the history
  3. Update deps (was incorrect) (#2417)

    AFAICT, jinja2 and requests are actually used,
    typing-extensions only in tests.
    Carreau authored Jun 15, 2026
    Configuration menu
    Copy the full SHA
    fb5cf9f View commit details
    Browse the repository at this point in the history

Commits on Jun 19, 2026

  1. Bump ws from 7.5.10 to 7.5.11 (#2419)

    Bumps [ws](https://github.com/websockets/ws) from 7.5.10 to 7.5.11.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/websockets/ws/releases">ws's
    releases</a>.</em></p>
    <blockquote>
    <h2>7.5.11</h2>
    <h1>Bug fixes</h1>
    <ul>
    <li>Backported 2b2abd45 to the 7.x release line (e14c4586).</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8"><code>fd36cd8</code></a>
    [dist] 7.5.11</li>
    <li><a
    href="https://github.com/websockets/ws/commit/e14c45861deca0cef60dec0f9109b694abebdf52"><code>e14c458</code></a>
    [security] Limit retained message parts</li>
    <li>See full diff in <a
    href="https://github.com/websockets/ws/compare/7.5.10...7.5.11">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ws&package-manager=npm_and_yarn&previous-version=7.5.10&new-version=7.5.11)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    b8acd7f View commit details
    Browse the repository at this point in the history
  2. Bump js-yaml from 4.1.1 to 4.2.0 (#2420)

    Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.2.0.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md">js-yaml's
    changelog</a>.</em></p>
    <blockquote>
    <h2>[4.2.0] - 2026-06-01</h2>
    <h3>Added</h3>
    <ul>
    <li>Added <code>docs/safety.md</code> with notes about processing
    untrusted YAML.</li>
    <li>Added <code>maxDepth</code> (100) loader option. Not a problem, but
    gives a better
    exception instead of RangeError on stack overflow.</li>
    <li>Added <code>maxMergeSeqLength</code> (20) loader option. Not a
    problem after <code>merge</code> fix,
    but an additional restriction for safety.</li>
    <li>Added sourcemaps to <code>dist/</code> builds.</li>
    </ul>
    <h3>Changed</h3>
    <ul>
    <li>Stop resolving numbers with underscores as numeric scalars, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/627">#627</a>.</li>
    <li>Switched dev toolchains to Vite / neostandard.</li>
    <li>Updated demo.</li>
    <li>Reorganized tests.</li>
    <li><code>dist/</code> files are no longer kept in the repository.</li>
    </ul>
    <h3>Fixed</h3>
    <ul>
    <li>Fix parsing of properties on the first implicit block mapping key,
    <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/62">#62</a>.</li>
    <li>Fix trailing whitespace handling when folding flow scalar lines, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/307">#307</a>.</li>
    <li>Reject top-level block scalars without content indentation, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/280">#280</a>.</li>
    <li>Ensure numbers survive round-trip, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/737">#737</a>.</li>
    <li>Fix test coverage for issue <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/221">#221</a>.</li>
    <li>Fix flow scalar trailing whitespace folding, <a
    href="https://redirect.github.com/nodeca/js-yaml/issues/307">#307</a>.</li>
    <li>Fix digits in YAML named tag handles.</li>
    </ul>
    <h3>Security</h3>
    <ul>
    <li>Fix potential DoS via quadratic complexity in merge - deduplicate
    repeated
    elements (makes sense for malformed files &gt; 10K).</li>
    </ul>
    <h2>[3.14.2] - 2025-11-15</h2>
    <h3>Security</h3>
    <ul>
    <li>Backported v4.1.1 fix to v3</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li>See full diff in <a
    href="https://github.com/nodeca/js-yaml/commits">compare view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=js-yaml&package-manager=npm_and_yarn&previous-version=4.1.1&new-version=4.2.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the
    [Security Alerts
    page](https://github.com/pydata/pydata-sphinx-theme/network/alerts).
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    025b517 View commit details
    Browse the repository at this point in the history
  3. Fix content of sidebar shifting vertically on page load (#2415)

    #2413
    
    Due to the svg-inline--fa class, the fontawesome script messes around
    with the sizing when the js executes at page load, causing vertical
    shifts in the layout below it for a split second. This is annoying when
    navigating between doc pages.
    
    Out of scope, but I think we should move away from the fontawesome js
    file, which is also very large (1.5MB) in favor of CSS+WOFF
    (#2115,
    #2379, and probably
    #2408)
    
    Before
    
    
    https://github.com/user-attachments/assets/9429611c-c9c4-47e6-9133-f5e8da1294ce
    
    
    After
    
    
    https://github.com/user-attachments/assets/15b2b35b-0394-4663-955b-9dc232edad18
    
    Notice that some other elements are jumping around at load time, this is
    the exact same problem and would be resolved by removing FA JS.
    Yann-P authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    275e50f View commit details
    Browse the repository at this point in the history
  4. Fix incorrect tox env name in prerelease docs build step (#2421)

    Closes #2418
    
    ## Summary
    
    The "Build PST docs and check for warnings 📖" step in `prerelease.yml`
    invoked `tox run -e docs-pyXXX-docs`, but no tox environment with that
    name is defined in `tox.ini`. tox silently composed an empty environment
    from the factor pattern and exited successfully without running
    `sphinx-build`, so the scheduled prerelease docs check has been passing
    while doing nothing.
    
    This PR drops the stray `docs-` prefix so the step calls the real
    `pyXXX-docs` environment defined at `tox.ini:111`
    (`[testenv:py3{11,14}{,-sphinx82}-docs]`). The accompanying example
    comment was updated to match.
    
    ## Verification
    
    I temporarily bypassed the `repository_owner == 'pydata'` guard on my
    fork and manually triggered the workflow against both the broken and
    fixed code.
    
    **Before fix (`docs-py311-docs` — malformed):** the step finishes in
    ~22s. tox sets up a venv from the `py311` factor and installs base
    packages, then exits with `OK` — `sphinx-build` is never invoked and no
    docs are rendered.
    
    https://github.com/yyccPhil/pydata-sphinx-theme/actions/runs/27667788899
    
    **After fix (`py311-docs` — real env):** the step actually runs
    `sphinx-build -b html docs/ docs/_build/html -nTv -w warnings.txt`,
    launches Sphinx 9.0.4, and renders the project's documentation (AutoAPI
    reading files, etc.). Total step time is in the minutes range, as
    expected for a real docs build.
    
    https://github.com/yyccPhil/pydata-sphinx-theme/actions/runs/27667654927
    
    Co-authored-by: Yann Pellegrini <3519082+Yann-P@users.noreply.github.com>
    yyccPhil and Yann-P authored Jun 19, 2026
    Configuration menu
    Copy the full SHA
    620d9eb View commit details
    Browse the repository at this point in the history

Commits on Jun 22, 2026

  1. Bump actions/checkout from 6.0.3 to 7.0.0 (#2423)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3
    to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0"><code>9c091bb</code></a>
    update error wording (<a
    href="https://redirect.github.com/actions/checkout/issues/2467">#2467</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/1044a6dea927916f2c38ba5aeffbc0a847b1221a"><code>1044a6d</code></a>
    getting ready for checkout v7 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2464">#2464</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f0282184c7ce73ab54c7e4ab5a617122602e575f"><code>f028218</code></a>
    Bump the minor-npm-dependencies group across 1 directory with 3 updates
    (<a
    href="https://redirect.github.com/actions/checkout/issues/2462">#2462</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/d914b262ffc244530a203ab40decab34c3abf34d"><code>d914b26</code></a>
    upgrade module to esm and update dependencies (<a
    href="https://redirect.github.com/actions/checkout/issues/2463">#2463</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/537c7ef99cef6e5ddb5e7ff5d16d14510503801d"><code>537c7ef</code></a>
    Bump <code>@​actions/core</code> and <code>@​actions/tool-cache</code>
    and Remove uuid (<a
    href="https://redirect.github.com/actions/checkout/issues/2459">#2459</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/130a169078a413d3a5246a393625e8e742f387f6"><code>130a169</code></a>
    Bump js-yaml from 4.1.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2461">#2461</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/7d09575332117a40b46e5e020664df234cd416f3"><code>7d09575</code></a>
    Bump flatted from 3.3.1 to 3.4.2 (<a
    href="https://redirect.github.com/actions/checkout/issues/2460">#2460</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/0f9f3aa320cb53abeb534aeb54048075d9697a0e"><code>0f9f3aa</code></a>
    Bump actions/publish-immutable-action (<a
    href="https://redirect.github.com/actions/checkout/issues/2458">#2458</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/f9e715a95fcd1f9253f77dd28f11e88d2d6460c7"><code>f9e715a</code></a>
    block checking out fork pr for pull_request_target and workflow_run (<a
    href="https://redirect.github.com/actions/checkout/issues/2454">#2454</a>)</li>
    <li>See full diff in <a
    href="https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/checkout&package-manager=github_actions&previous-version=6.0.3&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 22, 2026
    Configuration menu
    Copy the full SHA
    fc1a061 View commit details
    Browse the repository at this point in the history

Commits on Jun 24, 2026

  1. Bump internal actions (#2426)

    Yann-P authored Jun 24, 2026
    Configuration menu
    Copy the full SHA
    d001992 View commit details
    Browse the repository at this point in the history
  2. fix: stabilize Read the Docs Ubuntu image (#2429)

    ## Summary
    - Pin the Read the Docs build image to `ubuntu-24.04` instead of the
    moving `ubuntu-lts-latest` alias.
    - Replace `libasound2` with the concrete Ubuntu package `libasound2t64`
    so Chromium audio dependencies remain installable.
    
    ## Testing
    - [x] `python3 -u /tmp/verify_rtd_yaml.py`
    - [x] `python3 -u /tmp/fetch_rtd_docs.py`
    - [x] `git diff --check`
    
    Closes #2428
    
    ---------
    
    Co-authored-by: sanmaxdev <sanmaxdev@users.noreply.github.com>
    sanmaxdev and sanmaxdev authored Jun 24, 2026
    Configuration menu
    Copy the full SHA
    6dde1c3 View commit details
    Browse the repository at this point in the history

Commits on Jun 25, 2026

  1. Unpin internal actions (#2427)

    Closes #2383.
    
    This was introduced on purpose by
    
    4a1e789
    
    It makes sense to pin external actions for security but it has been a
    recurring footgun when it comes to internal actions:
    
    - every change in docs or CI has to be followed-up by a PR to re-pin the
    actions
    - if this step is forgotten, and it has happened two times already, it
    only fails during the release.
    - dependabot is inconsistent, opens 1 PR per pin and does not open all
    necessary PRs
    Yann-P authored Jun 25, 2026
    Configuration menu
    Copy the full SHA
    7d2dc8c View commit details
    Browse the repository at this point in the history

Commits on Jun 28, 2026

  1. Bump actions/setup-python from 6.2.0 to 6.3.0 (#2431)

    Bumps [actions/setup-python](https://github.com/actions/setup-python)
    from 6.2.0 to 6.3.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/setup-python/releases">actions/setup-python's
    releases</a>.</em></p>
    <blockquote>
    <h2>v6.3.0</h2>
    <h2>What's Changed</h2>
    <h3>Enhancement</h3>
    <ul>
    <li>Add RHEL support and include Linux distro in cache keys by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1323">actions/setup-python#1323</a></li>
    <li>Fix pip cache error handling on Windows by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1040">actions/setup-python#1040</a></li>
    </ul>
    <h3>Dependency update</h3>
    <ul>
    <li>Upgrade minimatch from 3.1.2 to 3.1.5 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1281">actions/setup-python#1281</a></li>
    <li>Upgrade actions dependencies by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a>
    with <a href="https://github.com/Copilot"><code>@​Copilot</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-python/pull/1303">actions/setup-python#1303</a></li>
    <li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
    denied by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1324">actions/setup-python#1324</a></li>
    <li>Upgrade dependency versions and test workflow configuration by <a
    href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1322">actions/setup-python#1322</a></li>
    </ul>
    <h3>Documentation</h3>
    <ul>
    <li>Update advanced-usage.md by <a
    href="https://github.com/Dunky-Z"><code>@​Dunky-Z</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/811">actions/setup-python#811</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a>
    with <a href="https://github.com/Copilot"><code>@​Copilot</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1303">actions/setup-python#1303</a></li>
    <li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1324">actions/setup-python#1324</a></li>
    <li><a href="https://github.com/Dunky-Z"><code>@​Dunky-Z</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/811">actions/setup-python#811</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-python/compare/v6...v6.3.0">https://github.com/actions/setup-python/compare/v6...v6.3.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/setup-python/commit/ece7cb06caefa5fff74198d8649806c4678c61a1"><code>ece7cb0</code></a>
    Fix pip cache error handling on Windows. (<a
    href="https://redirect.github.com/actions/setup-python/issues/1040">#1040</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/1d18d7af5f767c1259ede05a0a5bcc30f3dcf1cf"><code>1d18d7a</code></a>
    Update advanced-usage.md (<a
    href="https://redirect.github.com/actions/setup-python/issues/811">#811</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/d2b357a6a3a3687dd6781a416c0d24fcfd68660e"><code>d2b357a</code></a>
    Update dependency versions and test workflow configuration (<a
    href="https://redirect.github.com/actions/setup-python/issues/1322">#1322</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/8f639b1e75c1048640734b2bb46e22cecf136982"><code>8f639b1</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/setup-python/issues/1324">#1324</a>
    from jasongin/update-actions-cache-5.1.0</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/6731c2ba87f530c26324d128c8fdd53499a4d4b0"><code>6731c2b</code></a>
    Resolve high-severity audit issues</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/0cb1a84326b90186fcd211036c65b42819794c87"><code>0cb1a84</code></a>
    Add RHEL support and include Linux distro in cache keys (<a
    href="https://redirect.github.com/actions/setup-python/issues/1323">#1323</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/dc6eab6194394e0119523369788b507096f923e2"><code>dc6eab6</code></a>
    Update dist</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/6f4b74bfa2f520a380a620de3615c0dac427f4d3"><code>6f4b74b</code></a>
    Strict equality</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/fa8bde1a9cc6347d06948d66bcd68c598b79eaea"><code>fa8bde1</code></a>
    Bump <code>@​actions/cache</code> to 5.1.0, log cache write denied</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/c8813ba1bc76ebf779b911ad8ffccbf2e449cb48"><code>c8813ba</code></a>
    Upgrade <a href="https://github.com/actions"><code>@​actions</code></a>
    dependencies and update licenses (<a
    href="https://redirect.github.com/actions/setup-python/issues/1303">#1303</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...ece7cb06caefa5fff74198d8649806c4678c61a1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-python&package-manager=github_actions&previous-version=6.2.0&new-version=6.3.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 28, 2026
    Configuration menu
    Copy the full SHA
    6f2c50c View commit details
    Browse the repository at this point in the history
  2. Bump actions/cache from 5.0.5 to 6.1.0 (#2433)

    Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to
    6.1.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/cache/releases">actions/cache's
    releases</a>.</em></p>
    <blockquote>
    <h2>v6.1.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Bump <code>@​actions/cache</code> to v6.1.0 - handle read-only cache
    access by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/cache/pull/1768">actions/cache#1768</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/cache/compare/v6...v6.1.0">https://github.com/actions/cache/compare/v6...v6.1.0</a></p>
    <h2>v6.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update packages, migrate to ESM by <a
    href="https://github.com/Samirat"><code>@​Samirat</code></a> in <a
    href="https://redirect.github.com/actions/cache/pull/1760">actions/cache#1760</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/cache/compare/v5...v6.0.0">https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
    <h2>v5.1.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Bump <code>@​actions/cache</code> to v5.1.0 - handle read-only cache
    access by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/cache/pull/1775">actions/cache#1775</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/cache/compare/v5...v5.1.0">https://github.com/actions/cache/compare/v5...v5.1.0</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/cache/blob/main/RELEASES.md">actions/cache's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Releases</h1>
    <h2>How to prepare a release</h2>
    <blockquote>
    <p>[!NOTE]
    Relevant for maintainers with write access only.</p>
    </blockquote>
    <ol>
    <li>Switch to a new branch from <code>main</code>.</li>
    <li>Run <code>npm test</code> to ensure all tests are passing.</li>
    <li>Update the version in <a
    href="https://github.com/actions/cache/blob/main/package.json"><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
    <li>Run <code>npm run build</code> to update the compiled files.</li>
    <li>Update this <a
    href="https://github.com/actions/cache/blob/main/RELEASES.md"><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
    with the new version and changes in the <code>## Changelog</code>
    section.</li>
    <li>Run <code>licensed cache</code> to update the license report.</li>
    <li>Run <code>licensed status</code> and resolve any warnings by
    updating the <a
    href="https://github.com/actions/cache/blob/main/.licensed.yml"><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
    file with the exceptions.</li>
    <li>Commit your changes and push your branch upstream.</li>
    <li>Open a pull request against <code>main</code> and get it reviewed
    and merged.</li>
    <li>Draft a new release <a
    href="https://github.com/actions/cache/releases">https://github.com/actions/cache/releases</a>
    use the same version number used in <code>package.json</code>
    <ol>
    <li>Create a new tag with the version number.</li>
    <li>Auto generate release notes and update them to match the changes you
    made in <code>RELEASES.md</code>.</li>
    <li>Toggle the set as the latest release option.</li>
    <li>Publish the release.</li>
    </ol>
    </li>
    <li>Navigate to <a
    href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml">https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
    <ol>
    <li>There should be a workflow run queued with the same version
    number.</li>
    <li>Approve the run to publish the new version and update the major tags
    for this action.</li>
    </ol>
    </li>
    </ol>
    <h2>Changelog</h2>
    <h3>6.1.0</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
    href="https://redirect.github.com/actions/toolkit/pull/2435">actions/toolkit#2435
    Handle cache write error due to read-only token</a></li>
    <li>Switch redundant &quot;Cache save failed&quot; warning to debug log
    in save-only</li>
    </ul>
    <h3>6.0.0</h3>
    <ul>
    <li>Updated <code>@actions/cache</code> to ^6.0.1,
    <code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
    ^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
    <li>Migrated to ESM module system</li>
    <li>Upgraded Jest to v30 and test infrastructure to be ESM
    compatible</li>
    </ul>
    <h3>5.0.4</h3>
    <ul>
    <li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
    patterns)</li>
    <li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
    protection, header validation fixes)</li>
    <li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
    </ul>
    <h3>5.0.3</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
    href="https://github.com/actions/cache/security/dependabot/33">https://github.com/actions/cache/security/dependabot/33</a>)</li>
    <li>Bump <code>@actions/core</code> to v2.0.3</li>
    </ul>
    <h3>5.0.2</h3>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/cache/commit/55cc8345863c7cc4c66a329aec7e433d2d1c52a9"><code>55cc834</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/cache/issues/1768">#1768</a>
    from jasongin/readonly-cache</li>
    <li><a
    href="https://github.com/actions/cache/commit/d8cd72f230726cdf4457ebb61ec1b593a8d12337"><code>d8cd72f</code></a>
    Bump <code>@​actions/cache</code> to v6.1.0 - handle cache write error
    due to RO token</li>
    <li><a
    href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8"><code>2c8a9bd</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/cache/issues/1760">#1760</a>
    from actions/samirat/esm_migration_and_package_update</li>
    <li><a
    href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023"><code>e9b91fd</code></a>
    Prettier fixes</li>
    <li><a
    href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb"><code>e4884b8</code></a>
    Rebuild dist</li>
    <li><a
    href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f"><code>10baf01</code></a>
    Fixed licenses</li>
    <li><a
    href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37"><code>e39b386</code></a>
    Fix test mock return order</li>
    <li><a
    href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06"><code>b692820</code></a>
    PR feedback</li>
    <li><a
    href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1"><code>6074912</code></a>
    Rebuild dist bundles as ESM to match type:module</li>
    <li><a
    href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e"><code>5a912e8</code></a>
    Fix lint and jest issues</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/cache/compare/27d5ce7f107fe9357f9df03efb73ab90386fccae...55cc8345863c7cc4c66a329aec7e433d2d1c52a9">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/cache&package-manager=github_actions&previous-version=5.0.5&new-version=6.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 28, 2026
    Configuration menu
    Copy the full SHA
    6ac6322 View commit details
    Browse the repository at this point in the history
  3. Bump py-cov-action/python-coverage-comment-action from 3.41 to 4.1 (#…

    …2432)
    
    Bumps
    [py-cov-action/python-coverage-comment-action](https://github.com/py-cov-action/python-coverage-comment-action)
    from 3.41 to 4.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/py-cov-action/python-coverage-comment-action/releases">py-cov-action/python-coverage-comment-action's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.1</h2>
    <!-- raw HTML omitted -->
    <h2>What's Changed</h2>
    <p>(Should have been 4.0, but I borked the tag)</p>
    <h2>Breaking changes &amp; features</h2>
    <p>In <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/issues/698">#698</a>:
    <a href="https://docs.zizmor.sh/">Zizmor</a> compatibility means we
    don't commit using checkout's persisted credentials, and use the
    <code>GITHUB_TOKEN</code> to commit instead. Also, it's now officially
    recommended to pin this (and all other) actions in your workflows using
    a commit hash and not a tag. See <a
    href="https://github.com/suzuki-shunsuke/pinact">Pinact</a>. For the
    same reason, this action now uses <strong>immutable releases</strong> so
    you can't use <code>@v4</code> anymore in your workflows.
    In <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/issues/621">#621</a>
    and 718: If you want control over what exactly the action does (is it a
    PR (<code>process_pr</code>) or the main branch
    (<code>save_coverage_data_files</code>) or should it just create the PR
    comment(<code>post_comment</code>)), you can now specify
    <code>ACTIVITY</code>. The default heuristics should work for 99% of
    cases though. As part of solving that, we also discovered that
    <code>MAX_FILES_IN_COMMENT</code> has actually never worked, and we
    fixed it.</p>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/py-cov-action/python-coverage-comment-action/compare/v3...v4.1">https://github.com/py-cov-action/python-coverage-comment-action/compare/v3...v4.1</a></p>
    <!-- raw HTML omitted -->
    <h2>What's Changed</h2>
    <ul>
    <li>Add zizmor by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/698">py-cov-action/python-coverage-comment-action#698</a></li>
    <li>Improve error handling by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/695">py-cov-action/python-coverage-comment-action#695</a></li>
    <li>Switch pre-commit to prek and autofix by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/712">py-cov-action/python-coverage-comment-action#712</a></li>
    <li>Simplify renovate config by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/715">py-cov-action/python-coverage-comment-action#715</a></li>
    <li>Add pytest-subprocess, pytest-httpx, remove pytest-mock by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/716">py-cov-action/python-coverage-comment-action#716</a></li>
    <li>Add support for custom event dispatching by <a
    href="https://github.com/dgolombek"><code>@​dgolombek</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/621">py-cov-action/python-coverage-comment-action#621</a></li>
    <li>Advocate for pinning other actions in readme by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/717">py-cov-action/python-coverage-comment-action#717</a></li>
    <li>Add activity in action by <a
    href="https://github.com/ewjoachim"><code>@​ewjoachim</code></a> in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/718">py-cov-action/python-coverage-comment-action#718</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/dgolombek"><code>@​dgolombek</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/pull/621">py-cov-action/python-coverage-comment-action#621</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/py-cov-action/python-coverage-comment-action/compare/v3...v4.1">https://github.com/py-cov-action/python-coverage-comment-action/compare/v3...v4.1</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/5d8df5979747514c914e1c5a12335a7cf9a2745f"><code>5d8df59</code></a>
    Merge pull request <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/issues/718">#718</a>
    from py-cov-action/activities-input</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/9be84c44d8a3b156f60eee3b6c9af0b071fecf79"><code>9be84c4</code></a>
    Don't pass empty values, use defaults</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/b95bc7923d8098365f99a71fa7f1d7d55bf7441a"><code>b95bc79</code></a>
    Handle no-activity</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/edcd720ab98da8240c5b516d00b0efbceb688bf5"><code>edcd720</code></a>
    Add 2 missing params</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/b1edcf996436c1f0b9c38f43ba885657fcf95019"><code>b1edcf9</code></a>
    Add activity in action</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/239bb59e081ed93efa6487a9d26631e66b15013f"><code>239bb59</code></a>
    Merge pull request <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/issues/717">#717</a>
    from py-cov-action/immutability</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/9ebc4369677f1532e29814a2f006d884c350ae5c"><code>9ebc436</code></a>
    Document immutability</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/869b6c3b8b12aa4a9faada59265516ea57621c91"><code>869b6c3</code></a>
    Advocate for pinning other actions in readme</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/3742c86b2a66feb9df9a597afcc5eda21cfbc734"><code>3742c86</code></a>
    Merge pull request <a
    href="https://redirect.github.com/py-cov-action/python-coverage-comment-action/issues/621">#621</a>
    from dgolombek/custom_event_dispatching</li>
    <li><a
    href="https://github.com/py-cov-action/python-coverage-comment-action/commit/5589483665ff67f2a218a21db96c45f7414b0778"><code>5589483</code></a>
    Add missing test</li>
    <li>Additional commits viewable in <a
    href="https://github.com/py-cov-action/python-coverage-comment-action/compare/63f52f4fbbffada6e8dee8ec432de7e01df9ba79...5d8df5979747514c914e1c5a12335a7cf9a2745f">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=py-cov-action/python-coverage-comment-action&package-manager=github_actions&previous-version=3.41&new-version=4.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Jun 28, 2026
    Configuration menu
    Copy the full SHA
    fd586dc View commit details
    Browse the repository at this point in the history

Commits on Jul 2, 2026

  1. Fix broken link in our example gallery and replace it with another one (

    #2430)
    
    Closes #2405
    
    Removed decentralchain (down for a week now, i.e.
    https://github.com/pydata/pydata-sphinx-theme/actions/runs/28152924774/job/83374582183)
    and add napari which is a long-time user.
    Yann-P authored Jul 2, 2026
    Configuration menu
    Copy the full SHA
    266c201 View commit details
    Browse the repository at this point in the history

Commits on Jul 6, 2026

  1. [pre-commit.ci] pre-commit autoupdate hooks (#2435)

    <!--pre-commit.ci start-->
    updates:
    - [github.com/astral-sh/ruff-pre-commit: v0.15.15 →
    v0.15.20](astral-sh/ruff-pre-commit@v0.15.15...v0.15.20)
    - [github.com/Riverside-Healthcare/djLint: v1.36.4 →
    v1.40.3](djlint/djLint@v1.36.4...v1.40.3)
    <!--pre-commit.ci end-->
    
    Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
    pre-commit-ci[bot] authored Jul 6, 2026
    Configuration menu
    Copy the full SHA
    db2d3ab View commit details
    Browse the repository at this point in the history

Commits on Jul 8, 2026

  1. Configuration menu
    Copy the full SHA
    53488b7 View commit details
    Browse the repository at this point in the history

Commits on Jul 9, 2026

  1. Bump 0.19.0 -> 0.20.0 (#2437)

    Yann-P authored Jul 9, 2026
    Configuration menu
    Copy the full SHA
    3cffc43 View commit details
    Browse the repository at this point in the history
Loading