Skip to content

Bump @actions/core from 1.2.4 to 3.0.1 in /sonar-scanner-begin - #354

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/sonar-scanner-begin/actions/core-3.0.1
Open

Bump @actions/core from 1.2.4 to 3.0.1 in /sonar-scanner-begin#354
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/sonar-scanner-begin/actions/core-3.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps @actions/core from 1.2.4 to 3.0.1.

Changelog

Sourced from @​actions/core's changelog.

3.0.1

  • Bump undici from 6.23.0 to 6.24.1 #2348

3.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()

2.0.3

  • Bump @actions/http-client to 3.0.2

2.0.1

  • Bump @​actions/exec from 1.1.1 to 2.0.0 #2199

2.0.0

  • Add support for Node 24 #2110
  • Bump @​actions/http-client from 2.0.1 to 3.0.0

1.11.1

  • Fix uses of crypto.randomUUID on Node 18 and earlier #1842

1.11.0

  • Add platform info utilities #1551
  • Remove dependency on uuid package #1824

1.10.1

  • Fix error message reference in oidc utils #1511

1.10.0

  • saveState and setOutput now use environment files if available #1178
  • getMultilineInput now correctly trims whitespace by default #1185

1.9.1

  • Randomize delimiter when calling core.exportVariable

1.9.0

  • Added toPosixPath, toWin32Path and toPlatformPath utilities #1102

1.8.2

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​actions/core since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/sonar-scanner-begin/actions/core-3.0.1 branch from ec5d9bd to 4aa69eb Compare June 24, 2026 13:52
AndrewEhlo added a commit that referenced this pull request Jun 24, 2026
Combines 33 CI-validated, low-risk Dependabot PRs into one commit so the
whole batch can be rolled back with a single `git revert` if needed.

Included (safe):
- @types/node -> 25.9.3 (12 actions): #259 #267 #271 #278 #282 #286 #291
  #301 #308 #315 #330 #336
- typescript -> 6.0.3 (10): #258 #261 #273 #305 #333 #341 #342 #345 #349 #358
- @actions/exec -> 3.0.0 (unused dep, 6): #277 #289 #296 #300 #313 #337
- @actions/github -> 9.1.1 (TS/ncc-bundled): #322
- @actions/exec -> 3.0.0 (TS/ncc-bundled): #352
- axios -> 1.18.0 (bundled, dist rebuilt): #260
- form-data -> 4.0.6: #256
- actions/setup-python (SHA pin): #363

Excluded: CJS actions taking ESM-only @actions/* majors (the 63 failing
rebuilds + 6 false-greens #326 #327 #328 #353 #354 #355) — handled separately.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bumps [@actions/core](https://github.com/actions/toolkit/tree/HEAD/packages/core) from 1.2.4 to 3.0.1.
- [Changelog](https://github.com/actions/toolkit/blob/main/packages/core/RELEASES.md)
- [Commits](https://github.com/actions/toolkit/commits/HEAD/packages/core)

---
updated-dependencies:
- dependency-name: "@actions/core"
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/sonar-scanner-begin/actions/core-3.0.1 branch from 4aa69eb to 781ae79 Compare June 24, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant