Skip to content

chore(deps): bump NexusPHP/carson in / - #10583

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/github_actions-9579e648a9
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/github_actions-9579e648a9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps NexusPHP/carson in / from 1.6.0 to 1.7.0.

Updates NexusPHP/carson from 1.6.0 to 1.7.0

Release notes

Sourced from NexusPHP/carson's releases.

v1.7.0

What's Changed

Added

  • no-response-closer gains unlabel_on_response: when the item's author comments, pushes to the pull request, or replies in a review thread, the rule's label is removed, so an answered item is no longer closed for lack of a response. Off by default, set per rule or at the top level. Needs auto-labeler enabled.
  • triage-labeler gains sweep: when enabled, every open pull request is reconciled on the scheduled run, so a label missed by a cancelled run or by a review on a fork pull request is corrected within a day. It writes only where the label is wrong. Off by default.
  • An Actions section in SUBSCRIBERS.md lists each cross-subscriber action, its owner, who requests it, and which subscribers label directly.

Fixed

  • Review events on a pull request from a fork no longer produce a failed run. GitHub passes no secrets to pull_request_review and pull_request_review_comment there, so Carson could not authenticate and failed on the missing app_id. It now ends the run successfully with a notice. Empty credentials in any other situation still fail. The README and the no-response-closer, stale, and triage-labeler sections say what this means for fork pull requests.
  • stale, template-enforcer, triage-labeler, and auto-labeler's sync no longer fail the run when the label they are removing is already gone, for example removed by a maintainer in the same moment.

Contributors

Full Changelog: NexusPHP/carson@v1.6.0...v1.7.0

Changelog

Sourced from NexusPHP/carson's changelog.

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

Unreleased

v1.7.0 - 2026-09-21

Added

  • no-response-closer gains unlabel_on_response: when the item's author comments, pushes to the pull request, or replies in a review thread, the rule's label is removed, so an answered item is no longer closed for lack of a response. Off by default, set per rule or at the top level. Needs auto-labeler enabled.
  • triage-labeler gains sweep: when enabled, every open pull request is reconciled on the scheduled run, so a label missed by a cancelled run or by a review on a fork pull request is corrected within a day. It writes only where the label is wrong. Off by default.
  • An Actions section in SUBSCRIBERS.md lists each cross-subscriber action, its owner, who requests it, and which subscribers label directly.

Fixed

  • Review events on a pull request from a fork no longer produce a failed run. GitHub passes no secrets to pull_request_review and pull_request_review_comment there, so Carson could not authenticate and failed on the missing app_id. It now ends the run successfully with a notice. Empty credentials in any other situation still fail. The README and the no-response-closer, stale, and triage-labeler sections say what this means for fork pull requests.
  • stale, template-enforcer, triage-labeler, and auto-labeler's sync no longer fail the run when the label they are removing is already gone, for example removed by a maintainer in the same moment.

v1.6.0 - 2026-09-19

Added

  • no-response-closer gains rules: several labels, each with its own days_until_close, close_message, exempt_labels, and an only scope for issues or pull requests. The top-level keys act as defaults, and a configuration without rules behaves as before.
  • no-response-closer exposes {{label}} to close_message.
  • welcome accepts false for pull_request and issue in either bucket to switch that greeting off, and false for a whole bucket. An empty message, which used to post an empty comment, now does the same.
  • welcome gains exempt_roles: authors whose repository role is listed are never greeted.

Changed

  • welcome decides first time or returning by counting the author's earlier pull requests or issues in the repository, instead of reading author_association. GitHub reports the first-time associations on pull requests only, so issue authors without commits were never greeted, and it hides private organization members from an App. A leftover author_association list is ignored with a warning, except that an empty list still switches its bucket off.
  • welcome no longer greets a pull request opened as a draft. The greeting is posted on pull_request.ready_for_review instead, once.
  • Log lines name the item type wherever it is known, PR [#8](https://github.com/nexusphp/carson/issues/8) or issue [#8](https://github.com/nexusphp/carson/issues/8), instead of a bare [#8](https://github.com/nexusphp/carson/issues/8). The label, unlabel, and lock action handlers still log the bare number, since they receive only that.
  • auto-labeler names the labels it added or removed on request, and the implied labels it added. Every label list it logs is quoted: "bug", "needs review".
  • The startup log line reads Received push event instead of Received push.
  • A run ends with Finished in 2.4s, or Finished with failures in 2.4s when a subscriber or the dispatch failed.

Fixed

  • Scheduled searches in draft-policy, lock-old-issues, no-response-closer, and stale sent their cutoff as +00:00, which reaches GitHub as a space followed by the search term 00:00. Only items whose text contained 00:00 matched, a small fraction of the real candidates. The cutoff is now sent in the Z form.

v1.5.0 - 2026-09-18

Added

  • cache-pruner subscriber: deletes Actions caches of closed pull requests and deleted branches, and sweeps caches of since-closed pull requests and aged branch caches on schedule. Needs actions: write on the App.
  • auto-labeler gains sync_exempt: labels listed there are still added by rules but never removed by sync_labels.

... (truncated)

Commits
  • cb35604 Prepare changelog for v1.7.0
  • 6037e70 Reconcile triage labels on the scheduled run
  • 1d77195 Skip secretless review events on fork pull requests
  • 2d0b515 Rename CLAUDE.md to AGENTS.md
  • 778556a Document the action router in SUBSCRIBERS.md
  • 8dee091 Tolerate an already absent label on removal
  • 26da510 Let no-response-closer unlabel when the author responds
  • 65018fd [npm] Bump zod from 4.6.1 to 4.6.5 (#46)
  • d1aacb7 [npm] Bump @​types/node from 26.5.1 to 26.6.1 (#45)
  • 04a7f49 [npm] Bump the vitest group with 2 updates (#44)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps [NexusPHP/carson](https://github.com/nexusphp/carson) in `/` from 1.6.0 to 1.7.0.


Updates `NexusPHP/carson` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/nexusphp/carson/releases)
- [Changelog](https://github.com/NexusPHP/carson/blob/1.x/CHANGELOG.md)
- [Commits](NexusPHP/carson@e4b2fde...cb35604)

---
updated-dependencies:
- dependency-name: NexusPHP/carson
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github_actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update external dependencies github_actions Pull requests that update Github_actions code labels Sep 24, 2026
@paulbalandan

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Looks like NexusPHP/carson is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 27, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github_actions-9579e648a9 branch September 27, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update external dependencies github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants