Skip to content

Bump metcalfc/changelog-generator from 4.7.0 to 5.0.1 - #627

Merged
diemol merged 1 commit into
mainfrom
dependabot/github_actions/metcalfc/changelog-generator-5.0.1
Sep 15, 2026
Merged

diemol merged 1 commit into
mainfrom
dependabot/github_actions/metcalfc/changelog-generator-5.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor

Bumps metcalfc/changelog-generator from 4.7.0 to 5.0.1.

Release notes

Sourced from metcalfc/changelog-generator's releases.

Release v5.0.1

  • 031a640 - 5.0.1
  • 122a6c2 - Base the changelog on the previous release of the same line, and assert it ([#479](https://github.com/metcalfc/changelog-generator/issues/479))
  • 0bee5ad - fix: return the modified changelog as a real multiline output ([#478](https://github.com/metcalfc/changelog-generator/issues/478))

Release v5.0.0

Breaking change: commit subjects render as literal text

Every changelog line now wraps the commit subject in an inline-code span.

before:  - [f723555](https://github.com/metcalfc/changelog-generator/blob/HEAD/.../commit/f723555) - build(deps-dev): bump @vercel/ncc to 0.45.0 ([#470](https://github.com/metcalfc/changelog-generator/issues/470))
after:   - [f723555](https://github.com/metcalfc/changelog-generator/blob/HEAD/.../commit/f723555) - ` build(deps-dev): bump @vercel/ncc to 0.45.0 ([#470](https://github.com/metcalfc/changelog-generator/issues/470)) `

A commit subject is untrusted input. Anyone whose pull request you merge chooses that text, and this action pastes it directly into your release notes. Rendered as active Markdown, a subject could contribute links, images, @mentions, issue references, raw HTML, or additional changelog entries to a release it had no business editing. Rendering it as literal text closes that off.

What this costs you. Subjects render monospace, and [#123](https://github.com/metcalfc/changelog-generator/issues/123), [GH-123](https://github.com/metcalfc/changelog-generator/issues/123), bare commit SHAs, and :emoji: inside a subject no longer autolink. Because GitHub's squash merge appends ([#123](https://github.com/metcalfc/changelog-generator/issues/123)) to the subject by default, most lines in a typical repository lose that link. The generated commit link at the start of each line is unaffected. Control characters, line and paragraph separators, and bidirectional-control characters are replaced with spaces, so a subject can never span more than its own line.

No inputs or outputs changed, and the No Changes. sentinel is unchanged.

Staying on the previous format

v4.9.0 carries every security and dependency fix in this release -- including undici 7.29.0, which closes 12 advisories -- with the v4 output format untouched. Pin metcalfc/changelog-generator@v4 to stay there. The v4 tag will keep moving on the maintenance line.

What is in this release

Relative to v4.9.0, v5.0.0 adds only the escaping change. Both releases share everything else:

  • Render changelog subjects as literal text (#475) -- v5 only
  • Keep release tag names out of shell source (#473)
  • Verify release bundle before attestation (#474)
  • Bound the dependency overrides and clear the undici advisories (#476)
  • Stop bump:workflow rewriting pinned actions' provenance comments (#477)

... (truncated)

Commits
  • 031a640 5.0.1
  • 122a6c2 Base the changelog on the previous release of the same line, and assert it (#...
  • 0bee5ad fix: return the modified changelog as a real multiline output (#478)
  • c040ad6 5.0.0
  • 6a23679 fix: stop bump:workflow rewriting pinned actions' provenance comments (#477)
  • 8becfce fix(deps): bound the dependency overrides and clear the undici advisories (#476)
  • f723555 build(deps-dev): bump @​vercel/ncc from 0.44.1 to 0.45.0 (#470)
  • 88097f8 build(deps-dev): bump eslint from 10.8.1 to 10.9.0 (#472)
  • 430ccb9 build(deps-dev): bump globals from 17.9.0 to 17.11.0 (#471)
  • d40422b build(deps): bump the codeql-action group with 3 updates (#469)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 15, 2026
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@diemol

diemol commented Sep 15, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [metcalfc/changelog-generator](https://github.com/metcalfc/changelog-generator) from 4.7.0 to 5.0.1.
- [Release notes](https://github.com/metcalfc/changelog-generator/releases)
- [Changelog](https://github.com/metcalfc/changelog-generator/blob/main/release-notes.png)
- [Commits](metcalfc/changelog-generator@v4.7.0...v5.0.1)

---
updated-dependencies:
- dependency-name: metcalfc/changelog-generator
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/metcalfc/changelog-generator-5.0.1 branch from ea5cf7c to 121ea62 Compare September 15, 2026 14:24
@diemol
diemol merged commit b0aab9c into main Sep 15, 2026
12 checks passed
@diemol
diemol deleted the dependabot/github_actions/metcalfc/changelog-generator-5.0.1 branch September 15, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant