Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add & deprecate old markdownSummary export - #1073

Merged
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary
May 5, 2022
Merged

Add & deprecate old markdownSummary export#1073
robherley merged 1 commit into
mainfrom
robherley/deprecate-markdownsummary

Conversation

@robherley

Copy link
Copy Markdown
Contributor

We originally dark shipped this feature to some users as core.markdownSummary but since then the feature name has been changed to be "Job Summary". To avoid conflict with our public documentation and to maintain consistency, this'll be core.summary going forward.

However, we'll keep core.markdownSummary in the API and marked as deprecated for the next release.

Original release:

Rename:

@robherley
robherley requested a review from a team as a code ownerMay 5, 2022 19:47
@robherley
robherley merged commit c4ae214 into mainMay 5, 2022
@robherleyrobherley mentioned this pull request May 5, 2022
kodiakhqBot referenced this pull request in carbon-design-system/carbon-for-ibm-dotcom-web-components-template May 17, 2023
[![Mend Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [@actions/core](https://togithub.com/actions/toolkit) | [`1.6.0` -> `1.9.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.6.0/1.9.1) | [![age](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/age-slim)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/adoption-slim)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/compatibility-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://badges.renovateapi.com/packages/npm/@actions%2fcore/1.9.1/confidence-slim/1.6.0)](https://docs.renovatebot.com/merge-confidence/) |
### GitHub Vulnerability Alerts
#### [CVE-2022-35954](https://togithub.com/actions/toolkit/security/advisories/GHSA-7r3h-m5j6-3q42)
## Impact
The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author.
## Patches
Users should upgrade to `@actions/core v1.9.1`.
## Workarounds
If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`.
## References
[More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable)
If you have any questions or comments about this advisory:
* Open an issue in [`actions/toolkit`](https://togithub.com/actions/toolkit/issues)
---
### Release Notes
<details>
<summary>actions/toolkit</summary>
### [`v1.9.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;191)
- Randomize delimiter when calling `core.exportVariable`
### [`v1.9.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;190)
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](https://togithub.com/actions/toolkit/pull/1102)
### [`v1.8.2`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;182)
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](https://togithub.com/actions/toolkit/pull/1087)
### [`v1.8.1`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;181)
- Update to v2.0.0 of `@actions/http-client`
### [`v1.8.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;180)
- Deprecate `markdownSummary` extension export in favor of `summary`
- [https://github.com/actions/toolkit/pull/1072](https://togithub.com/actions/toolkit/pull/1072)
- [https://github.com/actions/toolkit/pull/1073](https://togithub.com/actions/toolkit/pull/1073)
### [`v1.7.0`](https://togithub.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#&#8203;170)
- [Added `markdownSummary` extension](https://togithub.com/actions/toolkit/pull/1014)
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.
---
This PR has been generated by [Mend Renovate](https://www.mend.io/free-developer-tools/renovate/). View repository job log [here](https://app.renovatebot.com/dashboard#github/carbon-design-system/carbon-for-ibm-dotcom-web-components-template).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzMi4xNjMuMCIsInVwZGF0ZWRJblZlciI6IjMyLjE2My4wIn0=-->
chhe pushed a commit to chhe/act_runner that referenced this pull request May 1, 2026
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@actions/core](https://github.com/actions/toolkit/tree/main/packages/core) ([source](https://github.com/actions/toolkit/tree/HEAD/packages/core)) | [`1.10.0` → `1.11.1`](https://renovatebot.com/diffs/npm/@actions%2fcore/1.10.0/1.11.1) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@actions%2fcore/1.11.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@actions%2fcore/1.10.0/1.11.1?slim=true) |
---
### Release Notes
<details>
<summary>actions/toolkit (@&#8203;actions/core)</summary>
### [`v1.11.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1111)
- Fix uses of `crypto.randomUUID` on Node 18 and earlier [#&#8203;1842](actions/toolkit#1842)
##### 1.11.0
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
##### 1.10.1
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
##### 1.10.0
- `saveState` and `setOutput` now use environment files if available [#&#8203;1178](actions/toolkit#1178)
- `getMultilineInput` now correctly trims whitespace by default [#&#8203;1185](actions/toolkit#1185)
##### 1.9.1
- Randomize delimiter when calling `core.exportVariable`
##### 1.9.0
- Added `toPosixPath`, `toWin32Path` and `toPlatformPath` utilities [#&#8203;1102](actions/toolkit#1102)
##### 1.8.2
- Update to v2.0.1 of `@actions/http-client` [#&#8203;1087](actions/toolkit#1087)
##### 1.8.1
- Update to v2.0.0 of `@actions/http-client`
##### 1.8.0
- Deprecate `markdownSummary` extension export in favor of `summary`
- [#&#8203;1072](actions/toolkit#1072)
- [#&#8203;1073](actions/toolkit#1073)
##### 1.7.0
- [Added `markdownSummary` extension](actions/toolkit#1014)
##### 1.6.0
- [Added OIDC Client function `getIDToken`](actions/toolkit#919)
- [Added `file` parameter to `AnnotationProperties`](actions/toolkit#896)
##### 1.5.0
- [Added support for notice annotations and more annotation fields](actions/toolkit#855)
##### 1.4.0
- [Added the `getMultilineInput` function](actions/toolkit#829)
##### 1.3.0
- [Added the trimWhitespace option to getInput](actions/toolkit#802)
- [Added the getBooleanInput function](actions/toolkit#725)
##### 1.2.7
- [Prepend newline for set-output](actions/toolkit#772)
##### 1.2.6
- [Update `exportVariable` and `addPath` to use environment files](actions/toolkit#571)
##### 1.2.5
- [Correctly bundle License File with package](actions/toolkit#548)
##### 1.2.4
- [Be more lenient in accepting non-string command inputs](actions/toolkit#405)
- [Add Echo commands](actions/toolkit#411)
##### 1.2.3
- [IsDebug logging](README.md#logging)
##### 1.2.2
- [Fix escaping for runner commands](actions/toolkit#302)
##### 1.2.1
- [Remove trailing comma from commands](actions/toolkit#263)
- [Add "types" to package.json](actions/toolkit#221)
##### 1.2.0
- saveState and getState functions for wrapper tasks (on finally entry points that run post job)
##### 1.1.3
- setSecret added to register a secret with the runner to be masked from the logs
- exportSecret which was not implemented and never worked was removed after clarification from product.
##### 1.1.1
- Add support for action input variables with multiple spaces [#&#8203;127](actions/toolkit#127)
- Switched ## commands to :: commands (should have no noticeable impact) \[[#&#8203;110](https://github.com/actions/toolkit/issues/110))([#&#8203;110](https://github.com/actions/toolkit/pull/110))
##### 1.1.0
- Added helpers for `group` and `endgroup` [#&#8203;98](actions/toolkit#98)
##### 1.0.0
- Initial release
### [`v1.11.0`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1110)
- Add platform info utilities [#&#8203;1551](actions/toolkit#1551)
- Remove dependency on `uuid` package [#&#8203;1824](actions/toolkit#1824)
### [`v1.10.1`](https://github.com/actions/toolkit/blob/HEAD/packages/core/RELEASES.md#1101)
- Fix error message reference in oidc utils [#&#8203;1511](actions/toolkit#1511)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Reviewed-on: https://gitea.com/gitea/runner/pulls/880
Reviewed-by: Nicolas <bircni@icloud.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
Co-committed-by: Renovate Bot <renovate-bot@gitea.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@robherley@konradpabjan