build(deps): bump azure/login from 3.0.1 to 3.1.0 - #477
Conversation
Bumps [azure/login](https://github.com/azure/login) from 3.0.1 to 3.1.0. - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@f5d393a...a641126) --- updated-dependencies: - dependency-name: azure/login dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Looks good — straightforward dependency version bump.
What was reviewed: the single-line change in .github/workflows/docs.yml bumping the pinned azure/login action from v3.0.1 to v3.1.0; confirmed the new reference is still pinned to a full-length commit SHA (not a mutable tag) consistent with the existing convention, and that no other workflow logic, permissions, or secrets usage changed.
Extended reasoning...
The diff touches only .github/workflows/docs.yml, changing the pinned commit SHA for azure/login from v3.0.1 to v3.1.0 with no other logic, permission, or secret handling changes. It remains pinned to a full commit SHA rather than a mutable tag, consistent with supply-chain hardening best practice. This is a mechanical dependency bump from dependabot with no ambiguity or security-sensitive logic change, so it is safe to approve.
Bumps azure/login from 3.0.1 to 3.1.0.
Release notes
Sourced from azure/login's releases.
Commits
a641126prepare release v3.1.03c5b5ceAdd max-context-population input to override Azure PowerShell MaxCont… (#642)fcd0340Bump browserslist from 4.21.4 to 4.28.8 (#637)5a8018fBump js-yaml from 3.14.2 to 3.15.2 (#643)a23dddfci: reduce scheduled test frequency and clarify workflow names (#639)4c016e0docs: document immutable release model and correct branch reference (#640)63f3c38Automate release tagging via deploy key + self-pin bump (#638)92a0b67Add the ability to prevent the masking of clientId (#634)5cb857dPin GitHub Actions to full-length commit SHAs (#636)d90bae5Cap@actions/execand@actions/corebelow the ESM-only 3.x majors (#628)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)