build(deps): bump azure/login from 3.0.1 to 3.1.0 - #142
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [azure/login](https://github.com/azure/login) from 3.0.1 to 3.1.0. - [Release notes](https://github.com/azure/login/releases) - [Commits](Azure/login@f5d393a...a641126) --- updated-dependencies: - dependency-name: azure/login dependency-version: 3.1.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, straightforward dependency bump.
What was reviewed: the single-line change in .github/workflows/docs.yml bumping the pinned azure/login action SHA from v3.0.1 to v3.1.0, with the version comment updated to match. Confirmed the new SHA corresponds to the v3.1.0 release tag and that the action remains pinned to a full commit SHA (not a mutable tag). No other workflow steps, permissions, secrets usage, or inputs were touched.
Extended reasoning...
The change is confined to .github/workflows/docs.yml, updating the pinned commit SHA for the azure/login action from 3.0.1 to 3.1.0 and its version comment; no other files changed. It touches CI/CD config but the step's secrets usage (client-id, tenant-id) and inputs are unmodified, and the action remains pinned to a full-length SHA rather than a mutable ref, so supply-chain risk is unchanged. This is a routine dependabot version bump, mechanical and self-contained, with no logic changes.
Bumps azure/login from 3.0.1 to 3.1.0.
Release notes
Sourced from azure/login's releases.
Commits
a641126prepare release v3.1.03c5b5ceAdd max-context-population input to override Azure PowerShell MaxCont… (#642)fcd0340Bump browserslist from 4.21.4 to 4.28.8 (#637)5a8018fBump js-yaml from 3.14.2 to 3.15.2 (#643)a23dddfci: reduce scheduled test frequency and clarify workflow names (#639)4c016e0docs: document immutable release model and correct branch reference (#640)63f3c38Automate release tagging via deploy key + self-pin bump (#638)92a0b67Add the ability to prevent the masking of clientId (#634)5cb857dPin GitHub Actions to full-length commit SHAs (#636)d90bae5Cap@actions/execand@actions/corebelow the ESM-only 3.x majors (#628)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)