Skip to content

Bump pnpm/action-setup from 5.0.0 to 6.0.0#3

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/action-setup-6.0.0
Closed

Bump pnpm/action-setup from 5.0.0 to 6.0.0#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/pnpm/action-setup-6.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 17, 2026

Bumps pnpm/action-setup from 5.0.0 to 6.0.0.

Release notes

Sourced from pnpm/action-setup's releases.

v6.0.0

Added support for pnpm v11.

Commits
  • 08c4be7 docs(README): update action-setup version
  • 5798914 chore: update .gitignore
  • ddffd66 fix: remove accidentally committed file
  • b43f991 fix: update pnpm to 11.0.0-rc.0
  • 3852509 README.md: bring versions up-to-date (#222)
  • 6e7bdbd chore: bump bootstrap pnpm to 11.0.0-beta.4-1 and add update script
  • 6b87c46 fix: Windows standalone mode — bypass broken npm shims (#217)
  • 994d756 feat: read pnpm version from devEngines.packageManager (#211)
  • 738f428 docs: upgrade pnpm/action-setup from v4 to v5
  • 62bce64 fix: extract pnpm version from packageManager field instead of returning unde...
  • Additional commits viewable in compare view

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 17, 2026

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@greptile-apps
Copy link
Copy Markdown

greptile-apps Bot commented Apr 17, 2026

Greptile Summary

This PR is a Dependabot-generated bump of pnpm/action-setup from v5.0.0 to v6.0.0 across both CI workflow files. The new version adds support for pnpm v11. All five action references are updated consistently, each pinned to the new commit SHA 08c4be7e2e672a47d11bd04269e27e5f3e8529cb with an accurate # v6.0.0 comment.

  • Updates pnpm/action-setup in .github/workflows/ci.yml (4 occurrences across check, workers-runtime, matrix, and package-validation jobs)
  • Updates pnpm/action-setup in .github/workflows/release.yml (1 occurrence in the release job)
  • The old commit hash was annotated as # v4.4.0 in the original YAML, but Dependabot identifies it as v5.0.0 — the comment was stale/incorrect before this PR; the new # v6.0.0 annotation is accurate

Confidence Score: 5/5

Safe to merge — automated dependency bump with no logic changes, consistent across all five occurrences, and pinned to a specific commit SHA.

This is a straightforward Dependabot version bump of a GitHub Actions action. All references are updated consistently, the commit SHA pinning follows best security practices, and the new version annotation is accurate.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/ci.yml Updates pnpm/action-setup SHA to v6.0.0 in all four jobs; change is consistent and correctly annotated.
.github/workflows/release.yml Updates pnpm/action-setup SHA to v6.0.0 in the single release job; change is consistent with ci.yml.

Reviews (1): Last reviewed commit: "Bump pnpm/action-setup from 5.0.0 to 6.0..." | Re-trigger Greptile

Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 5.0.0 to 6.0.0.
- [Release notes](https://github.com/pnpm/action-setup/releases)
- [Commits](pnpm/action-setup@fc06bc1...08c4be7)

---
updated-dependencies:
- dependency-name: pnpm/action-setup
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/pnpm/action-setup-6.0.0 branch from 3071204 to 3a1e8c7 Compare April 17, 2026 08:52
@alexpate alexpate closed this Apr 17, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 17, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/github_actions/pnpm/action-setup-6.0.0 branch April 17, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant