Skip to content

[UPDATE] (deps): Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 in /.github/workflows#554

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/dot-github/workflows/master/pypa/gh-action-pypi-publish-1.14.0
Open

[UPDATE] (deps): Bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 in /.github/workflows#554
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/github_actions/dot-github/workflows/master/pypa/gh-action-pypi-publish-1.14.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 14, 2026

Bumps pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0.

Release notes

Sourced from pypa/gh-action-pypi-publish's releases.

v1.14.0

✨ What's Changed

The main change in this release is that verbose and print-hash inputs are now on by default. This was contributed by @​whitequark💰 in #397.

📝 Docs

@​woodruffw💰 updated the mentions of PEP 740 to stop implying that it might be experimental (it hasn't been for quite a while!) in #388 and @​him2him2💰 brushed up some grammar in the README and SECURITY docs via #395.

🛠️ Internal Updates

@​woodruffw💰 bumped sigstore and pypi-attestations in the lock file (#391) and @​webknjaz💰 added infra for using type annotations in the project (#381).

💪 New Contributors

🪞 Full Diff: pypa/gh-action-pypi-publish@v1.13.0...v1.14.0

🧔‍♂️ Release Manager: @​webknjaz 🇺🇦

🙏 Special Thanks to @​facutuesca💰 and @​woodruffw💰 for helping maintain this project when I can't!

💬 Discuss on Bluesky 🦋, on Mastodon 🐘 and on GitHub.

GH Sponsors badge

Commits
  • cef2210 Merge pull request #397 from whitequark/patch-1
  • b4595e2 Enable verbose and print-hash by default.
  • e2bab26 Merge pull request #395 from him2him2/docs/fix-typos-and-grammar
  • 7495c38 docs: fix typos and grammar in README and SECURITY
  • 03f86fe Merge pull request #388 from woodruffw-forks/ww/rm-experimental
  • 4c78f1c Merge branch 'unstable/v1' into ww/rm-experimental
  • b5a6e8b deps: bump sigstore and pypi-attestations
  • a48a03e remove another experimental mention
  • 8087a88 action: remove a lingering mention of PEP 740 being experimental
  • 3317ede 🧪 Integrate actionlint via pre-commit framework
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.13.0 to 1.14.0.
- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)
- [Commits](pypa/gh-action-pypi-publish@ed0c539...cef2210)

---
updated-dependencies:
- dependency-name: pypa/gh-action-pypi-publish
  dependency-version: 1.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added this to the Code Style Technical Debt milestone Apr 14, 2026
@dependabot dependabot Bot added CI Continuous Integration Tooling Configs Improvements or additions to configuration Duplicate This issue or pull request already exists GitHub Anything Meta Testing Something can be verified labels Apr 14, 2026
@dependabot dependabot Bot temporarily deployed to Experimenting April 14, 2026 01:14 Inactive
@dependabot dependabot Bot added Configs Improvements or additions to configuration Testing Something can be verified CI Continuous Integration Tooling GitHub Anything Meta labels Apr 14, 2026
@deepsource-io
Copy link
Copy Markdown

deepsource-io Bot commented Apr 14, 2026

DeepSource Code Review

We reviewed changes in 3ab200c...896f1dd on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Coverage  

Code Review Summary

Analyzer Status Updated (UTC) Details
Python Apr 14, 2026 1:14a.m. Review ↗
Code coverage Apr 14, 2026 1:57a.m. Review ↗

Code Coverage Summary

Language Line Coverage (Overall)
Aggregate
100%
Python
100%

➟ Additional coverage metrics may have been reported. See full coverage report ↗


Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

@github-actions github-actions Bot added the Linter Any linter tool or setting file enhancements label Apr 14, 2026
@sonarqubecloud
Copy link
Copy Markdown

@dependabot dependabot Bot temporarily deployed to Experimenting April 14, 2026 01:14 Inactive
@dependabot dependabot Bot temporarily deployed to Experimenting April 14, 2026 01:16 Inactive
@dependabot dependabot Bot temporarily deployed to Experimenting April 14, 2026 01:16 Inactive
@codecov
Copy link
Copy Markdown

codecov Bot commented Apr 14, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@reactive-firewall reactive-firewall moved this from To do to Regressions in Multicast Project Apr 14, 2026
@reactive-firewall reactive-firewall added the BLOCKED ⚠︎ Unable to proceed at this time label Apr 14, 2026
@reactive-firewall reactive-firewall self-requested a review April 14, 2026 01:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

BLOCKED ⚠︎ Unable to proceed at this time CI Continuous Integration Tooling Configs Improvements or additions to configuration Duplicate This issue or pull request already exists GitHub Anything Meta Linter Any linter tool or setting file enhancements Testing Something can be verified

Projects

Status: Regressions

Development

Successfully merging this pull request may close these issues.

1 participant