Skip to content

⬆️ Bump quantecon/actions from 0.11.1 to 0.12.0 - #87

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/quantecon/actions-0.12.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/quantecon/actions-0.12.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps quantecon/actions from 0.11.1 to 0.12.0.

Release notes

Sourced from quantecon/actions's releases.

v0.12.0

Added

  • deploy-cloudflare: a new action that publishes a built site to an existing Cloudflare Worker behind Cloudflare Access, for members-only sites that GitHub Pages cannot serve on the Team plan (Pages access control needs Enterprise Cloud). It runs on push, schedule and workflow_dispatch; preview-cloudflare stays PR-only. The part worth building is the gate check. An unauthenticated request must be answered with a redirect to exactly the team's <team>.cloudflareaccess.com login domain. A 2xx fails as "the site is public", a redirect to another Access organisation fails, and so does anything else, including an unreachable host. The check runs before uploading, so a Worker that does not exist, is public, or is gated by the wrong organisation is refused with nothing uploaded. It runs again after the deploy, on production and on the new version's own preview URL (the config enables preview URLs, and a gate on the production hostname alone would leave that one public). It also runs when wrangler fails, because wrangler can fail after the version is live. An optional preview alias (alias: report-2026-08) is checked after its upload. Each check probes the site root and one real non-HTML file from the build, so a gate on the entry point alone cannot pass. The output URLs are constructed from inputs, never parsed from wrangler's output; only the version preview URL, which is probed but never output, comes from wrangler's version ID. The action does not create Workers or provision Access: an admin creates and gates each Worker once, and the deploy token is account-owned with Editor on that one Worker, so it cannot create an ungated Worker either. It takes the lessons of #105 for itself. wrangler is pinned exactly and installed with npm ci from a committed lockfile (Dependabot now tracks npm for this directory), and it runs uncaptured, so its errors reach the log. The action sets up Node 24 only when the runner has less than 22. The probe, scripts/check-access-gate.sh, is the one verified in the QuantEcon/status-projects#35 pilot. (#163)
  • CI: four deploy-cloudflare harness jobs, none needing a Cloudflare account. dc-gate-probe runs the probe against a local stand-in (.github/fixtures/access-gate/) for every response shape. dc-refuses-ungated asserts that a Worker which does not exist is refused before wrangler is even installed, with a positive control showing the same inputs reach wrangler once the gate is off. dc-inputs asserts that every invalid input fails in validation, including #163's own example alias 2026-08, which Cloudflare rejects because aliases must start with a letter. dc-wrangler-config dry-runs the generated config through the pinned wrangler, which is what a Dependabot bump of the lockfile is tested against. A real deploy is not covered; the first consumer deploy is its proof. (#163)
  • build-jupyter-cache: latex-requirements-file input, passed through to setup-environment. A pdflatex builder forces install-latex on, and in standard (non-container) mode setup-environment then hard-fails when its requirements file is missing, but the path could not be set from here. The default is latex-requirements.txt, setup-environment's own, and deliberately not '': the runner passes an explicit empty value through instead of applying the callee's default, which would have failed every standard-mode pdflatex build. Ignored in container mode, where the images ship LaTeX. (#109)
  • CI: bjc-builders-parse harness job for the builders fix below. It turns the runner into a container-mode host with the same /etc/quantecon-container marker a GPU AMI carries, so the internal setup-environment@v0 is a no-op and every build the parser enables fails in seconds on a missing source dir; the per-builder statuses then record exactly which builders were parsed. Two controls ('jupyter,pdflatex,html', and a two-line block value with a trailing comma) must attempt exactly their builders; 'html,pdf' and 'nojupyter' must abort with no builder run. The old substring parser

... (truncated)

Changelog

Sourced from quantecon/actions's changelog.

[0.12.0] - 2026-09-24

Added

  • deploy-cloudflare: a new action that publishes a built site to an existing Cloudflare Worker behind Cloudflare Access, for members-only sites that GitHub Pages cannot serve on the Team plan (Pages access control needs Enterprise Cloud). It runs on push, schedule and workflow_dispatch; preview-cloudflare stays PR-only. The part worth building is the gate check. An unauthenticated request must be answered with a redirect to exactly the team's <team>.cloudflareaccess.com login domain. A 2xx fails as "the site is public", a redirect to another Access organisation fails, and so does anything else, including an unreachable host. The check runs before uploading, so a Worker that does not exist, is public, or is gated by the wrong organisation is refused with nothing uploaded. It runs again after the deploy, on production and on the new version's own preview URL (the config enables preview URLs, and a gate on the production hostname alone would leave that one public). It also runs when wrangler fails, because wrangler can fail after the version is live. An optional preview alias (alias: report-2026-08) is checked after its upload. Each check probes the site root and one real non-HTML file from the build, so a gate on the entry point alone cannot pass. The output URLs are constructed from inputs, never parsed from wrangler's output; only the version preview URL, which is probed but never output, comes from wrangler's version ID. The action does not create Workers or provision Access: an admin creates and gates each Worker once, and the deploy token is account-owned with Editor on that one Worker, so it cannot create an ungated Worker either. It takes the lessons of #105 for itself. wrangler is pinned exactly and installed with npm ci from a committed lockfile (Dependabot now tracks npm for this directory), and it runs uncaptured, so its errors reach the log. The action sets up Node 24 only when the runner has less than 22. The probe, scripts/check-access-gate.sh, is the one verified in the QuantEcon/status-projects#35 pilot. (#163)
  • CI: four deploy-cloudflare harness jobs, none needing a Cloudflare account. dc-gate-probe runs the probe against a local stand-in (.github/fixtures/access-gate/) for every response shape. dc-refuses-ungated asserts that a Worker which does not exist is refused before wrangler is even installed, with a positive control showing the same inputs reach wrangler once the gate is off. dc-inputs asserts that every invalid input fails in validation, including #163's own example alias 2026-08, which Cloudflare rejects because aliases must start with a letter. dc-wrangler-config dry-runs the generated config through the pinned wrangler, which is what a Dependabot bump of the lockfile is tested against. A real deploy is not covered; the first consumer deploy is its proof. (#163)
  • build-jupyter-cache: latex-requirements-file input, passed through to setup-environment. A pdflatex builder forces install-latex on, and in standard (non-container) mode setup-environment then hard-fails when its requirements file is missing, but the path could not be set from here. The default is latex-requirements.txt, setup-environment's own, and deliberately not '': the runner passes an explicit empty value through instead of applying the callee's default, which would have failed every standard-mode pdflatex build. Ignored in container mode, where the images ship LaTeX. (#109)
  • CI: bjc-builders-parse harness job for the builders fix below. It turns the runner into a container-mode host with the same /etc/quantecon-container marker a GPU AMI carries, so the internal setup-environment@v0 is a no-op and every build the parser enables fails in seconds on a missing source dir; the per-builder statuses then record exactly which builders were parsed. Two controls ('jupyter,pdflatex,html', and a two-line block value with a trailing comma) must attempt exactly their builders; 'html,pdf' and 'nojupyter' must abort with no builder run. The old substring parser

... (truncated)

Commits
  • a53dbe4 release: v0.12.0 (#181)
  • 0baf959 ci: bump the github-actions group across 2 directories with 2 updates (#180)
  • 7a40cd4 fix(preview-*): surface deploy errors, pin the CLIs by lockfile, keep the Net...
  • 3cbab39 feat: deploy-cloudflare — publish private sites to a Worker behind Access, an...
  • 6a4548e fix(actions): #107 correctness batch and #109 code items (#173)
  • 0e514bf docs: 2026.06 baseline, measured image sizes, and READMEs reconciled with the...
  • b20c274 deps: bump the conda group across 2 directories with 1 update (#162)
  • df44407 test(containers): exercise the real theme and FreeFont path in the smoke fixt...
  • b8b1b33 ci: bump the github-actions group across 1 directory with 2 updates (#167)
  • 5e6967e fix(ci): make the image-size job report both sizes, and fail when it cannot (...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [quantecon/actions](https://github.com/quantecon/actions) from 0.11.1 to 0.12.0.
- [Release notes](https://github.com/quantecon/actions/releases)
- [Changelog](https://github.com/QuantEcon/actions/blob/main/CHANGELOG.md)
- [Commits](QuantEcon/actions@v0.11.1...v0.12.0)

---
updated-dependencies:
- dependency-name: quantecon/actions
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants