Skip to content

🐸 Versioned release#139

Merged
theoephraim merged 1 commit into
mainfrom
bumpy/version-packages
Jun 25, 2026
Merged

🐸 Versioned release#139
theoephraim merged 1 commit into
mainfrom
bumpy/version-packages

Conversation

@bumpy-bot

@bumpy-bot bumpy-bot commented Jun 25, 2026

Copy link
Copy Markdown
Collaborator

bumpy-frog

This PR was created and will be kept in sync by bumpy based on your bump files (in .bumpy/). Merge it when you are ready to release the packages listed below:

minor Minor releases

@varlock/bumpy 1.16.1 → 1.17.0 CHANGELOG.md

  • Added a global --cwd <dir> flag that runs bumpy as if it were started in <dir>. This makes the pull_request_target PR-check workflow safe against a previously-undocumented attack: a fork PR could commit a bunfig.toml/.npmrc that redirected where bunx @varlock/bumpy itself was fetched from (swapping in a malicious package at the pinned version). The recommended workflow now fetches and runs bumpy from a trusted base checkout and points it at the untrusted PR tree with --cwd ./pr, so package-manager config in the PR can no longer influence how bumpy is obtained. (bump file)

@varlock/bumpy@1.17.0
@bumpy-bot bumpy-bot force-pushed the bumpy/version-packages branch from 28ba3b7 to 5bd619b Compare June 25, 2026 06:25
@theoephraim theoephraim merged commit 4f1b5b6 into main Jun 25, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants