{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":308778040,"defaultBranch":"main","name":"deploy-appengine","ownerLogin":"google-github-actions","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2020-10-31T01:09:26.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/71461757?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1714590415.0","currentOid":""},"activityList":{"items":[{"before":"a456e2620c7c015ea6640fc7aec605240ca4d720","after":null,"ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-05-01T19:06:44.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"a034fd45aed2d6b4fee016401f0364fdc1e2bba4","after":"429c4012cd8417202d4147856b03421ec4f8717b","ref":"refs/heads/main","pushedAt":"2024-05-01T19:06:43.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Release: v2.1.2 (#366)\n\n## What's Changed\r\n* Disable prompts and set additional metrics by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/364\r\n* Update deps by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/365\r\n\r\n\r\n**Full Changelog**:\r\nhttps://github.com/google-github-actions/deploy-appengine/compare/v2.1.1...a034fd45aed2d6b4fee016401f0364fdc1e2bba4","shortMessageHtmlLink":"Release: v2.1.2 (#366)"}},{"before":null,"after":"a456e2620c7c015ea6640fc7aec605240ca4d720","ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-05-01T18:58:10.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"github-actions[bot]","name":null,"path":"/apps/github-actions","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/15368?s=80&v=4"},"commit":{"message":"Release: v2.1.2","shortMessageHtmlLink":"Release: v2.1.2"}},{"before":"96f21ddd9b6762a1d786c7c3eba9b1a4cba6e822","after":null,"ref":"refs/heads/sethvargo/deps","pushedAt":"2024-05-01T18:50:43.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"d82c52c90b0fa562d0db4e5ecdff6477bc8ee0af","after":"a034fd45aed2d6b4fee016401f0364fdc1e2bba4","ref":"refs/heads/main","pushedAt":"2024-05-01T18:50:42.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Update deps (#365)","shortMessageHtmlLink":"Update deps (#365)"}},{"before":null,"after":"96f21ddd9b6762a1d786c7c3eba9b1a4cba6e822","ref":"refs/heads/sethvargo/deps","pushedAt":"2024-05-01T18:40:39.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Update deps","shortMessageHtmlLink":"Update deps"}},{"before":"32f3d1eec8fcc91d905987a41a348317c9ac858b","after":null,"ref":"refs/heads/sethvargo/metrics","pushedAt":"2024-05-01T18:35:32.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"f217ff257a86208215e41b853ae0f140c505a3c7","after":"d82c52c90b0fa562d0db4e5ecdff6477bc8ee0af","ref":"refs/heads/main","pushedAt":"2024-05-01T18:35:31.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Disable prompts and set additional metrics (#364)","shortMessageHtmlLink":"Disable prompts and set additional metrics (#364)"}},{"before":"ea87b6d56c4266effe9f86a45136b133802fc8a7","after":"32f3d1eec8fcc91d905987a41a348317c9ac858b","ref":"refs/heads/sethvargo/metrics","pushedAt":"2024-05-01T18:33:31.000Z","pushType":"force_push","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Disable prompts and set additional metrics","shortMessageHtmlLink":"Disable prompts and set additional metrics"}},{"before":"7d9dfca3cfec4cd9587a9d9e4611421cfee34b93","after":"ea87b6d56c4266effe9f86a45136b133802fc8a7","ref":"refs/heads/sethvargo/metrics","pushedAt":"2024-05-01T18:31:35.000Z","pushType":"force_push","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Disable prompts and set additional metrics","shortMessageHtmlLink":"Disable prompts and set additional metrics"}},{"before":null,"after":"7d9dfca3cfec4cd9587a9d9e4611421cfee34b93","ref":"refs/heads/sethvargo/metrics","pushedAt":"2024-05-01T18:29:51.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Disable prompts and set additional metrics","shortMessageHtmlLink":"Disable prompts and set additional metrics"}},{"before":"693d5531d0275199f7d8b10f5b756dba88deefc6","after":"f217ff257a86208215e41b853ae0f140c505a3c7","ref":"refs/heads/main","pushedAt":"2024-04-29T23:27:10.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Release: v2.1.1 (#363)\n\n## What's Changed\r\n* security: bump undici from 5.28.2 to 5.28.3 by @dependabot in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/352\r\n* Docs: Added artifact register reader permission required for ci/cd\r\npipeline by @hawkeye-sama in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/356\r\n* build(deps): bump express from 4.18.2 to 4.19.2 in /example-app by\r\n@dependabot in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/357\r\n* security: bump undici from 5.28.3 to 5.28.4 by @dependabot in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/358\r\n* Default \"promote\" to true by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/362\r\n\r\n## New Contributors\r\n* @hawkeye-sama made their first contribution in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/356\r\n\r\n**Full Changelog**:\r\nhttps://github.com/google-github-actions/deploy-appengine/compare/v2.1.0...693d5531d0275199f7d8b10f5b756dba88deefc6","shortMessageHtmlLink":"Release: v2.1.1 (#363)"}},{"before":"29cd5a5ef235d8168c8718657305173eea49f8d2","after":null,"ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-04-29T23:27:10.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":null,"after":"29cd5a5ef235d8168c8718657305173eea49f8d2","ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-04-29T23:25:25.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"github-actions[bot]","name":null,"path":"/apps/github-actions","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/15368?s=80&v=4"},"commit":{"message":"Release: v2.1.1","shortMessageHtmlLink":"Release: v2.1.1"}},{"before":"1a0ea3005199974833cfd8a96f53c3a488d31444","after":null,"ref":"refs/heads/sethvargo/def","pushedAt":"2024-04-29T23:12:23.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"f53a32be19aee208391f7b60ec65be85bd494adf","after":"693d5531d0275199f7d8b10f5b756dba88deefc6","ref":"refs/heads/main","pushedAt":"2024-04-29T23:12:22.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Default \"promote\" to true (#362)\n\nThis restores a v0 and v1 behavior wherein the empty string is\r\nconsidered \"true\" instead of \"false\". Fixes GH-361.","shortMessageHtmlLink":"Default \"promote\" to true (#362)"}},{"before":null,"after":"1a0ea3005199974833cfd8a96f53c3a488d31444","ref":"refs/heads/sethvargo/def","pushedAt":"2024-04-29T23:09:31.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Default \"promote\" to true\n\nThis restores a v0 and v1 behavior wherein the empty string is considered \"true\" instead of \"false\". Fixes GH-361.","shortMessageHtmlLink":"Default \"promote\" to true"}},{"before":"58ad957cd25431b58fd5f597026492c91f6de984","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/undici-5.28.4","pushedAt":"2024-04-04T20:06:13.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"f0b1f5a4357be864872a725148aec01398542d19","after":"f53a32be19aee208391f7b60ec65be85bd494adf","ref":"refs/heads/main","pushedAt":"2024-04-04T20:06:12.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"security: bump undici from 5.28.3 to 5.28.4 (#358)\n\nBumps [undici](https://github.com/nodejs/undici) from 5.28.3 to 5.28.4.\r\n
\r\nRelease notes\r\n

Sourced from undici's\r\nreleases.

\r\n
\r\n

v5.28.4

\r\n

:warning: Security Release :warning:

\r\n\r\n

Full Changelog: https://github.com/nodejs/undici/compare/v5.28.3...v5.28.4

\r\n
\r\n
\r\n
\r\nCommits\r\n\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=5.28.3&new-version=5.28.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nYou can trigger a rebase of this PR by commenting `@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/google-github-actions/deploy-appengine/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"security: bump undici from 5.28.3 to 5.28.4 (#358)"}},{"before":null,"after":"58ad957cd25431b58fd5f597026492c91f6de984","ref":"refs/heads/dependabot/npm_and_yarn/undici-5.28.4","pushedAt":"2024-04-04T17:19:54.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"security: bump undici from 5.28.3 to 5.28.4\n\nBumps [undici](https://github.com/nodejs/undici) from 5.28.3 to 5.28.4.\n- [Release notes](https://github.com/nodejs/undici/releases)\n- [Commits](https://github.com/nodejs/undici/compare/v5.28.3...v5.28.4)\n\n---\nupdated-dependencies:\n- dependency-name: undici\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"security: bump undici from 5.28.3 to 5.28.4"}},{"before":"42dbb4f0005f5f60a6625d6202091384b158c53b","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/example-app/express-4.19.2","pushedAt":"2024-03-28T18:49:25.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"bfb3ff03db8f49c58fd3ef26658f1ffa0c0e85e6","after":"f0b1f5a4357be864872a725148aec01398542d19","ref":"refs/heads/main","pushedAt":"2024-03-28T18:49:24.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"build(deps): bump express from 4.18.2 to 4.19.2 in /example-app (#357)\n\nBumps [express](https://github.com/expressjs/express) from 4.18.2 to\r\n4.19.2.\r\n
\r\nRelease notes\r\n

Sourced from express's\r\nreleases.

\r\n
\r\n

4.19.2

\r\n

What's Changed

\r\n
    \r\n
  • Improved\r\nfix for open redirect allow list bypass
  • \r\n
\r\n

Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.19.2

\r\n

4.19.1

\r\n

What's Changed

\r\n
    \r\n
  • Fix ci after location patch by @​wesleytodd in expressjs/express#5552
  • \r\n
  • fixed un-edited version in history.md for 4.19.0 by @​wesleytodd in expressjs/express#5556
  • \r\n
\r\n

Full Changelog: https://github.com/expressjs/express/compare/4.19.0...4.19.1

\r\n

4.19.0

\r\n

What's Changed

\r\n
    \r\n
  • fix typo in release date by @​UlisesGascon\r\nin expressjs/express#5527
  • \r\n
  • docs: nominating @​wesleytodd to be\r\nproject captian by @​wesleytodd in expressjs/express#5511
  • \r\n
  • docs: loosen TC activity rules by @​wesleytodd in expressjs/express#5510
  • \r\n
  • Add note on how to update docs for new release by @​crandmck in expressjs/express#5541
  • \r\n
  • Prevent\r\nopen redirect allow list bypass due to encodeurl
  • \r\n
  • Release 4.19.0 by @​wesleytodd in expressjs/express#5551
  • \r\n
\r\n

New Contributors

\r\n
    \r\n
  • @​crandmck\r\nmade their first contribution in expressjs/express#5541
  • \r\n
\r\n

Full Changelog: https://github.com/expressjs/express/compare/4.18.3...4.19.0

\r\n

4.18.3

\r\n

Main Changes

\r\n
    \r\n
  • Fix routing requests without method
  • \r\n
  • deps: body-parser@1.20.2\r\n
      \r\n
    • Fix strict json error message on Node.js 19+
    • \r\n
    • deps: content-type@~1.0.5
    • \r\n
    • deps: raw-body@2.5.2
    • \r\n
    \r\n
  • \r\n
\r\n

Other Changes

\r\n
    \r\n
  • Use https: protocol instead of deprecated git: protocol by @​vcsjones in expressjs/express#5032
  • \r\n
  • build: Node.js@16.18 and Node.js@18.12 by @​abenhamdine in\r\nexpressjs/express#5034
  • \r\n
  • ci: update actions/checkout to v3 by @​armujahid in expressjs/express#5027
  • \r\n
  • test: remove unused function arguments in params by @​raksbisht in expressjs/express#5124
  • \r\n
  • Remove unused originalIndex from acceptParams by @​raksbisht in expressjs/express#5119
  • \r\n
  • Fixed typos by @​raksbisht in expressjs/express#5117
  • \r\n
  • examples: remove unused params by @​raksbisht in expressjs/express#5113
  • \r\n
  • fix: parameter str is not described in JSDoc by @​raksbisht in expressjs/express#5130
  • \r\n
  • fix: typos in History.md by @​raksbisht in expressjs/express#5131
  • \r\n
  • build : add Node.js@19.7 by @​abenhamdine in\r\nexpressjs/express#5028
  • \r\n
  • test: remove unused function arguments in params by @​raksbisht in expressjs/express#5137
  • \r\n
\r\n\r\n
\r\n

... (truncated)

\r\n
\r\n
\r\nChangelog\r\n

Sourced from express's\r\nchangelog.

\r\n
\r\n

4.19.2 / 2024-03-25

\r\n
    \r\n
  • Improved fix for open redirect allow list bypass
  • \r\n
\r\n

4.19.1 / 2024-03-20

\r\n
    \r\n
  • Allow passing non-strings to res.location with new encoding handling\r\nchecks
  • \r\n
\r\n

4.19.0 / 2024-03-20

\r\n
    \r\n
  • Prevent open redirect allow list bypass due to encodeurl
  • \r\n
  • deps: cookie@0.6.0
  • \r\n
\r\n

4.18.3 / 2024-02-29

\r\n
    \r\n
  • Fix routing requests without method
  • \r\n
  • deps: body-parser@1.20.2\r\n
      \r\n
    • Fix strict json error message on Node.js 19+
    • \r\n
    • deps: content-type@~1.0.5
    • \r\n
    • deps: raw-body@2.5.2
    • \r\n
    \r\n
  • \r\n
  • deps: cookie@0.6.0\r\n
      \r\n
    • Add partitioned option
    • \r\n
    \r\n
  • \r\n
\r\n
\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • 04bc627\r\n4.19.2
  • \r\n
  • da4d763\r\nImproved fix for open redirect allow list bypass
  • \r\n
  • 4f0f6cc\r\n4.19.1
  • \r\n
  • a003cfa\r\nAllow passing non-strings to res.location with new encoding handling\r\nchecks f...
  • \r\n
  • a1fa90f\r\nfixed un-edited version in history.md for 4.19.0
  • \r\n
  • 11f2b1d\r\nbuild: fix build due to inconsistent supertest behavior in older\r\nversions
  • \r\n
  • 084e365\r\n4.19.0
  • \r\n
  • 0867302\r\nPrevent open redirect allow list bypass due to encodeurl
  • \r\n
  • 567c9c6\r\nAdd note on how to update docs for new release (#5541)
  • \r\n
  • 69a4cf2\r\ndeps: cookie@0.6.0
  • \r\n
  • Additional commits viewable in compare\r\nview
  • \r\n
\r\n
\r\n
\r\nMaintainer changes\r\n

This version was pushed to npm by wesleytodd, a new releaser\r\nfor express since your current version.

\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=express&package-manager=npm_and_yarn&previous-version=4.18.2&new-version=4.19.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nDependabot will resolve any conflicts with this PR as long as you don't\r\nalter it yourself. You can also trigger a rebase manually by commenting\r\n`@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/google-github-actions/deploy-appengine/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"build(deps): bump express from 4.18.2 to 4.19.2 in /example-app (#357)"}},{"before":null,"after":"42dbb4f0005f5f60a6625d6202091384b158c53b","ref":"refs/heads/dependabot/npm_and_yarn/example-app/express-4.19.2","pushedAt":"2024-03-28T17:33:09.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"build(deps): bump express from 4.18.2 to 4.19.2 in /example-app\n\nBumps [express](https://github.com/expressjs/express) from 4.18.2 to 4.19.2.\n- [Release notes](https://github.com/expressjs/express/releases)\n- [Changelog](https://github.com/expressjs/express/blob/master/History.md)\n- [Commits](https://github.com/expressjs/express/compare/4.18.2...4.19.2)\n\n---\nupdated-dependencies:\n- dependency-name: express\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"build(deps): bump express from 4.18.2 to 4.19.2 in /example-app"}},{"before":"bb0ce0877f44a85501f9f3fedb4c939d88cb4135","after":"bfb3ff03db8f49c58fd3ef26658f1ffa0c0e85e6","ref":"refs/heads/main","pushedAt":"2024-03-12T15:13:39.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"verbanicm","name":"Mike Verbanic","path":"/verbanicm","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/5046972?s=80&v=4"},"commit":{"message":"Docs: Added artifact register reader permission required for ci/cd pipeline (#356)\n\nHi maintainers. This PR is based on #354 \r\n\r\nFound an issue that when deploying to App engine via github actions for\r\nstandard environment, you get logs with this error `reason:\r\ngeneric::permission_denied: failed to fetch manifest:\r\ngeneric::permission_denied` which is due to `Artifact Registry Reader`\r\nPermission missing from service account used. I did not encounter this\r\nissue for flexible environment.\r\nTested with following configurations\r\n`deploy.yaml` ( github workflow )\r\n```\r\nname: Deploy to GAE\r\n\r\non:\r\n # Triggers the workflow on push or pull request events but only for the main branch\r\n push:\r\n branches: [ main ]\r\n\r\njobs:\r\n deploy:\r\n name: Deploying to Google Cloud\r\n runs-on: ubuntu-latest\r\n \r\n steps:\r\n - name: Checkout\r\n uses: actions/checkout@v4\r\n\r\n - name: 'Auth GCP'\r\n uses: 'google-github-actions/auth@v2'\r\n with:\r\n credentials_json: '${{ secrets.GCP_DEPLOY }}'\r\n\r\n - id: deploy\r\n name: Deploy to App Engine\r\n uses: google-github-actions/deploy-appengine@v2\r\n with:\r\n deliverables: app.yaml\r\n project_id: ${{ secrets.GCP_PROJECT }}\r\n\r\n - name: Test output\r\n run: 'curl \"${{ steps.deploy.outputs.version_url }}\"'\r\n```\r\n\r\n`app.yaml`\r\n```\r\nservice: default\r\nruntime: nodejs18\r\nenv: standard\r\ninstance_class: F1\r\n\r\nenv_variables:\r\n NODE_ENV: production\r\n PORT: 8080\r\n\r\ninbound_services:\r\n- warmup\r\n\r\nautomatic_scaling:\r\n min_instances: 1\r\n max_instances: 2\r\n target_cpu_utilization: 0.75\r\n\r\n\r\nhandlers:\r\n- url: /.*\r\n script: auto\r\n secure: always\r\n redirect_http_response_code: 301\r\n```\r\n\r\nSigned-off-by: Bahroze Ali ","shortMessageHtmlLink":"Docs: Added artifact register reader permission required for ci/cd pi…"}},{"before":"df8a3b88297886584ccbacb56d3f68b22941b4dd","after":null,"ref":"refs/heads/dependabot/npm_and_yarn/undici-5.28.3","pushedAt":"2024-02-16T20:04:59.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"24e0c36ed7593b83beee803db490735c270338d6","after":"bb0ce0877f44a85501f9f3fedb4c939d88cb4135","ref":"refs/heads/main","pushedAt":"2024-02-16T20:04:58.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"security: bump undici from 5.28.2 to 5.28.3 (#352)\n\nBumps [undici](https://github.com/nodejs/undici) from 5.28.2 to 5.28.3.\r\n
\r\nRelease notes\r\n

Sourced from undici's\r\nreleases.

\r\n
\r\n

v5.28.3

\r\n

⚠️ Security Release ⚠️

\r\n

Fixes:

\r\n
    \r\n
  • CVE-2024-24758\r\nProxy-Authorization header not cleared on cross-origin redirect in\r\nfetch
  • \r\n
\r\n

Full Changelog: https://github.com/nodejs/undici/compare/v5.28.2...v5.28.3

\r\n
\r\n
\r\n
\r\nCommits\r\n
    \r\n
  • e71cb4c\r\nBumped v5.28.3
  • \r\n
  • 20c65b8\r\nFix tests for Node.js v20.11.0 (#2618)
  • \r\n
  • 8ec52cd\r\nFix tests for Node.js v21 (#2609)
  • \r\n
  • d3aa574\r\nMerge pull request from GHSA-3787-6prv-h9w3
  • \r\n
  • See full diff in compare\r\nview
  • \r\n
\r\n
\r\n
\r\n\r\n\r\n[![Dependabot compatibility\r\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=undici&package-manager=npm_and_yarn&previous-version=5.28.2&new-version=5.28.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\r\n\r\nYou can trigger a rebase of this PR by commenting `@dependabot rebase`.\r\n\r\n[//]: # (dependabot-automerge-start)\r\n[//]: # (dependabot-automerge-end)\r\n\r\n---\r\n\r\n
\r\nDependabot commands and options\r\n
\r\n\r\nYou can trigger Dependabot actions by commenting on this PR:\r\n- `@dependabot rebase` will rebase this PR\r\n- `@dependabot recreate` will recreate this PR, overwriting any edits\r\nthat have been made to it\r\n- `@dependabot merge` will merge this PR after your CI passes on it\r\n- `@dependabot squash and merge` will squash and merge this PR after\r\nyour CI passes on it\r\n- `@dependabot cancel merge` will cancel a previously requested merge\r\nand block automerging\r\n- `@dependabot reopen` will reopen this PR if it is closed\r\n- `@dependabot close` will close this PR and stop Dependabot recreating\r\nit. You can achieve the same result by closing it manually\r\n- `@dependabot show ignore conditions` will show all\r\nof the ignore conditions of the specified dependency\r\n- `@dependabot ignore this major version` will close this PR and stop\r\nDependabot creating any more for this major version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this minor version` will close this PR and stop\r\nDependabot creating any more for this minor version (unless you reopen\r\nthe PR or upgrade to it yourself)\r\n- `@dependabot ignore this dependency` will close this PR and stop\r\nDependabot creating any more for this dependency (unless you reopen the\r\nPR or upgrade to it yourself)\r\nYou can disable automated security fix PRs for this repo from the\r\n[Security Alerts\r\npage](https://github.com/google-github-actions/deploy-appengine/network/alerts).\r\n\r\n
\r\n\r\nSigned-off-by: dependabot[bot] \r\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>","shortMessageHtmlLink":"security: bump undici from 5.28.2 to 5.28.3 (#352)"}},{"before":null,"after":"df8a3b88297886584ccbacb56d3f68b22941b4dd","ref":"refs/heads/dependabot/npm_and_yarn/undici-5.28.3","pushedAt":"2024-02-16T18:36:12.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"dependabot[bot]","name":null,"path":"/apps/dependabot","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/29110?s=80&v=4"},"commit":{"message":"security: bump undici from 5.28.2 to 5.28.3\n\nBumps [undici](https://github.com/nodejs/undici) from 5.28.2 to 5.28.3.\n- [Release notes](https://github.com/nodejs/undici/releases)\n- [Commits](https://github.com/nodejs/undici/compare/v5.28.2...v5.28.3)\n\n---\nupdated-dependencies:\n- dependency-name: undici\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] ","shortMessageHtmlLink":"security: bump undici from 5.28.2 to 5.28.3"}},{"before":"4d4fe99460d3000d0a185f50851d2953634c97df","after":null,"ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-01-23T01:54:08.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"}},{"before":"81b21e6e276963f0cdc469d1846b86da6dbf1fad","after":"24e0c36ed7593b83beee803db490735c270338d6","ref":"refs/heads/main","pushedAt":"2024-01-23T01:54:07.000Z","pushType":"pr_merge","commitsCount":1,"pusher":{"login":"sethvargo","name":"Seth Vargo","path":"/sethvargo","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/408570?s=80&v=4"},"commit":{"message":"Release: v2.1.0 (#351)\n\n## What's Changed\r\n* Update README and CI to use latest version by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/342\r\n* docs: replace old parameter on example code by @nasustim in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/346\r\n* Stream output when debug is enabled by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/348\r\n* Update deps by @sethvargo in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/350\r\n\r\n## New Contributors\r\n* @nasustim made their first contribution in\r\nhttps://github.com/google-github-actions/deploy-appengine/pull/346\r\n\r\n**Full Changelog**:\r\nhttps://github.com/google-github-actions/deploy-appengine/compare/v2.0.0...81b21e6e276963f0cdc469d1846b86da6dbf1fad","shortMessageHtmlLink":"Release: v2.1.0 (#351)"}},{"before":null,"after":"4d4fe99460d3000d0a185f50851d2953634c97df","ref":"refs/heads/actions/draft-release-main","pushedAt":"2024-01-23T01:52:20.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"github-actions[bot]","name":null,"path":"/apps/github-actions","primaryAvatarUrl":"https://avatars.githubusercontent.com/in/15368?s=80&v=4"},"commit":{"message":"Release: v2.1.0","shortMessageHtmlLink":"Release: v2.1.0"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEPyVAkwA","startCursor":null,"endCursor":null}},"title":"Activity · google-github-actions/deploy-appengine"}