Skip to content

⬆️ Updates actions/github-script action to v9#556

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/actions-github-script-9.x
Open

⬆️ Updates actions/github-script action to v9#556
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/actions-github-script-9.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 19, 2026

This PR contains the following updates:

Package Type Update Change
actions/github-script action major v3.1v9.0.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

actions/github-script (actions/github-script)

v9

Compare Source

v9.0.0

Compare Source

New features:

  • getOctokit factory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients with getOctokit for details and examples.
  • Orchestration ID in user-agent — The ACTIONS_ORCHESTRATION_ID environment variable is automatically appended to the user-agent string for request tracing.

Breaking changes:

  • require('@​actions/github') no longer works in scripts. The upgrade to @actions/github v9 (ESM-only) means require('@​actions/github') will fail at runtime. If you previously used patterns like const { getOctokit } = require('@​actions/github') to create secondary clients, use the new injected getOctokit function instead — it's available directly in the script context with no imports needed.
  • getOctokit is now an injected function parameter. Scripts that declare const getOctokit = ... or let getOctokit = ... will get a SyntaxError because JavaScript does not allow const/let redeclaration of function parameters. Use the injected getOctokit directly, or use var getOctokit = ... if you need to redeclare it.
  • If your script accesses other @actions/github internals beyond the standard github/octokit client, you may need to update those references for v9 compatibility.
What's Changed
New Contributors

Full Changelog: actions/github-script@v8.0.0...v9.0.0

v8: .0.0

Compare Source

What's Changed
⚠️ Minimum Compatible Runner Version

v2.327.1
Release Notes

Make sure your runner is updated to this version or newer to use this release.

New Contributors

Full Changelog: actions/github-script@v7.1.0...v8.0.0

v8.0.0

Compare Source

v7.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v7...v7.1.0

v7.0.1

Compare Source

What's Changed

Full Changelog: actions/github-script@v7.0.0...v7.0.1

v7.0.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.4.1...v7.0.0

v7

Compare Source

v6.4.1

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.4.0...v6.4.1

v6.4.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.3.3...v6.4.0

v6.3.3

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.3.2...v6.3.3

v6.3.2

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.3.1...v6.3.2

v6.3.1

Compare Source

What's Changed

Full Changelog: actions/github-script@v6.3.0...v6.3.1

v6.3.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.2.0...v6.3.0

v6.2.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.1.1...v6.2.0

v6.1.1

Compare Source

What's Changed

Non-code changes

New Contributors

Full Changelog: actions/github-script@v6.1.0...v6.1.1

v6.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v6.0.0...v6.1.0

v6.0.0

Compare Source

What's Changed

Breaking Changes

With the update to Node 16 in #​235, all scripts will now be run with Node 16 rather than Node 12.

New Contributors

Full Changelog: actions/github-script@v5...v6.0.0

v6

Compare Source

v5.2.0

Compare Source

What's Changed

Full Changelog: actions/github-script@v5.1.1...v5.2.0

v5.1.1

Compare Source

What's Changed

Full Changelog: actions/github-script@v5.1.0...v5.1.1

v5.1.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/github-script@v5.0.0...v5.1.0

v5.0.0

Compare Source

What's Changed

Breaking Changes

As part of this update, the Octokit context available via github no longer has REST methods directly. These methods are available via github.rest.* - https://github.com/octokit/plugin-rest-endpoint-methods.js/releases/tag/v5.0.0

See https://github.com/actions/github-script#breaking-changes-in-v5

Full Changelog: actions/github-script@v4.1.1...v5.0.0

v5

Compare Source

v4.2.0

Compare Source

What's Changed

Full Changelog: actions/github-script@v4.1.1...v4.2.0

v4.1.1

Compare Source

What's Changed

Full Changelog: actions/github-script@v4.1.0...v4.1.1

v4.1.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/github-script@v4.0.2...v4.1.0

v4.1

Compare Source

v4.0.2: Update @​actions/core package

Compare Source

This release updates the @actions/core package to 1.2.7 - #​137

v4.0.1: Fix "require" search path

Compare Source

Previously, the wrapped require searched the existing module.paths and then process.cwd(). We now only search process.cwd(). See #​136 for details.

v4.0.0: Add support for relative and npm package require

Compare Source

This release adds support for relative require paths, as well as requiring npm modules installed in the working directory.

v4.0

Compare Source

v4

Compare Source

v3.2.0

Compare Source

What's Changed

Full Changelog: actions/github-script@v3.1.1...v3.2.0

v3.1.1: Add @actions/glob package

Compare Source

This releases adds the @actions/glob package, which can be used in scripts via the glob variable - #​127


Configuration

📅 Schedule: (in timezone Europe/Moscow)

  • Branch creation
    • "after 10pm every weekday,before 5am every weekday,every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@github-actions
Copy link
Copy Markdown

🏷️ [bumpr]
Next version:v2.0.2
Changes:v2.0.1...AlexRogalskiy:renovate/actions-github-script-9.x

1 similar comment
@github-actions
Copy link
Copy Markdown

🏷️ [bumpr]
Next version:v2.0.2
Changes:v2.0.1...AlexRogalskiy:renovate/actions-github-script-9.x

@github-actions
Copy link
Copy Markdown

Thanks for the PR!

This section of the codebase is owner by https://github.com/AlexRogalskiy/ - if they write a comment saying "LGTM" then it will be merged.

@renovate renovate Bot changed the title ⬆️ Updates actions/github-script action to v9 ⬆️ Updates actions/github-script action to v9 - autoclosed Apr 19, 2026
@renovate renovate Bot closed this Apr 19, 2026
@renovate renovate Bot deleted the renovate/actions-github-script-9.x branch April 19, 2026 14:03
@renovate renovate Bot changed the title ⬆️ Updates actions/github-script action to v9 - autoclosed ⬆️ Updates actions/github-script action to v9 Apr 21, 2026
@renovate renovate Bot reopened this Apr 21, 2026
@renovate renovate Bot force-pushed the renovate/actions-github-script-9.x branch 2 times, most recently from 5a1897b to 7c9e51d Compare April 21, 2026 19:00
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpretty-quick@​3.1.09910010086100
Addedsemantic-release@​17.3.9969910091100
Addedprettier@​2.2.1921009897100
Addedlint-staged@​10.5.49810010093100

View full report

@socket-security
Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: npm json-schema is vulnerable to Prototype Pollution

CVE: GHSA-896r-f27r-55mw json-schema is vulnerable to Prototype Pollution (CRITICAL)

Affected versions: < 0.4.0

Patched version: 0.4.0

From: package-lock.jsonnpm/@semantic-release/npm@7.0.10npm/jest@27.0.0-next.2npm/jest-circus@26.6.3npm/json-schema@0.2.3

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema@0.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Prototype Pollution in npm minimist

CVE: GHSA-xvch-5gv4-984h Prototype Pollution in minimist (CRITICAL)

Affected versions: >= 1.0.0 < 1.2.6; < 0.2.4

Patched version: 1.2.6

From: package-lock.jsonnpm/editorconfig-checker@3.3.0npm/folio@0.3.18npm/cz-conventional-changelog@3.3.0npm/@semantic-release/npm@7.0.10npm/jest@27.0.0-next.2npm/eslint-plugin-import@2.22.1npm/jest-circus@26.6.3npm/@semantic-release/release-notes-generator@9.0.1npm/minimist@1.2.5

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/minimist@1.2.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm npm is 94.0% likely obfuscated

Confidence: 0.94

Location: Package overview

From: package-lock.jsonnpm/@semantic-release/npm@7.0.10npm/npm@6.14.11

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/npm@6.14.11. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants