Skip to content

ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.37.0#274

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/The-PR-Agent/pr-agent-0.36.1
Closed

ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.37.0#274
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/The-PR-Agent/pr-agent-0.36.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor

Bumps The-PR-Agent/pr-agent from 0.36.0 to 0.37.0.

Release notes

Sourced from The-PR-Agent/pr-agent's releases.

v0.36.1

⚠️ Security

This release temporarily disables the /help_docs command as a mitigation for a credential-exposure vulnerability (#2445).

/help_docs accepted an untrusted runtime override of its git clone target (e.g. --pr_help_docs.repo_url=... from a PR comment), and the clone-URL host validation only checked substring containment. A host that merely contained the allowed host — e.g. github.com.attacker.tld — passed validation, so the git provider token was embedded into a clone URL pointing at an attacker-controlled host, exposing GITHUB_TOKEN (and the equivalent token on other providers).

What's Changed

🚀 Features

🐛 Bug Fixes

📚 Documentation

  • docs: Fix broken list markup in gitea installation document by @​brlin-tw in #2413

Full Changelog: The-PR-Agent/pr-agent@v0.36.0...v0.37.0

Commits
  • 85178be fix: make GitHub PR-description ticket selection deterministic (#2422)
  • ef851b5 chore: improve pr-agent maintenance path (#2431)
  • 4b00f3d chore: let Qodo auto-approve PRs after self-review (#2463)
  • 72504dd docs: use shell-portable env var names in install examples (#2439)
  • f45b6e0 fix(gitea): return repo settings as bytes so .pr_agent.toml loads (#2435)
  • 992cdef Add configurable .pr_agent.toml branch selection via CLI/env with GitHub fa...
  • 98e2b7c Create FUNDING.yml (#2462)
  • ea10b68 feat(A2A): migrate to A2A 1.0 protocol with artifact-based task completion (#...
  • 426951f feat(sambanova): add MiniMax-M3, keep M2.5 (#2461)
  • 3852765 test: strengthen focused unit coverage for core behavior (#2397)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot requested a review from a team as a code owner June 17, 2026 09:15
@github-actions

Copy link
Copy Markdown
Contributor

Failed to generate code suggestions for PR

@dependabot dependabot Bot changed the title ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.36.1 ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.37.0 Jun 22, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/The-PR-Agent/pr-agent-0.36.1 branch from 4c6a31f to 5eab4bc Compare June 22, 2026 06:56
Bumps [The-PR-Agent/pr-agent](https://github.com/the-pr-agent/pr-agent) from 0.36.0 to 0.37.0.
- [Release notes](https://github.com/the-pr-agent/pr-agent/releases)
- [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md)
- [Commits](The-PR-Agent/pr-agent@ffe1f89...85178be)

---
updated-dependencies:
- dependency-name: The-PR-Agent/pr-agent
  dependency-version: 0.36.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/The-PR-Agent/pr-agent-0.36.1 branch from 5eab4bc to 0495e43 Compare June 23, 2026 11:43
@dependabot @github

dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #303.

@dependabot dependabot Bot closed this Jun 24, 2026
@dependabot dependabot Bot deleted the dependabot/github_actions/The-PR-Agent/pr-agent-0.36.1 branch June 24, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants