Skip to content

ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.38.0#303

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/The-PR-Agent/pr-agent-0.37.0
Open

ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.38.0#303
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/The-PR-Agent/pr-agent-0.37.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor

Bumps The-PR-Agent/pr-agent from 0.36.0 to 0.38.0.

Release notes

Sourced from The-PR-Agent/pr-agent's releases.

v0.38.0

🚀 Features

🐛 Bug Fixes

📚 Documentation

Full Changelog: The-PR-Agent/pr-agent@v0.37.0...v0.38.0

v0.36.1

⚠️ Security

This release temporarily disables the /help_docs command as a mitigation for a credential-exposure vulnerability (#2445).

/help_docs accepted an untrusted runtime override of its git clone target (e.g. --pr_help_docs.repo_url=... from a PR comment), and the clone-URL host validation only checked substring containment. A host that merely contained the allowed host — e.g. github.com.attacker.tld — passed validation, so the git provider token was embedded into a clone URL pointing at an attacker-controlled host, exposing GITHUB_TOKEN (and the equivalent token on other providers).

What's Changed

🚀 Features

🐛 Bug Fixes

... (truncated)

Commits
  • bd09b6c chore(release): bump version to 0.38.0 [skip ci]
  • 65715b0 fix(azure): decode percent-encoded spaces in Azure DevOps PR URLs (#2080) (#2...
  • 254ab00 fix(describe): guard pr_description config reads against missing keys (#2238)...
  • 0374f0a docs: update the configuration example of the Deepseek model (#2472)
  • a2a6971 feat(deepseek): register deepseek-v4-pro and deepseek-v4-flash models (#2477)
  • 10b51ba fix user bot permission in Docs (#2470)
  • 01c31d1 feat(models): support Databricks-hosted models (#2464)
  • 74e4d98 fix(tickets): prevent /review and /describe crash on linked issues with sub-i...
  • 9f34d73 fix: don't overwrite PR title in /describe when generate_ai_title is false (#...
  • d26a143 fix: parse multi-hunk diffs in Gitea provider (#2137)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown
Contributor

Failed to generate code suggestions for PR

@dependabot dependabot Bot changed the title ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.37.0 ci(deps): bump The-PR-Agent/pr-agent from 0.36.0 to 0.38.0 Jun 27, 2026
@dependabot dependabot Bot force-pushed the dependabot/github_actions/The-PR-Agent/pr-agent-0.37.0 branch 3 times, most recently from e3a18ac to ba8a148 Compare June 29, 2026 14:40
Bumps [The-PR-Agent/pr-agent](https://github.com/the-pr-agent/pr-agent) from 0.36.0 to 0.38.0.
- [Release notes](https://github.com/the-pr-agent/pr-agent/releases)
- [Changelog](https://github.com/The-PR-Agent/pr-agent/blob/main/CHANGELOG.md)
- [Commits](The-PR-Agent/pr-agent@ffe1f89...bd09b6c)

---
updated-dependencies:
- dependency-name: The-PR-Agent/pr-agent
  dependency-version: 0.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/The-PR-Agent/pr-agent-0.37.0 branch from ba8a148 to e0d812d Compare June 29, 2026 22:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants