July 5, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.0.
This action is used across all versions by 131 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This setup-tombi release matches tombi v1.2.0.
Full Changelog: https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.0
July 5, 2026
configure-huawei-cloud-credentials
Version updated for https://github.com/vbem/configure-huawei-cloud-credentials to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/configure-huawei-cloud-credentials/compare/v1.0.0...v1.0.1
July 5, 2026
HumaneProxy Safety Benchmark
Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights 🔭 OpenTelemetry distributed tracing (#7) — export pipeline traces to Jaeger, Grafana Tempo, or Datadog via the new [telemetry] extra. Every request produces a pipeline.classify span with privacy-safe attributes (category, score, stage reached, message hash — never raw text). Zero overhead when disabled. 🌍 Region-aware care response — set safety.categories.self_harm.region: "IN" (any ISO country code) to surface that country’s crisis resources first, while always keeping the full international list. ☎️ Crisis helplines for new countries (#26) — Japan, South Korea, Spain, Italy, Mexico, New Zealand and more join the existing US/IN/GB/AU/CA/DE/FR/BR/ZA resources. 🗄️ Storage-backend consistency (#37) — the admin API, CLI, and MCP tools now route through the storage factory instead of raw SQLite, so Redis and PostgreSQL deployments see the same data everywhere. 📊 Query upgrades — escalation queries support date filtering (date_from/date_to) and sorting across all three backends. Fixed Multimodal content arrays: /chat extracts text from OpenAI-style content parts and no longer errors on string or malformed message content (#44, #45, #48). Empty /chat request bodies return a clean 400 (#41). CodeQL SQL-injection alerts resolved with statically generated SQL templates; timezone conversion and CSV triggers serialization fixed in escalation export. Security Admin Bearer-token comparison hardened against timing attacks with hmac.compare_digest (#18, #21). HTTP MCP hardened: binds to 127.0.0.1 by default, warns on public binds without a token, supports Bearer auth via HUMANE_PROXY_ADMIN_KEY, and bounds audit-log queries (#17). Docs & Tests Mermaid.js architecture diagram, README table of contents, corrected Stage-1 transition labels. New test coverage: Unicode/leet-speak heuristic edge cases, pipeline config validation, malformed payloads, decay-weighted-mean edge cases. Full Changelog: https://github.com/Vishisht16/Humane-Proxy/compare/v0.4.0...v0.5.0
July 5, 2026
Setup vp
Version updated for https://github.com/voidzero-dev/setup-vp to version v1.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): update dependency vite-plus to v0.2.2 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/104 feat: add GitLab CI/CD integration for setup-vp by @naokihaba in https://github.com/voidzero-dev/setup-vp/pull/97 New Contributors @naokihaba made their first contribution in https://github.com/voidzero-dev/setup-vp/pull/97 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.14.0...v1.15.0
July 5, 2026
Decionis Action Gate
Version updated for https://github.com/decionis/govern to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ⚡ Performance Local policy engine: the committed ```decionis rules block in DECIONIS_POLICY.md is evaluated in-process in microseconds, faithfully mirroring the platform evaluator. Deterministic allow/block verdicts act immediately; the API call becomes an async notarization off the critical path (signed dossiers, verify URLs, and badges still arrive). New local-eval input: auto (default) / strict (fully offline) / off (v1.8 behavior). Speculative shadow mode: run commands start immediately while the verdict resolves in the background — the gate adds ~zero latency. The step’s exit code is always the command’s; evaluation failures are notices. Shadow can no longer fail a build for any reason, and unconfigured gates (no secrets yet) are inert. Every run logs a Decionis timing — line so the speedups are visible. 🔧 Correctness API outcome normalization (APPROVE→allow, REJECT→block, REQUIRE_REVIEW→review) — enforce-mode run gating and fail-on now work against the live API vocabulary. New outputs: decision-source (local/api) and verdict-mismatch (local verdict vs notarizing API verdict, with a ::warning::). Example policies and the installer template set explicit rule priority and "domain": "*" so committed policies actually fire. 🚀 Onboarding install.sh ships in the repo: curl -fsSL https://decionis.com/govern/install.sh | sh -s -- --pr --inject writes a shadow workflow + starter policy, injects observe-only (continue-on-error) gate steps into existing workflows, and opens the onboarding PR. Badge/verify URLs pin the policy revision: &policy=sha256:<hash>. ✅ Compatibility All existing inputs/outputs unchanged; repos without a rules block see no decision-flow change. 143 tests, including end-to-end timing proofs against a mock API.
July 5, 2026
Zabbly Incus for GitHub Actions
Version updated for https://github.com/dionysius/incus-zabbly-actions to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dionysius/incus-zabbly-actions/compare/v1...v1.0.4
July 5, 2026
MUADDIB Scanner
Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.157.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Mutes the BURST PRE-ALERT Discord webhook by default (~700x/day, anti-corrélé avec les vrais incidents). Re-enable via MUADDIB_BURST_PREALERT_WEBHOOK=1. Console log + stats du daily summary inchangés.
July 5, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.29.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.
July 5, 2026
Setup Umka
Version updated for https://github.com/fabasoad/setup-umka-action to version v1.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/148 fix: issue found by markdownlint by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/149 chore(deps): bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/150 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-umka-action/pull/151 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/152 Full Changelog: https://github.com/fabasoad/setup-umka-action/compare/v1.5.1...v1.5.2
July 5, 2026
Ansible Molecule
Version updated for https://github.com/gofrolist/molecule-action to version v2.7.103.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.7.103 (2026-07-04) Bug Fixes deps: Bump ansible-lint from 26.4.0 to 26.6.0 (12f1ba1)
deps: Bump docker/build-push-action from 7.2.0 to 7.3.0 (3c32800)
deps: Bump docker/login-action from 4.2.0 to 4.3.0 (a0106d0)
deps: Bump docker/metadata-action from 6.1.0 to 6.2.0 (bc9c924)