UPDATED DAILY FROM GITHUB RELEASES
Follow the latest changes across the Simulation Engine, Game API, Injury Engine, and Web App.
Bumps actions/checkout from 6 to 7.
Sourced from actions/checkout's releases.
v7.0.0
What's Changed
- block checking out fork pr for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by
@dependabot[bot] in actions/checkout#2458- Bump flatted from 3.3.1 to 3.4.2 by
@dependabot[bot] in actions/checkout#2460- Bump js-yaml from 4.1.0 to 4.2.0 by
@dependabot[bot] in actions/checkout#2461- Bump
@actions/coreand@actions/tool-cacheand Remove uuid by@dependabot[bot] in actions/checkout#2459- upgrade module to esm and update dependencies by
@aiqiaoyin actions/checkout#2463- Bump the minor-npm-dependencies group across 1 directory with 3 updates by
@dependabot[bot] in actions/checkout#2462- getting ready for checkout v7 release by
@aiqiaoyin actions/checkout#2464- update error wording by
@aiqiaoyin actions/checkout#2467New Contributors
@aiqiaoymade their first contribution in actions/checkout#2454Full Changelog: actions/checkout@v6.0.3...v7.0.0
v6.0.3
What's Changed
- Update changelog by
@ericsciplein actions/checkout#2357- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- Update changelog for v6.0.3 by
@yaananthin actions/checkout#2446New Contributors
@yaananthmade their first contribution in actions/checkout#2414Full Changelog: actions/checkout@v6...v6.0.3
v6.0.2
What's Changed
- Add orchestration_id to git user-agent when ACTIONS_ORCHESTRATION_ID is set by
@TingluoHuangin actions/checkout#2355- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356Full Changelog: actions/checkout@v6.0.1...v6.0.2
v6.0.1
What's Changed
- Update all references from v5 and v4 to v6 by
@ericsciplein actions/checkout#2314- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327- Clarify v6 README by
@ericsciplein actions/checkout#2328Full Changelog: actions/checkout@v6...v6.0.1
Sourced from actions/checkout's changelog.
Changelog
v7.0.0
- Block checking out fork PR for pull_request_target and workflow_run by
@aiqiaoyin actions/checkout#2454- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by
@dependabot[bot] in actions/checkout#2458- Bump flatted from 3.3.1 to 3.4.2 by
@dependabot[bot] in actions/checkout#2460- Bump js-yaml from 4.1.0 to 4.2.0 by
@dependabot[bot] in actions/checkout#2461- Bump
@actions/coreand@actions/tool-cacheand Remove uuid by@dependabot[bot] in actions/checkout#2459- upgrade module to esm and update dependencies by
@aiqiaoyin actions/checkout#2463- Bump the minor-npm-dependencies group across 1 directory with 3 updates by
@dependabot[bot] in actions/checkout#2462v6.0.3
- Fix checkout init for SHA-256 repositories by
@yaananthin actions/checkout#2439- fix: expand merge commit SHA regex and add SHA-256 test cases by
@yaananthin actions/checkout#2414v6.0.2
- Fix tag handling: preserve annotations and explicit fetch-tags by
@ericsciplein actions/checkout#2356v6.0.1
- Add worktree support for persist-credentials includeIf by
@ericsciplein actions/checkout#2327v6.0.0
- Persist creds to a separate file by
@ericsciplein actions/checkout#2286- Update README to include Node.js 24 support details and requirements by
@salmanmkcin actions/checkout#2248v5.0.1
- Port v6 cleanup to v5 by
@ericsciplein actions/checkout#2301v5.0.0
- Update actions checkout to use node 24 by
@salmanmkcin actions/checkout#2226v4.3.1
- Port v6 cleanup to v4 by
@ericsciplein actions/checkout#2305v4.3.0
- docs: update README.md by
@motssin actions/checkout#1971- Add internal repos for checking out multiple repositories by
@mouismailin actions/checkout#1977- Documentation update - add recommended permissions to Readme by
@benwellsin actions/checkout#2043- Adjust positioning of user email note and permissions heading by
@joshmgrossin actions/checkout#2044- Update README.md by
@nebuk89in actions/checkout#2194- Update CODEOWNERS for actions by
@TingluoHuangin actions/checkout#2224- Update package dependencies by
@salmanmkcin actions/checkout#2236v4.2.2
url-helper.tsnow leverages well-known environment variables by@jww3in actions/checkout#1941- Expand unit test coverage for
isGhesby@jww3in actions/checkout#1946v4.2.1
- Check out other refs/* by commit if provided, fall back to ref by
@orhantoyin actions/checkout#1924
... (truncated)
9c091bb update error wording (#2467)1044a6d getting ready for checkout v7 release (#2464)f028218 Bump the minor-npm-dependencies group across 1 directory with 3 updates (#2462)d914b26 upgrade module to esm and update dependencies (#2463)537c7ef Bump @actions/core and @actions/tool-cache and Remove uuid (#2459)130a169 Bump js-yaml from 4.1.0 to 4.2.0 (#2461)7d09575 Bump flatted from 3.3.1 to 3.4.2 (#2460)0f9f3aa Bump actions/publish-immutable-action (#2458)f9e715a block checking out fork pr for pull_request_target and workflow_run (#2454)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR@dependabot recreate will recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Bumps googleapis/release-please-action from 4 to 5.
Sourced from googleapis/release-please-action's releases.
v5.0.0
5.0.0 (2026-04-22)
⚠ BREAKING CHANGES
- upgrade to node24 (#1188)
Features
Bug Fixes
v4.4.1
4.4.1 (2026-02-20)
Bug Fixes
v4.4.0
4.4.0 (2025-10-09)
Features
Bug Fixes
changelog-hostparameter ignored when using manifest configuration (#1151) (535c413)- bump mocha from 11.7.1 to 11.7.2 in the npm_and_yarn group across 1 directory (#1149) (3612a99)
- bump release-please from 17.1.2 to 17.1.3 (#1158) (66fbfe9)
v4.3.0
4.3.0 (2025-08-20)
Features
- deps: update release-please to 17.1.2 (f07192c)
v4.2.0
4.2.0 (2025-03-07)
... (truncated)
Sourced from googleapis/release-please-action's changelog.
4.1.1 (2024-05-14)
Bug Fixes
- bump release-please from 16.10.0 to 16.10.2 (#969) (aa764e0)
- bump the npm_and_yarn group with 1 update (#967) (ce529d4)
4.1.0 (2024-03-11)
Features
4.0.3 (2024-03-11)
Bug Fixes
4.0.2 (2023-12-18)
Bug Fixes
- bump release-please from 16.4.0 to 16.5.0 (#905) (df71963)
- log release-please version (#910) (2a496d1), closes #325
4.0.1 (2023-12-07)
Bug Fixes
4.0.0 (2023-12-01)
⚠ BREAKING CHANGES
- remove most configuration options in favor of manifest configuration to configure the release-please-action
- rewrite in typescript
- remove command option in favor of setting
release-typeandskip-github-release/skip-github-pull-request- run on node20
- deps: upgrade release-please to v16
- v4 release
Features
... (truncated)
Bumps actions/upload-artifact from 4 to 7.
Sourced from actions/upload-artifact's releases.
v7.0.0
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new
archiveparameter tofalseto skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. Thenameparameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.ESM
To support new versions of the
@actions/*packages, we've upgraded the package to ESM.What's Changed
- Add proxy integration test by
@Link- in actions/upload-artifact#754- Upgrade the module to ESM and bump dependencies by
@danwkennedyin actions/upload-artifact#762- Support direct file uploads by
@danwkennedyin actions/upload-artifact#764New Contributors
@Link- made their first contribution in actions/upload-artifact#754Full Changelog: actions/upload-artifact@v6...v7.0.0
v6.0.0
v6 - What's new
[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (
runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.Node.js 24
This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
- Upload Artifact Node 24 support by
@salmanmkcin actions/upload-artifact#719- fix: update
@actions/artifactfor Node.js 24 punycode deprecation by@salmanmkcin actions/upload-artifact#744- prepare release v6.0.0 for Node.js 24 support by
@salmanmkcin actions/upload-artifact#745Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0
v5.0.0
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.
- Update README.md by
@GhadimiRin actions/upload-artifact#681- Update README.md by
@nebuk89in actions/upload-artifact#712- Readme: spell out the first use of GHES by
@danwkennedyin actions/upload-artifact#727- Update GHES guidance to include reference to Node 20 version by
@patrikpolyakin actions/upload-artifact#725- Bump
@actions/artifacttov4.0.0- Prepare
v5.0.0by@danwkennedyin actions/upload-artifact#734
... (truncated)
043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency634250c Include changes in typespec/ts-http-runtime 0.3.5e454baa Readme: bump all the example versions to v7 (#796)74fad66 Update the readme with direct upload details (#795)bbbca2d Support direct file uploads (#764)589182c Upgrade the module to ESM and bump dependencies (#762)47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460 Add proxy integration testb7c566a Merge pull request #745 from actions/upload-artifact-v6-releasee516bc8 docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR@dependabot recreate will recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps actions/setup-dotnet from 5 to 6.
Sourced from actions/setup-dotnet's releases.
v6.0.0
What's Changed
- Migrate to ESM and upgrade dependencies by
@priyagupta108in actions/setup-dotnet#752- Bump actions/checkout from 6.0.3 to 7.0.0 by
@dependabot[bot] in actions/setup-dotnet#751- chore(deps): bump
@actions/cacheto 6.2.0 by@philip-gaiin actions/setup-dotnet#756New Contributors
@philip-gaimade their first contribution in actions/setup-dotnet#756Full Changelog: actions/setup-dotnet@v5...v6.0.0
v5.4.0
What's Changed
Enhancements
- Improve global.json SDK version validation for rollForward by
@priyagupta108in actions/setup-dotnet#742- Pin actions to commit SHAs in workflows by
@priya-kinthaliin actions/setup-dotnet#744- Expand the CSC problem matcher to light up more errors on GitHub. by
@StephenClearyin actions/setup-dotnet#717Documentation
- Docs(action): Explicitly mark all optional inputs with required: false by
@kranthipoturajuin actions/setup-dotnet#737Bug Fixes
- Fix global.json creation command by
@michal2612in actions/setup-dotnet#694Dependency Updates
- Upgrade
@actions/cacheto 5.1.0, log cache write denied by@jasonginin actions/setup-dotnet#746New Contributors
@jasonginmade their first contribution in actions/setup-dotnet#746@michal2612made their first contribution in actions/setup-dotnet#694@kranthipoturajumade their first contribution in actions/setup-dotnet#737@StephenClearymade their first contribution in actions/setup-dotnet#717Full Changelog: actions/setup-dotnet@v5...v5.4.0
v5.3.0
What's Changed
Enhancements
- Add dotnet-version: latest support with dotnet-channel input by
@mahabaleshwarsin actions/setup-dotnet#730- Support global.json's rollForward latest* variants by
@js6pakin actions/setup-dotnet#538- Improve version resolution by
@akoeplingerin actions/setup-dotnet#560Dependency Updates
... (truncated)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR@dependabot recreate will recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Adds automation that keeps gridiron-engine aligned with Gridiron.Injury releases by opening package bump PRs when Gridiron.Injury publishes a new package.
injury-package-published repository_dispatch events from the Gridiron.Injury release pipeline.This helps engine maintainers review Gridiron.Injury package updates through normal PR and CI checks before adopting them.
Updates the engine’s Gridiron.Injury dependency to the newly published 0.4.0 release so the engine stays aligned with the current injury package.
Gridiron.Injury from 0.3.0 to 0.4.0 in the engine package.This is a dependency-only update with no engine logic changes.
This PR was generated with Release Please. See documentation.
Clamped 0-yard sacks — where the pass-protection clamp caps YardsGained at 0 to prevent a safety when the offense is backed up to its own 1-yard line — were previously inferred as "not a sack" by YardsGained < 0 heuristics. This corrupted validator aggregate stats, engine player-stat attribution, and play result logging.
PassPlay.IsSack => SackResult != null — a single reliable sack signal (SackResult is only ever assigned on the genuine pass-protection sack path, never on completions, incompletions, spikes, scrambles, or interceptions).AggregateStats.cs): sack classification and the sack-yards matrix now key off IsSack instead of YardsGained < 0, so clamped 0-yard sacks are counted as sacks and no longer leak into incompletions.StatsAccumulator.cs): a clamped 0-yard sack no longer credits the QB a passing attempt or the receiver a target, and now correctly credits DL Sacks/Tackles and OL SacksAllowed.PassResult.cs): clamped 0-yard sacks log as "Sacked" rather than "Incomplete".12345, TestFluentSeedableRandom fluent methods including the new SackYardsBucketRoll).dotnet build && dotnet test: 0 warnings / 0 errors, 1982 passed, 6 skipped, 0 failed.GameProbabilities.cs, SackMatrix.cs) and the clamp logic itself are intentionally unchanged.This PR was generated with Release Please. See documentation.
Fixes a play-by-play logging regression introduced by #300. When PR #300 replaced the YardsGained < 0 sack heuristic with the new PassPlay.IsSack discriminator, the incomplete-vs-sack branch in PassResult.cs (!lastSegment.IsComplete && !play.IsSack) stopped excluding interceptions. As a result, a negative-yard interception return logged a spurious "Incomplete pass." line in addition to the correct interception log. The old YardsGained >= 0 predicate had accidentally suppressed this.
This is log-cosmetic only — no stat/aggregate corruption — but it produced contradictory play narration.
PassResult.cs: incomplete-pass branch now also guards && !play.Interception, so interception returns (including negative-yard returns) no longer emit an "Incomplete pass." log.AggregateStats.cs: simplified the hoisted isSack to passPlay?.IsSack ?? false. The earlier if (play.Interception) branch already classifies interceptions before the sack else if, so the removed !Interception/!IsTouchdown/!isComplete guards are behavior-preserving for all currently-modeled plays (verified against the full suite). This also avoids masking a future strip-sack defensive TD from sack totals.12345, fluent RNG): PassPlay_NegativeYardInterceptionReturn_LogsInterceptionNotIncompletePass — asserts a non-pick-six interception with negative net yards logs the interception and does not log "Incomplete pass".dotnet build && dotnet test: 1983 passed / 6 skipped / 0 failed (baseline 1982 + 1 new test), 0 warnings.play.Fumbles entry/recovery; and PassProtectionSkillsCheckResult logs the raw unclamped sack loss.Restores reliable Gridiron Engine package release automation so published engine releases can reach consumers through the NuGet feed once the required automation token is configured.
This uses the Release Please generic extra-files updater with the x-release-please-version annotation because the csproj version is an arbitrary metadata field rather than a standard manifest file. The publish workflow itself is unchanged.