Skip to content

ci(deps): bump supabase/setup-cli from 1.6.0 to 2.0.0#1035

Merged
ericsocrat merged 2 commits intomainfrom
dependabot/github_actions/main/third-party-ea2dea1e48
Apr 30, 2026
Merged

ci(deps): bump supabase/setup-cli from 1.6.0 to 2.0.0#1035
ericsocrat merged 2 commits intomainfrom
dependabot/github_actions/main/third-party-ea2dea1e48

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 27, 2026

Bumps the third-party group with 1 update: supabase/setup-cli.

Updates supabase/setup-cli from 1.6.0 to 2.0.0

Release notes

Sourced from supabase/setup-cli's releases.

v2.0.0

This major release refreshes the action internals, CI coverage, and release pipeline while keeping usage straightforward with uses: supabase/setup-cli@v2.

Highlights

  • Switched the action implementation to a composite action flow and modernized runtime/dependency setup.
  • Improved CLI version resolution: when version is omitted, the action now detects it from root lockfiles (bun.lock, pnpm-lock.yaml, package-lock.json) and falls back to latest.
  • Expanded validation with dedicated CI + E2E workflows and updated docs/examples around @v2.
  • Hardened repository automation and supply-chain posture (pinned actions, Dependabot workflow/policy updates, licensed workflow fixes).
  • Migrated away from old bundled distribution/test setup to a cleaner Bun-based project structure.

Maintenance updates

  • Dependency refreshes across Bun/TypeScript and GitHub Actions tooling.
  • Documentation and workflow cleanup for long-term maintainability.

Contributors

Thanks to everyone who contributed to this release:

Full changelog

36 commits between v1.6.0 and v2.0.0
Compare changes

Commits
  • df56b21 chore(deps-dev): bump the bun-minor-patch group with 2 updates (#419)
  • 6c93bde chore(deps-dev): bump @​types/bun from 1.3.11 to 1.3.12 in the bun-minor-patch...
  • 7fcab5b chore(deps-dev): bump @​typescript/native-preview from 7.0.0-dev.20260409.1 to...
  • 6081904 [codex] fix dependabot actions cooldown config (#414)
  • c099ad8 fix: auto-approval and refine dependabot policy (#412)
  • afb0a59 fix: await main function (#411)
  • 7fef86c fix: licensed workflow trigger (#413)
  • 337fb0d chore(deps-dev): bump @​typescript/native-preview from 7.0.0-dev.20260401.1 to...
  • 33d1b57 chore(deps-dev): bump the bun-development group with 3 updates (#408)
  • 24d47d8 chore(deps): bump ruby/setup-ruby from 1.299.0 to 1.300.0 in the actions-mino...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the third-party group with 1 update: [supabase/setup-cli](https://github.com/supabase/setup-cli).


Updates `supabase/setup-cli` from 1.6.0 to 2.0.0
- [Release notes](https://github.com/supabase/setup-cli/releases)
- [Commits](supabase/setup-cli@b60b589...df56b21)

---
updated-dependencies:
- dependency-name: supabase/setup-cli
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: third-party
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added ci CI/CD / GitHub Actions workflows dependencies Dependency updates (Dependabot) labels Apr 27, 2026
@dependabot dependabot Bot requested a review from ericsocrat as a code owner April 27, 2026 04:36
@vercel
Copy link
Copy Markdown

vercel Bot commented Apr 27, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tryvit Ready Ready Preview, Comment Apr 30, 2026 10:26am

@github-actions github-actions Bot added major-update Major version bump requiring manual review needs-review Requires human review before merge labels Apr 27, 2026
@ericsocrat ericsocrat changed the title deps(actions)(deps): bump supabase/setup-cli from 1.6.0 to 2.0.0 in the third-party group ci(deps): bump supabase/setup-cli from 1.6.0 to 2.0.0 Apr 30, 2026
@ericsocrat ericsocrat merged commit 4c00620 into main Apr 30, 2026
13 checks passed
@ericsocrat ericsocrat deleted the dependabot/github_actions/main/third-party-ea2dea1e48 branch April 30, 2026 10:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD / GitHub Actions workflows dependencies Dependency updates (Dependabot) major-update Major version bump requiring manual review needs-review Requires human review before merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant