Skip to content

Bump taskcluster from 107.0.0 to 108.1.0 - #2853

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/taskcluster-108.1.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/taskcluster-108.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps taskcluster from 107.0.0 to 108.1.0.

Release notes

Sourced from taskcluster's releases.

v108.1.0

GENERAL

▶ [patch] Bumps uv to v0.12.8 for the in-tree ci and python docker images, the taskgraph decision image to v24.2.3, the git for windows version to v2.55.0, and the nvm version used during releases to v0.40.7.

▶ [patch] Upgrades to Node.js v24.20.0.

▶ [patch] Upgrades to go1.27.1 and golangci-lint v2.13.2.

Release notes here.

▶ [patch] Upgrades to rust v1.98.0.

WORKER-DEPLOYERS

▶ [patch] Generic Worker no longer deadlocks on shutdown or when interrupted with Ctrl+C / SIGINT while a task is running. Shutdown waits on task completions until no tasks remain, instead of blocking on a wait group that only advanced when those completions were processed.

▶ [patch] bug 2069456 On Windows multiuser workers, command environment read by generic-worker from the task directory will now refuse to follow links.

▶ [patch] bug 2069456 On Windows multiuser workers, command scripts written by generic-worker into the task directory will now refuse to follow links.

USERS

▶ [minor] bug 1917274 The github service publishes a new exchange/taskcluster-github/v1/taskcluster-yml-update message when a push changes a repository's .taskcluster.yml. The ordinary push message is still published as well, so existing consumers are unaffected.

The payload names the organization, the repository, the ref that was pushed to, and the webhook delivery id, and nothing else. It deliberately does not carry the file's contents. A consumer can therefore act on a push in one repository from inside another, treating the ref as a value to compare against rather than one to pass on.

DEVELOPERS

▶ [patch] bug 2066797 Changes the pull-request policy to public_restricted and isolates trusted and untrusted task graphs. External pull requests run at level 1 with separate caches, without secrets or generic-worker CI, and rebuild Docker images instead of sharing an image index. Collaborators can trigger the full level-3 graph with /taskcluster run.

▶ [patch] #9093 UI Scopes pages (ViewScope and ScopesetExpander) switch from GraphQL to direct REST service calls.

▶ [patch] #9074 UI WMViewWorkers and WMViewWorkerPools pages switches to use direct REST API calls

... (truncated)

Changelog

Sourced from taskcluster's changelog.

v108.1.0

GENERAL

▶ [patch] Bumps uv to v0.12.8 for the in-tree ci and python docker images, the taskgraph decision image to v24.2.3, the git for windows version to v2.55.0, and the nvm version used during releases to v0.40.7.

▶ [patch] Upgrades to Node.js v24.20.0.

▶ [patch] Upgrades to go1.27.1 and golangci-lint v2.13.2.

Release notes here.

▶ [patch] Upgrades to rust v1.98.0.

WORKER-DEPLOYERS

▶ [patch] Generic Worker no longer deadlocks on shutdown or when interrupted with Ctrl+C / SIGINT while a task is running. Shutdown waits on task completions until no tasks remain, instead of blocking on a wait group that only advanced when those completions were processed.

▶ [patch] bug 2069456 On Windows multiuser workers, command environment read by generic-worker from the task directory will now refuse to follow links.

▶ [patch] bug 2069456 On Windows multiuser workers, command scripts written by generic-worker into the task directory will now refuse to follow links.

USERS

▶ [minor] bug 1917274 The github service publishes a new exchange/taskcluster-github/v1/taskcluster-yml-update message when a push changes a repository's .taskcluster.yml. The ordinary push message is still published as well, so existing consumers are unaffected.

The payload names the organization, the repository, the ref that was pushed to, and the webhook delivery id, and nothing else. It deliberately does not carry the file's contents. A consumer can therefore act on a push in one repository from inside another, treating the ref as a value to compare against rather than one to pass on.

DEVELOPERS

▶ [patch] bug 2066797 Changes the pull-request policy to public_restricted and isolates trusted and untrusted task graphs. External pull requests run at level 1 with separate caches, without secrets or generic-worker CI, and rebuild Docker images instead of sharing an image index. Collaborators can trigger the full level-3 graph with /taskcluster run.

▶ [patch] #9093 UI Scopes pages (ViewScope and ScopesetExpander) switch from GraphQL to direct REST service calls.

▶ [patch] #9074

... (truncated)

Commits
  • f86624a v108.1.0
  • 5b76c14 Merge pull request #9075 from taskcluster/matt-boris/gwWaitForAllDeadlock
  • e0d30c3 fix(generic-worker): drain remaining task completions on shutdown
  • 38eb9fc Merge pull request #9048 from aminehmida/bug-1917274-taskcluster-yml-update
  • b5569a2 feat(ci): Switch taskcluster.yml to public_restricted (#9055)
  • 9c0fe29 Merge pull request #9130 from Eijebong/safefs-extra
  • 8fcd40d Bug 2069456 - Use safefs to read environment files from the task directory
  • 5974da0 Bug 2069456 - Use safefs when writing commands on windows multiuser workers
  • 253ec78 Merge pull request #9125 from taskcluster/docker-worker-schema-alignment
  • 7cbd636 Move TestDockerWorkerSchemaMatchesD2G to a posix-only file
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [taskcluster](https://github.com/taskcluster/taskcluster) from 107.0.0 to 108.1.0.
- [Release notes](https://github.com/taskcluster/taskcluster/releases)
- [Changelog](https://github.com/taskcluster/taskcluster/blob/main/CHANGELOG.md)
- [Commits](taskcluster/taskcluster@v107.0.0...v108.1.0)

---
updated-dependencies:
- dependency-name: taskcluster
  dependency-version: 108.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 14, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 15, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2854.

@dependabot dependabot Bot closed this Sep 15, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/taskcluster-108.1.0 branch September 15, 2026 00:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants