)]}'
{
  "log": [
    {
      "commit": "f8c383cb9d69b821ea3fd4e0279fb7a0ffbd94c6",
      "tree": "1ac010641ce1f795d720a70eef8f70c777944e16",
      "parents": [
        "6d31aed1acf67506ed8df35775fb321a8be8a984"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Sep 24 10:08:46 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 24 10:08:46 2026 +0800"
      },
      "message": "build(deps): bump taiki-e/install-action from 2.87.12 to 2.87.13 (#882)\n\nBumps\n[taiki-e/install-action](https://github.com/taiki-e/install-action) from\n2.87.12 to 2.87.13.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/releases\"\u003etaiki-e/install-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.87.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ezola@latest\u003c/code\u003e to 0.23.6.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003evacuum@latest\u003c/code\u003e to 0.30.5.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003etombi@latest\u003c/code\u003e to 1.5.5.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.167.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eprotoc-gen-connect-openapi@latest\u003c/code\u003e to 0.27.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eprek@latest\u003c/code\u003e to 0.5.3.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eosv-scanner@latest\u003c/code\u003e to 2.6.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.7.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.21.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-leptos@latest\u003c/code\u003e to 0.3.8.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-auditable@latest\u003c/code\u003e to 0.7.6.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md\"\u003etaiki-e/install-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003cp\u003eAll notable changes to this project will be documented in this\nfile.\u003c/p\u003e\n\u003cp\u003eThis project adheres to \u003ca href\u003d\"https://semver.org\"\u003eSemantic\nVersioning\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e[Unreleased]\u003c/h2\u003e\n\u003ch2\u003e[2.87.17] - 2026-09-20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.17.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.169.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekingfisher@latest\u003c/code\u003e to 2.5.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.25.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003egit-cliff@latest\u003c/code\u003e to 2.14.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-tarpaulin@latest\u003c/code\u003e to 0.37.3.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-leptos@latest\u003c/code\u003e to 0.3.9.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[2.87.16] - 2026-09-19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.16.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.168.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eprotoc@latest\u003c/code\u003e to 3.36.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.11.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[2.87.15] - 2026-09-18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003esyft@latest\u003c/code\u003e to 1.52.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.10.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekingfisher@latest\u003c/code\u003e to 2.4.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.23.1.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecoreutils@latest\u003c/code\u003e to 0.12.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/26e9283f268b880168bdbd2c545dfcd60ec2c6ab\"\u003e\u003ccode\u003e26e9283\u003c/code\u003e\u003c/a\u003e\nRelease 2.87.13\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/04a4a8246c7a2f2eaf87e42293bca7269081db97\"\u003e\u003ccode\u003e04a4a82\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003ezola@latest\u003c/code\u003e to 0.23.6\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/b9c60f15f4eb442f41065a510b0f59af400f446f\"\u003e\u003ccode\u003eb9c60f1\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003evacuum@latest\u003c/code\u003e to 0.30.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/b31d41ab50dced8ea9cf3c57e9d5cc72056195b8\"\u003e\u003ccode\u003eb31d41a\u003c/code\u003e\u003c/a\u003e\nUpdate uv manifest\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/1b200db2bbc6f05645c43889fb464ddf599f8342\"\u003e\u003ccode\u003e1b200db\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003etombi@latest\u003c/code\u003e to 1.5.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/d3a7a77950c0ece9292ebee57d72a8b83d4d352c\"\u003e\u003ccode\u003ed3a7a77\u003c/code\u003e\u003c/a\u003e\nUpdate sccache manifest\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/3e3c2df701b5f6f49f22ed085cd483c3a315a5ad\"\u003e\u003ccode\u003e3e3c2df\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.167\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/d4446731e441b4b4ec4f412c6f953fd4accd114b\"\u003e\u003ccode\u003ed444673\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003eprotoc-gen-connect-openapi@latest\u003c/code\u003e to 0.27.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/e75a66b87d55a9adef6d69af04b0f69631daf082\"\u003e\u003ccode\u003ee75a66b\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003eprek@latest\u003c/code\u003e to 0.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/034ed194fcb80aefbc57346f8e914946d777dee6\"\u003e\u003ccode\u003e034ed19\u003c/code\u003e\u003c/a\u003e\nUpdate oxfmt manifest\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/compare/3f74d7c16a4242f1c95561e98edc25d36adb4375...26e9283f268b880168bdbd2c545dfcd60ec2c6ab\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dtaiki-e/install-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.87.12\u0026new-version\u003d2.87.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6d31aed1acf67506ed8df35775fb321a8be8a984",
      "tree": "2c993395251d6edb5b7a408b1edc8c1e70fe9a15",
      "parents": [
        "6515ea49b207fa730f4ddad7df8bcebf709a50cc"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Tue Sep 22 16:59:17 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 22 16:59:17 2026 +0800"
      },
      "message": "chore: prepare v0.20.7 release (#880)\n\nPrepare Apache OpenDAL reqsign 0.20.7. Aliyun OSS, AWS core, Azure\nStorage, and Google receive minor bumps for their new public credential\ncapabilities; the facade and remaining crates receive patch bumps, with\nworkspace dependency requirements aligned.\n\nGoogle `Credential` now includes `signer_email`. Exhaustive struct\nliterals and patterns need to include the new field or use a\ndefault/rest pattern. Public downstream searches found no affected\nindependent callers; this release retains the current major versions\nwith that compatibility change documented."
    },
    {
      "commit": "6515ea49b207fa730f4ddad7df8bcebf709a50cc",
      "tree": "097bdafc95eb7363357b800b36598babd4ba5fcb",
      "parents": [
        "29f3a9a529f21a5ae0ae32cc9c0967045569d96d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Sep 21 22:37:47 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 21 22:37:47 2026 +0800"
      },
      "message": "build(deps): bump taiki-e/install-action from 2.87.4 to 2.87.12 (#879)\n\nBumps\n[taiki-e/install-action](https://github.com/taiki-e/install-action) from\n2.87.4 to 2.87.12.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/releases\"\u003etaiki-e/install-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.87.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ewasmtime@latest\u003c/code\u003e to 48.0.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ewasm-tools@latest\u003c/code\u003e to 1.259.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.13.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.165.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eprotoc-gen-connect-openapi@latest\u003c/code\u003e to 0.27.1.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.5.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-nextest@latest\u003c/code\u003e to 0.9.144.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.87.11\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ebiome@latest\u003c/code\u003e to 2.5.13.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.12.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.4.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.19.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.87.10\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ezizmor@latest\u003c/code\u003e to 1.30.1.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.11.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003etombi@latest\u003c/code\u003e to 1.5.4.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.164.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.3.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekingfisher@latest\u003c/code\u003e to 2.2.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.87.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eoxfmt@latest\u003c/code\u003e to 1.82.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.18.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ed2@latest\u003c/code\u003e to 0.9.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ebpf-linker@latest\u003c/code\u003e to 0.11.1.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.87.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003eshfmt@latest\u003c/code\u003e to 3.14.1.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md\"\u003etaiki-e/install-action\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003cp\u003eAll notable changes to this project will be documented in this\nfile.\u003c/p\u003e\n\u003cp\u003eThis project adheres to \u003ca href\u003d\"https://semver.org\"\u003eSemantic\nVersioning\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e[Unreleased]\u003c/h2\u003e\n\u003ch2\u003e[2.87.17] - 2026-09-20\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.17.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.169.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekingfisher@latest\u003c/code\u003e to 2.5.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.25.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003egit-cliff@latest\u003c/code\u003e to 2.14.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-tarpaulin@latest\u003c/code\u003e to 0.37.3.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecargo-leptos@latest\u003c/code\u003e to 0.3.9.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[2.87.16] - 2026-09-19\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.16.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.168.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003eprotoc@latest\u003c/code\u003e to 3.36.2.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.11.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[2.87.15] - 2026-09-18\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003esyft@latest\u003c/code\u003e to 1.52.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.10.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekingfisher@latest\u003c/code\u003e to 2.4.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ekache@latest\u003c/code\u003e to 0.23.1.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate \u003ccode\u003ecoreutils@latest\u003c/code\u003e to 0.12.0.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/3f74d7c16a4242f1c95561e98edc25d36adb4375\"\u003e\u003ccode\u003e3f74d7c\u003c/code\u003e\u003c/a\u003e\nRelease 2.87.12\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/e7f36aa5946476a40e5a2af1a5153c247e70d548\"\u003e\u003ccode\u003ee7f36aa\u003c/code\u003e\u003c/a\u003e\nUpdate wasmtime manifest\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/b208ecf6341e27a32fd9a0f8e1821a008552f41c\"\u003e\u003ccode\u003eb208ecf\u003c/code\u003e\u003c/a\u003e\nUpdate zola manifest\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/497268209395d5883d6a88462e1c9c6bf3fbbeff\"\u003e\u003ccode\u003e4972682\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003ewasmtime@latest\u003c/code\u003e to 48.0.2\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/9f978f55d62c453c7eb420ab8cc3f13ba748aa42\"\u003e\u003ccode\u003e9f978f5\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003ewasm-tools@latest\u003c/code\u003e to 1.259.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/01d96944a7a5eab62bfb45b5ba70d36285f8534c\"\u003e\u003ccode\u003e01d9694\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003euv@latest\u003c/code\u003e to 0.12.13\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/7af43af4f6fc1df7d126ab45be6a2e8770112f87\"\u003e\u003ccode\u003e7af43af\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003erelease-plz@latest\u003c/code\u003e to 0.3.165\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/5ebe8aae964ff306a8f78d0e61277195869cc640\"\u003e\u003ccode\u003e5ebe8aa\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003eprotoc-gen-connect-openapi@latest\u003c/code\u003e to 0.27.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/c054431878700879a4853ce12d3c492be3580620\"\u003e\u003ccode\u003ec054431\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003emise@latest\u003c/code\u003e to 2026.9.5\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/commit/2ad5cec3cabb51430ef1c2ac40ba63f32add42a9\"\u003e\u003ccode\u003e2ad5cec\u003c/code\u003e\u003c/a\u003e\nUpdate \u003ccode\u003ecargo-nextest@latest\u003c/code\u003e to 0.9.144\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/taiki-e/install-action/compare/e67fa11c4b9316fa714ddf0abed07a0c3143b95b...3f74d7c16a4242f1c95561e98edc25d36adb4375\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dtaiki-e/install-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.87.4\u0026new-version\u003d2.87.12)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "29f3a9a529f21a5ae0ae32cc9c0967045569d96d",
      "tree": "d5ec36f615008965ac6f3313c47eccecbc73f441",
      "parents": [
        "75a7526c8393b0d0c3a57119dfb6ec737da9a8e5"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Sep 10 17:56:56 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 10 17:56:56 2026 +0800"
      },
      "message": "fix(ci): isolate Azure live-test resources (#873)\n\nAzure live tests fail across providers when the shared `probe.txt`\ndisappears. The CI storage account has a lifecycle policy that deletes\nblobs older than one day, so a persistent probe cannot be a prerequisite\nfor running tests. Each live-test job now creates its own private probe\nand removes it after the test command exits. SAS cases receive a\nshort-lived, read-only token for that object. GitHub owns the Azure\nPipelines probe through completion or cancellation, preserving the\npipeline identity\u0027s existing Blob Reader access. A run variable carries\nthe probe URL without requiring new parameters in the deployed bootstrap\nYAML. The pipeline definition explicitly permits overriding this\nnon-secret variable at queue time; other queue-time variable\nrestrictions remain enabled.\n\nIMDS deployment retries also use distinct resource names and clean up\npartially created NICs and disks. This prevents a failed deployment in\n`eastus` from blocking the `eastus2` fallback with\n`InvalidResourceLocation`. The AWS IMDS VM also gets temporary swap for\nDocker installation, which previously exited with status 137 on\n`t3.nano`.\n\nManual validation on `460239b`: live Azure Shared Key and SAS reads\npassed through static/environment providers and signing tests; probe\ndeletion was verified after both successful tests and a command exiting\nwith status 42. The Azure IMDS live job passed in [GitHub\nActions](https://github.com/apache/opendal-reqsign/actions/runs/34318191615/job/102362919696).\nActual Azure Pipelines execution at `37c9713` passed in [run\n24](https://dev.azure.com/opendal/21fcc908-2c7c-4d8a-860c-494e79b71a15/_build/results?buildId\u003d24),\nincluding probe cleanup. YAML previews alone do not validate permission\nto override queue-time variables. All 63 GitHub checks passed on\n`2b7cab4`, including the complete [Azure live-test\nworkflow](https://github.com/apache/opendal-reqsign/actions/runs/34451684909)\nand [AWS live-test\nworkflow](https://github.com/apache/opendal-reqsign/actions/runs/34451684906).\nThe AWS IMDS bootstrap completed successfully with temporary swap."
    },
    {
      "commit": "75a7526c8393b0d0c3a57119dfb6ec737da9a8e5",
      "tree": "ac602ab181e4297e69b5756d39efd09716e67644",
      "parents": [
        "ad3ce5a1d067aba756296a4cc11aec164aa9fa32"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Wed Sep 09 01:42:16 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 09 01:42:16 2026 +0800"
      },
      "message": "chore: drop unnecessary futures dependency (#871)"
    },
    {
      "commit": "ad3ce5a1d067aba756296a4cc11aec164aa9fa32",
      "tree": "59adce572003c9d7841b5927feca86239a75d7c1",
      "parents": [
        "0466288735c6c0e42626543f13c7e2ffb9171248"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Tue Sep 08 18:07:46 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 18:07:46 2026 +0800"
      },
      "message": "refactor: unify async synchronization with AsyncBand (#870)\n\n## Summary\n\nReqsign uses Tokio and futures synchronization alongside AsyncBand,\nwhile concurrent Azure SAS cache misses can issue identical user\ndelegation key requests. Use AsyncBand consistently for async\nsynchronization and coalesce those Azure key requests.\n\n- Replace the Google client-side CAB cache and refresh mutexes with\n`asyncband::mutex::Mutex`.\n- Replace Tokio semaphores in the Azure and Google concurrency tests,\nand futures oneshot channels in the core signer tests and WASM Reqwest\nresponse bridge.\n- Use `Group::try_work` for Azure user delegation keys, partitioned by\naccount, endpoint, source-token fingerprint, service version, and\nrequested key start and expiry. Retain the bounded cache and per-grant\nSAS validity checks; waiting callers can retry after a failed or\ncancelled key request.\n- Declare AsyncBand features at their use sites and remove the replaced\nGoogle futures and WASM futures-channel dependencies.\n\n## Testing\n\nThe full workspace suite includes Google client-side CAB refresh\nsharing, partition isolation, and cancellation tests. The four Azure\ncoordination tests pass; three reproduce duplicate requests against the\noriginal implementation. The existing WASM HTTP test also passes under\nNode with wasm-bindgen-test-runner 0.2.128.\n\n- `cargo fmt --all -- --check`\n- `cargo clippy --workspace --all-targets --all-features -- -D warnings`\n- `cargo test --workspace --all-features --no-fail-fast` (including doc\ntests)\n- `cargo build --manifest-path reqsign/Cargo.toml --target\nwasm32-unknown-unknown --no-default-features --features\ndefault-context,aws,aws-v4a,azure,aliyun,tencent`\n- `cargo test --target wasm32-unknown-unknown -p\nreqsign-http-send-reqwest --test wasm`\n- `hawkeye check`\n\nRepository-wide scanning found no remaining direct uses of Tokio or\nfutures synchronization primitives. Live cloud service tests were not\nrun locally.\n\nAI assisted with the implementation, tests, and PR draft."
    },
    {
      "commit": "0466288735c6c0e42626543f13c7e2ffb9171248",
      "tree": "6f881dbc1c57ef12f11de5dd5b797ae1b9d6e0c8",
      "parents": [
        "613813b1570d5da398acf8889e986e0aa90211c3"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Tue Sep 08 13:40:59 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Sep 08 13:40:59 2026 +0800"
      },
      "message": "test(google): validate credentials with live services (#869)\n\nGoogle credential integration tests previously accepted token parsing\nand local mock-server behavior without proving that the resulting\ncredential could access Google Cloud. That left endpoint,\nprovider-chain, scope, and IAM regressions outside the acceptance\nboundary.\n\nThis change makes a fixed private Cloud Storage object the shared live\nacceptance oracle across static, file, environment, well-known, default,\nauthorized-user, workload-identity, token, impersonation, VM metadata,\nCredential Access Boundary, and signing paths. The deterministic suite\nalso replays sanitized responses captured from Google services and\nrejects fixtures that contain credential material.\n\nThe Google workflow now follows the AWS and Azure layout:\n\n- deterministic tests, live-resource preparation, and each credential\npath run as distinct jobs;\n- failures are isolated to the affected provider or signing path;\n- a final summary preserves one aggregate workflow result;\n- untrusted pull requests run only deterministic coverage, while\nsame-repository non-Dependabot pull requests and pushes to `main` run\nthe live suite.\n\nVM metadata coverage uses a private `e2-micro` instance with a bounded\nruntime and unconditional cleanup of the instance and uploaded test\nbinary. Persistent test resources remain in the personal `reqsign` GCP\nproject.\n\nThe PR also adds `Standard_D2s_v7` as an Azure IMDS test fallback in\n`eastus2`, where the older configured sizes can be unavailable or time\nout during VM startup.\n\nThe Azure IMDS test also uses a flat blob name so HNS cleanup removes\nthe binary without leaving empty per-run directories."
    },
    {
      "commit": "613813b1570d5da398acf8889e986e0aa90211c3",
      "tree": "0fff152974180aa3ed0800d3f0ab4d510d2284e1",
      "parents": [
        "0c93e4a97777776b09a499f23ba6bb06e0820482"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Sep 07 16:36:11 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Sep 07 16:36:11 2026 +0800"
      },
      "message": "build(deps): bump 1Password/load-secrets-action/configure from 4.1.1 to 5.0.1 (#853)\n\nBumps\n[1Password/load-secrets-action/configure](https://github.com/1password/load-secrets-action)\nfrom 4.1.1 to 5.0.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/releases\"\u003e1Password/load-secrets-action/configure\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect the authentication error message. It previously listed only\nthe CLI methods (\u003ccode\u003eOP_SERVICE_ACCOUNT_TOKEN\u003c/code\u003e, or\n\u003ccode\u003eOP_CONNECT_HOST\u003c/code\u003e + \u003ccode\u003eOP_CONNECT_TOKEN\u003c/code\u003e), which\nmisled anyone who meant to use Workload Identity but had one of those\nvariables missing or misspelled. It now lists\n\u003ccode\u003eOP_WORKLOAD_ID\u003c/code\u003e + \u003ccode\u003eOP_ENVIRONMENT_ID\u003c/code\u003e +\n\u003ccode\u003eOP_INTEGRATION_KEY\u003c/code\u003e as a third valid option. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/187\"\u003e#187\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump \u003ccode\u003e@1password/sdk\u003c/code\u003e from \u003ccode\u003e0.5.0-beta.1\u003c/code\u003e to\nthe stable \u003ccode\u003e0.5.0\u003c/code\u003e, and rebuild \u003ccode\u003edist/\u003c/code\u003e (including\n\u003ccode\u003ecore_bg.wasm\u003c/code\u003e). (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/187\"\u003e#187\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpdate the baked-in beta CLI fallback version:\n\u003ccode\u003e2.38.1-beta.02\u003c/code\u003e → \u003ccode\u003e2.39.0-beta.02\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHarden CI: add the StepSecurity harden-runner and pin GitHub Actions\nto commit SHAs across the E2E and fallback-version workflows, and\nrestrict workflow permissions. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/182\"\u003e#182\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v5.0.0...v5.0.1\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v5.0.0...v5.0.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Workload Identity authentication using the GitHub Actions OIDC\ntoken (public preview). (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v4.1.1...v5.0.0\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v4.1.1...v5.0.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0-beta.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFeature\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Workload Identity authentication using the GitHub Actions OIDC\ntoken (private beta) (\u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v4.0.0...v5.0.0-beta.1\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v4.0.0...v5.0.0-beta.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/70062d7a876d3eb6334754fa26efd2fbd90c32f2\"\u003e\u003ccode\u003e70062d7\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/190\"\u003e#190\u003c/a\u003e\nfrom 1Password/release/v5.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/6f5bd0ee534cf837bfa1f87ea2845aec1549d969\"\u003e\u003ccode\u003e6f5bd0e\u003c/code\u003e\u003c/a\u003e\nPrepare Release 5.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/846abe067a096b604798cbf52d62328922142eb3\"\u003e\u003ccode\u003e846abe0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/187\"\u003e#187\u003c/a\u003e\nfrom 1Password/jill/bump-to-stable-sdk\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/557708fd563fb71e25c7bd961d11c0ca93970072\"\u003e\u003ccode\u003e557708f\u003c/code\u003e\u003c/a\u003e\nBump sdk type\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2d8a25ce9566884d7eb34769a8a3a32031d3ff42\"\u003e\u003ccode\u003e2d8a25c\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/182\"\u003e#182\u003c/a\u003e\nfrom 1Password/chore/GHA-211518-stepsecurity-remediation\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/e544b780808654ba8ceba5fb2fe2897103d92ff4\"\u003e\u003ccode\u003ee544b78\u003c/code\u003e\u003c/a\u003e\nPrepare Release v5.0.0 (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/185\"\u003e#185\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/631992c4a12d3c60fd97d3c2dfbe51047a8b7fba\"\u003e\u003ccode\u003e631992c\u003c/code\u003e\u003c/a\u003e\nApply GitHub Actions security best practices\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/compare/eb2efd0703da22a93c467f2d1ffbb6826c11e19c...70062d7a876d3eb6334754fa26efd2fbd90c32f2\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0c93e4a97777776b09a499f23ba6bb06e0820482",
      "tree": "9961c74fe0cbd597af8015981825883c426a033b",
      "parents": [
        "242894350b058dde1bafa147a9b8958bdbfaa3fb"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Fri Sep 04 13:44:12 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Sep 04 13:44:12 2026 +0800"
      },
      "message": "refactor: replace mea with asyncband 0.7.1 (#868)"
    },
    {
      "commit": "242894350b058dde1bafa147a9b8958bdbfaa3fb",
      "tree": "6a8667b4b9d0086d309959cef46ab1967225c8b4",
      "parents": [
        "c95777905687f674b56a1f098ed178f6c239fbee"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Sep 03 20:08:40 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Sep 03 20:08:40 2026 +0800"
      },
      "message": "test(azure): cover credential providers with live services (#867)\n\nAzure credential-provider coverage relied on synthetic responses and\nlocal provider mocks, so it did not verify Microsoft Entra token\ncontracts or cloud-specific runtime behavior.\n\nThis change runs every Azure Storage credential provider against a fixed\nprivate Blob in trusted CI environments and uses redacted responses\ncaptured from Azure for deterministic parser coverage. It also fixes the\nactual-service mismatches exposed by that setup: Microsoft Entra v2\ntoken expiration uses `expires_in`, Azure Pipelines OIDC requests\nrequire the service connection ID, and IMDS must honor the configured\nendpoint while URL-encoding identity selectors. Token request failures\nreport status without including potentially sensitive response bodies.\n\nGitHub Actions keeps the existing secret names and gives each credential\nprovider an independent live-test job, matching the AWS workflow\u0027s\nfailure isolation and final summary. Static credentials, environment\ncredentials, client secret, client certificate, Azure CLI, workload\nidentity, IMDS, Azure Pipelines, and the default chain must each obtain\nreal credentials and sign a successful request to the private Blob. A\nseparate signing job validates Shared Key and SAS request signing\nagainst the same Blob; enabled signing tests require complete real\nconfiguration and do not fall back to dummy credentials.\n\nIMDS runs on an ephemeral private Azure VM with a user-assigned managed\nidentity. GitHub Actions uses Microsoft Entra OIDC to queue\n`AzurePipelinesCredentialProvider` in Azure DevOps, passes the exact\nGitHub ref and commit, waits for the result, and reports it as part of\nthe GitHub check. The Azure DevOps pipeline has no repository or\nscheduled trigger and uses an on-demand VMSS pool with zero standby\nagents.\n\nLive validation:\n\n- Azure Pipelines workload identity exchanged an OIDC token and signed a\nsuccessful request to the private Blob:\nhttps://dev.azure.com/opendal/21fcc908-2c7c-4d8a-860c-494e79b71a15/_build/results?buildId\u003d3\n- IMDS acquired a user-assigned managed identity token on an Azure VM\nand signed a successful request to the same private Blob; the temporary\nVM was removed after the test."
    },
    {
      "commit": "c95777905687f674b56a1f098ed178f6c239fbee",
      "tree": "1c5ff12832779b20792c6165ca6ebc5b699f387c",
      "parents": [
        "29d7b3c09baaa0c8d217989719fef8fa960d4167"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Wed Sep 02 21:48:17 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 21:48:17 2026 +0800"
      },
      "message": "ci: migrate to Hawkeye v7 (#866)"
    },
    {
      "commit": "29d7b3c09baaa0c8d217989719fef8fa960d4167",
      "tree": "5bce3502919ff212b3d81de629c7650b0f5d5bcd",
      "parents": [
        "0ec260fdaa06feea84baa046660664feba69cad9"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Sep 02 20:36:23 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 20:36:23 2026 +0800"
      },
      "message": "feat(google): add service account token provider (#863)\n\nCloses #859.\n\nService-account credential files currently produce a credential that\nonly `RequestSigner` can exchange for an OAuth token internally, so they\ncannot be composed with token-only consumers such as the server-side\nCredential Access Boundary granter.\n\nThis adds `ServiceAccountTokenCredentialProvider`, accepting either a\nbound `ServiceAccount` or an explicit Google credential provider. It\nperforms the JWT bearer exchange through the configured context and\nreturns a token-only `Credential` with the source service-account email\npreserved as signer identity. Static, file, and default credential\nsources can therefore feed both existing CAB granters without host-side\nOAuth protocol code.\n\nThe OAuth implementation is shared with `RequestSigner`. Scope\nresolution remains explicit override, then `GOOGLE_SCOPE`, then the\nCloud Platform default. The required `expires_in` response is converted\nto a conservative absolute expiration anchored immediately before\nnetwork I/O and revalidated after the response; private keys,\nassertions, access tokens, and response bodies are excluded from `Debug`\nand returned errors. The provider does not add another cache or change\nthe default credential chain.\n\nThe opt-in CAB live test now covers both server-side and client-side\nflows from service-account JSON. It was not exercised locally because\nthe live Google credentials and bucket configuration were not available."
    },
    {
      "commit": "0ec260fdaa06feea84baa046660664feba69cad9",
      "tree": "4ddd420809cff506f891df145b34198fa3a68863",
      "parents": [
        "f83016f9280d4b72bf6a97f1ff1331c0b57dc17d"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Sep 02 20:29:44 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 20:29:44 2026 +0800"
      },
      "message": "feat: accept caller-provided subject tokens (#864)\n\nCloses #861.\n\nHost applications can bind an opaque, optionally expiring subject token\ndirectly to AWS, Azure, and Google web-identity credential providers.\nToken state and validation remain private to each service alongside\nrole, audience, tenant, endpoint, and exchange semantics; existing file,\nenvironment, and external-account discovery paths remain compatible.\n\nKeeping direct-token handling service-local is deliberate. The existing\nfile and environment flows have different absence and parsing semantics,\nwhile the motivating server workflow already owns the request-scoped\ntoken. This avoids freezing a cross-service asynchronous token-source\ncontract before a shared runtime consumer exists.\n\nKnown source expiration is rejected before exchange I/O, provider debug\noutput is opaque, and token-bearing response bodies are excluded from\nexchange errors. AWS AssumeRoleWithWebIdentity sends form parameters in\na POST body so the subject token is not placed in the request URL.\n\nSigner cache ownership is unchanged: each signer/provider assembly is an\nidentity boundary, clones share the exchanged-credential cache, and\nreplacing the credential provider resets it.\n\nValidation covered the full workspace unit tests, doc tests, Clippy with\nall features and targets, facade all-features compilation, and the\nsupported WASM subset. Live cloud exchanges were not run."
    },
    {
      "commit": "f83016f9280d4b72bf6a97f1ff1331c0b57dc17d",
      "tree": "d385b8e71d736187293e013f4ba52e767a05dc5a",
      "parents": [
        "f66cecc9b8fa35063e32018f17dff3fbe34cc2a7"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Sep 02 20:18:39 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 20:18:39 2026 +0800"
      },
      "message": "feat(google): add service account impersonation granter (#862)\n\nGoogle service-account impersonation is currently tied to the fixed ADC\nand WIF provider flows, so callers cannot apply one target service\naccount to an arbitrary token-only Google credential source or compose\nthe result with Credential Access Boundary granting.\n\nAdd typed `ServiceAccountImpersonationGrant` and\n`ServiceAccountImpersonationGranter` APIs plus a Google-specific\ncredential-provider wrapper. The public flow constructs the canonical\nIAM Credentials endpoint, validates target/scopes/delegates and\nsource/output deadlines around I/O, and returns Google\u0027s authoritative\n`expireTime` with the target signer identity. Existing fixed-flow\nproviders retain their public behavior while sharing the strict\nrequest/response path, including sensitive bearer headers, redacted\nerrors, and mandatory expiration parsing.\n\nThe grant binds authorization configuration. Lifetime remains the\nservice-specific per-call `GrantCredential` parameter; the provider\nwrapper binds a fixed lifetime when provider-oriented composition needs\none.\n\nCloses #860.\n\nLive Google Cloud interoperability was not run for the new generic flow;\ndeterministic protocol tests cover its request shape, validation\nboundaries, cache lifecycle, malformed responses, and redaction\nbehavior."
    },
    {
      "commit": "f66cecc9b8fa35063e32018f17dff3fbe34cc2a7",
      "tree": "54e5c7a2027eebb5ac701f00cf40b12ce6e3d94e",
      "parents": [
        "c465c3c5b132f5d6e232bd98ad8efd623c0554be"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Sep 02 17:11:48 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Sep 02 17:11:48 2026 +0800"
      },
      "message": "build(deps): update quick-xml requirement from 0.41.0 to 0.42.0 (#858)\n\nUpdates the requirements on\n[quick-xml](https://github.com/tafia/quick-xml) to permit the latest\nversion.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/releases\"\u003equick-xml\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.41.0 - Secuirity fixes\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\nAdd \u003ccode\u003eNsReader::resolver_mut()\u003c/code\u003e and\n\u003ccode\u003eNamespaceResolver::{max_declarations_per_element,\nset_max_declarations_per_element}\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003e#969\u003c/a\u003e:\n\u003ccode\u003eAttributes\u003c/code\u003e (and anything that iterates\n\u003ccode\u003eBytesStart::attributes()\u003c/code\u003e with the default\n\u003ccode\u003ewith_checks(true)\u003c/code\u003e) no longer takes O(N²) time on a start\ntag with a large number of attributes. Small tags keep the previous\nlinear scan; larger ones switch to a 64-bit hash pre-filter, so the\nwhole tag is O(N). The exact \u003ccode\u003eAttrError::Duplicated(new,\nprev)\u003c/code\u003e positions are unchanged.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\n\u003ccode\u003eNamespaceResolver::push\u003c/code\u003e (and hence every\n\u003ccode\u003eNsReader\u003c/code\u003e \u003ccode\u003eStart\u003c/code\u003e/\u003ccode\u003eEmpty\u003c/code\u003e event) now\nrejects a start tag that declares more than\n\u003ccode\u003eDEFAULT_MAX_DECLARATIONS_PER_ELEMENT\u003c/code\u003e (256)\n\u003ccode\u003exmlns\u003c/code\u003e / \u003ccode\u003exmlns:*\u003c/code\u003e namespace bindings, returning\nthe new \u003ccode\u003eNamespaceError::TooManyDeclarations\u003c/code\u003e. Previously\n\u003ccode\u003epush\u003c/code\u003e allocated one \u003ccode\u003eNamespaceBinding\u003c/code\u003e per\ndeclaration with no upper bound, before the event was returned to the\ncaller, so an \u003ccode\u003eNsReader\u003c/code\u003e consumer could not bound its memory\nexposure on untrusted input. The limit is configurable via\n\u003ccode\u003eNamespaceResolver::set_max_declarations_per_element\u003c/code\u003e (use\n\u003ccode\u003eusize::MAX\u003c/code\u003e to disable).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003e#969\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003etafia/quick-xml#969\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003etafia/quick-xml#970\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/qifan-sailboat\"\u003e\u003ccode\u003e@​qifan-sailboat\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/972\"\u003etafia/quick-xml#972\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/compare/v0.40.1...v0.41.0\"\u003ehttps://github.com/tafia/quick-xml/compare/v0.40.1...v0.41.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/blob/master/Changelog.md\"\u003equick-xml\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.41.0 -- 2026-06-29\u003c/h2\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\nAdd \u003ccode\u003eNsReader::resolver_mut()\u003c/code\u003e and\n\u003ccode\u003eNamespaceResolver::{max_declarations_per_element,\nset_max_declarations_per_element}\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003e#969\u003c/a\u003e:\n\u003ccode\u003eAttributes\u003c/code\u003e (and anything that iterates\n\u003ccode\u003eBytesStart::attributes()\u003c/code\u003e\nwith the default \u003ccode\u003ewith_checks(true)\u003c/code\u003e) no longer takes O(N²)\ntime on a start\ntag with a large number of attributes. Small tags keep the previous\nlinear\nscan; larger ones switch to a 64-bit hash pre-filter, so the whole tag\nis\nO(N). The exact \u003ccode\u003eAttrError::Duplicated(new, prev)\u003c/code\u003e positions\nare unchanged.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\n\u003ccode\u003eNamespaceResolver::push\u003c/code\u003e (and hence every\n\u003ccode\u003eNsReader\u003c/code\u003e \u003ccode\u003eStart\u003c/code\u003e/\u003ccode\u003eEmpty\u003c/code\u003e\nevent) now rejects a start tag that declares more than 256\n\u003ccode\u003exmlns\u003c/code\u003e / \u003ccode\u003exmlns:*\u003c/code\u003e\nnamespace bindings, returning the new\n\u003ccode\u003eNamespaceError::TooManyDeclarations\u003c/code\u003e.\nPreviously \u003ccode\u003epush\u003c/code\u003e allocated one \u003ccode\u003eNamespaceBinding\u003c/code\u003e\nper declaration with no upper\nbound, before the event was returned to the caller, so an\n\u003ccode\u003eNsReader\u003c/code\u003e consumer\ncould not bound its memory exposure on untrusted input. The limit is\nconfigurable\nvia \u003ccode\u003eNamespaceResolver::set_max_declarations_per_element\u003c/code\u003e\n(use \u003ccode\u003eusize::MAX\u003c/code\u003e\nto disable).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003e#969\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/969\"\u003etafia/quick-xml#969\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003e#970\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/970\"\u003etafia/quick-xml#970\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e0.40.1 -- 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/964\"\u003e#964\u003c/a\u003e:\nFix \u003ccode\u003eunreachable!()\u003c/code\u003e panic in the serde deserializer when a\nDOCTYPE\ndeclaration appears between two text runs inside an element (e.g.\n\u003ccode\u003e\u0026lt;a\u0026gt;x\u0026lt;!DOCTYPE y\u0026gt;z\u0026lt;/a\u0026gt;\u003c/code\u003e). The DOCTYPE used\nto break \u003ccode\u003edrain_text\u003c/code\u003e\u0027s\nconsecutive-text merge, so two \u003ccode\u003eDeEvent::Text\u003c/code\u003e events reached\n\u003ccode\u003eread_text\u003c/code\u003e and tripped its \u0026quot;Cannot be two consequent\nText events\u0026quot;\ninvariant. DOCTYPE is now treated as transparent during text drain —\nit still goes through the entity resolver, but the surrounding text\nis merged into one run. Discovered via libFuzzer on a real-world\nSAML deserializer harness.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/964\"\u003e#964\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/964\"\u003etafia/quick-xml#964\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e0.40.0 -- 2026-05-11\u003c/h2\u003e\n\u003cp\u003eMSRV bumped to 1.79.\u003c/p\u003e\n\u003cp\u003eNow \u003ccode\u003equick-xml\u003c/code\u003e supports UTF-16 encoded documents. See the\nnew \u003ccode\u003eDecodingReader\u003c/code\u003e type.\u003c/p\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/compare/v0.41.0...v0.41.0\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c465c3c5b132f5d6e232bd98ad8efd623c0554be",
      "tree": "63462f646ccb6d943da27dfac2e2a59f25e03b0b",
      "parents": [
        "00672bd416323268e5f1a51e289c57b6f1d07f14"
      ],
      "author": {
        "name": "tonghuaroot (童话)",
        "email": "tonghuaroot@gmail.com",
        "time": "Thu Aug 27 14:46:43 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 14:46:43 2026 +0800"
      },
      "message": "feat(aliyun): add STS AssumeRole granter (#848)\n\nResolves #847. Part of #807.\n\nAdds `AssumeRoleGrant` and `AssumeRoleGranter` for Alibaba Cloud RAM STS\n`AssumeRole`, implementing `GrantCredential` in the same shape as the\nAWS granter (#813). The source credential supplied by `Granter` signs\nthe STS request directly; the returned credential carries exact\n`Expiration` and is never cached. `expires_in` maps to `DurationSeconds`\n(900..\u003d43200), and an optional inline session `Policy` is supported.\n\nThe STS request build, HMAC-SHA1 signing, and response parsing are\nextracted into a shared `assume_role` module that both the granter and\nthe existing `AssumeRoleCredentialProvider` reuse. The provider keeps\nits public API and `ProvideCredential` is unchanged.\n\n## Testing\n\n- `cargo fmt`, `cargo clippy --all-targets --all-features -- -D\nwarnings`, and `cargo test` all pass.\n- Deterministic tests over a mock `HttpSend`: golden signature over the\nexact signed parameter set, parameter assertions, and the\nsource-validation, duration-range, and post-I/O expiry error paths. The\nexisting provider signature test still passes, confirming the extracted\nsigning is byte-identical.\n- Validated end to end against real Alibaba Cloud STS: a base RAM user\ncredential assumes a role and receives a valid temporary credential.\n\nReal-service CI coverage needs Actions secrets and is tracked in #825;\nhappy to follow up on that wiring.\n\nThis change was written with AI assistance; I have reviewed and\nunderstand it."
    },
    {
      "commit": "00672bd416323268e5f1a51e289c57b6f1d07f14",
      "tree": "9e908f400c7e9d2c3036b1d8684ace8210a699a9",
      "parents": [
        "b980e52611fed92988224e3e67db74177e97b6a0"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Aug 27 14:45:23 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 14:45:23 2026 +0800"
      },
      "message": "fix(aws): configure S3 Express session provider grants (#851)\n\n`S3ExpressSessionProvider` is the S3 Express session credential source\nthat can be used directly by `Signer`, but it always requested\n`ReadWrite`. This left the typed `ReadOnly` and `MaximumAllowed`\nselections unavailable to automatic session refresh.\n\nAllow the provider to bind any `S3ExpressSessionGrantSelection` while\npreserving `ReadWrite` as the constructor default. Refreshed sessions\nretain the configured selection, including omission of\n`x-amz-create-session-mode` for `MaximumAllowed`.\n\nLive AWS acceptance was not run."
    },
    {
      "commit": "b980e52611fed92988224e3e67db74177e97b6a0",
      "tree": "dd3ec320ba6cb1f03a80bb5a66746cbd574c6a55",
      "parents": [
        "6818b17ef69302feec3b0beaaa8ff794fa8916bc"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Aug 27 14:45:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 27 14:45:07 2026 +0800"
      },
      "message": "feat(google): preserve signer identity in token credentials (#855)\n\nToken credentials issued for known service accounts currently discard\nthe signer identity, forcing consumers to duplicate the service account\nemail before query signing.\n\nPreserve provider-discovered signer emails on Google token credentials\nand use them for IAMCredentials `signBlob` query signing. An explicit\n`RequestSigner::with_signer_email` takes precedence, providers that\ncannot determine an identity retain the explicit configuration path, and\nBearer authentication ignores the query-signing identity.\n\nCloses #854"
    },
    {
      "commit": "6818b17ef69302feec3b0beaaa8ff794fa8916bc",
      "tree": "0dbac668fbca02db78c540c04d734a35d95d9a80",
      "parents": [
        "90aa91e3f26ec658509394cc770eba747a0a65b0"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon Aug 17 01:52:41 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 17 01:52:41 2026 +0800"
      },
      "message": "chore: prepare v0.20.6 release (#844)\n\nPrepare the workspace for Apache OpenDAL reqsign 0.20.6.\n\nThis release includes the S3 Express public API additions since v0.20.5,\nso `reqsign-aws-v4` moves from 3.2.0 to 3.3.0. `reqsign-core` receives a\npatch bump for signer refresh serialization, while the remaining\npublishable crates receive coordinated patch bumps. The facade moves to\n0.20.6."
    },
    {
      "commit": "90aa91e3f26ec658509394cc770eba747a0a65b0",
      "tree": "68c08d942b5c9d40911911a33f6c42e4e8fb4d61",
      "parents": [
        "610dfd0e22045118bb83d9d1dbe24e9c7630d90a"
      ],
      "author": {
        "name": "Qinxuan Chen",
        "email": "koushiro.cqx@gmail.com",
        "time": "Mon Aug 17 01:20:41 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 17 01:20:41 2026 +0800"
      },
      "message": "fix(docs): migrate from doc_auto_cfg to doc_cfg (#832)\n\nClose #831 \n\n## Error\n\n```\nRUSTDOCFLAGS\u003d\"--cfg docsrs\" cargo +nightly doc --no-deps\n```\n\n```\nerror[E0557]: feature has been removed\n  --\u003e reqsign/src/lib.rs:19:29\n   |\n19 | #![cfg_attr(docsrs, feature(doc_auto_cfg))]\n   |                             ^^^^^^^^^^^^ feature has been removed\n   |\n   \u003d note: removed in 1.92.0; see \u003chttps://github.com/rust-lang/rust/pull/138907\u003e for more information\n   \u003d note: merged into `doc_cfg`\n\nerror: Compilation failed, aborting rustdoc\n\nFor more information about this error, try `rustc --explain E0557`.\nerror: could not document `reqsign`\n```"
    },
    {
      "commit": "610dfd0e22045118bb83d9d1dbe24e9c7630d90a",
      "tree": "f6694e3ac61f20d8fc994d08df7bbcc8d2d48993",
      "parents": [
        "1440f997e312437280b6bd43c32308b5eeacb811"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon Aug 17 01:20:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Aug 17 01:20:22 2026 +0800"
      },
      "message": "feat(aws): support custom S3 Express CreateSession endpoints (#843)\n\n## Context\n\nS3 Express `CreateSession` configuration only accepted AWS\ndirectory-bucket names and derived AWS or AWS China Zonal endpoints.\nThat excluded S3-compatible deployments which expose `CreateSession` at\na deployment-owned origin. A concrete documented example is [MinIO\nAIStor S3 Express\nmode](https://docs.min.io/aistor/reference/aistor-server/s3-express/),\nwhose [S3 API compatibility\nreference](https://docs.min.io/aistor/developers/s3-api-compatibility/)\nlists `CreateSession`.\n\nThis adds a separate, fallible\n`S3ExpressSessionGranter::new_with_custom_endpoint` path that binds the\ncompatible bucket, SigV4 Region, and HTTPS origin before source\ncredentials can be loaded. It preserves the strict AWS constructor and\nexposes no synthetic Zone or partition. `custom` means\ncaller-configured, not verified: reqsign validates endpoint syntax but\ncannot determine service identity or protocol compatibility. The\nconfigured origin receives the AWS `Authorization` header and any source\n`x-amz-security-token`.\n\nLive AWS and MinIO AIStor interoperability were not run because this\ncheckout has no authorized endpoint or credential environment.\nDeterministic wire coverage does not establish interoperability.\n\nFixes #838"
    },
    {
      "commit": "1440f997e312437280b6bd43c32308b5eeacb811",
      "tree": "2e7c8a2afd919ca639686dc8ee27a1f15714202c",
      "parents": [
        "d710bff11d4a8a5d545b841d2d4a4dd1d0ff82e8"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Aug 14 13:29:59 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 14 13:29:59 2026 +0800"
      },
      "message": "fix: deduplicate concurrent signer credential refreshes (#842)\n\nConcurrent `Signer` calls can observe the same empty or stale credential\ncache and invoke the provider in parallel, causing issuance bursts at\ncold starts and refresh boundaries.\n\nThis serializes credential refresh per shared cache with a\nruntime-agnostic async mutex. Callers waiting on a successful refresh\nreuse the cached credential. A failed or cancelled refresh is not\ncached, so the next waiting or later caller retries. Request signing\nruns after releasing the mutex, preserving concurrent signing, exact\noperation-validity checks, atomic request mutation, and the existing\ncache-sharing rules.\n\nFixes #837"
    },
    {
      "commit": "d710bff11d4a8a5d545b841d2d4a4dd1d0ff82e8",
      "tree": "672077b159fa2d403b59ddce9661870fa7f37e48",
      "parents": [
        "97a67f083ed07ec6946dca0b84accb8b29fd5a96"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Aug 13 16:34:18 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 13 16:34:18 2026 +0800"
      },
      "message": "feat(aws): support IAM signing for S3 Express (#841)\n\n## Context\n\nS3 Express uses CreateSession credentials and the S3 session-token\nrepresentation by default. CopyObject, HeadBucket, and UploadPartCopy\ninstead require IAM credentials while retaining the s3express SigV4\nsigning name. Reqsign already distinguished the header forms internally,\nbut external callers could not select the IAM mode and presigning did\nnot model both token representations.\n\nThis exposes a request-signer opt-in for the standard AWS session-token\nrepresentation across header and query authentication. The default\nCreateSession representation remains unchanged, and the selection does\nnot modify or replace the caller\u0027s Credential.\n\nDeterministic protocol coverage checks exact canonical requests and\nsignatures against the AWS SigV4 implementation and preserves redaction.\nLive AWS acceptance remains unrun because the gated directory-bucket\nenvironment is not configured locally.\n\nFixes #836"
    },
    {
      "commit": "97a67f083ed07ec6946dca0b84accb8b29fd5a96",
      "tree": "7d34130461a822fe237ebcb19e37133b5dc700db",
      "parents": [
        "9d3208e7ee640f669c768ccfb80b8e1caf9a3326"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Aug 13 14:48:25 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 13 14:48:25 2026 +0800"
      },
      "message": "feat(aws): support maximum-allowed S3 Express sessions (#840)\n\n## Context\n\nS3 Express CreateSession gives an omitted session-mode header distinct\nsemantics: AWS attempts the maximum privilege allowed by policy, trying\nReadWrite before falling back to ReadOnly. The existing API could only\nrequest an explicit mode, forcing clients to choose without knowing the\ncaller\u0027s IAM permissions.\n\nThis adds a typed maximum-allowed grant selection that omits the header\nwhile preserving the exact wire behavior of explicit ReadOnly and\nReadWrite grants. It remains within the existing Granter composition,\nfixed five-minute session lifetime, and redaction boundary.\n\nFixes #835"
    },
    {
      "commit": "9d3208e7ee640f669c768ccfb80b8e1caf9a3326",
      "tree": "09bcf6b59867747544f1fbece630bbd835f589a0",
      "parents": [
        "e11dde0e55a84300c0397aa1faabafcce1235c0c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Aug 13 14:37:17 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 13 14:37:17 2026 +0800"
      },
      "message": "feat(aws): resolve S3 Express config from bucket (#839)\n\n## Context\n\n`S3ExpressSessionConfig::new` required callers with a complete directory\nbucket name and Region to duplicate reqsign\u0027s Zone ID and partition\nresolution before they could obtain the Zonal endpoint.\n\nThis adds `S3ExpressSessionConfig::from_bucket`, which validates the\ncomplete directory bucket name, extracts and binds its Zone ID, derives\nthe supported partition from the explicit Region, and constructs the\nexisting AWS or AWS China endpoint. The compatibility provider now uses\nthe same resolver, while the explicit constructor remains available and\nbehavior-compatible.\n\nLive AWS acceptance remains unrun because the gated S3 Express bucket\nenvironment is not configured locally; deterministic endpoint,\nvalidation, redaction, and pre-I/O coverage is included.\n\nFixes #834"
    },
    {
      "commit": "e11dde0e55a84300c0397aa1faabafcce1235c0c",
      "tree": "853cf1e44f148902e57fe9d1969de08b862ea61c",
      "parents": [
        "a8a8d43955b7ea3f231fbaff00db6767c26f5274"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Sat Aug 08 02:23:58 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Aug 08 02:23:58 2026 +0800"
      },
      "message": "test(aws): add real credential provider coverage (#830)\n\nAWS credential-provider CI currently treats local parsing and\nmock-server checks as live coverage for several providers. This leaves\nreal Cognito, ECS, IMDS, profile, process, and S3 Access Grants behavior\nunverified.\n\nThis adds a trusted live-test path backed by GitHub OIDC and ephemeral\nAWS resources. Real acceptance exposed and fixes two provider\nincompatibilities: Cognito can return expiration as a whole JSON float,\nand Fargate\u0027s task metadata URI must not override the container\ncredentials endpoint.\n\nSSO remains without a real-service CI job because the current provider\nrequires a pre-authorized legacy SSO cache and has no unattended token\nrefresh flow.\n\nPart of #825."
    },
    {
      "commit": "a8a8d43955b7ea3f231fbaff00db6767c26f5274",
      "tree": "3a3c8d420cc88f29a3e2dc4a227abc4e873a851c",
      "parents": [
        "0789a74d53db9f61ed4adb16b2aa3c89ec81f717"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Aug 07 17:06:04 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 07 17:06:04 2026 +0800"
      },
      "message": "chore: prepare v0.20.5 release (#824)\n\n## Summary\n- Prepare Apache OpenDAL reqsign **0.20.5** as an emergency patch\nrelease (skip DISCUSS).\n- Includes the required CI fix from #823 on top of current `main`.\n- Facade `reqsign` → `0.20.5`.\n- Minor bumps for new public APIs: `reqsign-core` `3.3.0`,\n`reqsign-aws-core` `3.1.0`, `reqsign-aws-v4` `3.2.0`,\n`reqsign-azure-storage` `3.2.0`, `reqsign-google` `3.1.0`.\n- Coordinated patch bumps for remaining published crates.\n\n## Test plan\n- [ ] CI green\n- [ ] After merge: cut `v0.20.5-rc.1`, upload dist/dev, open VOTE"
    },
    {
      "commit": "0789a74d53db9f61ed4adb16b2aa3c89ec81f717",
      "tree": "fc9fd58fd3c6b10b20b61cb855c0f5ce6818a3eb",
      "parents": [
        "40b4b12160ab246dd2d6b3e9856b79fc18ab13d7"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Aug 07 16:49:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Aug 07 16:49:52 2026 +0800"
      },
      "message": "ci: keep live-test gate env vars on cargo test steps (#823)\n\n## Summary\n- Move `REQSIGN_*_TEST*` gate flags from 1Password Load secrets steps\nonto the actual `cargo test` steps in AWS/Azure/Google workflows.\n- Assert each gate is `on` before running live tests so a missing gate\nfails the job instead of silently skipping.\n- Run `reqsign-aws-core` unit tests in the AWS workflow so invariants\nlike `EMPTY_STRING_SHA256` are always exercised.\n\n## Context\n`1Password/load-secrets-action` with `export-env: true` only forwards\n`op://` secrets to later steps. Literal gate env vars set on Load\nsecrets were dropped, so jobs such as `test_assume_role_provider`\nfinished in `0.00s` and still reported green. That allowed signing\nregressions (for example the published empty-string SHA256 typo) to slip\nthrough.\n\n## Test plan\n- [ ] Confirm AWS/Azure/Google live jobs no longer finish in ~0s when\nsecrets are available\n- [ ] Confirm assume-role / web-identity / signing jobs actually execute\ntests\n- [ ] Confirm a missing gate would fail via `test \"${GATE}\" \u003d \"on\"`\n- [ ] Confirm `unit_test` runs both `reqsign-aws-core` and\n`reqsign-aws-v4` lib tests"
    },
    {
      "commit": "40b4b12160ab246dd2d6b3e9856b79fc18ab13d7",
      "tree": "de501e7a6e5133b7c05137afdc745eb73685b3df",
      "parents": [
        "741aae0a063f4a11892be18f51133ee47105a3b9"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Thu Aug 06 10:21:15 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Aug 06 10:21:15 2026 +0800"
      },
      "message": "chore: Add draft project security threat-model document (#761)\n\n## Summary\n\nThis PR adds an initial draft of a project-level security\nthreat-model document (`draft-THREAT-MODEL.md`) so that automated\nsecurity scanners running against this repository have a\nmaintainer-facing reference for which classes of findings are\nin-scope vs. out-of-scope for the project.\n\nThe document follows the rubric format used by several other ASF\nprojects piloting improved security-model discoverability for\nagentic scanners. Every claim carries a provenance tag:\n\n- *(documented)* — paraphrased from public artefacts (this repo or\n  the project website), cited inline.\n- *(inferred)* — synthesised from code structure or domain\n  knowledge; the PMC has not confirmed.\n- *(maintainer)* — confirmed by a OpenDAL PMC member in response\n  to this draft. (Zero in this initial draft.)\n\nDraft stats:\n\n- ~9 documented claims\n- ~8 inferred claims (each maps to a §14 question)\n- 8 open questions for maintainers in §14\n\n§14 is the highest-leverage section: answering each question\neither promotes one *(inferred)* tag to *(maintainer)* or corrects\nthe underlying claim.\n\n## Scope note\n\nThis is a delta document; the canonical OpenDAL threat model lives at\napache/opendal:draft-THREAT-MODEL.md and is inherited as the baseline.\nNote: reqsign is also published to crates.io and consumed outside\nOpenDAL — the threat model must hold for non-OpenDAL embedders too.\n\n## Why \"draft-\" prefix?\n\nThe file is named `draft-THREAT-MODEL.md` rather than\n`SECURITY-THREAT-MODEL.md` because **this is a proposal for the\nPMC to review — please correct, reject, or discuss as needed.**\nOnce the PMC ratifies (or substantially edits) the content, the\nfile can be renamed in a follow-up PR and a discoverability\nscaffold (`AGENTS.md` → `SECURITY.md` → the model) added so\nscanners can mechanically follow the chain.\n\n## What this is, and what it is not\n\nThis is **not** a security audit. It is a working triage document\n— the reference a triager holds against an inbound report to\ndecide whether the report is about a OpenDAL-reqsign vulnerability or\nabout caller misuse / operator misconfiguration / an out-of-scope\nconcern.\n\nThe draft was generated by an automated agentic security scan\nbeing piloted by the ASF Security team; the discoverability work\nis independent of any specific scan run.\n\n## How to review\n\n1. §14 first. Each answer either confirms one *(inferred)* tag or\n   replaces the inferred claim with the correct one.\n2. After that, please skim §3 (out-of-scope) and §13 (triage\n   dispositions) — those govern how a vulnerability report would\n   be triaged.\n\nReply edits / corrections inline on the PR, or to the original\n`security@apache.org` thread, whichever fits the PMC\u0027s workflow.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)\n\n---------\n\nCo-authored-by: Claude Opus 4.7 (1M context) \u003cnoreply@anthropic.com\u003e\nCo-authored-by: Erick Guan \u003c297343+erickguan@users.noreply.github.com\u003e\nCo-authored-by: tison \u003cwander4096@gmail.com\u003e"
    },
    {
      "commit": "741aae0a063f4a11892be18f51133ee47105a3b9",
      "tree": "bc6406d8ab8a700a57eaeeb48a7394753b610908",
      "parents": [
        "7561049f9d5d7b394e0fca23b23c566d8abefe78"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Aug 05 17:56:28 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 17:56:28 2026 +0800"
      },
      "message": "feat(azure): add Service SAS granter (#817)\n\n## Why\n\nThe scoped credential-granting architecture added in #803 does not yet\nexpose Shared Key Service SAS issuance. Azure callers can presign\nindividual requests, but they cannot mint one bounded\n`Credential::SasToken` and compose it through `Granter\u003cCredential\u003e` and\nthe existing Azure signer.\n\nThis adds an account-bound, typed Service SAS granter for one complete\ncontainer or blob grant. It validates the Shared Key source and Azure\nconfiguration before local generation, shares canonical signing and\ntoken serialization with the compatibility APIs, and carries the exact\nsigned expiration in the returned credential. Existing Shared Key\nrequest signing, `ServiceSharedAccessSignature`, and Service SAS presign\nbehavior remain available unchanged.\n\nThe wire contract is covered by deterministic independently computed\nHMAC vectors and local core, Azure, documentation, lint, and WASM\nvalidation. No authorized Azure account was available, so live Azure HNS\nacceptance for the `o` and `p` permissions remains an explicit\nacceptance gap.\n\nPart of #807."
    },
    {
      "commit": "7561049f9d5d7b394e0fca23b23c566d8abefe78",
      "tree": "b53f2e5f64b88cb9b7f92ff0396995b97fab2947",
      "parents": [
        "702df3011dff05768141a77d1255f5579f4f584f"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Aug 05 17:33:54 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 17:33:54 2026 +0800"
      },
      "message": "ci: use asfml for discussion thread links (#819)\n\nGitHub Discussions are mirrored to `dev@opendal.apache.org`, but they\ncurrently do not expose the corresponding ASF mailing-list archive URL\nback in the Discussion.\n\nThis adds the same `asfml`-based workflow used by OpenDAL. It waits for\nthe mirror, resolves the root thread, and posts the archive URL as a\ndeduplicated Discussion comment. It also supports manual backfill\nthrough `workflow_dispatch`."
    },
    {
      "commit": "702df3011dff05768141a77d1255f5579f4f584f",
      "tree": "abd79f7ada60a3410bf089cf0914e6fef5c0b6a8",
      "parents": [
        "91bfb7318161ccb3ce050add9d9998f3e5827c8d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Aug 05 13:10:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Aug 05 13:10:52 2026 +0800"
      },
      "message": "build(deps): update pem requirement from 3.0 to 4.0 (#816)\n\nUpdates the requirements on [pem](https://github.com/jcreekmore/pem-rs)\nto permit the latest version.\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/blob/master/CHANGELOG.md\"\u003epem\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e3.0.6\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eswitch from serde to serde_core\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.5\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eupdated base version in the docs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.4\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eupdated base64 to 0.22.0\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.3\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eallow general whitespace separators instead of just newlines\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.2\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eallow EncodeConfig to be built in a const context\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.1\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003ereduce allocations in \u003ccode\u003epem::encode\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e3.0.0\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003etrim \u003ccode\u003eproptest\u003c/code\u003e features to prevent an MSRV break for\ntesting\u003c/li\u003e\n\u003cli\u003emake EncodeConfig struct extendable and add a line_wrap config\noption\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.0.1\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eFix serde support on no_std\u003c/li\u003e\n\u003cli\u003eDrop MSRV to 1.60\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e2.0\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdd no_std support\u003c/li\u003e\n\u003cli\u003eBump MSRV to 1.67\u003c/li\u003e\n\u003cli\u003eRefactor API to prevent direct modification and access of elements\nand to\nallow access to the optional rfc1421-described headers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.1.1\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAllow PEM files to be parsed with the optional rfc1421-described\nheaders\n(although you cannot retrieve the headers)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.1.0\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eAdd optional serde support\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.0.2\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eRemove dependency on Regex in favor of a hand-rolled parser\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.0.1\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003ehide the ASCII_ARMOR symbol to work around a linking issue with\n32-bit windows builds\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.0\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/99c15c08f1389153ed037c33750f8605bbf8bd55\"\u003e\u003ccode\u003e99c15c0\u003c/code\u003e\u003c/a\u003e\nchore: Release pem version 4.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/17335731c0f62bf9e5597aadc98108badc0382f9\"\u003e\u003ccode\u003e1733573\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/jcreekmore/pem-rs/issues/66\"\u003e#66\u003c/a\u003e\nfrom alex/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/ee57363352c9677a3c51bca6463b9f98ce423df9\"\u003e\u003ccode\u003eee57363\u003c/code\u003e\u003c/a\u003e\nraise msrv for testing to 1.71\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/a307fde39e81dfd6cd2fa4ef5e72c421119e0e2c\"\u003e\u003ccode\u003ea307fde\u003c/code\u003e\u003c/a\u003e\nraise msrv to 1.71\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/2b2ad45420fe32ea65936ecc22c5d75f380b1c84\"\u003e\u003ccode\u003e2b2ad45\u003c/code\u003e\u003c/a\u003e\nupgrade base64 to 0.23\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/4e28c91c5888065ce2bc9e40678371f5b48635b5\"\u003e\u003ccode\u003e4e28c91\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/jcreekmore/pem-rs/issues/65\"\u003e#65\u003c/a\u003e\nfrom alexanderkjall/upgrade-criterion\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/e87f7738db1b83ab273684b917416c8f2ac68e22\"\u003e\u003ccode\u003ee87f773\u003c/code\u003e\u003c/a\u003e\nupgrade criterion to 0.8\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/7d6157704805dcedf703229926938a71b1ddd0b1\"\u003e\u003ccode\u003e7d61577\u003c/code\u003e\u003c/a\u003e\nchore: Release pem version 3.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/d5e82b4a0954534c2e70a3bdc06261744a07af1b\"\u003e\u003ccode\u003ed5e82b4\u003c/code\u003e\u003c/a\u003e\nupdate the changelog for the release\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/commit/c8233434948ad2d3f9a42142037e3084dfd0beb5\"\u003e\u003ccode\u003ec823343\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/jcreekmore/pem-rs/issues/59\"\u003e#59\u003c/a\u003e\nfrom tottoto/switch-serde-to-serde-core\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/jcreekmore/pem-rs/compare/v3.0.0...v4.0.0\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "91bfb7318161ccb3ce050add9d9998f3e5827c8d",
      "tree": "f3ea5d90ff359bef7af6c552f10a63982d8d07fb",
      "parents": [
        "bb2b46397293be8c4a952b53444186133bc213d5"
      ],
      "author": {
        "name": "Erick Guan",
        "email": "297343+erickguan@users.noreply.github.com",
        "time": "Fri Jul 31 23:22:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 23:22:32 2026 +0800"
      },
      "message": "docs: add release files to all crates (#814)"
    },
    {
      "commit": "bb2b46397293be8c4a952b53444186133bc213d5",
      "tree": "a734ce5122892f59af61699928d71222131938ea",
      "parents": [
        "cd22149ee361bad49aab60ec651799e3d80811f4"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 31 17:35:15 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 17:35:15 2026 +0800"
      },
      "message": "feat(aws): add STS AssumeRole granter (#813)\n\nAWS STS AssumeRole is the first authority-transition flow that exercises\nreqsign\u0027s scoped credential-granting architecture on AWS. The source\ncredential must authorize each STS exchange while the resulting\ncredential derives authority from the target role, so this cannot be\nmodeled as monotonic downscoping or through a generic provider adapter.\n\nThis PR exposes that flow through the existing one-generic `Granter\u003cK\u003e`\ncomposition while retaining `AssumeRoleCredentialProvider` as the\nfixed-flow compatibility API.\n\nPart of #807.\n\nLive AWS acceptance remains gated on an authorized AssumeRole\nenvironment."
    },
    {
      "commit": "cd22149ee361bad49aab60ec651799e3d80811f4",
      "tree": "0109295b7feb0da3425635caf3c9a07a2da9a470",
      "parents": [
        "18d4043f0fb96c0cc59e7f68d009c6e42991f0c9"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 31 14:58:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 14:58:13 2026 +0800"
      },
      "message": "feat: add client-side GCP Credential Access Boundary (#808)\n\nCloses #804.\n\nGoogle\u0027s server-side Credential Access Boundary flow exchanges a source\nOAuth access token through STS for every granted credential. Workloads\nthat issue many differently scoped tokens need Google\u0027s client-side flow\nso they can reuse intermediary material without caching granted outputs.\n\nThis PR adds an explicitly selected, feature-gated client-side granter\nalongside an explicitly named server-side granter. Both remain\nservice-specific implementations of `GrantCredential\u003cCredential \u003d\nreqsign_google::Credential\u003e`, preserving the existing source-cache and\nGoogle signing architecture. The client keeps only bounded intermediary\nmaterial and generates a fresh output for every grant; there is no\nimplicit fallback between modes.\n\nThe implementation follows Google\u0027s intermediary-token and session-key\nprotocol, validates typed Cloud Storage boundaries, and fails closed if\nSTS returns an unsupported Tink AEAD key. The opt-in GCP\ninteroperability test still requires a service-account access token and\nbucket fixture, so live acceptance is not part of the local validation."
    },
    {
      "commit": "18d4043f0fb96c0cc59e7f68d009c6e42991f0c9",
      "tree": "090fd4be3543064194c681ff3d6575f87865abd0",
      "parents": [
        "0c739a4774f16e9cd80751e73b2d20e5c1e3a484"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 31 14:58:02 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 14:58:02 2026 +0800"
      },
      "message": "build(deps): bump 1Password/load-secrets-action from 4.0.1 to 4.1.1 (#810)\n\nBumps\n[1Password/load-secrets-action](https://github.com/1password/load-secrets-action)\nfrom 4.0.1 to 4.1.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/releases\"\u003e1Password/load-secrets-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd fallback version resolution so if app-updates.agilebits.com is\nunavailable, the action now falls back to Docker Hub and then a baked-in\npinned version. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/173\"\u003e#173\u003c/a\u003e\n)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHarden CI security: add \u003ccode\u003eStepSecurity\u003c/code\u003e harden runner and\npin GitHub Actions to commit SHAs across workflows, restrict workflow\npermissions, and add Dependabot config. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/174\"\u003e#174\u003c/a\u003e\n)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v4.0.1...v4.1.1\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v4.0.1...v4.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/eb2efd0703da22a93c467f2d1ffbb6826c11e19c\"\u003e\u003ccode\u003eeb2efd0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/183\"\u003e#183\u003c/a\u003e\nfrom 1Password/release/v4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/22158bd3a3712a4b6532a333bed309e230e9e3d2\"\u003e\u003ccode\u003e22158bd\u003c/code\u003e\u003c/a\u003e\nPrepare release\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/19a016fe1a9f5c9f7c9d3a8662416e73b2c89a30\"\u003e\u003ccode\u003e19a016f\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/174\"\u003e#174\u003c/a\u003e\nfrom 1Password/chore/GHA-151735-stepsecurity-remediation\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/01723ec64cd4c3735bb612662465ca5171aa6a56\"\u003e\u003ccode\u003e01723ec\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/173\"\u003e#173\u003c/a\u003e\nfrom 1Password/jill/add-docker-hub-fallback-for-cli-i...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/4eec4d1de6b8751e23d50619f57889919e3342c3\"\u003e\u003ccode\u003e4eec4d1\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2f9fe6862d5c77faca3c7d0e915b187ee88d65b4\"\u003e\u003ccode\u003e2f9fe68\u003c/code\u003e\u003c/a\u003e\nAdd CI release check for op version\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/c63b840e91ef76d1185a40fdeaf6e07ed02f5a6b\"\u003e\u003ccode\u003ec63b840\u003c/code\u003e\u003c/a\u003e\nApply GitHub Actions security best practices\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/d97149e3c782082e3e40b48c033a29b7aef12ee3\"\u003e\u003ccode\u003ed97149e\u003c/code\u003e\u003c/a\u003e\nRefactor E2E\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/b2408260f797a5c27a02a8d136e26f98617c360b\"\u003e\u003ccode\u003eb240826\u003c/code\u003e\u003c/a\u003e\nUpdate E2E tests\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/759227f200efd70f56485d44029aa8535d62dbb7\"\u003e\u003ccode\u003e759227f\u003c/code\u003e\u003c/a\u003e\nAdd pinned version\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/compare/3a12b0ab99d9cd590a3e9b5a90ea017210ed9556...eb2efd0703da22a93c467f2d1ffbb6826c11e19c\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003d1Password/load-secrets-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.0.1\u0026new-version\u003d4.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0c739a4774f16e9cd80751e73b2d20e5c1e3a484",
      "tree": "4c09f6ba7fadbaeee094ffe79d298a566f5181f2",
      "parents": [
        "c4912f8e60fa31909d124d93611f518cf187ed1d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 31 14:57:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 14:57:52 2026 +0800"
      },
      "message": "build(deps): bump 1Password/load-secrets-action/configure from 4.0.1 to 4.1.1 (#809)\n\nBumps\n[1Password/load-secrets-action/configure](https://github.com/1password/load-secrets-action)\nfrom 4.0.1 to 4.1.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/releases\"\u003e1Password/load-secrets-action/configure\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd fallback version resolution so if app-updates.agilebits.com is\nunavailable, the action now falls back to Docker Hub and then a baked-in\npinned version. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/173\"\u003e#173\u003c/a\u003e\n)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHarden CI security: add \u003ccode\u003eStepSecurity\u003c/code\u003e harden runner and\npin GitHub Actions to commit SHAs across workflows, restrict workflow\npermissions, and add Dependabot config. (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/174\"\u003e#174\u003c/a\u003e\n)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v4.0.1...v4.1.1\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v4.0.1...v4.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/eb2efd0703da22a93c467f2d1ffbb6826c11e19c\"\u003e\u003ccode\u003eeb2efd0\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/183\"\u003e#183\u003c/a\u003e\nfrom 1Password/release/v4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/22158bd3a3712a4b6532a333bed309e230e9e3d2\"\u003e\u003ccode\u003e22158bd\u003c/code\u003e\u003c/a\u003e\nPrepare release\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/19a016fe1a9f5c9f7c9d3a8662416e73b2c89a30\"\u003e\u003ccode\u003e19a016f\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/174\"\u003e#174\u003c/a\u003e\nfrom 1Password/chore/GHA-151735-stepsecurity-remediation\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/01723ec64cd4c3735bb612662465ca5171aa6a56\"\u003e\u003ccode\u003e01723ec\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/173\"\u003e#173\u003c/a\u003e\nfrom 1Password/jill/add-docker-hub-fallback-for-cli-i...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/4eec4d1de6b8751e23d50619f57889919e3342c3\"\u003e\u003ccode\u003e4eec4d1\u003c/code\u003e\u003c/a\u003e\nRebuild\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2f9fe6862d5c77faca3c7d0e915b187ee88d65b4\"\u003e\u003ccode\u003e2f9fe68\u003c/code\u003e\u003c/a\u003e\nAdd CI release check for op version\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/c63b840e91ef76d1185a40fdeaf6e07ed02f5a6b\"\u003e\u003ccode\u003ec63b840\u003c/code\u003e\u003c/a\u003e\nApply GitHub Actions security best practices\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/d97149e3c782082e3e40b48c033a29b7aef12ee3\"\u003e\u003ccode\u003ed97149e\u003c/code\u003e\u003c/a\u003e\nRefactor E2E\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/b2408260f797a5c27a02a8d136e26f98617c360b\"\u003e\u003ccode\u003eb240826\u003c/code\u003e\u003c/a\u003e\nUpdate E2E tests\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/759227f200efd70f56485d44029aa8535d62dbb7\"\u003e\u003ccode\u003e759227f\u003c/code\u003e\u003c/a\u003e\nAdd pinned version\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/compare/3a12b0ab99d9cd590a3e9b5a90ea017210ed9556...eb2efd0703da22a93c467f2d1ffbb6826c11e19c\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003d1Password/load-secrets-action/configure\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d4.0.1\u0026new-version\u003d4.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c4912f8e60fa31909d124d93611f518cf187ed1d",
      "tree": "0a44e838603c3f1daf19f3fba4df6b2cdfcf80e1",
      "parents": [
        "be02d93e6754d18e9868039235b57d14d8487912"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 31 14:57:38 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 14:57:38 2026 +0800"
      },
      "message": "feat(aws): add S3 Express CreateSession granter (#812)\n\n## Context\n\nS3 Express `CreateSession` already had a fixed-flow credential provider,\nbut callers could not use it through the scoped credential-granting\narchitecture introduced in #803. This makes the issuance path available\nas a service-specific `GrantCredential` implementation while preserving\n`S3ExpressSessionProvider` for compatibility.\n\nThe session configuration binds the directory bucket, Zone ID, Region,\nand AWS partition before source credential loading, preventing China\nRegions from being sent to the standard `amazonaws.com` DNS suffix. The\ngrant keeps AWS\u0027s explicit `ReadOnly`/`ReadWrite` modes, exact\ncredential expiration, redacted error handling, and direct composition\nwith the existing AWS signer. Transient `CreateSession` service failures\nremain retryable.\n\nThis advances the S3 Express item in #807. Historical protocol context\nis in #594.\n\nLive AWS acceptance remains gated on access to an authorized directory\nbucket; deterministic request/signing, expiration, redaction, provider\ncompatibility, and standard/AWS China endpoint coverage are included\nlocally."
    },
    {
      "commit": "be02d93e6754d18e9868039235b57d14d8487912",
      "tree": "f761fec5d0a8d90446f419d467af07df0a2028f4",
      "parents": [
        "38c06857028ae11fbc938984e6c0855a76433127"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 31 14:56:53 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 31 14:56:53 2026 +0800"
      },
      "message": "feat(aws): add S3 Access Grants GetDataAccess granter (#811)\n\nS3 Access Grants could not participate in reqsign\u0027s scoped\ncredential-granting flow even though the core\n`GrantCredential`/`Granter\u003cCredential\u003e` architecture and AWS SigV4\ncredential family were already available.\n\nThis adds an AWS-specific `GetDataAccess` granter that binds stable\naccount, Region, and endpoint configuration to one complete typed\ntarget, permission, and privilege grant. It signs with an explicit\nexisting AWS credential and returns the issued temporary `Credential`\nfor direct use by the existing AWS signer, while preserving pre-I/O\nvalidation, authoritative expiration, source-only caching, redaction,\nand native/WASM composition through `Context`.\n\nThe protocol tests use independently computed empty-payload and AWS\nSigV4 oracles. Live AWS acceptance with a real Access Grants instance\nand downstream allowed/denied S3 operations has not been run locally.\n\nPart of #807."
    },
    {
      "commit": "38c06857028ae11fbc938984e6c0855a76433127",
      "tree": "0281e852b015b8f4ea6c211e194a1be80e9f589a",
      "parents": [
        "79e2ba6f0db7776578bd7de67948a5eb53cf8a75"
      ],
      "author": {
        "name": "Qinxuan Chen",
        "email": "koushiro.cqx@gmail.com",
        "time": "Thu Jul 30 15:18:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 30 15:18:32 2026 +0800"
      },
      "message": "build: use Cargo resolver 3 (#806)\n\nAlign the virtual workspace resolver with Rust 2024 edition defaults.\n\nThis enables rust-version-aware dependency fallback for the workspace\nMSRV."
    },
    {
      "commit": "79e2ba6f0db7776578bd7de67948a5eb53cf8a75",
      "tree": "41d7e074ce96ca0b223f0046bb9d72906e075dd6",
      "parents": [
        "6392bc40540c0a5fa2f1388b9ba7931402257cde"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Jul 29 15:39:42 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 15:39:42 2026 +0800"
      },
      "message": "feat: add GCP Credential Access Boundary downscoping (#805)\n\n## Summary\n\nAdd a typed Google Cloud Credential Access Boundary grant and\nserver-side STS granter to `reqsign-google`. It reuses the\n`GrantCredential` / `Granter\u003cCredential\u003e` capability introduced in #803:\na token-only Google source credential authorizes the exchange, and the\nresult is an expiration-aware token-only `Credential` that the existing\nGoogle signing path can consume.\n\nThe service API constructs Cloud Storage bucket and object-prefix rules\nfrom validated types, emits the required list-prefix condition without\naccepting raw CEL or STS JSON, enforces the documented CAB and\ntoken-lifetime limits, and performs the exchange through\n`Context::http_send`. Source and output deadlines are checked around\nI/O, granted outputs are never cached, and credential material is\nredacted from errors and `Debug`.\n\nThis is the second service implementation of scoped credential granting\nafter Azure while keeping authorization semantics within the Google\ncrate. The client-issued intermediary-token and session-key flow is\nintentionally tracked separately in #804.\n\nLive GCP STS and Cloud Storage acceptance remains pending because no\ntest credential and bucket were available for this implementation.\n\nCloses #749."
    },
    {
      "commit": "6392bc40540c0a5fa2f1388b9ba7931402257cde",
      "tree": "42f8c549d8d309195581ef7ccd87c8a479d86820",
      "parents": [
        "f221055541d17cf14372b848da0b37bf8b81c726"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 29 12:22:03 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 12:22:03 2026 +0800"
      },
      "message": "build(deps): bump actions/setup-python from 6.3.0 to 7.0.0 (#802)\n\nBumps [actions/setup-python](https://github.com/actions/setup-python)\nfrom 6.3.0 to 7.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/setup-python/releases\"\u003eactions/setup-python\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eEnhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate to ESM and upgrade dependencies by \u003ca\nhref\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e@​priyagupta108\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1330\"\u003eactions/setup-python#1330\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin SHA commits and update docs with latest versions by \u003ca\nhref\u003d\"https://github.com/HarithaVattikuti\"\u003e\u003ccode\u003e@​HarithaVattikuti\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1338\"\u003eactions/setup-python#1338\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the pip-install input by \u003ca\nhref\u003d\"https://github.com/gowridurgad\"\u003e\u003ccode\u003e@​gowridurgad\u003c/code\u003e\u003c/a\u003e in\n\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1336\"\u003eactions/setup-python#1336\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix to Classify stderr warning messages as warnings instead of\nerrors in annotations by \u003ca\nhref\u003d\"https://github.com/lmvysakh\"\u003e\u003ccode\u003e@​lmvysakh\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1335\"\u003eactions/setup-python#1335\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate and retry manifest fetch to prevent silent failures by \u003ca\nhref\u003d\"https://github.com/priyagupta108\"\u003e\u003ccode\u003e@​priyagupta108\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1332\"\u003eactions/setup-python#1332\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependency Upgrade\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBump certifi from 2020.6.20 to 2024.7.4 in\n/\u003cstrong\u003etests\u003c/strong\u003e/data by \u003ca\nhref\u003d\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1328\"\u003eactions/setup-python#1328\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove EOL Python versions and Bumps numpy text fixture by \u003ca\nhref\u003d\"https://github.com/priya-kinthali\"\u003e\u003ccode\u003e@​priya-kinthali\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1333\"\u003eactions/setup-python#1333\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@​actions/cache\u003c/code\u003e to 6.2.0 by \u003ca\nhref\u003d\"https://github.com/philip-gai\"\u003e\u003ccode\u003e@​philip-gai\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1337\"\u003eactions/setup-python#1337\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/lmvysakh\"\u003e\u003ccode\u003e@​lmvysakh\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1335\"\u003eactions/setup-python#1335\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/philip-gai\"\u003e\u003ccode\u003e@​philip-gai\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/pull/1337\"\u003eactions/setup-python#1337\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/setup-python/compare/v6...v7.0.0\"\u003ehttps://github.com/actions/setup-python/compare/v6...v7.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/5fda3b95a4ea91299a34e894583c3862153e4b97\"\u003e\u003ccode\u003e5fda3b9\u003c/code\u003e\u003c/a\u003e\nPin SHA commits and update docs with latest versions (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1338\"\u003e#1338\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/4ab7e95f05e168b4356aebde89dd84f59c283d8e\"\u003e\u003ccode\u003e4ab7e95\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1337\"\u003e#1337\u003c/a\u003e\nfrom actions/philip-gai/bump-actions-cache-6-2-0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/0f3a009f475dbea83c0371cd85d099690fee8c5c\"\u003e\u003ccode\u003e0f3a009\u003c/code\u003e\u003c/a\u003e\nRemove the pip-install input (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1336\"\u003e#1336\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/f8cf4291c8b8e273ddd26e569454615c7315d932\"\u003e\u003ccode\u003ef8cf429\u003c/code\u003e\u003c/a\u003e\nMigrate to ESM and upgrade dependencies (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/54baeea5b34417d10a7479663a23cca53ea209b5\"\u003e\u003ccode\u003e54baeea\u003c/code\u003e\u003c/a\u003e\nValidate and retry manifest fetch to prevent silent failures (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/c7092773a316760f4ecfe498e4af668a4dafeac5\"\u003e\u003ccode\u003ec709277\u003c/code\u003e\u003c/a\u003e\nAnnotation code fix (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1335\"\u003e#1335\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/6849080452e69b330395e8a6d23cf90f56d76a1a\"\u003e\u003ccode\u003e6849080\u003c/code\u003e\u003c/a\u003e\nremove EOL Python versions and Bumps numpy text fixture (\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1333\"\u003e#1333\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/setup-python/commit/0903b469fbf4441aadfe4f4b249dc5b1fba3a73e\"\u003e\u003ccode\u003e0903b46\u003c/code\u003e\u003c/a\u003e\nBump certifi from 2020.6.20 to 2024.7.4 in /\u003cstrong\u003etests\u003c/strong\u003e/data\n(\u003ca\nhref\u003d\"https://redirect.github.com/actions/setup-python/issues/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b97\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/setup-python\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d6.3.0\u0026new-version\u003d7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f221055541d17cf14372b848da0b37bf8b81c726",
      "tree": "91b73eb635a594b0426b96a68f86df1fa839337c",
      "parents": [
        "35f77866cda3152ad208036b08846a901173031e"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Jul 29 12:20:35 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 12:20:35 2026 +0800"
      },
      "message": "feat: add scoped credential granting with Azure user delegation SAS (#803)\n\n## Overview\n\nreqsign currently composes credential providers with request signers,\nbut it has no lifecycle abstraction for using a service credential to\nissue another bounded, expiring credential in the same service family.\nThat leaves scoped credential vending to ad-hoc service APIs and makes\nsource credential caching, replacement isolation, post-I/O validity, and\nredaction difficult to apply consistently.\n\nThis introduces `GrantCredential` and `Granter\u003cK\u003e` in `reqsign-core`.\n`Granter\u003cK\u003e` loads and caches only the source credential, delegates\nservice-specific authorization semantics to `GrantCredential\u003cK\u003e`, and\nreturns credentials that remain directly consumable by the existing\n`Signer\u003cK\u003e`. The contract standardizes orchestration and lifecycle\nrather than imposing a cross-cloud scope model or promising strict\nmonotonic downscoping for every service.\n\nAzure User Delegation SAS is the first reference implementation. It\nexchanges a Bearer credential for a cached User Delegation Key,\nvalidates the account, endpoint, resource, path prefix, permissions, and\ntime bounds, and emits an expiration-aware `Credential::SasToken`.\nAdding expiration to that public variant is an intentional compatibility\nevolution required for exact validity checks.\n\nCloses #801.\nCloses #751.\nCloses #750.\nRefs #749."
    },
    {
      "commit": "35f77866cda3152ad208036b08846a901173031e",
      "tree": "30a526aa93d982075eaa90c8c11c68500cd353ab",
      "parents": [
        "666511cf6f6742534c00cba0e4aff4fe30daf692"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Tue Jul 28 13:33:29 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 13:33:29 2026 +0800"
      },
      "message": "chore: prepare v0.20.4 release (#799)\n\nPrepare the Apache OpenDAL reqsign 0.20.4 release candidate from the\ncurrent `main`.\n\nThe facade receives a patch bump. `reqsign-aws-v4` and\n`reqsign-volcengine-tos` receive minor bumps for their new public\ncapabilities, while the other established crates receive coordinated\npatch bumps. The newly bootstrapped `reqsign-aws-core` and\n`reqsign-aws-v4a` keep `3.0.3` as their first software release version."
    },
    {
      "commit": "666511cf6f6742534c00cba0e4aff4fe30daf692",
      "tree": "dc2429fb8f44dffa713c29d3aafbc9d2b4ffa9cb",
      "parents": [
        "f7d076b921cb4258f88d684f2ba4b19866358579"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Tue Jul 28 03:41:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 03:41:06 2026 +0800"
      },
      "message": "ci: migrate Rust crate publishing to Trusted Publishing (#798)"
    },
    {
      "commit": "f7d076b921cb4258f88d684f2ba4b19866358579",
      "tree": "25d974cd6f1ccf1fa7a6e6d0ee7de9ea6c2f34e0",
      "parents": [
        "977deca965903517aecc42927c5a6ae9a0a2a674"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon Jul 27 15:46:38 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 27 15:46:38 2026 +0800"
      },
      "message": "chore: upgrade base64 and p256 (#797)\n\n`base64` 0.23 and `p256` 0.14 are the latest stable release lines and\nkeep reqsign aligned with their upstream encoding and cryptography\nstacks.\n\n`base64` 0.23 enables unsafe SIMD by default, so this keeps only the\nexisting `std` behavior. `p256` 0.14 renames encoded-point conversion,\nrequiring the corresponding SigV4a public-key vector test update."
    },
    {
      "commit": "977deca965903517aecc42927c5a6ae9a0a2a674",
      "tree": "72538ad42d1155374192934c959c27d09783663d",
      "parents": [
        "478f4c42713ab90e8a817e0fc4fa0d7469bfce06"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon Jul 27 10:43:46 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 27 10:43:46 2026 +0800"
      },
      "message": "feat(aws): add SigV4a signing support (#795)\n\nAWS SigV4 derives signing keys from a single region, so it cannot\nauthenticate one request across multi-region AWS endpoints. SigV4a uses\nan asymmetric signing key and a signing region set to cover that use\ncase.\n\nThis adds a dedicated `reqsign-aws-v4a` signer and extracts credential\nproviders plus canonicalization into `reqsign-aws-core`, keeping\n`reqsign-aws-v4` focused on HMAC SigV4. The facade retains the existing\n`reqsign::aws` API for compatibility and exposes explicit `aws::v4` and\n`aws::v4a` modules.\n\nThe implementation supports header signing and query presigning,\npreserves the exact wire URI, and validates failure atomicity. It is\ncross-checked against AWS SigV4a key derivation vectors and the official\nRust `aws-sigv4` implementation.\n\nThis also makes the Aliyun default-provider unit test hermetic. Its\nfinal fallback previously reached the live ECS metadata endpoint during\nlocal workspace tests; the test now disables that unrelated provider and\nasserts that no HTTP request is made."
    },
    {
      "commit": "478f4c42713ab90e8a817e0fc4fa0d7469bfce06",
      "tree": "548bf6e10936996b925bc367855203d1fa728934",
      "parents": [
        "255471e548183ba00ff925b37daa9b9fdecfb680"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 24 23:02:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 23:02:07 2026 +0800"
      },
      "message": "build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#793)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0\nto 7.0.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/releases\"\u003eactions/checkout\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eskip running unsafe pr check if input is default by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2518\"\u003eactions/checkout#2518\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etrim only ascii whitespace for branch by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2521\"\u003eactions/checkout#2521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape values passed to --unset by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2530\"\u003eactions/checkout#2530\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/v7...v7.0.1\"\u003ehttps://github.com/actions/checkout/compare/v7...v7.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/checkout/blob/main/CHANGELOG.md\"\u003eactions/checkout\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog\u003c/h1\u003e\n\u003ch2\u003ev7.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip running unsafe pr check if input is default by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2518\"\u003eactions/checkout#2518\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTrim only ascii whitespace for branch by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2521\"\u003eactions/checkout#2521\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEscape values passed to --unset by \u003ca\nhref\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2530\"\u003eactions/checkout#2530\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev7.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBlock checking out fork PR for pull_request_target and workflow_run\nby \u003ca href\u003d\"https://github.com/aiqiaoy\"\u003e\u003ccode\u003e@​aiqiaoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2454\"\u003eactions/checkout#2454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVarious dependency updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix checkout init for SHA-256 repositories by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2439\"\u003eactions/checkout#2439\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: expand merge commit SHA regex and add SHA-256 test cases by \u003ca\nhref\u003d\"https://github.com/yaananth\"\u003e\u003ccode\u003e@​yaananth\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2414\"\u003eactions/checkout#2414\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix tag handling: preserve annotations and explicit fetch-tags by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2356\"\u003eactions/checkout#2356\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd worktree support for persist-credentials includeIf by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2327\"\u003eactions/checkout#2327\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev6.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePersist creds to a separate file by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2286\"\u003eactions/checkout#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README to include Node.js 24 support details and requirements\nby \u003ca href\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2248\"\u003eactions/checkout#2248\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v5 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2301\"\u003eactions/checkout#2301\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate actions checkout to use node 24 by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2226\"\u003eactions/checkout#2226\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePort v6 cleanup to v4 by \u003ca\nhref\u003d\"https://github.com/ericsciple\"\u003e\u003ccode\u003e@​ericsciple\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2305\"\u003eactions/checkout#2305\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocs: update README.md by \u003ca\nhref\u003d\"https://github.com/motss\"\u003e\u003ccode\u003e@​motss\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1971\"\u003eactions/checkout#1971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd internal repos for checking out multiple repositories by \u003ca\nhref\u003d\"https://github.com/mouismail\"\u003e\u003ccode\u003e@​mouismail\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1977\"\u003eactions/checkout#1977\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation update - add recommended permissions to Readme by \u003ca\nhref\u003d\"https://github.com/benwells\"\u003e\u003ccode\u003e@​benwells\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2043\"\u003eactions/checkout#2043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdjust positioning of user email note and permissions heading by \u003ca\nhref\u003d\"https://github.com/joshmgross\"\u003e\u003ccode\u003e@​joshmgross\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2044\"\u003eactions/checkout#2044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate README.md by \u003ca\nhref\u003d\"https://github.com/nebuk89\"\u003e\u003ccode\u003e@​nebuk89\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2194\"\u003eactions/checkout#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate CODEOWNERS for actions by \u003ca\nhref\u003d\"https://github.com/TingluoHuang\"\u003e\u003ccode\u003e@​TingluoHuang\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2224\"\u003eactions/checkout#2224\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate package dependencies by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/2236\"\u003eactions/checkout#2236\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eurl-helper.ts\u003c/code\u003e now leverages well-known environment\nvariables by \u003ca href\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e\nin \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1941\"\u003eactions/checkout#1941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand unit test coverage for \u003ccode\u003eisGhes\u003c/code\u003e by \u003ca\nhref\u003d\"https://github.com/jww3\"\u003e\u003ccode\u003e@​jww3\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1946\"\u003eactions/checkout#1946\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev4.2.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCheck out other refs/* by commit if provided, fall back to ref by \u003ca\nhref\u003d\"https://github.com/orhantoy\"\u003e\u003ccode\u003e@​orhantoy\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/pull/1924\"\u003eactions/checkout#1924\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003e\u003ccode\u003e3d3c42e\u003c/code\u003e\u003c/a\u003e\nprep v7.0.1 release (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2531\"\u003e#2531\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07\"\u003e\u003ccode\u003e2880268\u003c/code\u003e\u003c/a\u003e\nescape values passed to --unset (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2530\"\u003e#2530\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1\"\u003e\u003ccode\u003e12cd223\u003c/code\u003e\u003c/a\u003e\ntrim only ascii whitespace for branch (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2521\"\u003e#2521\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541\"\u003e\u003ccode\u003e62661c4\u003c/code\u003e\u003c/a\u003e\nskip running unsafe pr check if input is default (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2518\"\u003e#2518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f\"\u003e\u003ccode\u003ee8d4307\u003c/code\u003e\u003c/a\u003e\nBump the minor-actions-dependencies group with 2 updates (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2499\"\u003e#2499\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87\"\u003e\u003ccode\u003e631c942\u003c/code\u003e\u003c/a\u003e\neslint 9 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2474\"\u003e#2474\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e\"\u003e\u003ccode\u003e4f1f4ae\u003c/code\u003e\u003c/a\u003e\nBump actions/upload-artifact from 4 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2476\"\u003e#2476\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92\"\u003e\u003ccode\u003eba09753\u003c/code\u003e\u003c/a\u003e\nBump actions/checkout from 6 to 7 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2488\"\u003e#2488\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22\"\u003e\u003ccode\u003eb9e0990\u003c/code\u003e\u003c/a\u003e\nBump docker/login-action from 3.3.0 to 4.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2479\"\u003e#2479\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2\"\u003e\u003ccode\u003ee8cb398\u003c/code\u003e\u003c/a\u003e\nBump docker/build-push-action from 6.5.0 to 7.2.0 (\u003ca\nhref\u003d\"https://redirect.github.com/actions/checkout/issues/2478\"\u003e#2478\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/checkout\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d7.0.0\u0026new-version\u003d7.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "255471e548183ba00ff925b37daa9b9fdecfb680",
      "tree": "8f4c37e58510aa79ea59dcf297f2d18da4137161",
      "parents": [
        "410a19777d173c7216005f304076b7ce7dcd2af1"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 24 22:58:36 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 22:58:36 2026 +0800"
      },
      "message": "feat(aws): add profile selector to default provider (#794)\n\nAn AWS profile is shared across profile, SSO, and `credential_process`\ncredential sources, but callers currently have to reconstruct three\ndefault provider slots to select one explicit profile. This adds\n`DefaultCredentialProviderBuilder::with_profile(...)`, applying the\nselection to every enabled profile-aware slot while preserving\nprovider-specific settings, slot removal semantics, resolution order,\nand WASM platform gating.\n\nExplicit selection retains the precedence established by #792:\nconfigured profile, then `AWS_PROFILE`, then `default`. This lets\nOpenDAL expose per-operator profile selection for apache/opendal#7944\nwithout duplicating reqsign\u0027s default credential chain.\n\nCloses #791."
    },
    {
      "commit": "410a19777d173c7216005f304076b7ce7dcd2af1",
      "tree": "9b087473983bc46f39092ecf226e023533e1fb2a",
      "parents": [
        "6acff1e753924770bf01b6993f032afb0d270abc"
      ],
      "author": {
        "name": "Xin Sun",
        "email": "ddupgs@gmail.com",
        "time": "Fri Jul 24 20:57:45 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 20:57:45 2026 +0800"
      },
      "message": "feat(volcengine-tos): support presigned URLs (#779)\n\nPart of #752.\n\n## Summary\n\n- Add query-based TOS signing for presigned URLs.\n- Support security tokens, signed TOS headers, and explicit payload\nhashes.\n- Add deterministic coverage and a credential-gated real TOS integration\ntest.\n\nChanges outside the TOS service only fix Rust 1.97 Clippy warnings\nexposed by CI.\n\n## Verification\n\n- `cargo fmt --all -- --check`\n- `cargo clippy --workspace --all-targets --all-features -- -D warnings`\n- `cargo test --no-fail-fast`\n- Real TOS presigned PUT/GET/DELETE\n- OpenDAL TOS behavior suite: 54 passed on a versioning-enabled bucket\n\n---------\n\nCo-authored-by: Xuanwo \u003cgithub@xuanwo.io\u003e"
    },
    {
      "commit": "6acff1e753924770bf01b6993f032afb0d270abc",
      "tree": "2f0b191af3d96dd27b2c4b51ccaae336ad15f7f9",
      "parents": [
        "b1f72c17caa20ead87a20ffb2d2ba92266fe2f7c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 24 20:41:51 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 20:41:51 2026 +0800"
      },
      "message": "fix(aws): prefer explicitly configured profile (#792)\n\n`ProfileCredentialProvider::with_profile(...)` is explicit per-provider\nconfiguration, but `AWS_PROFILE` currently overrides it. This prevents\ncallers from reliably selecting different shared-config profiles for\nindependent providers in the same process and differs from the\nprecedence used by the SSO and process credential providers.\n\nResolve profiles in explicit configuration, `AWS_PROFILE`, then\n`default` order. Existing callers that do not configure a profile\nexplicitly continue to respect `AWS_PROFILE`; behavior changes only when\nan explicit profile conflicts with the ambient environment.\n\nCloses #790."
    },
    {
      "commit": "b1f72c17caa20ead87a20ffb2d2ba92266fe2f7c",
      "tree": "6ba96268ed93203c048442edb72e287c651a1e21",
      "parents": [
        "6894e267d4f1f77bd3cdf95f24eb30a72af62bb4"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 24 02:06:28 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 02:06:28 2026 +0800"
      },
      "message": "chore: prepare v0.20.3 release (#788)\n\nPrepare Apache OpenDAL reqsign v0.20.3 for the next release candidate.\n\nThis release includes the wire-request preservation fix from #785 and\nthe credential-validity contracts from #787. Because #787 adds\n`SignRequest::required_valid_until` to the public core API,\n`reqsign-core` advances from 3.1.0 to 3.2.0. The facade advances to\n0.20.3, and all remaining workspace crates receive coordinated patch\nbumps so `cargo publish --workspace` can publish the complete set\nconsistently."
    },
    {
      "commit": "6894e267d4f1f77bd3cdf95f24eb30a72af62bb4",
      "tree": "cd573907514c8da97ec49d3d00fcaad48018057a",
      "parents": [
        "195cd7aab17a2160b6aebd01e1ea85f97442c9f9"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri Jul 24 01:39:17 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 01:39:17 2026 +0800"
      },
      "message": "feat: define credential validity contracts (#787)\n\n## Summary\n\n`SigningCredential::is_valid()` currently mixes cache freshness with\nexact operation usability. This can make a successful refresh return the\nsame still-live token inside its proactive refresh window, only for the\nrequest signer to reject it. Core also interprets `expires_in` as a\nuniversal credential lifetime even though service authentication paths\nhave different requirements.\n\nThis change defines `is_valid()` as cache freshness and `is_valid_at()`\nas exact timestamp usability. It adds\n`SignRequest::required_valid_until()` so each service owns its signing\nclock, interpretation of `expires_in`, and explicit operation headroom.\nThe new hook has a default implementation, so normal downstream\nimplementations remain source-compatible while adopting the new\ndocumented semantics.\n\nCached credentials must be both fresh and usable for the operation.\nRefreshed credentials only need to satisfy the exact operation deadline\nand are cached even when they remain inside the refresh window. Provider\nerrors and `None` remain visible to the caller; `Signer` performs no\ninternal retry or stale-cache fallback. Individual provider-chain\nfallback policies are unchanged.\n\nThe built-in credential types and signers now implement these contracts\nfor AWS, Azure, Google, Aliyun, Huawei, Oracle, Tencent, and Volcengine,\nincluding direct-call validation and request failure atomicity.\n\nCloses #786."
    },
    {
      "commit": "195cd7aab17a2160b6aebd01e1ea85f97442c9f9",
      "tree": "7516bff4ca789d4d6ebbcdfcc6df098663f71d16",
      "parents": [
        "f7bc18ab3ddf62165cebedadcd9f56524040d03c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Jul 22 15:00:45 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 15:00:45 2026 +0800"
      },
      "message": "fix: preserve wire request representation during signing (#785)\n\nFixes #784.\n\nRequest signing currently conflates service canonicalization with the\nwire URI. As a result, SigningRequest::build/apply can decode or\notherwise rewrite caller-owned percent-encoded path and query\nrepresentations, and failures can leave a partially modified request\nhead.\n\nThis change defines URI input as fully percent-encoded and wire-ready.\nEach service derives its canonical signing view locally, header\nauthentication preserves URI identity, query authentication only appends\nprotocol-owned fields, and core commits URI and headers atomically after\nsuccessful signing. Existing Signer::sign, SignRequest::sign_request,\nand SigningRequest public shape stay unchanged, so OpenDAL call sites do\nnot need changes.\n\nCompatibility note: third-party SignRequest implementations must treat\nSigningRequest path and query as read-only canonicalization inputs and\nconstruct query-authentication output from the raw URI. Implementations\nthat relied on apply to rebuild or re-encode the URI may need\nadjustment."
    },
    {
      "commit": "f7bc18ab3ddf62165cebedadcd9f56524040d03c",
      "tree": "a51a8a01e6c4713be9bb509939f0fc5faa27f7c7",
      "parents": [
        "b49cd2996b9d2d9944e84481f8835ff55b188b97"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Sat Jul 11 04:16:36 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 11 04:16:36 2026 +0800"
      },
      "message": "chore: drop no longer relevant release steps (#781)"
    },
    {
      "commit": "b49cd2996b9d2d9944e84481f8835ff55b188b97",
      "tree": "433b1b88e84c52804aed4112b39eaac56f6e2f78",
      "parents": [
        "4214e9715be38b9d2b8a80aa1373fc5d73bd1634"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Mon Jul 06 20:18:30 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 20:18:30 2026 +0800"
      },
      "message": "chore: prepare v0.20.2 release (#775)\n\n## Summary\n\nPrepare Apache OpenDAL reqsign v0.20.2 release.\n\nVersion bumps:\n\n- `reqsign`: 0.20.1 -\u003e 0.20.2\n- `reqsign-core`: 3.0.1 -\u003e 3.1.0\n- `reqsign-azure-storage`: 3.0.1 -\u003e 3.1.0\n- `reqsign-aliyun-oss`: 3.1.0 -\u003e 3.1.1\n- Other 3.x workspace crates: 3.0.1 -\u003e 3.0.2\n- `reqsign-http-send-reqwest`: 4.0.1 -\u003e 4.0.2\n\nRationale:\n\n- `reqsign-core` adds the public `SigningCredential::is_valid_at` API.\n- `reqsign-azure-storage` adds public credential provider setters.\n- Other workspace crates are patch bumped for the workspace release.\n\n## Verification\n\n- `cargo check --workspace --all-targets --all-features`\n- `cargo fmt --all -- --check`\n- `cargo clippy --workspace --all-targets --all-features -- -D warnings`\n- `cargo test --no-fail-fast`\n- `cargo test --doc --all-features --workspace`\n- `cargo publish --workspace --dry-run --allow-dirty`\n\nNote: `wasm32-unknown-unknown` was not installed locally, so WASM target\nchecks are left to CI."
    },
    {
      "commit": "4214e9715be38b9d2b8a80aa1373fc5d73bd1634",
      "tree": "3e339e3c13cf1a9c5047b1dd1812f62f6744cd0d",
      "parents": [
        "e35e18b1e94a430f7e69559af9ae356ab9b6147b"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Sat Jul 04 13:07:54 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 13:07:54 2026 +0800"
      },
      "message": "chore: upgrade quick-xml to 0.41 (#774)\n\nSigned-off-by: tison \u003cwander4096@gmail.com\u003e"
    },
    {
      "commit": "e35e18b1e94a430f7e69559af9ae356ab9b6147b",
      "tree": "5ba7815f16513593a15eac5063e769abb24e5d3f",
      "parents": [
        "1dd00bb8633c00a95dc8a3c8ade6fbd81c0d1201"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 04 13:04:56 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 13:04:56 2026 +0800"
      },
      "message": "build(deps): bump 1Password/load-secrets-action from 4.0.0 to 4.0.1 (#768)\n\nBumps\n[1Password/load-secrets-action](https://github.com/1password/load-secrets-action)\nfrom 4.0.0 to 4.0.1.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/releases\"\u003e1Password/load-secrets-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.1\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003ch3\u003eFix\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a Windows specific issue where 1Password CLI installation\ncould fail because the downloaded archive lacked a .zip extension\nrequired by PowerShell’s archive extraction fallback. (\u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/154\"\u003e#154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from v5 to v6 in CI workflows. (\u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/156\"\u003e#156\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSecurity\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eHarden GitHub Actions workflows by pinning external actions to\nimmutable commit SHAs. (\u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/157\"\u003e#157\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd 1Password API Terms of Service notice to the README (\u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew Contributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/dagecko\"\u003e\u003ccode\u003e@​dagecko\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/157\"\u003e1Password/load-secrets-action#157\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/superteppo\"\u003e\u003ccode\u003e@​superteppo\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/154\"\u003e1Password/load-secrets-action#154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/libutcher\"\u003e\u003ccode\u003e@​libutcher\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/166\"\u003e1Password/load-secrets-action#166\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v4.0.0...v4.0.1\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v4.0.0...v4.0.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/3a12b0ab99d9cd590a3e9b5a90ea017210ed9556\"\u003e\u003ccode\u003e3a12b0a\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/167\"\u003e#167\u003c/a\u003e\nfrom 1Password/release/v4.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/0f0cd1b2cca821a593da63d07d393079bb151acb\"\u003e\u003ccode\u003e0f0cd1b\u003c/code\u003e\u003c/a\u003e\ncreate new build\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/be2f36bec409a934fef5d502f0864ab86af8faf7\"\u003e\u003ccode\u003ebe2f36b\u003c/code\u003e\u003c/a\u003e\nAdd Terms of Service to README (\u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/166\"\u003e#166\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/908aabfadefbbec4b622829114cad26439b67e77\"\u003e\u003ccode\u003e908aabf\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/154\"\u003e#154\u003c/a\u003e\nfrom superteppo/main\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/cc166c60deb878a166a3a11133c668415ef6aac8\"\u003e\u003ccode\u003ecc166c6\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/157\"\u003e#157\u003c/a\u003e\nfrom dagecko/runner-guard/fix-ci-security\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/080cd2d3be81ab40f269b8f3e54e98a2f7cdd6f6\"\u003e\u003ccode\u003e080cd2d\u003c/code\u003e\u003c/a\u003e\nMerge branch \u00271Password:main\u0027 into main\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2a321c3fe70e3ee7ea97b645c84fe870fb518d0c\"\u003e\u003ccode\u003e2a321c3\u003c/code\u003e\u003c/a\u003e\nfix: pin 4 unpinned action(s),extract 3 unsafe expression(s) to env\nvars\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2a9101f21de4fcc2ae46583a248b43d50ad0476a\"\u003e\u003ccode\u003e2a9101f\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/156\"\u003e#156\u003c/a\u003e\nfrom 1Password/jill/bump-actions\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/5b18565a3bb23363b250ce96e0b405de216f5a44\"\u003e\u003ccode\u003e5b18565\u003c/code\u003e\u003c/a\u003e\nbump actions\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/a763b8d28adee0398ab02627d7e2aa69e08945b4\"\u003e\u003ccode\u003ea763b8d\u003c/code\u003e\u003c/a\u003e\nfix installer error on windows\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/compare/92467eb28f72e8255933372f1e0707c567ce2259...3a12b0ab99d9cd590a3e9b5a90ea017210ed9556\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1dd00bb8633c00a95dc8a3c8ade6fbd81c0d1201",
      "tree": "a0fadf8c4565d9c812bb16a1d01fd646ae719cfa",
      "parents": [
        "22eeb1c1b4f6c631e2c3f6a6a70aeb9287eb4c98"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 04 12:31:39 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 12:31:39 2026 +0800"
      },
      "message": "build(deps): bump actions/checkout from 6.0.2 to 7.0.0 (#769)"
    },
    {
      "commit": "22eeb1c1b4f6c631e2c3f6a6a70aeb9287eb4c98",
      "tree": "ada1e98ea0300ba9b347c83b60ac4cecbb070be4",
      "parents": [
        "820993984923471cc410b9947c8550d2468df645"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sat Jul 04 12:31:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 12:31:07 2026 +0800"
      },
      "message": "build(deps): bump 1Password/load-secrets-action/configure from 4.0.0 to 4.0.1 (#770)"
    },
    {
      "commit": "820993984923471cc410b9947c8550d2468df645",
      "tree": "d2d061d1280cda0cbcce6c7a66076a9b666524ca",
      "parents": [
        "b1e572a3a8946476f244eff29ecfe7b9570fb1d7"
      ],
      "author": {
        "name": "tison",
        "email": "wander4096@gmail.com",
        "time": "Sat Jul 04 12:29:39 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 12:29:39 2026 +0800"
      },
      "message": "refactor: make reqsign-core jwt optional (#773)"
    },
    {
      "commit": "b1e572a3a8946476f244eff29ecfe7b9570fb1d7",
      "tree": "85777f65aeaaa73bc82e902b368ce8d215049064",
      "parents": [
        "5c526bab3345051790e867bc846a40acc93c165c"
      ],
      "author": {
        "name": "Colin Marc",
        "email": "hi@colinmarc.com",
        "time": "Sat Jul 04 06:27:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 04 12:27:18 2026 +0800"
      },
      "message": "feat: check credential validity against signature expiration (#772)"
    },
    {
      "commit": "5c526bab3345051790e867bc846a40acc93c165c",
      "tree": "09a7e9e6cc6d9fa8c19949b7661c68b3b112d207",
      "parents": [
        "54a4d10f7c09984f0cfbb19deaf0b38a6cd1e146"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon Jun 01 17:19:18 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 17:19:18 2026 +0800"
      },
      "message": "docs: add reqsign release skill (#763)\n\nAdd a reusable release skill for Apache OpenDAL reqsign.\n\nThe skill captures the Apache RC flow used for the 0.20.1 release:\nversion bump PR, signed RC tag, source artifacts, ASF dist upload,\nvote/result, formal tag, crates.io publish, GitHub Release, and recovery\nnotes for common release mistakes."
    },
    {
      "commit": "54a4d10f7c09984f0cfbb19deaf0b38a6cd1e146",
      "tree": "87bc2ecf572e3c44498d869b3b96e4ffa6e58be4",
      "parents": [
        "3a50c2c1f269109c5901b121791c4b4489cdafca"
      ],
      "author": {
        "name": "Yuang Gao",
        "email": "91290127+YuangGao@users.noreply.github.com",
        "time": "Thu May 28 02:21:27 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 28 17:21:27 2026 +0800"
      },
      "message": "feat(azure-storage): add missing setters for client secret and workload identity providers (#760)\n\n## Which issue does this PR close?\n\n- Closes #756.\n\n## What changes are included in this PR?\n\n`ClientSecretCredentialProvider`:\n- Add `client_secret` and `authority_host` fields with corresponding\nsetters.\n- `provide_credential` now reads `self.client_id` / `self.client_secret`\n/ `self.authority_host` first, falling back to `AZURE_CLIENT_ID` /\n`AZURE_CLIENT_SECRET` / `AZURE_AUTHORITY_HOST`. Fixes `with_client_id`\nbeing a silent no-op.\n\n`WorkloadIdentityCredentialProvider`:\n- Add `client_id`, `federated_token_file`, and `authority_host` fields\nwith corresponding setters.\n- `provide_credential` now reads each from `self` first, falling back to\nenv vars. Fixes `with_tenant_id` being a silent no-op"
    },
    {
      "commit": "3a50c2c1f269109c5901b121791c4b4489cdafca",
      "tree": "a570cfc702998574f5e6d4d8e0ee24d331b2612a",
      "parents": [
        "6d7af22845aa70e4f9273cfe7b1e9f6bd5749438"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri May 22 17:37:15 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 17:37:15 2026 +0800"
      },
      "message": "chore: prepare v0.20.1 release\n\nPrepare workspace manifests for v0.20.1 release."
    },
    {
      "commit": "6d7af22845aa70e4f9273cfe7b1e9f6bd5749438",
      "tree": "71026976c0fdcd1ed0d69f503ea2bf9231a67cd8",
      "parents": [
        "aa879f11975721e223fa0c592f74b20b94c750fd"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Fri May 22 17:05:39 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 17:05:39 2026 +0800"
      },
      "message": "refactor: Remove jsonwebtoken dependency (#757)\n\nCloses #754.\n\nThis removes `jsonwebtoken` from the workspace instead of adding crypto\nbackend feature selection for it. Reqsign only needs to generate RS256\nclient assertions for Google and Azure, so the PR replaces those call\nsites with a small internal RS256 JWT encoder built on the existing\n`rsa`, `serde_json`, and `base64` dependencies.\n\nThis supersedes #755 by removing the dependency path that pulled\n`aws-lc-rs` into normal builds."
    },
    {
      "commit": "aa879f11975721e223fa0c592f74b20b94c750fd",
      "tree": "8252d6525538d4470169f968ebb5305bbbe0e3ab",
      "parents": [
        "bb87cb8459b13c243b06827e43aa2b04ff1eef93"
      ],
      "author": {
        "name": "Tamir Duberstein",
        "email": "tamird@gmail.com",
        "time": "Fri May 22 10:40:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 16:40:18 2026 +0800"
      },
      "message": "Clarify Azure version header ownership (#746)\n\nReqsign no longer owns Azure service-version header insertion. Document\nthat callers should provide `x-ms-version` for ordinary Azure Storage\nrequests and omit it only for batch sub-requests.\n\nThis changed in aa28ce2e4db673c6f0fa9fc31533b39e856ad825."
    },
    {
      "commit": "bb87cb8459b13c243b06827e43aa2b04ff1eef93",
      "tree": "7bd89f59287111171f509e4759320fe59f266754",
      "parents": [
        "9aba16ea2c2766844aedf32c3e6a9701a08f6ec6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri May 22 16:17:34 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 16:17:34 2026 +0800"
      },
      "message": "build(deps): update quick-xml requirement from 0.39.2 to 0.40.0 (#753)\n\nUpdates the requirements on\n[quick-xml](https://github.com/tafia/quick-xml) to permit the latest\nversion.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/releases\"\u003equick-xml\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.40.0 - UTF-16 and ISO-2022-JP encodings supported\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cp\u003eMSRV bumped to 1.79.\u003c/p\u003e\n\u003cp\u003eNow \u003ccode\u003equick-xml\u003c/code\u003e supports the UTF-16 and ISO-2022-JP\nencoded documents. See the new \u003ccode\u003eDecodingReader\u003c/code\u003e type.\u003c/p\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\nAdd \u003ccode\u003eDecodingReader\u003c/code\u003e, a \u003ccode\u003eBufRead\u003c/code\u003e adapter that\nauto-detects encoding from BOM or XML declaration and transcodes to\nUTF-8. Enabled by the \u003ccode\u003eencoding\u003c/code\u003e feature.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nAdd new enumeration \u003ccode\u003eXmlVersion\u003c/code\u003e and typified getter\n\u003ccode\u003eBytesDecl::xml_version()\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nAdd new error variant \u003ccode\u003eIllFormedError::UnknownVersion\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\nAdd new error variant\n\u003ccode\u003eEscapeError::TooManyNestedEntities\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\nImproved compliance with the XML attribute value normalization process\nby adding\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::normalized_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::normalized_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decoded_and_normalized_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decoded_and_normalized_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ewhich ought to be used in place of deprecated\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::unescape_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::unescape_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decode_and_unescape_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decode_and_unescape_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDeprecated functions now behaves the same as newly added.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nUse correct rules for EOL normalization in \u003ccode\u003eDeserializer\u003c/code\u003e\nwhen parse XML 1.0 documents. Previously XML 1.1. rules was\napplied.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/914\"\u003e#914\u003c/a\u003e:\nRemove deprecated \u003ccode\u003e.prefixes()\u003c/code\u003e, \u003ccode\u003e.resolve()\u003c/code\u003e,\n\u003ccode\u003e.resolve_attribute()\u003c/code\u003e, and \u003ccode\u003e.resolve_element()\u003c/code\u003e\nof \u003ccode\u003eNsReader\u003c/code\u003e. Use \u003ccode\u003e.resolver().\u0026lt;...\u0026gt;\u003c/code\u003e\nmethods instead.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nNow \u003ccode\u003eBytesText::xml_content\u003c/code\u003e,\n\u003ccode\u003eBytesCData::xml_content\u003c/code\u003e and\n\u003ccode\u003eBytesRef::xml_content\u003c/code\u003e accepts \u003ccode\u003eXmlVersion\u003c/code\u003e\nparameter to apply correct EOL normalization rules.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/944\"\u003e#944\u003c/a\u003e:\n\u003ccode\u003eread_text()\u003c/code\u003e now returns \u003ccode\u003eBytesText\u003c/code\u003e which allows\nyou to get the content with properly normalized EOLs. To get the\nprevious behavior use \u003ccode\u003e.read_text().decode()?\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\nBumped MSRV from 1.59 (Feb 2022) to 1.79 (June 2024)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003etafia/quick-xml#371\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/914\"\u003e#914\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/914\"\u003etafia/quick-xml#914\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/938\"\u003etafia/quick-xml#938\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/944\"\u003e#944\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/944\"\u003etafia/quick-xml#944\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/956\"\u003etafia/quick-xml#956\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/dobermai\"\u003e\u003ccode\u003e@​dobermai\u003c/code\u003e\u003c/a\u003e\nmade their first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/958\"\u003etafia/quick-xml#958\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/compare/v0.39.4...v0.40.0\"\u003ehttps://github.com/tafia/quick-xml/compare/v0.39.4...v0.40.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/blob/master/Changelog.md\"\u003equick-xml\u0027s\nchangelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.40.0 -- 2026-05-11\u003c/h2\u003e\n\u003cp\u003eMSRV bumped to 1.79.\u003c/p\u003e\n\u003cp\u003eNow \u003ccode\u003equick-xml\u003c/code\u003e supports the UTF-16 encoded documents. See\nthe new \u003ccode\u003eDecodingReader\u003c/code\u003e type.\u003c/p\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\nAdd \u003ccode\u003eDecodingReader\u003c/code\u003e, a \u003ccode\u003eBufRead\u003c/code\u003e adapter that\nauto-detects encoding\nfrom BOM or XML declaration and transcodes to UTF-8. Enabled by the\n\u003ccode\u003eencoding\u003c/code\u003e feature.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nAdd new enumeration \u003ccode\u003eXmlVersion\u003c/code\u003e and typified getter\n\u003ccode\u003eBytesDecl::xml_version()\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nAdd new error variant \u003ccode\u003eIllFormedError::UnknownVersion\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\nAdd new error variant\n\u003ccode\u003eEscapeError::TooManyNestedEntities\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\nImproved compliance with the XML attribute value normalization process\nby adding\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::normalized_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::normalized_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decoded_and_normalized_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decoded_and_normalized_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ewhich ought to be used in place of deprecated\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::unescape_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::unescape_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decode_and_unescape_value()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAttribute::decode_and_unescape_value_with()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDeprecated functions now behaves the same as newly added.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nUse correct rules for EOL normalization in \u003ccode\u003eDeserializer\u003c/code\u003e\nwhen parse XML 1.0 documents.\nPreviously XML 1.1. rules was applied.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/914\"\u003e#914\u003c/a\u003e:\nRemove deprecated \u003ccode\u003e.prefixes()\u003c/code\u003e, \u003ccode\u003e.resolve()\u003c/code\u003e,\n\u003ccode\u003e.resolve_attribute()\u003c/code\u003e, and \u003ccode\u003e.resolve_element()\u003c/code\u003e\nof \u003ccode\u003eNsReader\u003c/code\u003e. Use \u003ccode\u003e.resolver().\u0026lt;...\u0026gt;\u003c/code\u003e\nmethods instead.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\nNow \u003ccode\u003eBytesText::xml_content\u003c/code\u003e,\n\u003ccode\u003eBytesCData::xml_content\u003c/code\u003e and\n\u003ccode\u003eBytesRef::xml_content\u003c/code\u003e\naccepts \u003ccode\u003eXmlVersion\u003c/code\u003e parameter to apply correct EOL\nnormalization rules.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/944\"\u003e#944\u003c/a\u003e:\n\u003ccode\u003eread_text()\u003c/code\u003e now returns \u003ccode\u003eBytesText\u003c/code\u003e which allows\nyou to get the content with\nproperly normalized EOLs. To get the previous behavior use\n\u003ccode\u003e.read_text().decode()?\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\nBumped MSRV from 1.59 (Feb 2022) to 1.79 (June 2024)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003e#371\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/371\"\u003etafia/quick-xml#371\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/914\"\u003e#914\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/914\"\u003etafia/quick-xml#914\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/938\"\u003e#938\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/938\"\u003etafia/quick-xml#938\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/944\"\u003e#944\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/944\"\u003etafia/quick-xml#944\u003c/a\u003e\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e:\n\u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/pull/956\"\u003etafia/quick-xml#956\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e0.39.4 -- 2026-05-08\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/2778564d592ca25d6315ea20b5105c74addfce5e\"\u003e\u003ccode\u003e2778564\u003c/code\u003e\u003c/a\u003e\nRelease 0.40.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/393db036811e7473b22d875109cd07acb183580f\"\u003e\u003ccode\u003e393db03\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/962\"\u003e#962\u003c/a\u003e\nfrom Mingun/prepare-0.40\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/a27709a457126f129b06d20309316be74056234c\"\u003e\u003ccode\u003ea27709a\u003c/code\u003e\u003c/a\u003e\nFix misprint in code example\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/0c0c914bc753075abdab92dcd94fc95c6a195b25\"\u003e\u003ccode\u003e0c0c914\u003c/code\u003e\u003c/a\u003e\nMake some functions const and enable clippy::missing_const_for_fn\nlint\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/bf4ffe5020cbe256c441c2cd26adf8716f6e5324\"\u003e\u003ccode\u003ebf4ffe5\u003c/code\u003e\u003c/a\u003e\nFix clippy warning: use \u003ccode\u003e.first()\u003c/code\u003e instead of\n\u003ccode\u003e.get(0)\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/d69baad385aeb489d4761469cc9738c21aa41c4f\"\u003e\u003ccode\u003ed69baad\u003c/code\u003e\u003c/a\u003e\nFix clippy warning: remove unnecessary after\n241f01e20ff679e9248f2ae424c9ba82...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/8e0ae4f7f4f2d0dda9f000f094bdf9b8e2b915a5\"\u003e\u003ccode\u003e8e0ae4f\u003c/code\u003e\u003c/a\u003e\nFix clippy warning: use \u003ccode\u003estrip_prefix\u003c/code\u003e instead of manual\nstripping\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/b795a5db737ad1b9c3fa8e61b31215fe1aba9552\"\u003e\u003ccode\u003eb795a5d\u003c/code\u003e\u003c/a\u003e\nRemove outdated documentation line that accidentally remained after\n99d2870a3...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/94e61ed5c0dbc8f18ce7e4bdc77a4a14fac71111\"\u003e\u003ccode\u003e94e61ed\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/tafia/quick-xml/issues/956\"\u003e#956\u003c/a\u003e\nfrom dralley/decode\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/commit/b918b0bab8c5b98cfc84f7322bd80fa3cc80f5b4\"\u003e\u003ccode\u003eb918b0b\u003c/code\u003e\u003c/a\u003e\nExpand tests using DecodingReader\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/tafia/quick-xml/compare/v0.39.2...v0.40.0\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "9aba16ea2c2766844aedf32c3e6a9701a08f6ec6",
      "tree": "f77f878d16e9b636d5887e87fcd658dce86b72cb",
      "parents": [
        "7ebc4d5a0a993106f67de638e7956ab4ff182785"
      ],
      "author": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Fri May 22 03:16:54 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 22 16:16:54 2026 +0800"
      },
      "message": "[INFRA] Set up default rulesets for default and release branches (#747)\n\nThis Pull Request enables the repository to conform with the \"sane\ndefault security settings\" of the Apache Software Foundation by\nconfiguring a default branch ruleset that protects the default branch\nand any release branches.\n\nNote that `~DEFAULT_BRANCH` is a GitHub symbolic link to the current\ndefault branch (HEAD) of the repository and does not need changing.\nIf the managing project does not wish to set up these defaults, please\nclose this Pull Request. Alternatively, the project may merge this Pull\nRequest to apply the changes immediately.\n\nIf no action is taken, this Pull Request will be automatically merged by\nthe Apache Infrastructure team on **2026-06-14** (30 days from now).\n\nFor any further information, please reach us on Slack or at:\nusers@infra.apache.org"
    },
    {
      "commit": "7ebc4d5a0a993106f67de638e7956ab4ff182785",
      "tree": "ec6914c68892a1fa9889cb47f0986c4d6b6158b4",
      "parents": [
        "361d38b433a3c58b849538d138e3c6767c626b3c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon May 18 16:32:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 18 16:32:22 2026 +0800"
      },
      "message": "Add ASF allowlist check (#745)\n\nAdd the ASF infrastructure allowlist check for GitHub workflow changes\nso new action references are validated before merge.\n\nThis also normalizes the 1Password action references to the upstream\ncasing and updates Azure login to the allowlisted v3 ref, so the new\ncheck passes against the current ASF allowlist."
    },
    {
      "commit": "361d38b433a3c58b849538d138e3c6767c626b3c",
      "tree": "63bf59e3cc55f5083e69d048388919eedc6f7f12",
      "parents": [
        "4f2dca68173e1dc810eef38d1c7dc9c8190cfa2d"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Tue May 12 12:11:19 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 12 12:11:19 2026 +0800"
      },
      "message": "Support explicit Aliyun OIDC config (#744)\n\nThis PR lets `AssumeRoleWithOidcCredentialProvider` accept the required\nOIDC settings through typed builder methods, so embedders no longer need\nto synthesize runtime environment variables just to use structured\nconfig.\n\nThe existing environment-variable path remains available as a\nconvenience fallback, while explicitly configured values take precedence\nand can fully bypass env lookup when all required OIDC fields are\nprovided.\n\nCloses #734."
    },
    {
      "commit": "4f2dca68173e1dc810eef38d1c7dc9c8190cfa2d",
      "tree": "7a6f413409083ae06642e948aa34643a8455d584",
      "parents": [
        "b50f609530f05aae43d5cdc515a0c9aa5b38e8d0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 12 09:25:56 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 12 09:25:56 2026 +0800"
      },
      "message": "build(deps): bump 1password/load-secrets-action from 3.2.1 to 4.0.0 (#737)\n\nBumps\n[1password/load-secrets-action](https://github.com/1password/load-secrets-action)\nfrom 3.2.1 to 4.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/releases\"\u003e1password/load-secrets-action\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eClear \u003cstrong\u003enpm audit\u003c/strong\u003e / \u003cstrong\u003eDependabot\u003c/strong\u003e\nfindings via \u003cstrong\u003e\u003ccode\u003enpm audit fix\u003c/code\u003e\u003c/strong\u003e where safe\n(e.g. \u003cstrong\u003eajv\u003c/strong\u003e, \u003cstrong\u003eflatted\u003c/strong\u003e,\n\u003cstrong\u003eundici\u003c/strong\u003e, and other resolvable \u003cstrong\u003eminimatch\u003c/strong\u003e\nupdates). \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/151\"\u003e#151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAction runtime updated from Node 20 to \u003cstrong\u003eNode 24\u003c/strong\u003e for\nGitHub Actions compatibility (\u003ca\nhref\u003d\"https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/\"\u003edeprecation\nnotice\u003c/a\u003e). \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/148\"\u003e#148\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/jjavieralv\"\u003e\u003ccode\u003e@​jjavieralv\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/1Password/load-secrets-action/pull/149\"\u003e1Password/load-secrets-action#149\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/compare/v3...v4.0.0\"\u003ehttps://github.com/1Password/load-secrets-action/compare/v3...v4.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/92467eb28f72e8255933372f1e0707c567ce2259\"\u003e\u003ccode\u003e92467eb\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/153\"\u003e#153\u003c/a\u003e\nfrom 1Password/release/v4.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/21f21cb3122f5fe7bfdfd67df466dcdb3779307e\"\u003e\u003ccode\u003e21f21cb\u003c/code\u003e\u003c/a\u003e\nUpdate readme\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/a82b5b0e6208219fa3988afa58471e77f1ae24c7\"\u003e\u003ccode\u003ea82b5b0\u003c/code\u003e\u003c/a\u003e\ncreate new build\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/355a4641a8ce03214b1d4713e4df46ce299aa659\"\u003e\u003ccode\u003e355a464\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/151\"\u003e#151\u003c/a\u003e\nfrom 1Password/fix/dependabot-alerts\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/50dbf2f36c578393af5f8c525f7b55fd04ec600c\"\u003e\u003ccode\u003e50dbf2f\u003c/code\u003e\u003c/a\u003e\nRun npm isntall\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/2a602963c2584abcf77cd466b8b6e386f833f3b2\"\u003e\u003ccode\u003e2a60296\u003c/code\u003e\u003c/a\u003e\nUndo version bump\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/61e04e231d813e6a6f186baa3c659316dfe1ddaa\"\u003e\u003ccode\u003e61e04e2\u003c/code\u003e\u003c/a\u003e\nOveride minimatch\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/93d1217e3f210e307b4fc30ee8e0e18f590a1e0e\"\u003e\u003ccode\u003e93d1217\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/1password/load-secrets-action/issues/150\"\u003e#150\u003c/a\u003e\nfrom 1Password/jill/update-tests-to-use-node-24\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/17a79a92a6dc3496470258dff9b216fd5033b503\"\u003e\u003ccode\u003e17a79a9\u003c/code\u003e\u003c/a\u003e\nUndo mistaken udpate\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/1Password/load-secrets-action/commit/7a0b59f9ab438aecbc232501a58d8c34a18f6591\"\u003e\u003ccode\u003e7a0b59f\u003c/code\u003e\u003c/a\u003e\nUpdate to v6\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/1password/load-secrets-action/compare/dafbe7cb03502b260e2b2893c753c352eee545bf...92467eb28f72e8255933372f1e0707c567ce2259\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003d1password/load-secrets-action\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d3.2.1\u0026new-version\u003d4.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nYou can trigger a rebase of this PR by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\n\u003e **Note**\n\u003e Automatic rebases have been disabled on this pull request as it has\nbeen open for over 30 days.\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b50f609530f05aae43d5cdc515a0c9aa5b38e8d0",
      "tree": "e80fb06c0d9dd94f97fcec85af8fb4d156d783aa",
      "parents": [
        "73ebc4b893b5ef1094005e079c4cf6e848a3e1fe"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 12 09:25:30 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 12 09:25:30 2026 +0800"
      },
      "message": "build(deps): bump azure/login from 2.3.0 to 3.0.0 (#735)\n\nBumps [azure/login](https://github.com/azure/login) from 2.3.0 to 3.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/azure/login/releases\"\u003eazure/login\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eAzure Login Action v3.0.0\u003c/h2\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade nodejs from 20 to 24 and update dependencies by \u003ca\nhref\u003d\"https://github.com/YanaXu\"\u003e\u003ccode\u003e@​YanaXu\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/Azure/login/pull/578\"\u003eAzure/login#578\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/Azure/login/compare/v2.3.0...v3.0.0\"\u003ehttps://github.com/Azure/login/compare/v2.3.0...v3.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/Azure/login/commit/532459ea530d8321f2fb9bb10d1e0bcf23869a43\"\u003e\u003ccode\u003e532459e\u003c/code\u003e\u003c/a\u003e\nprepare release v3.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/Azure/login/commit/893aa84218880a3fafd9a6d332ff1aea7108f1fe\"\u003e\u003ccode\u003e893aa84\u003c/code\u003e\u003c/a\u003e\nupgrade Azure Login Action version in README (\u003ca\nhref\u003d\"https://redirect.github.com/azure/login/issues/579\"\u003e#579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/Azure/login/commit/ce6a9ff965c6b99ee966eee159baa8c35e135635\"\u003e\u003ccode\u003ece6a9ff\u003c/code\u003e\u003c/a\u003e\nupgrade nodejs from 20 to 24 and update dependencies (\u003ca\nhref\u003d\"https://redirect.github.com/azure/login/issues/578\"\u003e#578\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca\nhref\u003d\"https://github.com/azure/login/compare/a457da9ea143d694b1b9c7c869ebb04ebe844ef5...532459ea530d8321f2fb9bb10d1e0bcf23869a43\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dazure/login\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d2.3.0\u0026new-version\u003d3.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nYou can trigger a rebase of this PR by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\n\u003e **Note**\n\u003e Automatic rebases have been disabled on this pull request as it has\nbeen open for over 30 days.\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "73ebc4b893b5ef1094005e079c4cf6e848a3e1fe",
      "tree": "648a0ec61c666eaf2e9f37c31fa1e378529a6e10",
      "parents": [
        "712082079745d902f2f53b8c6c3d61eb0e647ce5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 12 01:29:33 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 12 01:29:33 2026 +0800"
      },
      "message": "build(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#741)\n\nBumps [actions/github-script](https://github.com/actions/github-script)\nfrom 8.0.0 to 9.0.0.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca\nhref\u003d\"https://github.com/actions/github-script/releases\"\u003eactions/github-script\u0027s\nreleases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev9.0.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eNew features:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003egetOctokit\u003c/code\u003e factory function\u003c/strong\u003e —\nAvailable directly in the script context. Create additional\nauthenticated Octokit clients with different tokens for multi-token\nworkflows, GitHub App tokens, and cross-org access. See \u003ca\nhref\u003d\"https://github.com/actions/github-script#creating-additional-clients-with-getoctokit\"\u003eCreating\nadditional clients with \u003ccode\u003egetOctokit\u003c/code\u003e\u003c/a\u003e for details and\nexamples.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eOrchestration ID in user-agent\u003c/strong\u003e — The\n\u003ccode\u003eACTIONS_ORCHESTRATION_ID\u003c/code\u003e environment variable is\nautomatically appended to the user-agent string for request\ntracing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBreaking changes:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003erequire(\u0027@actions/github\u0027)\u003c/code\u003e no longer works in\nscripts.\u003c/strong\u003e The upgrade to \u003ccode\u003e@actions/github\u003c/code\u003e v9\n(ESM-only) means \u003ccode\u003erequire(\u0027@actions/github\u0027)\u003c/code\u003e will fail at\nruntime. If you previously used patterns like \u003ccode\u003econst { getOctokit }\n\u003d require(\u0027@actions/github\u0027)\u003c/code\u003e to create secondary clients, use the\nnew injected \u003ccode\u003egetOctokit\u003c/code\u003e function instead — it\u0027s available\ndirectly in the script context with no imports needed.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egetOctokit\u003c/code\u003e is now an injected function parameter.\nScripts that declare \u003ccode\u003econst getOctokit \u003d ...\u003c/code\u003e or \u003ccode\u003elet\ngetOctokit \u003d ...\u003c/code\u003e will get a \u003ccode\u003eSyntaxError\u003c/code\u003e because\nJavaScript does not allow \u003ccode\u003econst\u003c/code\u003e/\u003ccode\u003elet\u003c/code\u003e\nredeclaration of function parameters. Use the injected\n\u003ccode\u003egetOctokit\u003c/code\u003e directly, or use \u003ccode\u003evar getOctokit \u003d\n...\u003c/code\u003e if you need to redeclare it.\u003c/li\u003e\n\u003cli\u003eIf your script accesses other \u003ccode\u003e@actions/github\u003c/code\u003e internals\nbeyond the standard \u003ccode\u003egithub\u003c/code\u003e/\u003ccode\u003eoctokit\u003c/code\u003e client, you\nmay need to update those references for v9 compatibility.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat\u0027s Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd ACTIONS_ORCHESTRATION_ID to user-agent string by \u003ca\nhref\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/pull/695\"\u003eactions/github-script#695\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: use deployment: false for integration test environments by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/pull/712\"\u003eactions/github-script#712\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat!: add getOctokit to script context, upgrade\n\u003ccode\u003e@​actions/github\u003c/code\u003e v9, \u003ccode\u003e@​octokit/core\u003c/code\u003e v7, and\nrelated packages by \u003ca\nhref\u003d\"https://github.com/salmanmkc\"\u003e\u003ccode\u003e@​salmanmkc\u003c/code\u003e\u003c/a\u003e in \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/pull/700\"\u003eactions/github-script#700\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href\u003d\"https://github.com/Copilot\"\u003e\u003ccode\u003e@​Copilot\u003c/code\u003e\u003c/a\u003e made\ntheir first contribution in \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/pull/695\"\u003eactions/github-script#695\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca\nhref\u003d\"https://github.com/actions/github-script/compare/v8.0.0...v9.0.0\"\u003ehttps://github.com/actions/github-script/compare/v8.0.0...v9.0.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/3a2844b7e9c422d3c10d287c895573f7108da1b3\"\u003e\u003ccode\u003e3a2844b\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/issues/700\"\u003e#700\u003c/a\u003e\nfrom actions/salmanmkc/expose-getoctokit + prepare re...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/ca10bbdd1a7739de09e99a200c7a59f5d73a4079\"\u003e\u003ccode\u003eca10bbd\u003c/code\u003e\u003c/a\u003e\nfix: use \u003ccode\u003e@​octokit/core/\u003c/code\u003etypes import for v7\ncompatibility\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/86e48e20ac85c970ed1f96e718fd068173948b7b\"\u003e\u003ccode\u003e86e48e2\u003c/code\u003e\u003c/a\u003e\nmerge: incorporate main branch changes\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/c1084728b5b935ec4ddc1e4cee877b01797b3ff9\"\u003e\u003ccode\u003ec108472\u003c/code\u003e\u003c/a\u003e\nchore: rebuild dist for v9 upgrade and getOctokit factory\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/afff112e4f8b57c718168af75b89ce00bc8d091d\"\u003e\u003ccode\u003eafff112\u003c/code\u003e\u003c/a\u003e\nMerge pull request \u003ca\nhref\u003d\"https://redirect.github.com/actions/github-script/issues/712\"\u003e#712\u003c/a\u003e\nfrom actions/salmanmkc/deployment-false + fix user-ag...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/ff8117e5b78c415f814f39ad6998f424fee7b817\"\u003e\u003ccode\u003eff8117e\u003c/code\u003e\u003c/a\u003e\nci: fix user-agent test to handle orchestration ID\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/81c6b7876079abe10ff715951c9fc7b3e1ab389d\"\u003e\u003ccode\u003e81c6b78\u003c/code\u003e\u003c/a\u003e\nci: use deployment: false to suppress deployment noise from integration\ntests\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/3953caf8858d318f37b6cc53a9f5708859b5a7b7\"\u003e\u003ccode\u003e3953caf\u003c/code\u003e\u003c/a\u003e\ndocs: update README examples from \u003ca\nhref\u003d\"https://github.com/v8\"\u003e\u003ccode\u003e@​v8\u003c/code\u003e\u003c/a\u003e to \u003ca\nhref\u003d\"https://github.com/v9\"\u003e\u003ccode\u003e@​v9\u003c/code\u003e\u003c/a\u003e, add getOctokit docs\nand v9 brea...\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/c17d55b90dcdb3d554d0027a6c180a7adc2daf78\"\u003e\u003ccode\u003ec17d55b\u003c/code\u003e\u003c/a\u003e\nci: add getOctokit integration test job\u003c/li\u003e\n\u003cli\u003e\u003ca\nhref\u003d\"https://github.com/actions/github-script/commit/a047196d9a02fe92098771cafbb98c2f1814e408\"\u003e\u003ccode\u003ea047196\u003c/code\u003e\u003c/a\u003e\ntest: add getOctokit integration tests via callAsyncFunction\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca\nhref\u003d\"https://github.com/actions/github-script/compare/ed597411d8f924073f98dfc5c65a23a2325f34cd...3a2844b7e9c422d3c10d287c895573f7108da1b3\"\u003ecompare\nview\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility\nscore](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name\u003dactions/github-script\u0026package-manager\u003dgithub_actions\u0026previous-version\u003d8.0.0\u0026new-version\u003d9.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don\u0027t\nalter it yourself. You can also trigger a rebase manually by commenting\n`@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits\nthat have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all\nof the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop\nDependabot creating any more for this major version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop\nDependabot creating any more for this minor version (unless you reopen\nthe PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop\nDependabot creating any more for this dependency (unless you reopen the\nPR or upgrade to it yourself)\n\n\n\u003c/details\u003e\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "712082079745d902f2f53b8c6c3d61eb0e647ce5",
      "tree": "6e9feb55c446add342448133f662a075700f89bb",
      "parents": [
        "a3c923fe2fce1823dcbd06cbe31bd41d1338a927"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Mon May 11 23:13:26 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 23:13:26 2026 +0800"
      },
      "message": "Upgrade RustCrypto hash dependencies (#743)\n\nThis upgrades the direct RustCrypto hash/MAC dependencies to the current\nstable line: hmac 0.13 and sha1/sha2 0.11. The RSA crate is\nintentionally left on the latest stable 0.9 series, so RSA signing code\nuses rsa::sha2::Sha256 to keep that digest-0.10 boundary isolated while\nthe rest of reqsign moves forward.\n\nCargo.lock is ignored in this repository, so this PR only updates\nmanifests and the small API adaptations required by the new hash crates."
    },
    {
      "commit": "a3c923fe2fce1823dcbd06cbe31bd41d1338a927",
      "tree": "02d650369fdb72e2887d60a6cd7828cebe33fc1a",
      "parents": [
        "9c67ccc929f0b4bd432f70b81759d5fd98a65512"
      ],
      "author": {
        "name": "Ben Beasley",
        "email": "code@musicinmybrain.net",
        "time": "Fri Mar 27 12:32:34 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Mar 27 20:32:34 2026 +0800"
      },
      "message": "fix: Fix missing LICENSE file in published reqsign-volcengine-tos crate (#736)\n\nThis is the same fix as\nhttps://github.com/apache/opendal-reqsign/pull/635, but for the new\n`volcengine-tos` service."
    },
    {
      "commit": "9c67ccc929f0b4bd432f70b81759d5fd98a65512",
      "tree": "b573de3b134ff35193240b4e56331913ca72655f",
      "parents": [
        "0976884a738b22110e29fe7bed88caedd5392d50"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 15:45:12 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 15:45:12 2026 +0800"
      },
      "message": "feat(aliyun-oss): add signature v2 signing support (#725)\n\nThis PR adds OSS Signature V2 support to `reqsign-aliyun-oss`, covering\nboth header signing and presign.\n\nIt extends the signer parity work after V4 by adding the remaining OSS\nsigning variant with deterministic tests and updated docs."
    },
    {
      "commit": "0976884a738b22110e29fe7bed88caedd5392d50",
      "tree": "6e6b0c10d8d49ae85be9b1f8d0df903a0038fc21",
      "parents": [
        "3b749afa8ed2ee249e126c41fb6432f48dbcbb3c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 15:38:08 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 15:38:08 2026 +0800"
      },
      "message": "fix(aliyun-oss): normalize custom sts endpoints (#726)\n\nThis fixes a correctness bug in Aliyun OSS STS endpoint handling: when\n`ALIBABA_CLOUD_STS_ENDPOINT` was set to a full URL, the AssumeRole path\nprefixed `https://` again and produced a malformed request URI.\n\nThe change normalizes custom STS endpoints so both bare hosts and full\nURLs work consistently across the AK-based AssumeRole provider and the\nOIDC-based STS provider. It also adds regression coverage for the\nenv-configured full-URL case.\n\nContext: found while reviewing the latest 20 commits on `main`,\nspecifically the new AssumeRole provider added in #724."
    },
    {
      "commit": "3b749afa8ed2ee249e126c41fb6432f48dbcbb3c",
      "tree": "f7cfea97e68e63885a6a9922c605324aa1b9a4d5",
      "parents": [
        "bf20a01f0185072348d6150ea33ec9681d3625a8"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 05:27:34 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 05:27:34 2026 +0800"
      },
      "message": "feat(google): support aws external account sources (#728)\n\nGoogle external account credentials also support the AWS-specific\n`credential_source` shape from AIP-4117. This teaches `reqsign-google`\nto resolve `aws1` region and credentials from environment variables or\nIMDS, mint the signed `GetCallerIdentity` subject token, and exchange it\nthrough the existing STS flow.\n\nThis follows the executable `external_account` support in #727 and keeps\nthe change fully inside `services/google`."
    },
    {
      "commit": "bf20a01f0185072348d6150ea33ec9681d3625a8",
      "tree": "7d4d94a987841c5b0c61685e13926064100e7633",
      "parents": [
        "85ed1dd30680682789f0869fcc7ec40d93b49bbe"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 05:23:36 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 05:23:36 2026 +0800"
      },
      "message": "feat(google): support executable external account sources (#727)\n\nThis adds executable-sourced `external_account` support for Google\ncredentials by extending the existing Google service-layer provider with\nAIP-4117 style executable loading, cache-file reuse, and validation. It\nkeeps the change scoped to `services/google` and uses the existing\ncommand execution context instead of introducing new core abstractions.\n\nThis is the first PR in a stacked series for broader Google WIF\ncoverage. The follow-up PR will focus on AWS provider-specific\n`credential_source` handling."
    },
    {
      "commit": "85ed1dd30680682789f0869fcc7ec40d93b49bbe",
      "tree": "88b7f5cccefd40329e7aafc8d94952aee721d4cf",
      "parents": [
        "3dc1cf19b2d69b35459cbcecabbd488bf0e69a5b"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 04:24:58 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 04:24:58 2026 +0800"
      },
      "message": "feat(aliyun-oss): add credentials URI and ECS RAM role providers (#721)\n\nThis stacked PR builds on #720 by adding the two network-based runtime\ncredential sources needed for Aliyun OSS parity: `credentials_uri` and\nECS RAM role metadata.\n\nIt introduces dedicated slot/no-slot builder entries, keeps refresh\nbehavior aligned with `reqsign_core::Signer` cache semantics, and adds\nfocused tests for chain order, IMDS fallback, and refresh-before-expiry\nbehavior. Related to #684."
    },
    {
      "commit": "3dc1cf19b2d69b35459cbcecabbd488bf0e69a5b",
      "tree": "0a5888fa6609a2db792afb1f7d2e04eaa2d604e7",
      "parents": [
        "34db49cc08b3e7b939b2c73aa3295d509b836788"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 02:50:16 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 02:50:16 2026 +0800"
      },
      "message": "feat(aliyun-oss): add assume role credential provider (#724)\n\nThis PR adds an AK-based AssumeRole provider for `reqsign-aliyun-oss`\nand wires it into the default credential builder.\n\nIt extends the OSS credential parity work with a non-recursive base\nprovider chain and keeps the builder semantics aligned with the new\nslot-based API."
    },
    {
      "commit": "34db49cc08b3e7b939b2c73aa3295d509b836788",
      "tree": "8ef48d845d3cca1eddc4fcd5ba7f312e7768a0d8",
      "parents": [
        "81399926577bbc7913c9d10192bc1a56f3f35265"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 01:59:38 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 01:59:38 2026 +0800"
      },
      "message": "feat(aliyun-oss): add signature v4 signing support (#723)\n\nThis stacked PR builds on #719 and adds OSS Signature V4 support for\nboth header signing and presigned URLs.\n\nIt reuses the signer API introduced in the parent PR, keeps V1 as the\ndefault, and adds golden-style tests for canonical requests,\nstring-to-sign construction, repeated query-key ordering, and final V4\noutput. Related to #684."
    },
    {
      "commit": "81399926577bbc7913c9d10192bc1a56f3f35265",
      "tree": "ea3e84463b1886d58d9e5e3d12a003cb5680c64c",
      "parents": [
        "7fccb97bd5e87e7471e38fdda34142c1821fce36"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 01:48:25 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 01:48:25 2026 +0800"
      },
      "message": "feat(aliyun-oss): add shared credentials and config file providers (#722)\n\nThis stacked PR builds on #720 by adding the two Alibaba shared file\nsources that are distinct from the OSS profile file: shared\n`credentials.ini` and `config.json` providers.\n\nIt keeps the slot boundaries explicit (`credentials_file` and\n`config_file`), limits this PR to direct static modes, and adds\nprecedence tests showing these file-based providers slot cleanly in\nfront of OIDC. Related to #684."
    },
    {
      "commit": "7fccb97bd5e87e7471e38fdda34142c1821fce36",
      "tree": "c3ed1f5337842b1c2139eac31f749bfec734cbea",
      "parents": [
        "1fe7000c942c80adb4409dab61f12b436eb34327"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 01:42:20 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 01:42:20 2026 +0800"
      },
      "message": "refactor(aliyun-oss): prepare signer for region-aware signing (#719)\n\nThis PR narrows the Aliyun OSS signer API to the part we can commit to\ntoday: region configuration on `RequestSigner`.\n\nIt keeps current V1 behavior unchanged, avoids exposing\nnot-yet-implemented signing-version switches, and adds tests/docs that\nlock in `with_region(...)` as a no-op for V1 while reserving the\nconfiguration path needed for future V4 work. Related to #684."
    },
    {
      "commit": "1fe7000c942c80adb4409dab61f12b436eb34327",
      "tree": "2ed3aa246831bf229d5dbbfa7dca7257bc8298c4",
      "parents": [
        "1f6d84bef58bb1418ddc64eab861349313126d84"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 01:39:03 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 01:39:03 2026 +0800"
      },
      "message": "feat(aliyun-oss): add OSS env aliases and profile provider (#720)\n\nThis PR expands the low-risk Aliyun OSS credential chain by adding OSS\nenvironment-variable aliases and a dedicated `~/.oss/credentials`\nprofile provider.\n\nIt keeps the new slot/no-slot builder API consistent with the repository\npolicy, inserts `oss_profile` between env and OIDC in the default chain,\nand adds focused tests for precedence, profile selection, and chain\nordering. Related to #684."
    },
    {
      "commit": "1f6d84bef58bb1418ddc64eab861349313126d84",
      "tree": "11ef430adb54a927a670a5991827a3680ee15dc9",
      "parents": [
        "710917e27299aad1da3b9d3e8cb620bfc5c82c40"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Thu Mar 19 01:31:16 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Mar 19 01:31:16 2026 +0800"
      },
      "message": "fix(aliyun-oss): sign canonicalized OSS headers in presign (#718)\n\nThis PR fixes a V1 presign correctness gap in Aliyun OSS: canonicalized\n`x-oss-*` headers now participate in the string-to-sign when generating\npresigned URLs.\n\nThe change keeps the existing STS query-token behavior intact, adds\nfocused regression tests for presign/header canonicalization, and\naddresses one of the concrete bugs called out in #684."
    },
    {
      "commit": "710917e27299aad1da3b9d3e8cb620bfc5c82c40",
      "tree": "33e60662797b4842bf1640117d5764c0631fd15c",
      "parents": [
        "9fd8cdb4cf6df8e5a04d1a65025e93de0673bd89"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 19:09:07 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 19:09:07 2026 +0800"
      },
      "message": "refactor: migrate huaweicloud-obs default credential provider builder API (#717)\n\nAlign `reqsign-huaweicloud-obs` with the new default credential provider\nAPI defined in `docs/default-credential-provider-api.md`.\n\nThis service only exposes the `env` default slot, so the PR keeps the\npublic builder on the `env(...)` / `no_env()` shape and updates examples\nand tests to cover explicit removal and re-adding of that slot."
    },
    {
      "commit": "9fd8cdb4cf6df8e5a04d1a65025e93de0673bd89",
      "tree": "e99936a936304112867e7d64add4e95403eefa2e",
      "parents": [
        "4b8be5ec348d29a40c9de77b74b78e8cd053a82c"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 19:08:21 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 19:08:21 2026 +0800"
      },
      "message": "refactor(aws-v4): migrate default credential builder (#713)\n\nThis updates `services/aws-v4` to the `DefaultCredentialProvider` slot\nAPI defined in `docs/default-credential-provider-api.md`. The builder\nnow exposes slot and no-slot methods only, and `build()` only pushes\nconfigured `Some(...)` slots without fallback re-enabling.\n\nThe aws-v4 README was refreshed to the current public API, and the crate\ntests now cover both `process(...)` and `no_process()` so the removal\nsemantics are exercised directly in this service."
    },
    {
      "commit": "4b8be5ec348d29a40c9de77b74b78e8cd053a82c",
      "tree": "ec52aa73f0a450eca9f9aef80ddcc32aa6e58eca",
      "parents": [
        "38265ddfbb28057225ca05581f651bd86c52e9a5"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 19:06:04 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 19:06:04 2026 +0800"
      },
      "message": "feat(volcengine-tos): migrate default credential builder api (#712)\n\nMigrate the Volcengine TOS default credential provider to the slot-based\nbuilder API from the default credential provider design. This removes\nthe legacy configure/disable env API, keeps env as the only public slot,\nand adds coverage that `no_env()` actually removes the provider from the\nchain.\n\nThis PR is part of the service-by-service migration toward the new\n`DefaultCredentialProvider` API documented in\n`docs/default-credential-provider-api.md`."
    },
    {
      "commit": "38265ddfbb28057225ca05581f651bd86c52e9a5",
      "tree": "72ad3bd4c63981360fe73a9cbd72353da4c88980",
      "parents": [
        "fc1e49108f8e3cc3c1c001983ac2e9b03df58c64"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:58:01 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:58:01 2026 +0800"
      },
      "message": "services/oracle: migrate default credential builder API (#710)\n\nThis updates Oracle\u0027s `DefaultCredentialProviderBuilder` to match the\nnew repository-wide slot API design, removing the legacy `configure_*`\nand `disable_*(bool)` methods.\n\nThe builder now models `env` and `config_file` as explicit optional\nslots, and the tests cover that `no_env()` and `no_config_file()`\nactually remove those providers instead of re-enabling them during\n`build()`."
    },
    {
      "commit": "fc1e49108f8e3cc3c1c001983ac2e9b03df58c64",
      "tree": "7582608870407a9639b6b66b3780e9d1ad09544f",
      "parents": [
        "56cc5a85aef517f893ffab7be5badfd9d7be4b09"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:57:06 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:57:06 2026 +0800"
      },
      "message": "refactor(aliyun-oss): migrate default credential provider API (#716)\n\nMigrate reqsign-aliyun-oss to the new DefaultCredentialProvider slot API\nso the public builder matches the repository design. This removes the\nlegacy configure/disable surface, renames the OIDC slot explicitly, and\nupdates Aliyun-specific docs and tests to cover slot removal semantics."
    },
    {
      "commit": "56cc5a85aef517f893ffab7be5badfd9d7be4b09",
      "tree": "2dee127418d8931633ee5dfc11fea2090211591b",
      "parents": [
        "a9fbc1c30f98d343dd4da38d439b7916277935af"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:56:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:56:22 2026 +0800"
      },
      "message": "feat: migrate azure-storage default credential provider API (#715)\n\nThis migrates `reqsign-azure-storage` to the slot-based\n`DefaultCredentialProvider` builder defined in\n`docs/default-credential-provider-api.md`.\nIt removes the legacy `configure_*` and `disable_*(bool)` APIs, keeps\nthe existing default chain and wasm/non-wasm slot set, and updates\ndocs/examples/tests to cover `no_slot()` removal semantics."
    },
    {
      "commit": "a9fbc1c30f98d343dd4da38d439b7916277935af",
      "tree": "d66a0ff89b7666ec1c206eb656e675709ae07f64",
      "parents": [
        "bbf41ec87209878cfaeac6c99ddb77322ce8afe0"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:55:23 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:55:23 2026 +0800"
      },
      "message": "feat(google): migrate default credential provider API (#714)\n\nThis updates the Google default credential provider to match the\nrepository-wide API defined in\n`docs/default-credential-provider-api.md`. The builder now uses explicit\n`slot(...)` and `no_slot()` methods for the env, well-known ADC, and VM\nmetadata providers, and removes the old patch-style and boolean-toggle\nAPIs.\n\nThe change also exports the Google-specific env and well-known ADC\nproviders so callers can still customize those slots directly, and adds\ntests that verify removed slots are truly absent from the default chain."
    },
    {
      "commit": "bbf41ec87209878cfaeac6c99ddb77322ce8afe0",
      "tree": "35016cb138d3c86cca6dce62abbd55d9afb29fd5",
      "parents": [
        "75decdbd4899d5e06c3613ca1bae59ef85012ffc"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:53:55 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:53:55 2026 +0800"
      },
      "message": "services/tencent-cos: migrate default credential provider API (#711)\n\nThis changes the Tencent COS `DefaultCredentialProvider` builder to\nfollow the repository\u0027s new default credential provider API design.\nIt replaces the legacy `configure_*` and `disable_*(bool)` methods with\nexplicit `env` and `web_identity` slots plus `no_*` removal APIs, and\nadds tests that verify removed slots are not re-enabled during\n`build()`."
    },
    {
      "commit": "75decdbd4899d5e06c3613ca1bae59ef85012ffc",
      "tree": "81be46cc10178cae9b87940f3a2ade9909c9062f",
      "parents": [
        "c5400d8d2cb3a309f2171f3ec24ac0c066fdfcd5"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:49:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:49:13 2026 +0800"
      },
      "message": "feat: migrate huaweicloud-obs default credential provider API (#709)\n\nThis updates the Huawei Cloud OBS default credential provider to match\nthe repository\u0027s new builder API contract.\n\nThe builder now exposes explicit `env(...)` and `no_env()` slot\ncontrols, removes the legacy `configure_*` and `disable_*(bool)` APIs,\nand keeps removed slots out of the chain instead of re-enabling them\nduring `build()`."
    },
    {
      "commit": "c5400d8d2cb3a309f2171f3ec24ac0c066fdfcd5",
      "tree": "32b1e26a863bf95a74cd1069f1b5f937142af475",
      "parents": [
        "35f3ede60f498d6c0234a2ce27c23e8100a9c738"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:39:32 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:39:32 2026 +0800"
      },
      "message": "docs: define default credential provider API policy (#708)\n\nThis PR turns the default credential provider API shape into explicit\nrepository documentation instead of leaving it implicit in legacy\nimplementations. It records the authoritative design in\n`docs/default-credential-provider-api.md` and keeps `AGENTS.md` focused\non durable agent-facing constraints.\n\nIt also converts `CLAUDE.md` into an alias of `AGENTS.md` so repository\nguidance has a single source of truth before we start the API refactor\nitself."
    },
    {
      "commit": "35f3ede60f498d6c0234a2ce27c23e8100a9c738",
      "tree": "b9a28624a583204946f864e8828b232e800b2d89",
      "parents": [
        "561a93a294a5b679133b1e7e3cd13f482cd9cb43"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 18:37:13 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 18:37:13 2026 +0800"
      },
      "message": "feat(google): add explicit file and token providers (#707)\n\nThis PR adds built-in Google credential providers for explicit\n`credential_path` and raw access token inputs so downstream integrations\nno longer need local adapters. It keeps the existing core caching model\nunchanged while factoring JSON credential parsing into a shared helper\nreused by default, static, and file-based providers.\n\nThis also adds targeted tests for file-path credentials and token\nproviders, including token-path loading and expiration handling. Related\nissues: #694, #696."
    },
    {
      "commit": "561a93a294a5b679133b1e7e3cd13f482cd9cb43",
      "tree": "0929f9956f492c7a7822db2c3fb81d0f0ba38601",
      "parents": [
        "2e566d0c3ba38692afb2603d907fba8dd89f8bc1"
      ],
      "author": {
        "name": "Xuanwo",
        "email": "github@xuanwo.io",
        "time": "Wed Mar 18 17:38:03 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 17:38:03 2026 +0800"
      },
      "message": "reqsign-google: support selecting service account in VM metadata provider (#706)\n\nThis PR adds service account selection support to reqsign-google\u0027s VM\nmetadata provider so integrations running on GCE can request tokens for\na non-default service account without shipping a local custom provider.\n\nThe default ADC builder can now pass that option through\n`configure_vm_metadata(...)`, and the existing behavior remains\nunchanged when no service account is configured.\n\nCloses #695."
    },
    {
      "commit": "2e566d0c3ba38692afb2603d907fba8dd89f8bc1",
      "tree": "cc3ae9216f21410028a46b25fec664082718f097",
      "parents": [
        "d87031dc4a7e81583fe76d8f0f521da2930c89b1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Mar 18 17:03:53 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Mar 18 17:03:53 2026 +0800"
      },
      "message": "fix(google): use rsa rand_core rng for signing (#699)\n\nGoogle service account signing only needs an RNG for RSA blinding during\nprivate-key operations.\n\nThis change switches the signer to `rsa::rand_core::OsRng` and removes\nthe direct `rand` dependency from `reqsign-google` and the workspace. It\nkeeps the RNG source aligned with `rsa`\u0027s `rand_core` version and avoids\nbinding this crate to `rand`\u0027s higher-level API surface.\n\n---------\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nCo-authored-by: Xuanwo \u003cgithub@xuanwo.io\u003e"
    }
  ],
  "next": "d87031dc4a7e81583fe76d8f0f521da2930c89b1"
}
