Skip to content

Bump taskcluster from 96.1.0 to 108.0.0 - #128

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/taskcluster-108.0.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/taskcluster-108.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor

Bumps taskcluster from 96.1.0 to 108.0.0.

Release notes

Sourced from taskcluster's releases.

v108.0.0

DEPLOYERS

▶ [MAJOR] bug 2060854 The web-server now validates REGISTERED_CLIENTS at startup. Client registrations with unknown properties, invalid property types, or requirePkce: true when responseType is not code must be corrected before upgrading.

Startup validation also rejects a maxExpires that fromNow cannot parse or that does not resolve to a future date (such as '', 0 seconds or -1 year, which would have issued already-expired credentials), and non-unique clientId.

Each redirectUri must now be an absolute http: or https: URL.

WORKER-DEPLOYERS

▶ [MAJOR] bug 2065117 Workers will now refuse to hand a task ownership of a hardlinked file that belongs to anyone but the previous owner of the tree being chowned.

▶ [MAJOR] bug 2059762 Workers will now refuse to operate caches / mounts if they have to resolve a junction on windows or a symlink on linux/macos (unless the parent of the symlink is only writable by root).

▶ [patch] bug 2058249 Fix a bug where uploading logs and writing CoT artifacts was following symlinks

▶ [patch] #8943 Generic Worker no longer garbage collects a file cache that a running task is still using in capacity > 1 cases. Relatedly, when a cached download no longer matches a task's required SHA256, the stale entry is now dropped from the cache table immediately (with its deletion deferred until any tasks still using it finish) instead of being served to the task again.

▶ [patch] #8944 Generic Worker no longer leaks disk space when cache files remain on disk without a cache table entry. Garbage collection and worker startup now delete anything in the caches directory that the worker does not know about, so a failed deletion (or a leftover from a crash) is retried instead of occupying space forever.

▶ [patch] Generic-worker will once again report errors if internally ran commands fail

ADMINS

▶ [patch] bug 2058254 Generic worker on windows won't follow junctions anymore when changing ownership/rights/deleting cached files.

USERS

▶ [MAJOR] bug 2060854 The web-server OAuth authorization-code exchange now requires the requesting client_id to match the client that received the code. Existing authorization-code clients must include their registered client_id when exchanging codes. Clients can also use PKCE with the S256 challenge method, and deployments can require PKCE for individual registered clients.

▶ [minor] #9056 Generic worker will now resolve a task as exception if it read the content of an optional artifact but then failed to upload it

... (truncated)

Changelog

Sourced from taskcluster's changelog.

v108.0.0

DEPLOYERS

▶ [MAJOR] bug 2060854 The web-server now validates REGISTERED_CLIENTS at startup. Client registrations with unknown properties, invalid property types, or requirePkce: true when responseType is not code must be corrected before upgrading.

Startup validation also rejects a maxExpires that fromNow cannot parse or that does not resolve to a future date (such as '', 0 seconds or -1 year, which would have issued already-expired credentials), and non-unique clientId.

Each redirectUri must now be an absolute http: or https: URL.

WORKER-DEPLOYERS

▶ [MAJOR] bug 2065117 Workers will now refuse to hand a task ownership of a hardlinked file that belongs to anyone but the previous owner of the tree being chowned.

▶ [MAJOR] bug 2059762 Workers will now refuse to operate caches / mounts if they have to resolve a junction on windows or a symlink on linux/macos (unless the parent of the symlink is only writable by root).

▶ [patch] bug 2058249 Fix a bug where uploading logs and writing CoT artifacts was following symlinks

▶ [patch] #8943 Generic Worker no longer garbage collects a file cache that a running task is still using in capacity > 1 cases. Relatedly, when a cached download no longer matches a task's required SHA256, the stale entry is now dropped from the cache table immediately (with its deletion deferred until any tasks still using it finish) instead of being served to the task again.

▶ [patch] #8944 Generic Worker no longer leaks disk space when cache files remain on disk without a cache table entry. Garbage collection and worker startup now delete anything in the caches directory that the worker does not know about, so a failed deletion (or a leftover from a crash) is retried instead of occupying space forever.

▶ [patch] Generic-worker will once again report errors if internally ran commands fail

ADMINS

▶ [patch] bug 2058254 Generic worker on windows won't follow junctions anymore when changing ownership/rights/deleting cached files.

USERS

▶ [MAJOR] bug 2060854 The web-server OAuth authorization-code exchange now requires the requesting client_id to match the client that received the code. Existing authorization-code clients must include their registered client_id when exchanging codes. Clients can also use PKCE with the S256 challenge method, and deployments can require PKCE for individual registered clients.

▶ [minor] #9056 Generic worker will now resolve a task as exception if it read the content of an optional artifact but then failed to upload it

... (truncated)

Commits
  • ae7697a v108.0.0
  • 650889e Merge pull request #9076 from Eijebong/no-link-to-the-past
  • 4eeb161 Fix renames on windows when the destination file is 1 char only
  • 668ccb7 When creating the backing log, return a RW handle
  • 9196fdd Pin files open while granting on them so link counts can't be raced
  • e581daf Bug 2059762 - Don't let the root side of fileutil.Copy resolve links
  • 9d15ff0 Strengthen our hard links checking in safefs.refuseIfIrregular
  • de5804d Bug 2059762 - Restore mv semantics in windows cross device move
  • 686e094 Refuse to try uploading non regular files as artifact
  • 76a990a Bug 2058249 - Handle rdp.json like every other reserved file
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [taskcluster](https://github.com/taskcluster/taskcluster) from 96.1.0 to 108.0.0.
- [Release notes](https://github.com/taskcluster/taskcluster/releases)
- [Changelog](https://github.com/taskcluster/taskcluster/blob/main/CHANGELOG.md)
- [Commits](taskcluster/taskcluster@v96.1.0...v108.0.0)

---
updated-dependencies:
- dependency-name: taskcluster
  dependency-version: 108.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #129.

@dependabot dependabot Bot closed this Sep 14, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/taskcluster-108.0.0 branch September 14, 2026 21:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants