Skip to content

ci: bump the github-actions group with 3 updates - #160

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-08965766d6
Closed

ci: bump the github-actions group with 3 updates#160
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/github-actions-08965766d6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 3 updates: actions/checkout, dependabot/fetch-metadata and release-drafter/release-drafter.

Updates actions/checkout from 6.0.3 to 7.0.0

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates dependabot/fetch-metadata from 2.4.0 to 3.1.0

Release notes

Sourced from dependabot/fetch-metadata's releases.

v3.1.0

What's Changed

New Contributors

Full Changelog: dependabot/fetch-metadata@v3...v3.1.0

v3.0.0

The breaking change is requiring Node.js version v24 as the Actions runtime.

What's Changed

... (truncated)

Commits
  • 25dd0e3 v3.1.0 (#692)
  • e073f50 Merge pull request #705 from dependabot/dependabot/npm_and_yarn/hono-4.12.14
  • 0670e16 build(deps-dev): bump hono from 4.12.12 to 4.12.14
  • 7a7fe10 Merge pull request #702 from dependabot/dependabot/npm_and_yarn/dependencies-...
  • 5168191 Updating dist build
  • 23882e1 build(deps): bump @​actions/github in the dependencies group
  • 1072469 Merge pull request #701 from dependabot/dependabot/github_actions/actions/cre...
  • 43f8a00 build(deps): bump actions/create-github-app-token from 3.0.0 to 3.1.1
  • b4d904a Merge pull request #703 from dependabot/dependabot/npm_and_yarn/globals-17.5.0
  • c8046bb build(deps-dev): bump globals from 17.4.0 to 17.5.0
  • Additional commits viewable in compare view

Updates release-drafter/release-drafter from 7.3.1 to 7.4.0

Release notes

Sourced from release-drafter/release-drafter's releases.

v7.4.0

What's Changed

New

Maintenance

Documentation

Dependency Updates

Full Changelog: release-drafter/release-drafter@v7.3.1...v7.4.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) and [release-drafter/release-drafter](https://github.com/release-drafter/release-drafter).


Updates `actions/checkout` from 6.0.3 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@df4cb1c...9c091bb)

Updates `dependabot/fetch-metadata` from 2.4.0 to 3.1.0
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@08eff52...25dd0e3)

Updates `release-drafter/release-drafter` from 7.3.1 to 7.4.0
- [Release notes](https://github.com/release-drafter/release-drafter/releases)
- [Commits](release-drafter/release-drafter@693d20e...ed4bc48)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: dependabot/fetch-metadata
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: release-drafter/release-drafter
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencias Atualização de dependências (composer, npm, actions) label Jun 18, 2026
@github-actions

Copy link
Copy Markdown
Contributor

📦 Bundle size

✅ Sem regressão de tamanho — gzip total inalterado.

Arquivo PR (gzip) Master (gzip) Δ gzip PR (raw) Δ raw
admin.js 11.3 KB 11.3 KB = 45.3 KB =
forum.js 34.0 KB 34.0 KB = 133.5 KB =
forum/components/AllDiscussionsPage.js 2.7 KB 2.7 KB = 8.7 KB =
forum/components/AvocadoPostsSearchPage.js 2.4 KB 2.4 KB = 7.3 KB =
forum/components/AvocadoSearchPage.js 5.3 KB 5.3 KB = 19.5 KB =
forum/components/TagPage.js 3.4 KB 3.4 KB = 11.0 KB =
forum/components/TeamPage.js 1.4 KB 1.4 KB = 3.8 KB =
forum/components/UserProfilePage.js 2.5 KB 2.5 KB = 10.2 KB =
Total 62.9 KB 62.9 KB = 239.2 KB =

gzip nível 9. 🟢 = menor que o master · 🔴 = maior. Report-only — não bloqueia o merge.

@github-actions

Copy link
Copy Markdown
Contributor

🔒 Regressão de segurança (Semgrep diff vs master)

✅ Sem regressão — nenhum achado novo de vulnerabilidade introduzido por esta PR.

@github-actions

Copy link
Copy Markdown
Contributor

🔬 Performance benchmark

Home (/)

Métrica PR Master (baseline) Δ
Performance (score) 82 81 🟢 1pp (1.2%)
FCP 1792 ms 1819 ms 🟢 -28 ms (-1.5%)
LCP 1954 ms 2023 ms 🟢 -69 ms (-3.4%)
TBT 67 ms 60 ms 🔴 +7 ms (11.7%)
CLS 0.000 0.000 (=)
Speed Index 1792 ms 1819 ms 🟢 -28 ms (-1.5%)
TTI 1954 ms 2023 ms 🟢 -69 ms (-3.4%)

💡 Recomendações (Lighthouse + dicas Flarum 2 / Avocado)

  • Sem compressão de texto — economia ~880 ms · ~1101 KB
    Habilite gzip/brotli no servidor (nginx: gzip on; gzip_types text/css application/javascript; ou brotli on; brotli_types ...). Esse é um setting de host, não da extensão, mas reportar aqui ajuda.
  • JavaScript não utilizado — economia ~640 ms · ~517 KB
    Use import() dinâmico para componentes só usados em rotas específicas (TeamPage, AvocadoSearchPage). O webpack faz split automático se você usar import("./components/TeamPage") dentro do routes ao invés de import estático no topo do index.tsx.
  • CSS não utilizado — economia ~480 ms · ~538 KB
    O bundle forum.css carrega tudo de less/forum/**. Divida por rota (Home/Discussion/Tag) via Extend\Frontend->css() condicional no JS, ou use PurgeCSS no webpack para o build de produção.
  • Recursos bloqueando o render — economia ~400 ms
    Mova CSS não-crítico para <link rel="preload"> ou injete inline o CSS above-the-fold do forum.less. Em Flarum 2, o forum.css é servido como bloqueante por padrão — considere media="print" onload para folhas não-críticas (ex.: dark theme).
  • Cache HTTP curto — 8 resources found
    Os assets versionados em /assets/forum-<hash>.js deveriam ter Cache-Control: public, max-age=31536000, immutable. Configure no nginx/apache, não no Flarum.

/discussions

Métrica PR Master (baseline) Δ
Performance (score) 87 87 (=)
FCP 1449 ms 1450 ms 🟢 -1 ms (-0.1%)
LCP 1797 ms 1796 ms 🔴 +1 ms (0.0%)
TBT 3 ms 4 ms 🟢 -1 ms (-25.0%)
CLS 0.000 0.000 (=)
Speed Index 1449 ms 1450 ms 🟢 -1 ms (-0.1%)
TTI 1797 ms 1796 ms 🔴 +1 ms (0.0%)

💡 Recomendações (Lighthouse + dicas Flarum 2 / Avocado)

  • Sem compressão de texto — economia ~920 ms · ~1107 KB
    Habilite gzip/brotli no servidor (nginx: gzip on; gzip_types text/css application/javascript; ou brotli on; brotli_types ...). Esse é um setting de host, não da extensão, mas reportar aqui ajuda.
  • JavaScript não utilizado — economia ~550 ms · ~540 KB
    Use import() dinâmico para componentes só usados em rotas específicas (TeamPage, AvocadoSearchPage). O webpack faz split automático se você usar import("./components/TeamPage") dentro do routes ao invés de import estático no topo do index.tsx.
  • Recursos bloqueando o render — economia ~520 ms
    Mova CSS não-crítico para <link rel="preload"> ou injete inline o CSS above-the-fold do forum.less. Em Flarum 2, o forum.css é servido como bloqueante por padrão — considere media="print" onload para folhas não-críticas (ex.: dark theme).
  • CSS não utilizado — economia ~480 ms · ~544 KB
    O bundle forum.css carrega tudo de less/forum/**. Divida por rota (Home/Discussion/Tag) via Extend\Frontend->css() condicional no JS, ou use PurgeCSS no webpack para o build de produção.
  • Cache HTTP curto — 9 resources found
    Os assets versionados em /assets/forum-<hash>.js deveriam ter Cache-Control: public, max-age=31536000, immutable. Configure no nginx/apache, não no Flarum.

/tags

Métrica PR Master (baseline) Δ
Performance (score) 88 88 (=)
FCP 1428 ms 1415 ms 🔴 +13 ms (0.9%)
LCP 1730 ms 1717 ms 🔴 +13 ms (0.8%)
TBT 0 ms 0 ms (=)
CLS 0.000 0.000 (=)
Speed Index 1428 ms 1415 ms 🔴 +13 ms (0.9%)
TTI 1730 ms 1717 ms 🔴 +13 ms (0.8%)

💡 Recomendações (Lighthouse + dicas Flarum 2 / Avocado)

  • Sem compressão de texto — economia ~880 ms · ~1102 KB
    Habilite gzip/brotli no servidor (nginx: gzip on; gzip_types text/css application/javascript; ou brotli on; brotli_types ...). Esse é um setting de host, não da extensão, mas reportar aqui ajuda.
  • JavaScript não utilizado — economia ~530 ms · ~544 KB
    Use import() dinâmico para componentes só usados em rotas específicas (TeamPage, AvocadoSearchPage). O webpack faz split automático se você usar import("./components/TeamPage") dentro do routes ao invés de import estático no topo do index.tsx.
  • CSS não utilizado — economia ~480 ms · ~543 KB
    O bundle forum.css carrega tudo de less/forum/**. Divida por rota (Home/Discussion/Tag) via Extend\Frontend->css() condicional no JS, ou use PurgeCSS no webpack para o build de produção.
  • Recursos bloqueando o render — economia ~480 ms
    Mova CSS não-crítico para <link rel="preload"> ou injete inline o CSS above-the-fold do forum.less. Em Flarum 2, o forum.css é servido como bloqueante por padrão — considere media="print" onload para folhas não-críticas (ex.: dark theme).
  • Cache HTTP curto — 8 resources found
    Os assets versionados em /assets/forum-<hash>.js deveriam ter Cache-Control: public, max-age=31536000, immutable. Configure no nginx/apache, não no Flarum.

🥑 Dicas gerais para acelerar o tema (Flarum 2 + Avocado)

  1. Build de produção minificado — confirme que npm run build rodou com mode: production (já é o caso no js/package.json). Webpack tree-shakes import { x } from "flarum/..." se o consumo for explícito.
  2. Split por rotaindex.tsx importa todos os Components no topo. Trocar para import() dinâmico nas rotas raramente acessadas (TeamPage, AvocadoSearchPage, TagsPage) reduz o forum.js inicial.
  3. Less crítico inline — Flarum 2 serve forum.css bloqueando. Considere extrair o CSS above-the-fold (header + 1ª thread visível) e injetar inline via Extend\Frontend->content(InlineCriticalCss::class).
  4. Avatares — sirva via <img loading="lazy"> em todos os ThreadCards/PostCards que não estiverem no fold inicial.
  5. <link rel="preconnect"> — se você usa CDN para fontes ou avatares S3, adicione preconnects no header.
  6. Extend\Frontend->js() rodam síncronos — todo arquivo js/dist/forum.js é parseado no boot. Cada extend() no index.tsx roda antes da primeira pintura.
  7. opcache + view cache — no host: opcache.enable=1, opcache.validate_timestamps=0 em produção, e php flarum cache:clear no deploy.
  8. HTTP/2 + Brotli no host — o Flarum gera bundles grandes; sem brotli você paga em transferência.

Lighthouse desktop, 1 run por URL. 🟢 = melhorou vs master · 🔴 = regrediu.

@dependabot @github

dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 18, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-08965766d6 branch June 18, 2026 23:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencias Atualização de dependências (composer, npm, actions)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants