fix(deps): update dependency @taskcluster/client to v110 - #1060
Merged
jcristau merged 1 commit intoOct 1, 2026
Merged
Conversation
jcristau
approved these changes
Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
107.0.0→110.1.0Release Notes
taskcluster/taskcluster (@taskcluster/client)
v110.1.0Compare Source
DEPLOYERS
▶ [minor] bug 1599247
The auth service's
gcpCredentialsendpoint now supports any number of GCP projects configured ingcp_credentials_allowed_projects, rather than being limited to a single project. Each configured project keeps its own credentials andallowedServiceAccountsallow-list, and requests are scoped to the project named in the request path.WORKER-DEPLOYERS
▶ [patch] bug 2071937
Generic Worker on Windows no longer interpolates
payload.osGroupsinto a PowerShell-Commandstring when adding or removing the task user from OS groups. Membership is updated withNetLocalGroupAddMembers/NetLocalGroupDelMembers, so group names cannot break out of a PowerShell single-quoted literal (including via Unicode quotation marks U+2018–U+201B).▶ [patch]
On Windows, the worker now replaces the whole security descriptor of the files it secures instead of just dropping ACL inheritance on it. The ownership is now also changed to
BUILTIN\AdministratorsUSERS
▶ [minor]
index.findTasksAtIndexno longer returns expired indices▶ [patch] #9127
Dashboard shows pending and claimed task counts for task queues that worker-manager does not own (hardware workers, for example).
These queues were previously missing from the dashboard's task totals entirely.
Discovering them requires the
queue:list-task-queuesscope, plusqueue:pending-count:<taskQueueId>andqueue:claimed-count:<taskQueueId>for each queue.▶ [patch] #9172
In the python client, importing
taskcluster.helperbefore anything fromtaskcluster.aiono longer leavestaskcluster.aiowithout any of its clients▶ [patch]
Indexing a task no longer silently does nothing when an expired entry with a higher rank still exists at the same index path
▶ [patch] #9065
The worker pools list now shows a "Claimed Tasks" column alongside "Pending Tasks". The claimed counts already came back from the batched
taskQueueCountsrequest the page makes, so this adds no extra API calls.▶ [patch] #9065
UI: Dashboard and Worker Manager load pending/claimed counts in batched requests. Stopping capacity is no longer shown.
Public deployments must grant both
queue:pending-count:*andqueue:claimed-count:*to theanonymousrole for these counts to appear.▶ [patch]
UI: hardened task artifact log links with proper encoding.
▶ [patch] bug 2072160
Worker-manager improves error handling when duplicate static worker is created.
DEVELOPERS
▶ [patch]
yarn db:newandyarn db:renumberdon't require you to provide eitherADMIN_DB_URLorUSERNAME_PREFIXanymoreOTHER
▶ Additional changes not described here: #9119, #9127.
Automated Package Updates
1 Dependabot updates
fe3ec0e)v110.0.0Compare Source
WORKER-DEPLOYERS
▶ [patch] #7447
Generic-worker no longer chowns read-only content that is mounted as the task
user.
▶ [patch] bug 2071940
Use LSA to store the next task user's password instead of storing it as plaintext in the registry
ADMINS
▶ [patch] #9156
Worker-pool errors from failed Azure ARM deployments now include the nested, actionable ARM error in the error description. This makes errors like "image X was not found in " visible in the UI and API.
USERS
▶ [MAJOR] bug 2060945
A writable directory cache will now refuse being mounted at a
directorythat already exists.▶ [MAJOR] bug 2060945
Moving a directory into place now refuses a destination that already exists on
every platform: on Windows it no longer replaces an existing file, and on POSIX
systems it no longer replaces an existing empty directory.
▶ [patch] #9007
Generic Worker no longer panics when the Queue rejects a
createArtifactcall with a 4xx response. The task is resolved asexception/malformed-payload, or asexception/resource-unavailablefor 408 and 429.logs.liveandlogs.backingmust now match^[\x20-\x7e]+$, and a non-empty artifactnamemust match the same character set. An empty artifactnameis still allowed and means "derive frompath"; if thatpathcontains other characters, the Queue still rejects the artifact at upload time.▶ [patch] #9058
GitHub tasks no longer fail when concurrent pull request events race with automatic cancellation.
▶ [patch] bug 2072198
Mounting a cache on Windows no longer fails when the cache contains a file that is hardlinked more than once inside the cache itself
OTHER
▶ Additional changes not described here: #9126, #9149.
v109.0.0Compare Source
GENERAL
▶ [MAJOR]
The deprecated Auth service Azure Credentials API methods have been removed:
azureAccounts,azureTables,azureTableSAS,azureContainers, andazureContainerSAS. No known Taskclustercomponent uses these methods.
The
auth.azure_accountsHelm property is no longer allowed, and the correspondingAZURE_ACCOUNTSenvironment variable is no longer used. Deployers must removeauth.azure_accountsfrom their Helm values before upgrading.WORKER-DEPLOYERS
▶ [MAJOR] bug 2069456
When uploading artifacts, Generic Worker multiuser engine will now create
temporary files as the worker user (
root/LocalSystem) and stream contentinto them as the task user.
The internal
generic-worker copy-to-temp-filecommand has been replaced withgeneric-worker cat-fileUSERS
▶ [MAJOR] bug 2069332
When uploading an optional artifact, if it's not readable (or encounters any
unreadable file for directory artifacts), the task will now fail instead of
silently omitting that file.
▶ [minor] #9065
The Queue service now exposes
taskQueueCountsBatchto fetch pending andclaimed task counts for multiple task queues in one request.
Automated Package Updates
4 Dependabot updates
583fcbc)b4391b0)a19e347)65c3bd3)v108.1.0Compare Source
GENERAL
▶ [patch]
Bumps
uvto v0.12.8 for the in-treeciandpythondocker images, the taskgraph decision image to v24.2.3, the git for windows version to v2.55.0, and thenvmversion used during releases to v0.40.7.▶ [patch]
Upgrades to Node.js v24.20.0.
▶ [patch]
Upgrades to go1.27.1 and golangci-lint v2.13.2.
Release notes here.
▶ [patch]
Upgrades to rust v1.98.0.
WORKER-DEPLOYERS
▶ [patch]
Generic Worker no longer deadlocks on shutdown or when interrupted with Ctrl+C /
SIGINTwhile a task is running. Shutdown waits on task completions until no tasks remain, instead of blocking on a wait group that only advanced when those completions were processed.▶ [patch] bug 2069456
On Windows multiuser workers, command environment read by generic-worker from the task directory will now refuse to follow links.
▶ [patch] bug 2069456
On Windows multiuser workers, command scripts written by generic-worker into the task directory will now refuse to follow links.
USERS
▶ [minor] bug 1917274
The github service publishes a new
exchange/taskcluster-github/v1/taskcluster-yml-updatemessage when a push changes a repository's
.taskcluster.yml. The ordinarypushmessage is still published as well, so existing consumers are unaffected.
The payload names the organization, the repository, the ref that was pushed to, and
the webhook delivery id, and nothing else. It deliberately does not carry the file's
contents. A consumer can therefore act on a push in one repository from inside
another, treating the ref as a value to compare against rather than one to pass on.
DEVELOPERS
▶ [patch] bug 2066797
Changes the pull-request policy to
public_restrictedand isolates trusted and untrusted task graphs. External pull requests run at level 1 with separate caches, without secrets or generic-worker CI, and rebuild Docker images instead of sharing an image index. Collaborators can trigger the full level-3 graph with/taskcluster run.▶ [patch] #9093
UI Scopes pages (ViewScope and ScopesetExpander) switch from GraphQL to direct REST service calls.
▶ [patch] #9074
UI WMViewWorkers and WMViewWorkerPools pages switches to use direct REST API calls
OTHER
▶ Additional change not described here: #9117.
Automated Package Updates
18 Dependabot updates
9dbdb66)1ac7895)a1a68c4)663adc5)e03dee4)3ef6f64)461a509)a61e720)63ef0ad)26bd1ca)1229008)a1caab2)e17bb92)ee02263)81e7451)1bc2af0)a8f5046)f6555fb)v108.0.0Compare Source
DEPLOYERS
▶ [MAJOR] bug 2060854
The web-server now validates
REGISTERED_CLIENTSat startup. Client registrations with unknown properties, invalid property types, orrequirePkce: truewhenresponseTypeis notcodemust be corrected before upgrading.Startup validation also rejects a
maxExpiresthatfromNowcannot parse or that does not resolve to a future date (such as'',0 secondsor-1 year, which would have issued already-expired credentials), and non-uniqueclientId.Each
redirectUrimust now be an absolutehttp:orhttps:URL.WORKER-DEPLOYERS
▶ [MAJOR] bug 2065117
Workers will now refuse to hand a task ownership of a hardlinked file that
belongs to anyone but the previous owner of the tree being chowned.
▶ [MAJOR] bug 2059762
Workers will now refuse to operate caches / mounts if they have to resolve a
junction on windows or a symlink on linux/macos (unless the parent of the
symlink is only writable by root).
▶ [patch] bug 2058249
Fix a bug where uploading logs and writing CoT artifacts was following symlinks
▶ [patch] #8943
Generic Worker no longer garbage collects a file cache that a running task is still using in
capacity> 1 cases. Relatedly, when a cached download no longer matches a task's required SHA256, the stale entry is now dropped from the cache table immediately (with its deletion deferred until any tasks still using it finish) instead of being served to the task again.▶ [patch] #8944
Generic Worker no longer leaks disk space when cache files remain on disk without a cache table entry. Garbage collection and worker startup now delete anything in the caches directory that the worker does not know about, so a failed deletion (or a leftover from a crash) is retried instead of occupying space forever.
▶ [patch]
Generic-worker will once again report errors if internally ran commands fail
ADMINS
▶ [patch] bug 2058254
Generic worker on windows won't follow junctions anymore when changing
ownership/rights/deleting cached files.
USERS
▶ [MAJOR] bug 2060854
The web-server OAuth authorization-code exchange now requires the requesting
client_idto match the client that received the code.Existing authorization-code clients must include their registered
client_idwhen exchanging codes.Clients can also use PKCE with the S256 challenge method, and deployments can require PKCE for individual registered clients.
▶ [minor] #9056
Generic worker will now resolve a task as exception if it read the content of an
optional artifact but then failed to upload it
▶ [patch] bug 2060854
Third-party OAuth2 clients registered with more than one
redirectUriare now granted CORS access from every registered origin. Previously only the first entry's origin was allowed, so calls to/login/oauth/tokenand/login/oauth/credentialsfrom any other registered origin were blocked by the browser.▶ [patch] #9066
Fixes UI regression in
react-codemirror2where editing text in any textarea would be very slow.▶ [patch] bug 2064002
Notifications through task routes now validate the name of the template used just like the rest API
▶ [patch] #8751
The GitHub service now creates a build record for every unique
taskGroupIddefined in.taskcluster.yml, so checks and statuses are reported for all task groups, not justthe first task's group.
DEVELOPERS
▶ [patch] #8992
UI ClaimedTasks and PendingTasks pages switch from GraphQL to direct service calls
▶ [patch] #9011
UI Denylist page switches from GraphQL to direct service calls
▶ [patch] #9023
UI Hooks page switches to use direct REST API calls
The View Hook page showed a Next Scheduled Date which is now removed from UI.
This was done as GraphQL invoked an outdated REST endpoint getHookStatus for which we do not have any alternate endpoint or way to get this information.
▶ [patch] #9006
UI Task Index page switches to use decorator for api call. Removed the now-unused
indexedTask,namespaces, andtaskNamespaceGraphQL queries and their resolvers/loaders from web-server, since the UI no longer uses them. Other GraphQL queries againstTask(e.g.latestArtifacts, still used by the Interactive Connect page) are untouched.▶ [patch] #9060
UI ViewProvisioners and ViewWorkerTypes pages switch from GraphQL to direct service calls
▶ [patch] #9072
UI ViewWorker and ViewWorkers pages switch from GraphQL to direct service calls
▶ [patch] #9045
UI WMEditWorkerPool and WMLaunchConfigs pages switch from GraphQL to direct service calls
▶ [patch] #9063
UI WMViewErrorCenter and WMViewErrors pages switch from GraphQL to direct service calls
Automated Package Updates
8 Dependabot updates
cc72983)3dd2210)266f2f0)7b1d322)50a514e)7f33e92)592df42)f71a8d1)Configuration
📅 Schedule: (in timezone UTC)
* * 1 * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.