Bump the github-actions group across 1 directory with 8 updates - #48842
Bump the github-actions group across 1 directory with 8 updates#48842dependabot[bot] wants to merge 1 commit into
Conversation
|
Azure Pipelines: Successfully started running 1 pipeline(s). 9 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
🟡 Changes recommended
Generated lock-file manifests remain inconsistent with their updated executable action pins.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Updates pinned GitHub Actions across CI and agentic workflows.
Changes:
- Upgrades checkout, runtime setup, cache, and GitHub Script actions.
- Updates gh-aw setup actions in maintenance and generated workflows.
- Retains SHA-pinned dependencies.
File summaries
| File | Description |
|---|---|
.github/workflows/verify-links.yml |
Updates checkout. |
.github/workflows/typespec-python-regenerate.yml |
Updates checkout, Node, Python, and GitHub Script actions. |
.github/workflows/post-apiview.yml |
Updates checkout. |
.github/workflows/pipeline-analysis-next-steps.lock.yml |
Updates generated agentic workflow dependencies. |
.github/workflows/pipeline-analysis-auto-fix.lock.yml |
Updates generated auto-fix dependencies. |
.github/workflows/mgmt-sdk-pr-review.lock.yml |
Updates gh-aw setup. |
.github/workflows/issue-triage.lock.yml |
Updates generated triage dependencies. |
.github/workflows/doc-consistency-check.lock.yml |
Updates generated documentation-check dependencies. |
.github/workflows/dependency-checker.yml |
Updates checkout and Python setup. |
.github/workflows/copilot-setup-steps.yml |
Updates Copilot environment actions. |
.github/workflows/azure-sdk-tools.yml |
Updates tool-test actions. |
.github/workflows/agentics-maintenance.yml |
Updates agentic maintenance dependencies. |
.github/workflows/actionlint.yml |
Updates checkout. |
Review details
Suppressed comments (1)
.github/workflows/typespec-python-regenerate.yml:102
- This second checkout annotation also still says v6 while the updated SHA is v7.0.1. Update it to match the actual action major.
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- Files reviewed: 13/13 changed files
- Comments generated: 9
- Review effort level: Balanced
| - name: Setup Scripts | ||
| id: setup | ||
| uses: github/gh-aw-actions/setup@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 |
| - name: Setup Scripts | ||
| id: setup | ||
| uses: github/gh-aw-actions/setup@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 |
| - name: Setup Scripts | ||
| id: setup | ||
| uses: github/gh-aw-actions/setup@423b3dc04bbf1b1797194a4a75aa5cf5d0d4f5b3 # v0.87.1 | ||
| uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 |
| - name: Setup Scripts | ||
| id: setup | ||
| uses: github/gh-aw-actions/setup@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 |
| - name: Setup Scripts | ||
| id: setup | ||
| uses: github/gh-aw-actions/setup@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 |
| - name: Checkout azure-sdk-for-python | ||
| # SHA corresponds to actions/checkout@v6 | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| - name: Setup Node.js | ||
| # SHA corresponds to actions/setup-node@v6 | ||
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | ||
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 |
| - name: Setup Python | ||
| # SHA corresponds to actions/setup-python@v5 | ||
| uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 | ||
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 |
| - name: Send failure notification | ||
| # SHA corresponds to actions/github-script@v7 | ||
| uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0 | ||
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 |
6f2ad77 to
43b5861
Compare
There was a problem hiding this comment.
🟡 Changes recommended
Moderate version-alignment, generated-lock consistency, and annotation issues remain unresolved.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
Suppressed comments (10)
.github/workflows/doc-consistency-check.lock.yml:99
- This lock file is generated by gh-aw v0.80.9, but its executable references now differ from the old action SHAs retained in
gh-aw-manifest. Besides making dependency metadata inaccurate,gh aw compilewill restore the compiler-generated pins. Upgrade gh-aw and regenerate this file rather than patching generateduseslines.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/issue-triage.lock.yml:108
- This lock file is generated by gh-aw v0.80.9, but only its executable action references were bumped; the
gh-aw-manifeststill records the v0.80.9 setup action and prior cache/checkout/setup-node pins. The metadata is therefore stale and recompilation will discard these edits. Upgrade the compiler and regenerate the lock file instead.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/mgmt-sdk-pr-review.lock.yml:96
- This generated lock's metadata says compiler v0.87.1 and its manifest still pins the v0.87.1 setup SHA, while the executable jobs now use v0.87.5. That makes the lock internally inconsistent and recompilation will overwrite the manual pin. Upgrade gh-aw to v0.87.5 and regenerate this lock file so metadata and generated jobs remain synchronized.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/pipeline-analysis-auto-fix.lock.yml:164
- This lock file is generated by gh-aw v0.80.9, and its
gh-aw-manifeststill recordssetupv0.80.9 plus the old cache/setup-node pins. Updating only executableuseslines leaves the lock metadata inconsistent and the nextgh aw compilewill regenerate these references. Upgrade the gh-aw compiler and regenerate the lock file instead.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/pipeline-analysis-next-steps.lock.yml:156
- This lock file is generated by gh-aw v0.80.9, and its
gh-aw-manifeststill recordssetupv0.80.9 plus the old cache/checkout/setup-node SHAs. Updating only executableuseslines leaves the lock metadata inconsistent and the nextgh aw compilewill regenerate these pins. Upgrade the gh-aw compiler and regenerate the lock file instead of editing generated action references directly.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/typespec-python-regenerate.yml:40
- The preceding annotation still says this SHA is for checkout v6, but the pin is now v7.0.1. Update the annotation so future SHA audits do not rely on incorrect version information.
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
.github/workflows/typespec-python-regenerate.yml:102
- The checkout pin was upgraded to v7.0.1, but its SHA annotation still identifies v6. Keep the annotation synchronized with the pinned major version.
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
.github/workflows/typespec-python-regenerate.yml:431
- The SHA annotation says github-script v7, but the changed pin is v9.0.0. Synchronize the annotation with the action version.
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
.github/workflows/typespec-python-regenerate.yml:142
- The SHA annotation still identifies setup-python v5 even though this line now pins v7.0.0. Update it to avoid misleading future maintenance.
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
.github/workflows/typespec-python-regenerate.yml:136
- The SHA annotation is stale after this upgrade: it identifies setup-node v6 while the pinned action is v7.0.0.
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
- Files reviewed: 13/13 changed files
- Comments generated: 2
- Review effort level: Balanced
| uses: github/gh-aw-actions/setup-cli@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup-cli@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 | ||
| with: | ||
| version: v0.80.9 |
| uses: github/gh-aw-actions/setup-cli@8c7d04ebf1ece56cd381446125da3e0f6896294a # v0.80.9 | ||
| uses: github/gh-aw-actions/setup-cli@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5 | ||
| with: | ||
| version: v0.80.9 |
Bumps the github-actions group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.1` | | [github/gh-aw-actions/setup](https://github.com/github/gh-aw-actions) | `0.80.9` | `0.87.5` | | [actions/github-script](https://github.com/actions/github-script) | `7.1.0` | `9.0.0` | | [github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions) | `0.80.9` | `0.87.5` | | [actions/cache/restore](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/cache/save](https://github.com/actions/cache) | `5.0.5` | `6.1.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `7.0.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `6.4.0` | `7.0.0` | Updates `actions/checkout` from 6.0.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6.0.2...3d3c42e) Updates `github/gh-aw-actions/setup` from 0.80.9 to 0.87.5 - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@v0.80.9...2a78d04) Updates `actions/github-script` from 7.1.0 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v7.1.0...3a2844b) Updates `github/gh-aw-actions/setup-cli` from 0.80.9 to 0.87.5 - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@8c7d04e...2a78d04) Updates `actions/cache/restore` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v5.0.5...55cc834) Updates `actions/cache/save` from 5.0.5 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v5.0.5...55cc834) Updates `actions/setup-python` from 5.6.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5.6.0...5fda3b9) Updates `actions/setup-node` from 6.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v6.4.0...8207627) --- updated-dependencies: - dependency-name: actions/cache/restore dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache/save dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/gh-aw-actions/setup dependency-version: 0.87.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/gh-aw-actions/setup-cli dependency-version: 0.87.5 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
43b5861 to
fec2079
Compare
|
One or more custom setup steps configured for this repository failed during this Copilot code review run: Setup steps run before each review. If the review above is missing context, or no review was posted at all, the failing step above may be the cause. See the workflow run for failure details, fix your setup steps configuration, and re-request a review. Note You can configure setup steps for Copilot code review separately from Copilot cloud agent with a |
There was a problem hiding this comment.
🟡 Changes recommended
Regenerate generated workflows and manifests, upgrade the gh-aw CLI, and correct stale SHA annotations.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review details
Suppressed comments (10)
.github/workflows/agentics-maintenance.yml:99
- This file is marked as generated by gh-aw v0.80.9, and its
setup-clisteps still explicitly install v0.80.9, so manually changing the generated action pins leaves the maintenance workflow on the old generator/CLI and the next regeneration can restore the old pins. Upgrade gh-aw and regenerate this workflow instead.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/doc-consistency-check.lock.yml:99
- Regenerate this lock file after changing the pins. Its machine-readable
gh-aw-manifeststill declares the old cache, checkout, setup-node, and gh-aw setup SHAs, while the workflow steps now execute the new SHAs, so tooling consuming the manifest receives an inaccurate dependency set. The file header explicitly marks this file as generated and directs updates throughgh aw compile.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/issue-triage.lock.yml:108
- Regenerate this lock file after changing the pins. Its machine-readable
gh-aw-manifeststill declares the old cache, checkout, setup-node, and gh-aw setup SHAs, while the workflow steps now execute the new SHAs, so tooling consuming the manifest receives an inaccurate dependency set. The file header explicitly marks this file as generated and directs updates throughgh aw compile.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/mgmt-sdk-pr-review.lock.yml:96
- Regenerate this lock file after changing the pin. Its machine-readable
gh-aw-manifeststill declares the previous gh-aw setup SHA while every setup step now executes the new SHA, so tooling consuming the manifest receives an inaccurate dependency set. The file header explicitly marks this file as generated and directs updates throughgh aw compile.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/pipeline-analysis-auto-fix.lock.yml:164
- Regenerate this lock file after changing the pins. Its machine-readable
gh-aw-manifeststill declares the old cache, setup-node, and gh-aw setup SHAs, while the workflow steps now execute the new SHAs, so tooling consuming the manifest receives an inaccurate dependency set. The file header explicitly marks this file as generated and directs updates throughgh aw compile.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/pipeline-analysis-next-steps.lock.yml:156
- Regenerate this lock file after changing the pins. Its machine-readable
gh-aw-manifeststill declares the old cache, checkout, setup-node, and gh-aw setup SHAs, while the workflow steps now execute the new SHAs, so tooling consuming the manifest receives an inaccurate dependency set. The file header explicitly marks this file as generated and directs updates throughgh aw compile.
uses: github/gh-aw-actions/setup@2a78d04403fdc6907d0f05327cffac9dbad5312d # v0.87.5
.github/workflows/typespec-python-regenerate.yml:136
- The SHA annotation still identifies setup-node v6, but this step now pins v7.0.0. Update the annotation with the dependency so it remains trustworthy.
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
.github/workflows/typespec-python-regenerate.yml:142
- The SHA annotation still identifies setup-python v5, but this step now pins v7.0.0. Update the annotation with the dependency so it remains trustworthy.
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
.github/workflows/typespec-python-regenerate.yml:431
- The SHA annotation still identifies github-script v7, but this step now pins v9.0.0. Update the annotation with the dependency so it remains trustworthy.
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
.github/workflows/typespec-python-regenerate.yml:40
- The SHA annotation still identifies checkout v6, but this step now pins v7.0.1. Update the annotation with the dependency so it remains trustworthy.
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- Files reviewed: 13/13 changed files
- Comments generated: 1
- Review effort level: Balanced
| # "azure-sdk-for-python" causing spec.includes("azure") to match all specs | ||
| # in regenerate.ts, which breaks unbranded package name detection | ||
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | ||
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
Bumps the github-actions group with 8 updates in the / directory:
6.0.27.0.10.80.90.87.57.1.09.0.00.80.90.87.55.0.56.1.05.0.56.1.05.6.07.0.06.4.07.0.0Updates
actions/checkoutfrom 6.0.2 to 7.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
github/gh-aw-actions/setupfrom 0.80.9 to 0.87.5Release notes
Sourced from github/gh-aw-actions/setup's releases.
... (truncated)
Commits
2a78d04chore: sync actions from gh-aw@v0.87.5 (#218)ea4b911chore: sync actions from gh-aw@v0.87.4 (#217)b304200chore: sync actions from gh-aw@v0.87.2 (#216)423b3dcchore: sync actions from gh-aw@v0.87.1 (#215)b77e0d5chore: sync actions from gh-aw@v0.87.0 (#214)30aadb1chore: sync actions from gh-aw@v0.86.3 (#213)6aab9e5chore: sync actions from gh-aw@v0.86.2 (#212)8914f47chore: sync actions from gh-aw@v0.86.1 (#211)19356acchore: sync actions from gh-aw@v0.86.0 (#210)2709137chore: sync actions from gh-aw@v0.85.4 (#209)Updates
actions/github-scriptfrom 7.1.0 to 9.0.0Release notes
Sourced from actions/github-script's releases.
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionUpdates
github/gh-aw-actions/setup-clifrom 0.80.9 to 0.87.5Release notes
Sourced from github/gh-aw-actions/setup-cli's releases.
... (truncated)
Commits
2a78d04chore: sync actions from gh-aw@v0.87.5 (#218)ea4b911chore: sync actions from gh-aw@v0.87.4 (#217)b304200chore: sync actions from gh-aw@v0.87.2 (#216)423b3dcchore: sync actions from gh-aw@v0.87.1 (#215)b77e0d5chore: sync actions from gh-aw@v0.87.0 (#214)30aadb1chore: sync actions from gh-aw@v0.86.3 (#213)6aab9e5chore: sync actions from gh-aw@v0.86.2 (#212)8914f47chore: sync actions from gh-aw@v0.86.1 (#211)19356acchore: sync actions from gh-aw@v0.86.0 (#210)2709137chore: sync actions from gh-aw@v0.85.4 (#209)Updates
actions/cache/restorefrom 5.0.5 to 6.1.0Release notes
Sourced from actions/cache/restore's releases.
Changelog
Sourced from actions/cache/restore's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
actions/cache/savefrom 5.0.5 to 6.1.0Release notes
Sourced from actions/cache/save's releases.
Changelog
Sourced from actions/cache/save's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
actions/setup-pythonfrom 5.6.0 to 7.0.0Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
5fda3b9Pin SHA commits and update docs with latest versions (#1338)4ab7e95Merge pull request #1337 from actions/philip-gai/bump-actions-cache-6-2-00f3a009Remove the pip-install input (#1336)f8cf429Migrate to ESM and upgrade dependencies (#1330)54baeeaValidate and retry manifest fetch to prevent silent failures (#1332)c709277Annotation code fix (#1335)6849080remove EOL Python versions and Bumps numpy text fixture (#1333)0903b46Bump certifi from 2020.6.20 to 2024.7.4 in /tests/data (#1328)ece7cb0Fix pip cache error handling on Windows. (#1040)1d18d7aUpdate advanced-usage.md (#811)Updates
actions/setup-nodefrom 6.4.0 to 7.0.0Release notes
Sourced from actions/setup-node's releases.
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)