chore(deps): bump the actions group across 1 directory with 3 updates - #744
chore(deps): bump the actions group across 1 directory with 3 updates#744dependabot[bot] wants to merge 1 commit into
Conversation
|
🔍 OpenCodeReview found 2 issue(s) in this PR.
|
| - uses: actions/upload-artifact@v7 | ||
| with: | ||
| name: binary-${{ matrix.goos }}-${{ matrix.goarch }} | ||
| path: ${{ env.bin_name }} |
There was a problem hiding this comment.
[other · medium]
Version inconsistency: upload-artifact is being upgraded to v7, but download-artifact is being upgraded to v8. While these actions may have independent versioning, this mismatch could indicate:
- An accidental version typo (should both be v7 or both be v8?)
- Potential compatibility issues between different major versions
Recommendation: Verify that upload-artifact@v7 and download-artifact@v8 are compatible with each other, or consider using matching versions (e.g., both v7 or both v8) to ensure artifacts uploaded by one can be reliably downloaded by the other.
| steps: | ||
| # fetch-depth: 0 so the non-blocking docs check can diff base...head. | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
[other · high]
Potentially invalid action version: Jumping from actions/checkout@v4 to @v7 skips two major versions (v5, v6). GitHub's first-party actions typically increment one major version at a time. Please verify that v7 is an actual released version of actions/checkout — if this tag doesn't exist, the workflow will fail at runtime with a "Unable to resolve action" error.
Similarly, the other changed files bump actions/upload-artifact to @v7 and actions/download-artifact to @v8. Please double-check that all target versions exist and review their respective changelogs for breaking changes (e.g., removed/renamed inputs, changed default behaviors).
cf64f91 to
145db2b
Compare
Bumps the actions group with 3 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/upload-artifact](https://github.com/actions/upload-artifact) and [actions/download-artifact](https://github.com/actions/download-artifact). Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Commits](actions/checkout@v4...v7) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) Updates `actions/download-artifact` from 4 to 8 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
145db2b to
c2d2715
Compare
Bumps the actions group with 3 updates in the / directory: actions/checkout, actions/upload-artifact and actions/download-artifact.
Updates
actions/checkoutfrom 4 to 7Release notes
Sourced from actions/checkout's releases.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
actions/upload-artifactfrom 4 to 7Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEUpdates
actions/download-artifactfrom 4 to 8Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they do