-
Notifications
You must be signed in to change notification settings - Fork 0
deps(actions): bump the github-actions group with 14 updates #4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
deps(actions): bump the github-actions group with 14 updates #4
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
c59afac to
aaa5782
Compare
Bumps the github-actions group with 14 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.3.1` | `6.0.1` | | [actions/cache](https://github.com/actions/cache) | `4.3.0` | `5.0.1` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `6.0.0` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4` | `7` | | [peter-evans/repository-dispatch](https://github.com/peter-evans/repository-dispatch) | `3` | `4` | | [mozilla-actions/sccache-action](https://github.com/mozilla-actions/sccache-action) | `676c0e67b665684f17941acf5cc3af83bcf10228` | `9e326ebed976843c9932b3aa0e021c6f50310eb4` | | [EmbarkStudios/cargo-deny-action](https://github.com/embarkstudios/cargo-deny-action) | `ef301417264190a1eb9f26fcf171642070085c5b` | `3f4a782664881cf5725d0ffd23969fcce89fd868` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `4.6.0` | `5.5.2` | | [actions/labeler](https://github.com/actions/labeler) | `5.0.0` | `6.0.1` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `6` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `6` | | [gitleaks/gitleaks-action](https://github.com/gitleaks/gitleaks-action) | `dcedce43c6f43de0b836d1fe38946645c9c638dc` | `ff98106e4c7b2bc287b24eaf42907196329070c7` | | [actions/dependency-review-action](https://github.com/actions/dependency-review-action) | `46a3c492319c890177366b6ef46d6b4f89743ed4` | `3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261` | | [actions/stale](https://github.com/actions/stale) | `9.1.0` | `10.1.1` | Updates `actions/checkout` from 4.3.1 to 6.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@34e1148...8e8c483) Updates `actions/cache` from 4.3.0 to 5.0.1 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@0057852...9255dc7) Updates `actions/upload-artifact` from 4.6.2 to 6.0.0 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...b7c566a) Updates `actions/download-artifact` from 4 to 7 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v7) Updates `peter-evans/repository-dispatch` from 3 to 4 - [Release notes](https://github.com/peter-evans/repository-dispatch/releases) - [Commits](peter-evans/repository-dispatch@v3...v4) Updates `mozilla-actions/sccache-action` from 676c0e67b665684f17941acf5cc3af83bcf10228 to 9e326ebed976843c9932b3aa0e021c6f50310eb4 - [Release notes](https://github.com/mozilla-actions/sccache-action/releases) - [Commits](Mozilla-Actions/sccache-action@676c0e6...9e326eb) Updates `EmbarkStudios/cargo-deny-action` from ef301417264190a1eb9f26fcf171642070085c5b to 3f4a782664881cf5725d0ffd23969fcce89fd868 - [Release notes](https://github.com/embarkstudios/cargo-deny-action/releases) - [Commits](EmbarkStudios/cargo-deny-action@ef30141...3f4a782) Updates `codecov/codecov-action` from 4.6.0 to 5.5.2 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@b9fd7d1...671740a) Updates `actions/labeler` from 5.0.0 to 6.0.1 - [Release notes](https://github.com/actions/labeler/releases) - [Commits](actions/labeler@8558fd7...634933e) Updates `actions/setup-node` from 4 to 6 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v6) Updates `actions/setup-python` from 5 to 6 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v6) Updates `gitleaks/gitleaks-action` from dcedce43c6f43de0b836d1fe38946645c9c638dc to ff98106e4c7b2bc287b24eaf42907196329070c7 - [Release notes](https://github.com/gitleaks/gitleaks-action/releases) - [Commits](gitleaks/gitleaks-action@dcedce4...ff98106) Updates `actions/dependency-review-action` from 46a3c492319c890177366b6ef46d6b4f89743ed4 to 3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 - [Release notes](https://github.com/actions/dependency-review-action/releases) - [Commits](actions/dependency-review-action@46a3c49...3c4e3dc) Updates `actions/stale` from 9.1.0 to 10.1.1 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@5bef64f...9971854) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/cache dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: peter-evans/repository-dispatch dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: mozilla-actions/sccache-action dependency-version: 9e326ebed976843c9932b3aa0e021c6f50310eb4 dependency-type: direct:production dependency-group: github-actions - dependency-name: EmbarkStudios/cargo-deny-action dependency-version: 3f4a782664881cf5725d0ffd23969fcce89fd868 dependency-type: direct:production dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 5.5.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/labeler dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: gitleaks/gitleaks-action dependency-version: ff98106e4c7b2bc287b24eaf42907196329070c7 dependency-type: direct:production dependency-group: github-actions - dependency-name: actions/dependency-review-action dependency-version: 3c4e3dcb1aa7874d2c16be7d79418e9b7efd6261 dependency-type: direct:production dependency-group: github-actions - dependency-name: actions/stale dependency-version: 10.1.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <[email protected]>
aaa5782 to
33b147a
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR updates 14 GitHub Actions dependencies to their latest versions, including several major version bumps. The changes bring support for Node.js 24 runtime and improve compatibility with the latest GitHub Actions features.
Key Changes:
- Major version updates for core actions (checkout v4→v6, cache v4→v5, upload-artifact v4→v6, download-artifact v4→v7)
- Updates to SHA-based references for security-focused actions (sccache, cargo-deny, gitleaks)
- Version bumps for third-party actions (codecov v4→v5, labeler v5→v6, stale v9→v10, peter-evans/repository-dispatch v3→v4)
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 76 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/stale.yml | Updated actions/stale SHA reference for v10 |
| .github/workflows/security.yml | Updated checkout, upload-artifact, cache, cargo-deny, gitleaks, and dependency-review actions |
| .github/workflows/release.yml | Updated checkout, upload-artifact, download-artifact, setup-node, setup-python, and repository-dispatch actions |
| .github/workflows/quality-gates.yml | Updated checkout, upload-artifact, cache, and cargo-deny actions |
| .github/workflows/labeler.yml | Updated actions/labeler SHA reference for v6 |
| .github/workflows/ci.yml | Updated checkout, sccache, upload-artifact, download-artifact, cache, cargo-deny, and codecov actions |
| .github/workflows/brand-assets.yml | Updated checkout, upload-artifact, download-artifact, and repository-dispatch actions |
| .github/workflows/benchmark.yml | Updated checkout, cache, and upload-artifact actions |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
|
||
| steps: | ||
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/checkout is being updated from 4.3.1 to 6.0.1. The comment should be updated to "# v6" to accurately reflect the major version.
| - name: Upload changelog artifact | ||
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | ||
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/upload-artifact is being updated from 4.6.2 to 6.0.0. The comment should be updated to "# v6" to accurately reflect the major version.
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v4 | |
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 |
|
|
||
| - name: Download shell completions | ||
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | ||
| uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/download-artifact is being updated from 4 to 7. The comment should be updated to "# v7" to accurately reflect the major version.
| steps: | ||
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/checkout is being updated from 4.3.1 to 6.0.1. The comment should be updated to "# v6" to accurately reflect the major version.
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 | |
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 |
| - name: Upload license report | ||
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | ||
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/upload-artifact is being updated from 4.6.2 to 6.0.0. The comment should be updated to "# v6" to accurately reflect the major version.
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v4 | |
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 |
| - name: Upload artifact (Unix) | ||
| if: runner.os != 'Windows' | ||
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | ||
| uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/upload-artifact is being updated from 4.6.2 to 6.0.0. The comment should be updated to "# v6" to accurately reflect the major version.
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/checkout is being updated from 4.3.1 to 6.0.1. The comment should be updated to "# v6" to accurately reflect the major version.
| uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 | |
| uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 |
|
|
||
| steps: | ||
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/checkout is being updated from 4.3.1 to 6.0.1. The comment should be updated to "# v6" to accurately reflect the major version.
|
|
||
| - name: Cache cargo | ||
| uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 | ||
| uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/cache is being updated from 4.3.0 to 5.0.1. The comment should be updated to "# v5" to accurately reflect the major version.
| uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v4 | |
| uses: actions/cache@9255dc7a253b0ccc959486e2bca901246202afeb # v5 |
|
|
||
| steps: | ||
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | ||
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 |
Copilot
AI
Jan 9, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The version comment "# v4" is inconsistent with the actual version being used. According to the PR description, actions/checkout is being updated from 4.3.1 to 6.0.1. The comment should be updated to "# v6" to accurately reflect the major version.
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 | |
| - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6 |
Bumps the github-actions group with 14 updates:
4.3.16.0.14.3.05.0.14.6.26.0.04734676c0e67b665684f17941acf5cc3af83bcf102289e326ebed976843c9932b3aa0e021c6f50310eb4ef301417264190a1eb9f26fcf171642070085c5b3f4a782664881cf5725d0ffd23969fcce89fd8684.6.05.5.25.0.06.0.14656dcedce43c6f43de0b836d1fe38946645c9c638dcff98106e4c7b2bc287b24eaf42907196329070c746a3c492319c890177366b6ef46d6b4f89743ed43c4e3dcb1aa7874d2c16be7d79418e9b7efd62619.1.010.1.1Updates
actions/checkoutfrom 4.3.1 to 6.0.1Release notes
Sourced from actions/checkout's releases.
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
8e8c483Clarify v6 README (#2328)033fa0dAdd worktree support for persist-credentials includeIf (#2327)c2d88d3Update all references from v5 and v4 to v6 (#2314)1af3b93update readme/changelog for v6 (#2311)71cf226v6-beta (#2298)069c695Persist creds to a separate file (#2286)ff7abcdUpdate README to include Node.js 24 support details and requirements (#2248)08c6903Prepare v5.0.0 release (#2238)9f26565Update actions checkout to use node 24 (#2226)Updates
actions/cachefrom 4.3.0 to 5.0.1Release notes
Sourced from actions/cache's releases.
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
9255dc7Merge pull request #1686 from actions/cache-v5.0.1-release8ff5423chore: release v5.0.19233019Merge pull request #1685 from salmanmkc/node24-storage-blob-fixb975f2bfix: add peer property to package-lock.json for dependenciesd0a0e18fix: update license files for@actions/cache, fast-xml-parser, and strnum74de208fix: update@actions/cacheto ^5.0.1 for Node.js 24 punycode fixac7f115peerb0f846bfix: update@actions/cachewith storage-blob fix for Node.js 24 punycode depr...a783357Merge pull request #1684 from actions/prepare-cache-v5-release3bb0d78docs: highlight v5 runner requirement in releasesUpdates
actions/upload-artifactfrom 4.6.2 to 6.0.0Release notes
Sourced from actions/upload-artifact's releases.
Commits
b7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEddc45eddocs: update README to correct action name for Node.js 24 support615b319chore: release v6.0.0 for Node.js 24 support017748bMerge pull request #744 from actions/fix-storage-blob38d4c79chore: rebuild dist7d27270chore: add missing license cache files for@actions/core,@actions/io, and mi...5f643d3chore: update license files for@actions/artifact@5.0.1 dependencies1df1684chore: update package-lock.json with@actions/artifact@5.0.1b5b1a91fix: update@actions/artifactto ^5.0.0 for Node.js 24 punycode fixUpdates
actions/download-artifactfrom 4 to 7Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
37930b1Merge pull request #452 from actions/download-artifact-v7-release72582b9doc: update readme0d2ec9dchore: release v7.0.0 for Node.js 24 supportfd7ae8fMerge pull request #451 from actions/fix-storage-blobd484700chore: restore minimatch.dep.yml license file03a8080chore: remove obsolete dependency license files56fe6d9chore: update@actions/artifactlicense file to 5.0.18e3ebc4chore: update package-lock.json with@actions/artifact@5.0.11e3c4b4fix: update@actions/artifactto ^5.0.0 for Node.js 24 punycode fix458627dchore: use local@actions/artifactpackage for Node.js 24 testingUpdates
peter-evans/repository-dispatchfrom 3 to 4Release notes
Sourced from peter-evans/repository-dispatch's releases.
... (truncated)
Commits
28959ceFix node version in actions.yml (#433)25d29c2build(deps-dev): bump@types/nodein the npm group (#432)830136cbuild(deps): bump the github-actions group with 3 updates (#431)2c856c6ci: update dependabot config6673907build(deps-dev): bump@types/nodefrom 18.19.127 to 18.19.129 (#429)952a211build(deps): bump peter-evans/repository-dispatch from 3 to 4 (#428)5fc4efddocs: update readmea628c95feat: v4 (#427)de78ac1build(deps-dev): bump@vercel/nccfrom 0.38.3 to 0.38.4 (#425)f49fa7fbuild(deps-dev): bump@types/nodefrom 18.19.124 to 18.19.127 (#426)Updates
mozilla-actions/sccache-actionfrom 676c0e67b665684f17941acf5cc3af83bcf10228 to 9e326ebed976843c9932b3aa0e021c6f50310eb4Commits
Updates
EmbarkStudios/cargo-deny-actionfrom ef301417264190a1eb9f26fcf171642070085c5b to 3f4a782664881cf5725d0ffd23969fcce89fd868Commits
Updates
codecov/codecov-actionfrom 4.6.0 to 5.5.2Release notes
Sourced from codecov/codecov-action's releases.
... (truncated)
Changelog
Sourced from codecov/codecov-action's changelog.
... (truncated)
Commits
671740achore(release): 5.5.2 (#1902)96b38e9chore:disable_searchalignment (#1881)9b6d1f8check gpg only when skip-validation = false (#1894)5a10915chore(release): 5.5.1 (#1873)