chore(deps): bump actions/download-artifact from 4 to 8 - #7
Merged
fonkamloic merged 1 commit intoAug 12, 2026
Merged
Conversation
Contributor
|
@dependabot rebase |
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions/download-artifact-8
branch
from
August 12, 2026 14:10
232bccd to
d564f89
Compare
dependabot
Bot
deleted the
dependabot/github_actions/actions/download-artifact-8
branch
August 12, 2026 14:11
Contributor
|
Local review (the bot cannot run on dependabot events — no secrets): 1-line actions major bump; every usage in this repo pins explicit, stable inputs (checkout: defaults only; setup-node: node-version 20 + npm cache; setup-java: temurin/17; upload/download-artifact: plain name+path single-artifact pair, landing in the same batch so the pair stays consistent). Publish workflows are tag-triggered, so CI here does not exercise them — residual risk accepted, recoverable by re-tag. No Critical/Medium. |
fonkamloic
added a commit
that referenced
this pull request
Aug 12, 2026
…p-java to v5 (#43) * chore(deps): bump actions/checkout to v7, upload-artifact to v7, setup-java to v5 Replicates dependabot #8/#9/#11, which the branch ruleset blocks from merging (bot-authored PRs never receive the Copilot review the copilot_code_review rule waits for). Same review rationale as noted on those PRs: every usage pins explicit stable inputs; the upload/download-artifact pair stays consistent (download@v8 landed via #7); publish workflows are tag-triggered so the residual risk surfaces only at the next release and is recoverable by re-tag. * Review Medium: match the artifact pair at v8, fail release on empty dist upload-artifact goes v8 (not v7) so the tag-only upload/download pair shares a major, and the GitHub release step now fails when dist/*.zip matches nothing instead of silently publishing a release without the plugin. * upload-artifact back to v7 — v8 does not exist for the upload action The upload/download majors are simply offset (upload latest is v7, download latest is v8, both on the shared v4+ artifact backend), which is exactly the pairing dependabot proposed. fail_on_unmatched_files stays: an empty dist/ must fail the release.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/download-artifact from 4 to 8.
Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they do