Skip to content

chore(deps): bump actions/download-artifact from 4 to 8 - #7

Merged
fonkamloic merged 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8
Aug 12, 2026
Merged

chore(deps): bump actions/download-artifact from 4 to 8#7
fonkamloic merged 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 2, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/download-artifact from 4 to 8.

Release notes

Sourced from actions/download-artifact's releases.

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v7.0.0

v7 - What's new

[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

New Contributors

Full Changelog: actions/download-artifact@v6.0.0...v7.0.0

v6.0.0

... (truncated)

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Apr 2, 2026
@fonkamloic

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/download-artifact-8 branch from 232bccd to d564f89 Compare August 12, 2026 14:10
@fonkamloic
fonkamloic merged commit 42f1203 into main Aug 12, 2026
2 of 3 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/download-artifact-8 branch August 12, 2026 14:11
@fonkamloic

Copy link
Copy Markdown
Contributor

Local review (the bot cannot run on dependabot events — no secrets): 1-line actions major bump; every usage in this repo pins explicit, stable inputs (checkout: defaults only; setup-node: node-version 20 + npm cache; setup-java: temurin/17; upload/download-artifact: plain name+path single-artifact pair, landing in the same batch so the pair stays consistent). Publish workflows are tag-triggered, so CI here does not exercise them — residual risk accepted, recoverable by re-tag. No Critical/Medium.

fonkamloic added a commit that referenced this pull request Aug 12, 2026
…p-java to v5 (#43)

* chore(deps): bump actions/checkout to v7, upload-artifact to v7, setup-java to v5

Replicates dependabot #8/#9/#11, which the branch ruleset blocks from
merging (bot-authored PRs never receive the Copilot review the
copilot_code_review rule waits for). Same review rationale as noted on
those PRs: every usage pins explicit stable inputs; the
upload/download-artifact pair stays consistent (download@v8 landed via
#7); publish workflows are tag-triggered so the residual risk surfaces
only at the next release and is recoverable by re-tag.

* Review Medium: match the artifact pair at v8, fail release on empty dist

upload-artifact goes v8 (not v7) so the tag-only upload/download pair
shares a major, and the GitHub release step now fails when dist/*.zip
matches nothing instead of silently publishing a release without the
plugin.

* upload-artifact back to v7 — v8 does not exist for the upload action

The upload/download majors are simply offset (upload latest is v7,
download latest is v8, both on the shared v4+ artifact backend), which
is exactly the pairing dependabot proposed. fail_on_unmatched_files
stays: an empty dist/ must fail the release.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant