🚨 Update github actions (main) (major) - #1679
renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests.
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
e4b43a1 to
cf6e91d
Compare
cf6e91d to
88adc4b
Compare
0f4e8e1 to
8bbcd9b
Compare
d434b3b to
7ff12a4
Compare
7ff12a4 to
d8efd66
Compare
6aab9ac to
d0a72c0
Compare
fc1e847 to
bc16505
Compare
bc16505 to
83d9f86
Compare
ReviewFindingsMedium
Info
Previous runReviewRenovate-generated PR that bumps five GitHub Actions to new major versions with commit-SHA pinning updated. The changes are mechanical value-only edits inside Human maintainer sign-off is still required because the PR touches a protected governance path ( FindingsMedium
Previous run (2)ReviewFindingsMedium
Info
Notes
Previous run (3)ReviewFindingsLow
Previous run (4)ReviewFindingsMedium
Previous run (5)ReviewFindingsHigh
Next steps:
Previous run (6)ReviewFindingsHigh
Next steps:
Previous run (7)ReviewFindingsHigh
Previous run (8)ReviewFindingsHigh
Previous run (9)ReviewVerdict: Approve Mechanical Renovate dependency bump updating five GitHub Actions to their next major versions. All changes are SHA pin + version comment swaps with no structural, permission, or configuration modifications. Dimension Summary
Key Verifications
All SHA pins verified as resolving to their claimed version tags.
Previous run (10)ReviewVerdict: Approve SummaryThis Renovate PR updates four GitHub Actions to their next major versions across five workflow files. All changes are mechanical SHA-pin + version-comment swaps (9 additions, 9 deletions).
Correctness ✅
Security ✅
Intent & Scope ✅Mechanical Renovate bot dependency update — authorization is implicit from the automated, value-only nature of the change. Style ✅All changes follow the established Documentation ✅No documentation references specific CI action versions. No staleness concerns.
Labels: PR modifies GitHub Actions workflow files Previous run (11)Review of #1679 — Update GitHub Actions (major)Verdict: ✅ Approve This PR is a routine Renovate dependency update that bumps four GitHub Actions to new major versions across five workflow files. All changes are pure commit SHA pin swaps with updated version comments — no workflow logic, permissions, inputs, or secrets are modified. Actions Updated
Breaking Change Analysis
Security
No findings.
Previous run (12)ReviewFindingsHigh
Medium
Low
Info
Previous run (13)ReviewFindingsHigh
Medium
Info
Previous run (14)ReviewFindingsHigh
Medium
Low
Info
Previous run (15)ReviewFindingsHigh
Medium
Low
Info
|
83d9f86 to
3614c3a
Compare
|
🤖 Finished Review · ✅ Success · Started 6:08 PM UTC · Completed 6:15 PM UTC |
3614c3a to
d88fa78
Compare
|
🤖 Finished Review · ✅ Success · Started 8:51 PM UTC · Completed 8:58 PM UTC |
476f3ab to
f2072f5
Compare
|
🤖 Finished Review · ✅ Success · Started 7:38 PM UTC · Completed 7:49 PM UTC Commit: |
f2072f5 to
53b26c8
Compare
|
🤖 Finished Review · ✅ Success · Started 10:32 PM UTC · Completed 10:41 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.62 |
|
Risk Assessment: moderate (2/5) DetailsSmall SHA-pinned Renovate bump of five GitHub Actions across CI workflows with no logic changes; protected-path and major-version bumps warrant moderate rather than low risk. Previous runRisk Assessment: moderate (2/5) DetailsSmall renovate-bot GitHub Actions version bump touching only CI workflow files; low churn, no security-sensitive or dependency changes, though protected-path and CI-workflow signals lift the score slightly above minimum. Previous run (2)Risk Assessment: elevated (3/5) DetailsSmall, SHA-pinned Renovate bump but touches only protected .github/ CI infrastructure with five simultaneous major-version action upgrades and no test coverage, warranting elevated (but not high) risk. Previous run (3)Risk Assessment: moderate (2/5) DetailsMultiple protected CI workflow files touched with recent changes; Renovate bot making standard dependency pin updates; low git churn and single-author files across 90 days mitigate risk. |
Superseded by updated review
53b26c8 to
c47f453
Compare
|
🤖 Finished Review · ✅ Success · Started 10:04 PM UTC · Completed 10:13 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $4.66 |
691a7df to
9a204dc
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
🤖 Finished Review · ✅ Success · Started 5:18 PM UTC · Completed 5:24 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.05 |
9a204dc to
6738d98
Compare
|
🤖 Finished Review · ✅ Success · Started 1:34 PM UTC · Completed 1:42 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $3.08 |
6738d98 to
aefa8c5
Compare
|
🤖 Finished Review · ✅ Success · Started 6:23 PM UTC · Completed 6:30 PM UTC Commit: Runtime: claude · Model: opus → claude-opus-4-7 · Effort: high · Cost: $2.65 |
This PR contains the following updates:
v6.1.0→v7.0.1v6.5.0→v7.0.0v6.0.0→v7.0.1v5.5.5→v7.0.0v7.1.0v2.6.2→v3.0.3Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
v7.0.0Compare Source
actions/setup-go (actions/setup-go)
v7.0.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/setup-go@v6...v7.0.0
actions/upload-artifact (actions/upload-artifact)
v7.0.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v7...v7.0.1
v7.0.0Compare Source
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new
archiveparameter tofalseto skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. Thenameparameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.ESM
To support new versions of the
@actions/*packages, we've upgraded the package to ESM.What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v6...v7.0.0
codecov/codecov-action (codecov/codecov-action)
v7.0.0Compare Source
codecovsecurityaccount. We have deleted the account and are usingcodecovsecopswith the original gpg keyWhat's Changed
Full Changelog: codecov/codecov-action@v6.0.1...v7.0.0
v6.0.2Compare Source
This is a copy of the
v7.0.0release to make updates easierWhat's Changed
Full Changelog: codecov/codecov-action@v6.0.1...v6.0.2
v6.0.1Compare Source
What's Changed
Full Changelog: codecov/codecov-action@v6.0.0...v6.0.1
v6.0.0Compare Source
What's Changed
Full Changelog: codecov/codecov-action@v5.5.4...v6.0.0
softprops/action-gh-release (softprops/action-gh-release)
v3.0.3Compare Source
3.0.3is a maintenance release with updated dependencies. It also safelyclassifies malformed GitHub API errors to avoid secondary failures (#822).
What's Changed
Bug fixes 🐛
Other Changes 🔄
v3.0.2Compare Source
3.0.2is a patch release focused on release reliability and compatibility. Itreuses existing draft releases when publishing prereleases, supports replacing
release assets on Gitea, hardens streamed asset uploads, and provides clearer
release-creation diagnostics. It also includes TypeScript, coverage, and tooling
maintenance merged since
3.0.1.This release fixes #795, #438, and #803. The upload transport hardening covers the
historical failure reported in #790, although current hosted Node 24 runners did
not reproduce it naturally. The diagnostics work is related to #786 and does not
claim a reproducible release-creation fix.
What's Changed
Exciting New Features 🎉
Bug fixes 🐛
Other Changes 🔄
3.0.1v3.0.1Compare Source
3.0.1
v3.0.0Compare Source
3.0.0is a major release that moves the action runtime from Node 20 to Node 24.Use
v3on GitHub-hosted runners and self-hosted fleets that already support theNode 24 Actions runtime. If you still need the last Node 20-compatible line, stay on
v2.6.2.What's Changed
Other Changes 🔄
@types/nodeto the Node 24 line and allow future Dependabot updatesv3;v2remains pinned to the latest2.xreleaseConfiguration
📅 Schedule: (UTC)
* 0-3 * * *)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.