Repository navigation
chore(deps): bump cachix/install-nix-action from 27 to 31 - #33
dependabot[bot] wants to merge 1 commit into
Conversation
97912b1 to
f11b32a
Compare
|
🔍 Arkana PR Review — Summary: Dependabot bump of Changes: Minimal — two line changes, version tag only. No config changes to Assessment:
Verdict: Clean dependency bump with security improvements. No concerns. |
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 27 to 31. - [Release notes](https://github.com/cachix/install-nix-action/releases) - [Changelog](https://github.com/cachix/install-nix-action/blob/master/RELEASE.md) - [Commits](cachix/install-nix-action@v27...v31) --- updated-dependencies: - dependency-name: cachix/install-nix-action dependency-version: '31' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
f11b32a to
a22567d
Compare
arkana-ai-bot
left a comment
There was a problem hiding this comment.
LGTM as a CI-only change. Non-protocol; no runtime/signing/VTXO code touched.
Scope check:
- Bumps
cachix/install-nix-actionfrom v27 → v31 in.github/workflows/cli.yml:57,.github/workflows/integration-test.yml:26,.github/workflows/release.yml:22. - Confirmed via
gh api .../contents/.github/workflows?ref=a22567dthat these are the only three workflows at the PR head; noinstall-nix-actionusage was missed. (acme-test.ymlon current master does not exist at this PR head, so no gap there — but note it will need its own bump if this branch gets rebased and acme-test.yml has since arrived on master with v27.) - Inputs (
nix_path: nixpkgs=channel:nixos-25.11,extra_nix_config: experimental-features = nix-command flakes) remain supported in v31 — no schema change to the action'swith:block.
Notes / non-blocking:
- v31 release notes flag two security advisories in the intervening Nix versions (GHSA-qc7j-jgf3-qmhg macOS privilege escalation on 2.30.0, and the Nix/Lix/Guix privesc series). Upgrading is the right call.
- Supply-chain posture unchanged: still pinning to a mutable major tag (
@v31) rather than a commit SHA. Not a regression from v27, but worth considering pinning to a SHA + Dependabot updates if you want tamper-evident CI (the release notes themselves highlight that upstream now pins actions to hashes). Out of scope for this PR. release.ymlruns privileged operations (git push to master, tag creation) after installing Nix — same trust boundary as before, so no new exposure.
No changes requested.
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps cachix/install-nix-action from 27 to 31.
Release notes
Sourced from cachix/install-nix-action's releases.
... (truncated)
Changelog
Sourced from cachix/install-nix-action's changelog.
Commits
96951a3Merge pull request #271 from cachix/create-pull-request/patch6281169nix: 2.34.2 -> 2.34.451f3067Revert "ci: use 25.11 for channel tests"15118c1ci: use 25.11 for channel testse1ac057Merge pull request #270 from cachix/create-pull-request/patchd181b96nix: 2.34.1 -> 2.34.21ca7d21Merge pull request #269 from cachix/create-pull-request/patchb613734nix: 2.34.0 -> 2.34.119effe9Merge pull request #267 from cachix/create-pull-request/patchd3f3b99nix: 2.33.3 -> 2.34.0