chore(deps): bump actions/setup-node from 6 to 7 - #6976
Conversation
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v6...v7) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage remains at 96%, unchanged from the Code Coverage is in Public Preview. Learn more and provide us with your feedback. |
PR Review Advisor — Blocking findings reportedAdvisor assessment: Blockers require maintainer review Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: Blockers
|
|
Dependabot attempted to update this pull request, but because the branch |
|
Superseded by #7161, which preserves the original Dependabot update with co-author credit while updating every current workflow reference, pinning the official v7.0.0 commit immutably, and adding the current workflow-boundary coverage. Thank you to Dependabot for identifying and opening the dependency update. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
<!-- markdownlint-disable MD041 --> ## Summary Updates every production `actions/setup-node` reference from v6 to the official immutable v7.0.0 commit. This is a fresh, maintainable replacement for #6976; the original Dependabot author is credited throughout the branch history. ## Changes - Pin all 44 production `actions/setup-node` references to `820762786026740c76f36085b0efc47a31fe5020` (`v7.0.0`). - Preserve the trusted `prepare-e2e` boundary by pinning all 78 consumers to the first commit in this branch, whose action content already contains the v7 update. - Update workflow-boundary constants and tests so mutable or stale setup-node pins remain rejected. - Keep the bootstrap history intact because later commits intentionally reference the first commit as an immutable action source. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates <!-- Check one tests line and one docs line. Check other lines when applicable. Add every requested justification or approval reference. --> - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: this changes internal GitHub Actions pins and workflow-boundary tests only; no user-facing behavior or documentation surface changes. - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: independent review verified the official signed v7.0.0 source, immutable self-reference, trusted-checkout boundary, YAML validity, and absence of permission or secret-handling changes. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification <!-- Check each applicable item only when supported by the requested evidence. Run targeted tests once per relevant change set and rerun after later edits or hook autofixes that can affect the tested behavior. Do not rerun hook-covered checks. --> - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — 317 workflow/security tests passed across 17 files at the pin-complete head; after syncing the current-main sandbox permission fix, exact-head validation passed 89/89 tests across 6 workflow and sandbox-contract files. All changed YAML parsed in the pre-commit hook and `git diff --check` is clean. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: not run; focused workflow and security-contract coverage was used for this pin-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `no-docs-needed` - Evidence: GitHub Actions dependency pins and workflow-contract tests changed; no user-facing behavior or documentation surface changed. Pin-complete validation passed 317/317 tests across 17 files, and exact-head post-sync validation passed 89/89 tests across 6 files. - Agent: Codex Desktop <!-- docs-review-head-sha: 8ffb799 --> <!-- docs-review-agents-blob-sha: 9c9b36d --> --- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated CI and E2E workflows (including shared composite actions) to use a refreshed, pinned `actions/setup-node` reference aligned with v7.0.0 for improved consistency and stronger supply-chain pinning. * Refreshed trusted E2E workspace preparation action pins where applicable. * **Tests** * Updated workflow boundary and integrity tests to match the new pinned `actions/setup-node` references and the refreshed trusted E2E preparation action pins. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps actions/setup-node from 6 to 7.
Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)