Repository navigation
Bump the github-actions group across 1 directory with 10 updates - #226
Conversation
SanabriaRusso
left a comment
There was a problem hiding this comment.
Approve — routine group bump, pin convention preserved, two red checks are Dependabot artifacts
Verified by execution, not by reading the diff.
What actually changed
git diff origin/main pr/226 -- .github/workflows touches only uses: lines. Nothing else in
any of the 9 files moved — verified by filtering the diff for non-uses: hunks (result: none).
| Action | main | this PR | Notes |
|---|---|---|---|
actions/checkout |
v2 / v4 | v7 | node24 runtime; v7 also blocks fork checkout under pull_request_target/workflow_run |
actions/setup-node |
v2 / v4 | v7 | v5 added auto-caching keyed on packageManager; v7 removed the dummy NODE_AUTH_TOKEN export |
actions/cache |
v4 | v6 | node24 + ESM |
actions/upload-artifact |
v4 | v7 | v7 adds archive: (default true = old behaviour) |
codecov/codecov-action |
v4 | v7 | v5 renamed file→files, plugin→plugins |
google-github-actions/auth |
v2.1.5 | v3.0.0 | "Bump to Node 24 and remove old parameters" |
docker/login-action |
v3 | v4 | node24 + ESM |
docker/setup-buildx-action |
v3.6.1 | v4.3.0 | v4 "remove deprecated inputs/outputs" |
docker/build-push-action |
v6.7.0 | v7.3.0 | v7 removed DOCKER_BUILD_NO_SUMMARY, DOCKER_BUILD_EXPORT_RETENTION_DAYS |
anchore/sbom-action |
e22c3899… (v0.24.0) |
3ad72834… (v0.24.2) |
SHA pin preserved |
The three traps I checked, all clear
1. No removed input is one this repo passes. I read action.yml at each target tag rather than
trusting the changelog:
google-github-actions/auth@v3.0.0—credentials_jsonis still an input (required: false).
build.yaml:47-49keeps working. The "removed old parameters" were not this one.actions/upload-artifact@v7.0.1—if-no-files-foundstill exists (defaultwarn).
#192'ssecurity.yaml:52 if-no-files-found: erroris still a valid input, andarchivedefaults
totrue, soname/pathsemantics are unchanged.codecov/codecov-action@v7.0.0—filesandfail_ci_if_errorboth still exist. The repo
already usesfiles:(unit-tests.yaml:35), not the v5-deprecatedfile:.docker/setup-buildx-action@v4.3.0— the repo passes zero inputs, so "remove deprecated
inputs/outputs" cannot bite.docker/build-push-action@v7.3.0—grep -rn "DOCKER_BUILD_" .github/workflows/→ no matches, so
neither removed env var is in use.actions/setup-node@v5's auto-caching only triggers on apackageManagerfield in
package.json; this repo has none (grep -n packageManager package.json→ no match), so no
surprise cache step appears.setup-node@v7's dropped dummyNODE_AUTH_TOKENexport is a no-op
here:publish-npm.ymlpublishes via OIDC trusted publishing (npm publish --provenance) and
never setsregistry-urlorNODE_AUTH_TOKEN.
2. Runner floor. Every one of these majors moves to the node24 runtime and needs Actions
Runner ≥ 2.327.1. grep -rn "runs-on" .github/workflows/ → all 11 jobs are ubuntu-latest
(GitHub-hosted). No self-hosted runner to upgrade.
3. Nothing from #192 or #207 was disturbed. At the PR head:
publish-npm.yml:39stillnpm install -g npm@11— the trusted-publishing pin survives.security.yaml:13 contents: read,:28 npm ci --ignore-scripts,:52 if-no-files-found: error.grep -rn "pull_request_target\|workflow_run" .github/workflows/→ none, socheckout@v7's new
fork-checkout block is a no-op here (and would be a hardening, not a regression, if it applied).
Pin convention preserved. On main exactly 1 of 31 uses: lines is SHA-pinned
(security.yaml:42 anchore/sbom-action@e22c3899… # v0.24.0); the rest are floating major tags. This
PR keeps the SHA pin (rotated to 3ad72834… # v0.24.2) and keeps tags elsewhere. No
SHA→tag downgrade.
YAML parses. All 10 workflow files at the PR head load cleanly (YAML.safe_load), jobs intact:
build-and-deploy, test, linting, live-api, devnet-dump, publish, Run-Tests, npm-audit, sbom, smoke-load, unit-tests.
The two red checks are not caused by this diff
gh pr checks 226: Run-Tests ✅ 14m43s, Linting ✅, unit-tests ✅, smoke-load ✅,
npm audit ✅, SBOM ✅ (that last one exercises upload-artifact@v7 with
if-no-files-found: error and passes). Two fail:
build-and-deploy— the failing step's own message:
google-github-actions/auth failed with: the GitHub Action workflow must specify exactly one of "workload_identity_provider" or "credentials_json"! … By default, secrets are not passed to workflows triggered from forks, including Dependabot.env.GCP_SA_KEYresolved empty. Same
validation exists in v2 — this is the Dependabot secret scope, not the v3 bump.Check Schema—Resource not accessible by integration - checks/runs#create-a-check-run.
graphql-inspector.yamlis not in this PR's diff; the DependabotGITHUB_TOKENis read-only
so it cannot create a check run.
Confirmed structurally: both of #222's green runs were triggered by actor=dkijania
(a maintainer push to the Dependabot branch), while this PR's run is actor=dependabot[bot]. Same
workflows, different token — that is the entire difference.
Non-blocking
- 4 of the 10 bumps are never exercised by PR CI:
auth@v3andbuild-push-action@v7(the job
aborts at auth),login-action@v4(tag pushes only),codecov-action@v7(pushtomainonly).
I verified their inputs survive by readingaction.ymlat each tag, but that is static analysis.
If you want the publish path proven before merge, push an empty commit to
dependabot/github_actions/github-actions-6c364a58f9— that re-runsbuild-and-deployunder a
maintainer token withGCP_SA_KEYavailable, exactly as happened on #222. One commit, ~4 minutes. security.yaml:27andnightly-devnet-dump.yaml:56still saynode-version: '20', which reached
EOL on 2026-04-30. Out of scope for an action-version bump, but it is the last Node 20 left in the
repo and it is the workflow that runs the #192 audit gate.codecov-actionv5+ is tokenless for public repos and can be rate-limited;fail_ci_if_error: falseand thepush-to-main-only condition mean this cannot turn a PR red.
Bumps the github-actions group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `2` | `7` | | [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.6.1` | `4.3.0` | | [actions/cache](https://github.com/actions/cache) | `4` | `6` | | [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.5` | `3.0.0` | | [docker/login-action](https://github.com/docker/login-action) | `3` | `4` | | [docker/build-push-action](https://github.com/docker/build-push-action) | `6.7.0` | `7.3.0` | | [actions/setup-node](https://github.com/actions/setup-node) | `2` | `7` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.24.0` | `0.24.2` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `4` | `7` | Updates `actions/checkout` from 2 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v2...v7) Updates `docker/setup-buildx-action` from 3.6.1 to 4.3.0 - [Release notes](https://github.com/docker/setup-buildx-action/releases) - [Commits](docker/setup-buildx-action@v3.6.1...v4.3.0) Updates `actions/cache` from 4 to 6 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v4...v6) Updates `google-github-actions/auth` from 2.1.5 to 3.0.0 - [Release notes](https://github.com/google-github-actions/auth/releases) - [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md) - [Commits](google-github-actions/auth@v2.1.5...v3.0.0) Updates `docker/login-action` from 3 to 4 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@v3...v4) Updates `docker/build-push-action` from 6.7.0 to 7.3.0 - [Release notes](https://github.com/docker/build-push-action/releases) - [Commits](docker/build-push-action@v6.7.0...v7.3.0) Updates `actions/setup-node` from 2 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v2...v7) Updates `anchore/sbom-action` from 0.24.0 to 0.24.2 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@e22c389...3ad7283) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) Updates `codecov/codecov-action` from 4 to 7 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@v4...v7) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.24.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/build-push-action dependency-version: 7.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/login-action dependency-version: '4' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: docker/setup-buildx-action dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: google-github-actions/auth dependency-version: 3.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
f2700c6 to
9053081
Compare
Bumps the github-actions group with 10 updates in the / directory:
273.6.14.3.0462.1.53.0.0346.7.07.3.0270.24.00.24.24747Updates
actions/checkoutfrom 2 to 7Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
docker/setup-buildx-actionfrom 3.6.1 to 4.3.0Release notes
Sourced from docker/setup-buildx-action's releases.
... (truncated)
Commits
37fe631Merge pull request #595 from docker/dependabot/npm_and_yarn/docker/actions-to...b5c4f91[dependabot skip] chore: update generated content3e93b63build(deps): bump@docker/actions-toolkitfrom 0.92.0 to 0.95.0e527031Merge pull request #600 from docker/dependabot/npm_and_yarn/brace-expansion-1...c68814b[dependabot skip] chore: update generated content3f891b0build(deps): bump brace-expansion from 1.1.13 to 1.1.18787db26Merge pull request #585 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1f779368[dependabot skip] chore: update generated content7d5e604build(deps): bump js-yaml from 5.2.0 to 5.3.0292c2fbMerge pull request #590 from docker/dependabot/github_actions/actions/setup-n...Updates
actions/cachefrom 4 to 6Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesUpdates
google-github-actions/authfrom 2.1.5 to 3.0.0Release notes
Sourced from google-github-actions/auth's releases.
... (truncated)
Commits
7c6bc77Release: v3.0.0 (#510)42e4997Remove hacky script (#509)5ea4dc1Bump to Node 24 and remove old parameters (#508)c200f36Release: v2.1.13 (#507)3a53be7Update deps (#506)b7593edRelease: v2.1.12 (#503)c1ee334Add retries for getIDToken (#502)140bb51Release: v2.1.11 (#501)ab3132eUpdate deps (#500)25b96baAdd linters (#499)Updates
docker/login-actionfrom 3 to 4Release notes
Sourced from docker/login-action's releases.
... (truncated)
Commits
dbcb813Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...5bcb015[dependabot skip] chore: update generated contentb30b2f2build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...9087f1eMerge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.20009830[dependabot skip] chore: update generated content2325523build(deps): bump js-yaml from 5.2.1 to 5.2.24ec1d4aMerge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.225fc99baMerge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...e512bd5Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...a146c91Merge pull request #1059 from crazy-max/harden-buildx-scope-pathsUpdates
docker/build-push-actionfrom 6.7.0 to 7.3.0Release notes
Sourced from docker/build-push-action's releases.
... (truncated)
Commits
53b7df9Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-t...154298c[dependabot skip] chore: update generated contentcb1238bchore(deps): Bump@docker/actions-toolkitfrom 0.91.0 to 0.92.024f845dMerge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.09c69730[dependabot skip] chore: update generated contentbc3a3a5Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/co...a82c504chore(deps): Bump js-yaml from 4.1.1 to 4.3.00285a75Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-...c6ad2a3Merge pull request #1575 from docker/dependabot/github_actions/actions/checko...d37484fMerge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0Updates
actions/setup-nodefrom 2 to 7Release notes
Sourced from actions/setup-node's releases.