Skip to content

Bump the github-actions group across 1 directory with 10 updates - #226

Merged
dkijania merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-6c364a58f9
Sep 2, 2026
Merged

dkijania merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-6c364a58f9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 10 updates in the / directory:

Package From To
actions/checkout 2 7
docker/setup-buildx-action 3.6.1 4.3.0
actions/cache 4 6
google-github-actions/auth 2.1.5 3.0.0
docker/login-action 3 4
docker/build-push-action 6.7.0 7.3.0
actions/setup-node 2 7
anchore/sbom-action 0.24.0 0.24.2
actions/upload-artifact 4 7
codecov/codecov-action 4 7

Updates actions/checkout from 2 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates docker/setup-buildx-action from 3.6.1 to 4.3.0

Release notes

Sourced from docker/setup-buildx-action's releases.

v4.3.0

Full Changelog: docker/setup-buildx-action@v4.2.0...v4.3.0

v4.2.0

Full Changelog: docker/setup-buildx-action@v4.1.0...v4.2.0

v4.1.0

Full Changelog: docker/setup-buildx-action@v4.0.0...v4.1.0

v4.0.0

... (truncated)

Commits
  • 37fe631 Merge pull request #595 from docker/dependabot/npm_and_yarn/docker/actions-to...
  • b5c4f91 [dependabot skip] chore: update generated content
  • 3e93b63 build(deps): bump @​docker/actions-toolkit from 0.92.0 to 0.95.0
  • e527031 Merge pull request #600 from docker/dependabot/npm_and_yarn/brace-expansion-1...
  • c68814b [dependabot skip] chore: update generated content
  • 3f891b0 build(deps): bump brace-expansion from 1.1.13 to 1.1.18
  • 787db26 Merge pull request #585 from docker/dependabot/npm_and_yarn/js-yaml-5.2.1
  • f779368 [dependabot skip] chore: update generated content
  • 7d5e604 build(deps): bump js-yaml from 5.2.0 to 5.3.0
  • 292c2fb Merge pull request #590 from docker/dependabot/github_actions/actions/setup-n...
  • Additional commits viewable in compare view

Updates actions/cache from 4 to 6

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Updates google-github-actions/auth from 2.1.5 to 3.0.0

Release notes

Sourced from google-github-actions/auth's releases.

v3.0.0

What's Changed

Full Changelog: google-github-actions/auth@v2...v3.0.0

v2.1.13

What's Changed

Full Changelog: google-github-actions/auth@v2.1.12...v2.1.13

v2.1.12

What's Changed

Full Changelog: google-github-actions/auth@v2.1.11...v2.1.12

v2.1.11

What's Changed

Full Changelog: google-github-actions/auth@v2.1.10...v2.1.11

v2.1.10

What's Changed

Full Changelog: google-github-actions/auth@v2.1.9...v2.1.10

v2.1.9

What's Changed

... (truncated)

Commits

Updates docker/login-action from 3 to 4

Release notes

Sourced from docker/login-action's releases.

v4.0.0

Full Changelog: docker/login-action@v3.7.0...v4.0.0

v3.7.0

Full Changelog: docker/login-action@v3.6.0...v3.7.0

v3.6.0

Full Changelog: docker/login-action@v3.5.0...v3.6.0

v3.5.0

Full Changelog: docker/login-action@v3.4.0...v3.5.0

v3.4.0

Full Changelog: docker/login-action@v3.3.0...v3.4.0

... (truncated)

Commits
  • dbcb813 Merge pull request #1051 from docker/dependabot/npm_and_yarn/aws-sdk-dependen...
  • 5bcb015 [dependabot skip] chore: update generated content
  • b30b2f2 build(deps): bump the aws-sdk-dependencies group across 1 directory with 2 up...
  • 9087f1e Merge pull request #1057 from docker/dependabot/npm_and_yarn/js-yaml-5.2.2
  • 0009830 [dependabot skip] chore: update generated content
  • 2325523 build(deps): bump js-yaml from 5.2.1 to 5.2.2
  • 4ec1d4a Merge pull request #1056 from docker/dependabot/npm_and_yarn/postcss-8.5.22
  • 5fc99ba Merge pull request #1053 from docker/dependabot/github_actions/aws-actions/co...
  • e512bd5 Merge pull request #1052 from docker/dependabot/github_actions/codeql-actions...
  • a146c91 Merge pull request #1059 from crazy-max/harden-buildx-scope-paths
  • Additional commits viewable in compare view

Updates docker/build-push-action from 6.7.0 to 7.3.0

Release notes

Sourced from docker/build-push-action's releases.

v7.3.0

Full Changelog: docker/build-push-action@v7.2.0...v7.3.0

v7.2.0

Full Changelog: docker/build-push-action@v7.1.0...v7.2.0

v7.1.0

Full Changelog: docker/build-push-action@v7.0.0...v7.1.0

v7.0.0

Full Changelog: docker/build-push-action@v6.19.2...v7.0.0

v6.19.2

... (truncated)

Commits
  • 53b7df9 Merge pull request #1572 from docker/dependabot/npm_and_yarn/docker/actions-t...
  • 154298c [dependabot skip] chore: update generated content
  • cb1238b chore(deps): Bump @​docker/actions-toolkit from 0.91.0 to 0.92.0
  • 24f845d Merge pull request #1566 from docker/dependabot/npm_and_yarn/js-yaml-4.2.0
  • 9c69730 [dependabot skip] chore: update generated content
  • bc3a3a5 Merge pull request #1574 from docker/dependabot/github_actions/aws-actions/co...
  • a82c504 chore(deps): Bump js-yaml from 4.1.1 to 4.3.0
  • 0285a75 Merge pull request #1573 from docker/dependabot/github_actions/actions/cache-...
  • c6ad2a3 Merge pull request #1575 from docker/dependabot/github_actions/actions/checko...
  • d37484f Merge pull request #1564 from docker/dependabot/npm_and_yarn/undici-6.27.0
  • Additional commits viewable in compare view

Updates actions/setup-node from 2 to 7

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

  • Remove dummy NO...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 2, 2026
SanabriaRusso
SanabriaRusso previously approved these changes Sep 2, 2026

@SanabriaRusso SanabriaRusso left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve — routine group bump, pin convention preserved, two red checks are Dependabot artifacts

Verified by execution, not by reading the diff.

What actually changed

git diff origin/main pr/226 -- .github/workflows touches only uses: lines. Nothing else in
any of the 9 files moved — verified by filtering the diff for non-uses: hunks (result: none).

Action main this PR Notes
actions/checkout v2 / v4 v7 node24 runtime; v7 also blocks fork checkout under pull_request_target/workflow_run
actions/setup-node v2 / v4 v7 v5 added auto-caching keyed on packageManager; v7 removed the dummy NODE_AUTH_TOKEN export
actions/cache v4 v6 node24 + ESM
actions/upload-artifact v4 v7 v7 adds archive: (default true = old behaviour)
codecov/codecov-action v4 v7 v5 renamed file→files, plugin→plugins
google-github-actions/auth v2.1.5 v3.0.0 "Bump to Node 24 and remove old parameters"
docker/login-action v3 v4 node24 + ESM
docker/setup-buildx-action v3.6.1 v4.3.0 v4 "remove deprecated inputs/outputs"
docker/build-push-action v6.7.0 v7.3.0 v7 removed DOCKER_BUILD_NO_SUMMARY, DOCKER_BUILD_EXPORT_RETENTION_DAYS
anchore/sbom-action e22c3899… (v0.24.0) 3ad72834… (v0.24.2) SHA pin preserved

The three traps I checked, all clear

1. No removed input is one this repo passes. I read action.yml at each target tag rather than
trusting the changelog:

  • google-github-actions/auth@v3.0.0 — credentials_json is still an input (required: false).
    build.yaml:47-49 keeps working. The "removed old parameters" were not this one.
  • actions/upload-artifact@v7.0.1 — if-no-files-found still exists (default warn).
    #192's security.yaml:52 if-no-files-found: error is still a valid input, and archive defaults
    to true, so name/path semantics are unchanged.
  • codecov/codecov-action@v7.0.0 — files and fail_ci_if_error both still exist. The repo
    already uses files: (unit-tests.yaml:35), not the v5-deprecated file:.
  • docker/setup-buildx-action@v4.3.0 — the repo passes zero inputs, so "remove deprecated
    inputs/outputs" cannot bite.
  • docker/build-push-action@v7.3.0 — grep -rn "DOCKER_BUILD_" .github/workflows/ → no matches, so
    neither removed env var is in use.
  • actions/setup-node@v5's auto-caching only triggers on a packageManager field in
    package.json; this repo has none (grep -n packageManager package.json → no match), so no
    surprise cache step appears. setup-node@v7's dropped dummy NODE_AUTH_TOKEN export is a no-op
    here: publish-npm.yml publishes via OIDC trusted publishing (npm publish --provenance) and
    never sets registry-url or NODE_AUTH_TOKEN.

2. Runner floor. Every one of these majors moves to the node24 runtime and needs Actions
Runner ≥ 2.327.1. grep -rn "runs-on" .github/workflows/ → all 11 jobs are ubuntu-latest
(GitHub-hosted). No self-hosted runner to upgrade.

3. Nothing from #192 or #207 was disturbed. At the PR head:

  • publish-npm.yml:39 still npm install -g npm@11 — the trusted-publishing pin survives.
  • security.yaml:13 contents: read, :28 npm ci --ignore-scripts, :52 if-no-files-found: error.
  • grep -rn "pull_request_target\|workflow_run" .github/workflows/ → none, so checkout@v7's new
    fork-checkout block is a no-op here (and would be a hardening, not a regression, if it applied).

Pin convention preserved. On main exactly 1 of 31 uses: lines is SHA-pinned
(security.yaml:42 anchore/sbom-action@e22c3899… # v0.24.0); the rest are floating major tags. This
PR keeps the SHA pin (rotated to 3ad72834… # v0.24.2) and keeps tags elsewhere. No
SHA→tag downgrade.

YAML parses. All 10 workflow files at the PR head load cleanly (YAML.safe_load), jobs intact:
build-and-deploy, test, linting, live-api, devnet-dump, publish, Run-Tests, npm-audit, sbom, smoke-load, unit-tests.

The two red checks are not caused by this diff

gh pr checks 226: Run-Tests ✅ 14m43s, Linting ✅, unit-tests ✅, smoke-load ✅,
npm audit ✅, SBOM ✅ (that last one exercises upload-artifact@v7 with
if-no-files-found: error and passes). Two fail:

  • build-and-deploy — the failing step's own message:
    google-github-actions/auth failed with: the GitHub Action workflow must specify exactly one of "workload_identity_provider" or "credentials_json"! … By default, secrets are not passed to workflows triggered from forks, including Dependabot. env.GCP_SA_KEY resolved empty. Same
    validation exists in v2 — this is the Dependabot secret scope, not the v3 bump.
  • Check Schema — Resource not accessible by integration - checks/runs#create-a-check-run.
    graphql-inspector.yaml is not in this PR's diff; the Dependabot GITHUB_TOKEN is read-only
    so it cannot create a check run.

Confirmed structurally: both of #222's green runs were triggered by actor=dkijania
(a maintainer push to the Dependabot branch), while this PR's run is actor=dependabot[bot]. Same
workflows, different token — that is the entire difference.

Non-blocking

  • 4 of the 10 bumps are never exercised by PR CI: auth@v3 and build-push-action@v7 (the job
    aborts at auth), login-action@v4 (tag pushes only), codecov-action@v7 (push to main only).
    I verified their inputs survive by reading action.yml at each tag, but that is static analysis.
    If you want the publish path proven before merge, push an empty commit to
    dependabot/github_actions/github-actions-6c364a58f9 — that re-runs build-and-deploy under a
    maintainer token with GCP_SA_KEY available, exactly as happened on #222. One commit, ~4 minutes.
  • security.yaml:27 and nightly-devnet-dump.yaml:56 still say node-version: '20', which reached
    EOL on 2026-04-30. Out of scope for an action-version bump, but it is the last Node 20 left in the
    repo and it is the workflow that runs the #192 audit gate.
  • codecov-action v5+ is tokenless for public repos and can be rate-limited; fail_ci_if_error: false and the push-to-main-only condition mean this cannot turn a PR red.

Bumps the github-actions group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `2` | `7` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `3.6.1` | `4.3.0` |
| [actions/cache](https://github.com/actions/cache) | `4` | `6` |
| [google-github-actions/auth](https://github.com/google-github-actions/auth) | `2.1.5` | `3.0.0` |
| [docker/login-action](https://github.com/docker/login-action) | `3` | `4` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `6.7.0` | `7.3.0` |
| [actions/setup-node](https://github.com/actions/setup-node) | `2` | `7` |
| [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.24.0` | `0.24.2` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` |
| [codecov/codecov-action](https://github.com/codecov/codecov-action) | `4` | `7` |



Updates `actions/checkout` from 2 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v2...v7)

Updates `docker/setup-buildx-action` from 3.6.1 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@v3.6.1...v4.3.0)

Updates `actions/cache` from 4 to 6
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

Updates `google-github-actions/auth` from 2.1.5 to 3.0.0
- [Release notes](https://github.com/google-github-actions/auth/releases)
- [Changelog](https://github.com/google-github-actions/auth/blob/main/CHANGELOG.md)
- [Commits](google-github-actions/auth@v2.1.5...v3.0.0)

Updates `docker/login-action` from 3 to 4
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](docker/login-action@v3...v4)

Updates `docker/build-push-action` from 6.7.0 to 7.3.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](docker/build-push-action@v6.7.0...v7.3.0)

Updates `actions/setup-node` from 2 to 7
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v2...v7)

Updates `anchore/sbom-action` from 0.24.0 to 0.24.2
- [Release notes](https://github.com/anchore/sbom-action/releases)
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md)
- [Commits](anchore/sbom-action@e22c389...3ad7283)

Updates `actions/upload-artifact` from 4 to 7
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

Updates `codecov/codecov-action` from 4 to 7
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@v4...v7)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: anchore/sbom-action
  dependency-version: 0.24.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: codecov/codecov-action
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/build-push-action
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/login-action
  dependency-version: '4'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: google-github-actions/auth
  dependency-version: 3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-6c364a58f9 branch from f2700c6 to 9053081 Compare September 2, 2026 17:07
@dkijania
dkijania merged commit 6484a3e into main Sep 2, 2026
8 checks passed
@dkijania
dkijania deleted the dependabot/github_actions/github-actions-6c364a58f9 branch September 2, 2026 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants