Skip to content

chore(ci): bump actions/upload-artifact from 4.6.2 to 7.0.1#36

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1
Open

chore(ci): bump actions/upload-artifact from 4.6.2 to 7.0.1#36
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 21, 2026

Bumps actions/upload-artifact from 4.6.2 to 7.0.1.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github May 21, 2026

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot requested a review from a team as a code owner May 21, 2026 12:04
@github-actions github-actions Bot added the size/XS PR size: XS label May 21, 2026
Copy link
Copy Markdown

@Jerry-Xin Jerry-Xin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary: This PR is relevant to the project and safely updates the pinned actions/upload-artifact version in the Docker publish workflow.

βœ… Highlights

  • Project relevance gate: passes. The change affects .github/workflows/docker-publish.yml, which is part of this repository’s release pipeline.
  • .github/workflows/docker-publish.yml:207: The action remains pinned to an exact commit SHA, matching the repository’s existing supply-chain hardening pattern.
  • .github/workflows/docker-publish.yml:209-212: Existing inputs (name, path, if-no-files-found, retention-days) remain valid for upload-artifact@v7.0.1.
  • .github/workflows/docker-publish.yml:165-169: The upload runs on GitHub-hosted runners, so the new Node 24 runtime requirement for v7 should not block this workflow.
  • .github/workflows/docker-publish.yml:222-227: The downstream download-artifact usage is still compatible with the uploaded digest artifacts.

No πŸ”΄ Critical issues found. No test changes are required for this dependency-only workflow pin update; validation will come from the next Docker publish workflow run.

Copy link
Copy Markdown
Contributor

@lml2468 lml2468 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[APPROVE β€” COMMENT due to self-review restriction] Independent cross-review.

Verified:

  1. SHA pin integrity β€” 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a matches actions/upload-artifact tag v7.0.1 exactly (lightweight tag, direct commit ref). βœ…
  2. Usage compatibility β€” The with parameters used (name, path, if-no-files-found, retention-days) are stable across v4β†’v7. The Artifacts v2 wire format is unchanged. βœ…
  3. Paired action β€” download-artifact at line 223 is still pinned to v4.3.0. PR #38 (bump download-artifact from 4.3.0 to 8.0.1) is already open to handle this. Both should merge for consistency, but v4 download is wire-compatible with v7 upload so merging this first is safe. βœ…
  4. CI β€” All checks green including welcome / welcome (PR #34 fix took effect). βœ…

No blocking issues. Standard Dependabot version bump, SHA verified.

Copy link
Copy Markdown
Contributor

@lml2468 lml2468 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[APPROVE β€” self-review, posting as COMMENT] Correct SHA-pinned bump.

βœ… upload-artifact 4.6.2 β†’ 7.0.1: SHA updated from ea165f8 β†’ 043fb46, version comment updated.

⚠️ Coordination required with PR #38 (download-artifact 4β†’8): upload-artifact and download-artifact must use a compatible artifact storage backend. v4 upload/download share the same backend; v7 upload introduces direct-upload support. Recommend merging #36 and #38 together in the same batch, or verifying cross-version compatibility in the release notes before merging individually.

No other issues. Ready to merge alongside #38.

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@ea165f8...043fb46)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.1 branch from c4b7de9 to 506e6b8 Compare May 27, 2026 05:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS PR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants