Skip to content

deps(actions)(deps): bump the github-actions group with 3 updates - #83

Merged
scttfrdmn merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-087343986b
Aug 3, 2026
Merged

deps(actions)(deps): bump the github-actions group with 3 updates#83
scttfrdmn merged 2 commits into
mainfrom
dependabot/github_actions/github-actions-087343986b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 3 updates: actions/checkout, actions/setup-java and softprops/action-gh-release.

Updates actions/checkout from 6.0.3 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/setup-java from 5.4.0 to 5.6.0

Release notes

Sourced from actions/setup-java's releases.

v5.6.0

What's Changed

Full Changelog: actions/setup-java@v5...v5.6.0

v5.5.0

What's Changed

New Contributors

Full Changelog: actions/setup-java@v5...v5.5.0

Commits
  • 03ad4de Backport #1097/#1098: cache Maven and Gradle wrapper distributions separately...
  • d229d2e Backport #1111: Preserve Maven toolchains across repeated setup-java runs (#1...
  • bbf0f69 dist: Cover Tencent Kona JDK 25 (#1110)
  • 513edc4 feat: expose cache-primary-key output (#597) [v5 backport] (#1089)
  • 62df799 Add Maven compiler problem matcher for javac diagnostics (#1087)
  • 176156a chore: bump version to 5.6.0 for v5 release line
  • bf7b8de build: rebuild dist for backported changes (#1079, #1083, #1084)
  • 0173e6d Infer distribution from asdf .tool-versions vendor prefix (#1084)
  • f45cd82 Rename jdkFile input to jdk-file with deprecated alias (#1083)
  • e2863ad Map Zulu x86 architecture to i686 for Azul Metadata API (#1079)
  • Additional commits viewable in compare view

Updates softprops/action-gh-release from 2.6.2 to 3.0.2

Release notes

Sourced from softprops/action-gh-release's releases.

v3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

v3.0.1

3.0.1

  • maintenance release with updated dependencies

v3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on v2.6.2.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; v2 remains pinned to the latest 2.x release
Changelog

Sourced from softprops/action-gh-release's changelog.

3.0.2

3.0.2 is a patch release focused on release reliability and compatibility. It reuses existing draft releases when publishing prereleases, supports replacing release assets on Gitea, hardens streamed asset uploads, and provides clearer release-creation diagnostics. It also includes TypeScript, coverage, and tooling maintenance merged since 3.0.1.

This release fixes #795, #438, and #803. The upload transport hardening covers the historical failure reported in #790, although current hosted Node 24 runners did not reproduce it naturally. The diagnostics work is related to #786 and does not claim a reproducible release-creation fix.

What's Changed

Exciting New Features 🎉

Bug fixes 🐛

Other Changes 🔄

3.0.1

  • maintenance release with updated dependencies

3.0.0

3.0.0 is a major release that moves the action runtime from Node 20 to Node 24. Use v3 on GitHub-hosted runners and self-hosted fleets that already support the Node 24 Actions runtime. v2.6.2 was the final Node 20-compatible release and is no longer maintained or supported.

What's Changed

Other Changes 🔄

  • Move the action runtime and bundle target to Node 24
  • Update @types/node to the Node 24 line and allow future Dependabot updates
  • Keep the floating major tag on v3; freeze v2 at the final v2.6.2 release

... (truncated)

Commits
  • 3d0d988 release 3.0.2 (#818)
  • 7e13ed4 fix: clarify release creation 404 errors (#817)
  • e6c70a5 fix: replace existing release assets on Gitea (#816)
  • f345337 fix: publish existing draft releases as prereleases (#801)
  • d8a89a2 fix: upload small checksum assets reliably (#815)
  • 45ece40 chore(deps): remove unused TypeScript tooling (#814)
  • f6b913c feat: improve release error reporting and test coverage (#813)
  • 15f193d chore(deps): upgrade TypeScript to 7 (#812)
  • cc8268d chore(deps): bump actions/checkout in the github-actions group (#810)
  • fd0ed1e chore(deps): bump the npm group with 3 updates (#811)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [actions/setup-java](https://github.com/actions/setup-java) and [softprops/action-gh-release](https://github.com/softprops/action-gh-release).


Updates `actions/checkout` from 6.0.3 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@df4cb1c...3d3c42e)

Updates `actions/setup-java` from 5.4.0 to 5.6.0
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@1bcf9fb...03ad4de)

Updates `softprops/action-gh-release` from 2.6.2 to 3.0.2
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](softprops/action-gh-release@3bb1273...3d0d988)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/setup-java
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 3, 2026
Dependabot's bump moved actions/checkout to 3d3c42e while writing `# v6` on all
five refs. That SHA is v7.0.1. A three-major jump was labelled as a same-line
bump, and the label is the only human-readable part of a pin — a wrong one is
worse than none, because it makes the diff look routine.

Labels corrected to the tags the SHAs actually carry:
  actions/checkout             3d3c42e  # v6      -> # v7.0.1
  actions/setup-java           03ad4de  # v5      -> # v5.6.0
  gradle/actions/setup-gradle  48b5f21  # v4      -> # v4.4.3  (pre-existing on main)

SpawnCiHygieneTest passed the mislabelled bump because it only required that
SOME `# vN` be present. It now requires an exact vX.Y.Z: a bare major can keep
meaning something new as the pin moves, an exact version either matches or is a
visible lie. That is the strongest form of the claim checkable offline, so the
Spock suite stays hermetic.

scripts/verify-pins.sh does the network half — resolve each SHA against the tag
its comment claims — and is wired into ci.yml, so it gates PRs and catches the
next mislabelled bump before merge, not after.

Both checks accept annotated-tag pins. setup-gradle pins v4.4.3's tag OBJECT
(48b5f21) rather than the commit (ed40850); GitHub resolves either. An earlier
draft compared against one form only and reported a correct pin as mislabelled,
printing "comment says v4.4.3 ... SHA is actually v4.4.3".

The majors are safe here, checked rather than assumed:
- action-gh-release@v3 moves to the Node 24 runtime. orion runs runner 2.336.0
  and checkout@v6.0.3 was already `using: node24` and passing, so the runtime is
  present.
- checkout@v7's only behavior change blocks fork checkouts under
  pull_request_target / workflow_run. Neither trigger appears in this repo.

checkout@v7.0.1 was already exercised by this PR on both runners: ci.yml on
self-hosted orion and security.yml on ubuntu-latest. Only release.yml is
unexercised until the next tag.

Verified: ./gradlew test green (96 tests, 5 hygiene features); verify-pins.sh OK
on all 12 pins; shellcheck clean. Mutation-tested — bare-major label, wrong
label, nonexistent tag and altered SHA each fail, workflows byte-identical
after. build.gradle version untouched (0.10.0).
@scttfrdmn

Copy link
Copy Markdown
Collaborator

Pushed a fix commit — this bump was mislabelled and I'd have merged a three-major jump thinking it was a patch.

The defect

The bump moved actions/checkout to 3d3c42e but wrote # v6 on all five refs. That SHA is v7.0.1. v6 actually points at d23441a. So the diff read as a routine same-line bump while actually crossing a major boundary.

The label is the only human-readable part of a pin. A wrong one is worse than a missing one, because it makes the diff look boring.

Corrected to the tags the SHAs really carry:

Action SHA was now
actions/checkout 3d3c42e # v6 # v7.0.1
actions/setup-java 03ad4de # v5 # v5.6.0
gradle/actions/setup-gradle 48b5f21 # v4 # v4.4.3

That last one is pre-existing on main, not from this PR — same class of bug, just older.

Why the hygiene test didn't catch it

SpawnCiHygieneTest required only that some # vN comment be present, never that it was true. Both halves are now covered:

  • Offline (Spock): a pin must name an exact vX.Y.Z. A bare major can silently keep meaning something new as the pin moves; an exact version either matches the SHA or is a visible lie a reviewer can resolve. That's the strongest version of the claim checkable without network, so the suite stays hermetic.
  • Networked (scripts/verify-pins.sh, new, wired into ci.yml): resolves each SHA against the tag its comment claims and fails if they disagree. It runs on PRs, so the next mislabelled bump is caught before merge.

Both accept annotated-tag pins. setup-gradle pins v4.4.3's tag object (48b5f21) rather than the commit (ed40850) and GitHub resolves either — my first draft compared against one form only and absurdly reported comment says v4.4.3 ... SHA is actually v4.4.3. Fixed.

The majors are safe here — checked, not assumed

  • action-gh-release@v3 moves to the Node 24 runtime. This mattered because release.yml runs on self-hosted orion, not a GitHub runner. orion is on runner 2.336.0, and checkout@v6.0.3 was already using: node24 and passing there — so the runtime is present.
  • checkout@v7's one behavior change blocks fork checkouts under pull_request_target / workflow_run. Neither trigger exists in this repo (grepped all three workflows).

Worth noting checkout@v7.0.1 was already exercised by this PR on both runner types — ci.yml on orion, security.yml on ubuntu-latest. Only release.yml stays unexercised until the next tag, which is inherent to a release workflow.

Verification

  • ./gradlew test green — 96 tests, 5 hygiene features
  • ./scripts/verify-pins.sh — OK on all 12 pins
  • shellcheck clean
  • Mutation-tested: bare-major label, restored-wrong label, nonexistent tag, and altered-SHA each fail; workflow files byte-identical afterward
  • build.gradle version untouched at 0.10.0 (release workflow verifies tag↔version)

@scttfrdmn
scttfrdmn merged commit af5a687 into main Aug 3, 2026
4 checks passed
@scttfrdmn
scttfrdmn deleted the dependabot/github_actions/github-actions-087343986b branch August 3, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant