Skip to content

chore(deps): bump actions/upload-artifact from 4 to 7 - #2326

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1
Open

chore(deps): bump actions/upload-artifact from 4 to 7#2326
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 19, 2026

Copy link
Copy Markdown

Bumps actions/upload-artifact from 4 to 7.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 19, 2026
@dependabot
dependabot Bot requested a review from twoimo as a code owner July 19, 2026 19:43
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 19, 2026
@vercel

vercel Bot commented Jul 19, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
tzudong Ignored Ignored Preview Aug 11, 2026 11:08am

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5ba7b716aa

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

- name: Upload sanitized source-validation receipt
if: always()
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the G037 workflow contract for the new pin

When backend.supabase.tests.test_g037_hosted_closure_workflow is run, it still asserts that the workflow's uses set contains actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08; after this line points at 043fb46..., that source-contract test fails before validating the hosted-closure safety checks. Please update the backend contract test or centralize the approved upload-artifact hash as part of this bump.

Useful? React with 👍 / 👎.

- name: Upload bounded sanitized source receipt
if: always()
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the G040 workflow contract for the new pin

When backend.supabase.tests.test_g040_prefix_recovery_workflow is run, its UPLOAD constant still names actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08, and the test both checks the allowed uses set and looks up the upload step by that exact value. With this workflow now using 043fb46..., the contract test fails instead of protecting the G040 source-validation boundary, so the test needs the same approved-hash update.

Useful? React with 👍 / 👎.

@dependabot dependabot Bot changed the title build(deps): bump actions/upload-artifact from 4.3.3 to 7.0.1 chore(deps): bump actions/upload-artifact from 4.3.3 to 7.0.1 Jul 31, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.1 branch from 5ba7b71 to 7521e59 Compare July 31, 2026 16:43

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7521e59029

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

subject-path: ${{ runner.temp }}/g038-source-receipt/receipt.json
- name: Upload authenticated source receipt and exact attestation bundle
uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the G038 source contract pin

The G038 workflow now uses the v7.0.1 SHA, but backend/supabase/tests/test_g038_workflow.py still defines UPLOAD as actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 and then compares both the full actions list and this upload step to that constant in assert_safe_workflow (lines 82-99). In any environment with PyYAML installed, the G038 source-contract test fails before it can validate the account-deletion source-only boundary, so this bump needs the same test/approved-hash update as the workflow.

Useful? React with 👍 / 👎.

@dependabot dependabot Bot changed the title chore(deps): bump actions/upload-artifact from 4.3.3 to 7.0.1 chore(deps): bump actions/upload-artifact from 4 to 7 Aug 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.1 branch 2 times, most recently from 9f09305 to 84efc77 Compare August 11, 2026 10:06

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 84efc7708c

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

- name: Upload sanitized local nightly artifacts
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the nightly source contract for v7

When the Bun source-contract suite runs, this changed upload step no longer satisfies apps/web/tests-unit/nightly-regression-workflow.test.ts, which still asserts that the local nightly workflow contains actions/upload-artifact@v4 in the sanitized-artifact contract. I verified cd apps/web && bun test tests-unit/nightly-regression-workflow.test.ts now fails on that assertion, so the workflow bump needs the paired test update (or the workflow should keep the expected version) before CI can pass.

Useful? React with 👍 / 👎.

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.1 branch from 84efc77 to 4d5b12f Compare August 11, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants