chore(deps): bump actions/upload-artifact from 4 to 7 - #2326
chore(deps): bump actions/upload-artifact from 4 to 7#2326dependabot[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ba7b716aa
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| - name: Upload sanitized source-validation receipt | ||
| if: always() | ||
| uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4 |
There was a problem hiding this comment.
Update the G037 workflow contract for the new pin
When backend.supabase.tests.test_g037_hosted_closure_workflow is run, it still asserts that the workflow's uses set contains actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08; after this line points at 043fb46..., that source-contract test fails before validating the hosted-closure safety checks. Please update the backend contract test or centralize the approved upload-artifact hash as part of this bump.
Useful? React with 👍 / 👎.
| - name: Upload bounded sanitized source receipt | ||
| if: always() | ||
| uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4 |
There was a problem hiding this comment.
Update the G040 workflow contract for the new pin
When backend.supabase.tests.test_g040_prefix_recovery_workflow is run, its UPLOAD constant still names actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08, and the test both checks the allowed uses set and looks up the upload step by that exact value. With this workflow now using 043fb46..., the contract test fails instead of protecting the G040 source-validation boundary, so the test needs the same approved-hash update.
Useful? React with 👍 / 👎.
5ba7b71 to
7521e59
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7521e59029
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| subject-path: ${{ runner.temp }}/g038-source-receipt/receipt.json | ||
| - name: Upload authenticated source receipt and exact attestation bundle | ||
| uses: actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 # actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # actions/upload-artifact@v4 |
There was a problem hiding this comment.
Update the G038 source contract pin
The G038 workflow now uses the v7.0.1 SHA, but backend/supabase/tests/test_g038_workflow.py still defines UPLOAD as actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08 and then compares both the full actions list and this upload step to that constant in assert_safe_workflow (lines 82-99). In any environment with PyYAML installed, the G038 source-contract test fails before it can validate the account-deletion source-only boundary, so this bump needs the same test/approved-hash update as the workflow.
Useful? React with 👍 / 👎.
9f09305 to
84efc77
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 84efc7708c
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| - name: Upload sanitized local nightly artifacts | ||
| if: always() | ||
| uses: actions/upload-artifact@v4 | ||
| uses: actions/upload-artifact@v7 |
There was a problem hiding this comment.
Update the nightly source contract for v7
When the Bun source-contract suite runs, this changed upload step no longer satisfies apps/web/tests-unit/nightly-regression-workflow.test.ts, which still asserts that the local nightly workflow contains actions/upload-artifact@v4 in the sanitized-artifact contract. I verified cd apps/web && bun test tests-unit/nightly-regression-workflow.test.ts now fails on that assertion, so the workflow bump needs the paired test update (or the workflow should keep the expected version) before CI can pass.
Useful? React with 👍 / 👎.
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
84efc77 to
4d5b12f
Compare
Bumps actions/upload-artifact from 4 to 7.
Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in README