chore(ci): bump the actions group across 1 directory with 2 updates - #449
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
e16b0f6 to
a0e1f7a
Compare
Bumps the actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance). Updates `actions/checkout` from 5.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v5...3d3c42e) Updates `actions/attest-build-provenance` from 3.0.0 to 4.2.2 - [Release notes](https://github.com/actions/attest-build-provenance/releases) - [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md) - [Commits](actions/attest-build-provenance@977bb37...4d10147) --- updated-dependencies: - dependency-name: actions/attest-build-provenance dependency-version: 4.2.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
a0e1f7a to
6750dcb
Compare
|
AI-assisted dependency review (OpenCode), advisory. Reviewed at the current head; Both pins verified against the upstream tag objects, not just the comment: Both resolve to One thing worth a deliberate look:
So the two-major jump is safe for this workflow specifically, and v7.0.1 is a security-positive move. I also checked the other four call sites: Scope is minimal and correct: two No objection. Verified, not just skimmed. |
wz-gsa
left a comment
There was a problem hiding this comment.
Dependabot actions-group bump (actions/checkout + actions/setup-python patch versions). CI green, no functional change to workflow logic. Approving per standing dependency-update policy.
#513) The branch-protection required check "acq offline suite under bash 3.2" came from a job in bash32-compat.yml whose workflow-level pull_request trigger had a paths: filter (acq, acq.backends/**, scripts/test-acq-lib.sh, scripts/test-acq-bats, test/bats/**). When a PR's diff didn't touch those paths, GitHub never created a check-run for that job at all -- not a 'skipped, passing' status, no status whatsoever -- so the required context sat 'Expected'/pending forever and blocked merge even though every check that DID run was green. This is GitHub's own documented failure mode for a required check backed by a path-filtered workflow trigger. It just blocked #449 (a routine dependabot actions-version bump touching only .github/workflows/release.yml) and required an admin-bypass merge to unblock. Fix (the documented gate-job mitigation, validated via a 7-role nexus-agents consensus_vote panel, 83% approve): - Removed the workflow-level paths: filter so the workflow always triggers. - Added a cheap 'changes' job that computes relevance via git diff --name-only against the PR base (same technique markdown-quality.yml's link-check job already uses -- no new marketplace action). Fails closed: any error computing the diff is a job failure, never a silent 'not relevant'. - The expensive job (build bash 3.2.57 from source, run the offline suite) is now conditional on the changes job reporting relevant; renamed to avoid a duplicate-job-name status-check ambiguity with the gate below. - Added an always-running 'gate' job that IS the required check, posted under the SAME required-check name the single job used before ('acq offline suite under bash 3.2') -- so this fix needs zero out-of-band branch-protection/ruleset changes. It fails closed on BOTH upstream jobs: needs.changes.result must be success (a failure in the cheap relevance step must not be laundered into a pass via the downstream job's consequent skip), and needs.test-acq-bash32.result must be success or skipped. Verified locally: reproduced the changes job's git-diff logic against two real commits (workflow-only change -> relevant=false; acq.backends/msb.sh change -> relevant=true), and exercised the gate's shell logic directly against all 5 (changes result, test result) combinations -- passes only on (success, success) and (success, skipped), fails on every other combination including the failure-laundering case (failure, skipped). actionlint clean on all workflow files. Documented as Known Failure Mode #41 (prevention: any workflow backing a required check must have no trigger-level path filter, or must follow this gate-job pattern).
Bumps the actions group with 2 updates in the / directory: actions/checkout and actions/attest-build-provenance.
Updates
actions/checkoutfrom 5.0.0 to 7.0.1Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
actions/attest-build-provenancefrom 3.0.0 to 4.2.2Release notes
Sourced from actions/attest-build-provenance's releases.
... (truncated)
Commits
4d10147Bump actions/attest from 4.2.0 to 4.2.1 in the actions-minor group (#862)e3fe62eBump the actions-minor group with 2 updates (#860)0f67c3fBump actions/checkout from 6.0.3 to 7.0.0 (#857)21b787dUpdate actions/attest to v4.1.1 (#858)f14352aadd dependabot cooldown (#851)2c04a00Bump actions/checkout from 6.0.2 to 6.0.3 in the actions-minor group (#850)10334b5remove badges from README (#840)c5efebdremove prober workflows (#837)a2bbfa2bump actions/attest from 4.0.0 to 4.1.0 (#838)0856891update RELEASE.md docs (#836)