Skip to content

chore(ci): bump the actions group across 1 directory with 2 updates - #449

Merged
wz-gsa merged 2 commits into
mainfrom
dependabot/github_actions/actions-33caa12136
Sep 24, 2026
Merged

wz-gsa merged 2 commits into
mainfrom
dependabot/github_actions/actions-33caa12136

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates in the / directory: actions/checkout and actions/attest-build-provenance.

Updates actions/checkout from 5.0.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/attest-build-provenance from 3.0.0 to 4.2.2

Release notes

Sourced from actions/attest-build-provenance's releases.

v4.2.2

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.1...v4.2.2

v4.1.1

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.1.0...v4.1.1

v4.1.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

Full Changelog: actions/attest-build-provenance@v4.0.0...v4.1.0

v4.0.0

[!NOTE] As of version 4, actions/attest-build-provenance is simply a wrapper on top of actions/attest.

Existing applications may continue to use the attest-build-provenance action, but new implementations should use actions/attest instead.

What's Changed

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot changed the title chore(ci): bump the actions group with 2 updates chore(ci): bump the actions group across 1 directory with 2 updates Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-33caa12136 branch 3 times, most recently from e16b0f6 to a0e1f7a Compare September 21, 2026 04:48
Bumps the actions group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance).


Updates `actions/checkout` from 5.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v5...3d3c42e)

Updates `actions/attest-build-provenance` from 3.0.0 to 4.2.2
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](actions/attest-build-provenance@977bb37...4d10147)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: 4.2.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-33caa12136 branch from a0e1f7a to 6750dcb Compare September 21, 2026 09:18
@wz-gsa

wz-gsa commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

AI-assisted dependency review (OpenCode), advisory. Reviewed at the current head; main at 8e6160c. Checks green (Conventional Commit Title, pre-commit); BLOCKED is the missing approving review, not a failure.

Both pins verified against the upstream tag objects, not just the comment:

$ gh api repos/actions/checkout/git/refs/tags/v7.0.1 --jq .object
  {"sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","type":"commit"}   ✓ matches the diff
$ gh api repos/actions/attest-build-provenance/git/refs/tags/v4.2.2 --jq .object
  {"sha":"4d101475d8b20a2381f78447822ac1eab6504dd8","type":"commit"}   ✓ matches the diff

Both resolve to type: commit (not an annotated-tag object), and both SHAs equal what the diff pins — so the # v7.0.1 / # v4.2.2 trailing comments are accurate and the pin is to an immutable commit.

One thing worth a deliberate look: actions/checkout jumps two majors here (v5 → v7), which dependabot's grouped-bump title doesn't convey.

  • v6.0.0 changed credential handling — "Persist creds to a separate file" (#2286). This step sets persist-credentials: false, so it opts out of that path entirely.
  • v7.0.0 added "block checking out fork pr for pull_request_target and workflow_run" (#2454) — the one genuinely breaking change. I checked: release.yml triggers on push: branches: [main] and workflow_dispatch only, so neither blocked event applies.
  • v7.0.1 is hardening on top: "escape values passed to --unset", "trim only ascii whitespace for branch", "skip running unsafe pr check if input is default".

So the two-major jump is safe for this workflow specifically, and v7.0.1 is a security-positive move. I also checked the other four call sites: bash32-compat.yml, pre-commit.yml, and markdown-quality.yml (×2) are already on 3d3c42e5… / v7.0.1, and no workflow in the repo uses pull_request_target or workflow_run at all. So the v7 blocking change is inapplicable repo-wide, and this PR brings release.yml into line with the rest.

Scope is minimal and correct: two uses: lines in one file, no permissions change (attestations: write was already there), no new secret exposure. The attestation action is the thing signing release assets, so keeping it current matters more than most bumps.

No objection. Verified, not just skimmed.

@wz-gsa
wz-gsa enabled auto-merge (squash) September 24, 2026 12:54

@wz-gsa wz-gsa left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot actions-group bump (actions/checkout + actions/setup-python patch versions). CI green, no functional change to workflow logic. Approving per standing dependency-update policy.

@wz-gsa
wz-gsa merged commit bb380bb into main Sep 24, 2026
2 checks passed
@wz-gsa
wz-gsa deleted the dependabot/github_actions/actions-33caa12136 branch September 24, 2026 13:23
mogul pushed a commit that referenced this pull request Sep 24, 2026
#513)

The branch-protection required check "acq offline suite under bash 3.2"
came from a job in bash32-compat.yml whose workflow-level pull_request
trigger had a paths: filter (acq, acq.backends/**, scripts/test-acq-lib.sh,
scripts/test-acq-bats, test/bats/**). When a PR's diff didn't touch those
paths, GitHub never created a check-run for that job at all -- not a
'skipped, passing' status, no status whatsoever -- so the required context
sat 'Expected'/pending forever and blocked merge even though every check
that DID run was green. This is GitHub's own documented failure mode for a
required check backed by a path-filtered workflow trigger.

It just blocked #449 (a routine dependabot
actions-version bump touching only .github/workflows/release.yml) and
required an admin-bypass merge to unblock.

Fix (the documented gate-job mitigation, validated via a 7-role
nexus-agents consensus_vote panel, 83% approve):

- Removed the workflow-level paths: filter so the workflow always triggers.
- Added a cheap 'changes' job that computes relevance via git diff
  --name-only against the PR base (same technique markdown-quality.yml's
  link-check job already uses -- no new marketplace action). Fails closed:
  any error computing the diff is a job failure, never a silent
  'not relevant'.
- The expensive job (build bash 3.2.57 from source, run the offline suite)
  is now conditional on the changes job reporting relevant; renamed to
  avoid a duplicate-job-name status-check ambiguity with the gate below.
- Added an always-running 'gate' job that IS the required check, posted
  under the SAME required-check name the single job used before
  ('acq offline suite under bash 3.2') -- so this fix needs zero
  out-of-band branch-protection/ruleset changes. It fails closed on BOTH
  upstream jobs: needs.changes.result must be success (a failure in the
  cheap relevance step must not be laundered into a pass via the
  downstream job's consequent skip), and needs.test-acq-bash32.result must
  be success or skipped.

Verified locally: reproduced the changes job's git-diff logic against two
real commits (workflow-only change -> relevant=false; acq.backends/msb.sh
change -> relevant=true), and exercised the gate's shell logic directly
against all 5 (changes result, test result) combinations -- passes only on
(success, success) and (success, skipped), fails on every other
combination including the failure-laundering case (failure, skipped).
actionlint clean on all workflow files.

Documented as Known Failure Mode #41 (prevention: any workflow backing a
required check must have no trigger-level path filter, or must follow this
gate-job pattern).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant