Skip to content

Update actions/cache action to v6 - #4042

Merged
amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/actions-cache-6.x
Jul 9, 2026
Merged

amitsingh-007 merged 1 commit into
renovate-updatesfrom
renovate/actions-cache-6.x

Conversation

@amitsingh-007

@amitsingh-007 amitsingh-007 commented Jul 8, 2026 •

Copy link
Copy Markdown
Owner

This PR contains the following updates:

Package Type Update Change
actions/cache action major v5 → v6

Release Notes

actions/cache (actions/cache)

v6.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v6

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

Greptile Summary

This PR bumps actions/cache from v5 to v6 in both the Playwright and release CI workflow files, as generated by Renovate.

  • The change is limited to two version tag updates (@v5 → @v6) across .github/workflows/playwright.yml and .github/workflows/release.yml, with no changes to any inputs or step logic.
  • The v6 release notes indicate internal package updates and an ESM migration, with no breaking changes to the standard path/key/restore-keys inputs or the cache-hit output used here.

Confidence Score: 5/5

Safe to merge — this is a routine version bump touching only action version tags with no logic changes.

The diff is two one-line changes updating an action version tag. The actions/cache@v6 release notes document no breaking changes to inputs or outputs relevant to this usage, and the conditional Playwright install logic (cache-hit != 'true') continues to work as before.

No files require special attention.

Reviews (1): Last reviewed commit: "Update actions/cache action to v6" | Re-trigger Greptile

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Bump GitHub Actions cache step from actions/cache v5 to v6

⚙️ Configuration changes 🕐 Less than 10 minutes

Grey Divider

AI Description

• Update Playwright workflow caching to use actions/cache@v6.
• Update release workflow caching to use actions/cache@v6.
Diagram

graph TD
  A["GitHub Actions"] --> B["playwright.yml"] --> C{{"actions/cache@v6"}}
  A --> D["release.yml"] --> C
  subgraph Legend
    direction LR
    _svc["Workflow runner"] ~~~ _file["Workflow file"] ~~~ _ext{{"External action"}}
  end
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Pin actions/cache to a commit SHA
  • ➕ Stronger supply-chain security and reproducibility
  • ➕ Avoids unexpected behavior changes from tag retargeting
  • ➖ More maintenance overhead to keep SHAs updated
  • ➖ Less readable than semver tags
2. Rely on setup-* action built-in caching only (where applicable)
  • ➕ Fewer discrete cache steps to maintain
  • ➕ Potentially simpler workflows
  • ➖ May not cover Playwright browser binary paths as needed
  • ➖ Harder to tune cache paths/keys for Playwright specifically

Recommendation: The current approach (upgrade to actions/cache@v6) is appropriate and low-risk for keeping CI dependencies current. If your org has a security policy around third-party actions, consider pinning to a commit SHA as a follow-up; otherwise merging as-is is reasonable.

Files changed (2) +2 / -2

Other (2) +2 / -2
playwright.ymlUpgrade Playwright cache step to actions/cache@v6 +1/-1

Upgrade Playwright cache step to actions/cache@v6

• Updates the Playwright binaries cache step to use actions/cache v6 instead of v5. No cache paths/keys or job logic are changed.

.github/workflows/playwright.yml

release.ymlUpgrade release cache step to actions/cache@v6 +1/-1

Upgrade release cache step to actions/cache@v6

• Updates the Playwright binaries cache step in the release workflow to use actions/cache v6. No other workflow behavior is modified.

.github/workflows/release.yml

@qodo-code-review

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Context used
✅ Compliance rules (platform): 22 rules

Grey Divider


Informational

1. Floating cache action tag 🐞 Bug ⛨ Security
Description
The workflows use actions/cache@v6 (a floating major tag), so future v6.x changes can be pulled
into CI without any PR when upstream releases a new version or moves the tag. This increases
supply-chain trust exposure and can introduce unreviewed CI behavior changes.
Code

.github/workflows/playwright.yml[84]

+        uses: actions/cache@v6
Relevance

⭐ Low

Repo routinely uses floating action tags (e.g., actions/cache@v5, checkout@v6, vercel-action@v42)
without SHA pinning.

PR-#3871
PR-#3991
PR-#3743

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
Both workflows now use the floating actions/cache@v6 tag, demonstrating the action is not pinned
to an immutable ref.

.github/workflows/playwright.yml[83-92]
.github/workflows/release.yml[75-84]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Both workflows reference `actions/cache@v6`, which is a floating tag. This makes CI non-reproducible over time and increases supply-chain trust exposure because the executed action code can change without any change in this repo.

## Issue Context
This PR updates the cache step from v5 to v6 in two workflow files; the same pinning improvement should be applied in both locations.

## Fix
Pin `actions/cache` to an immutable reference, preferably a commit SHA (best), or at minimum a fully qualified version tag (e.g. `v6.1.0`).

## Fix Focus Areas
- .github/workflows/playwright.yml[83-92]
- .github/workflows/release.yml[75-84]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

@amitsingh-007
amitsingh-007 merged commit fa7f20c into renovate-updates Jul 9, 2026
2 checks passed
@amitsingh-007
amitsingh-007 deleted the renovate/actions-cache-6.x branch July 9, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant