Bump actions/upload-artifact from 4.6.2 to 7.0.1 - #19
Conversation
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…tion bumps (#21) * Add the GitHub community scaffolding, and delete the last duplicated renderer PackReportWriter carried a second copy of MarkdownWriter's table renderer and its own escaper, and the two had drifted: `ask --format markdown` stated the row counts on truncation while a committed pack report did not, so the same data made two different claims about how complete it was. There is now one implementation, which makes the drift impossible rather than merely tested against. Community health files, none of which existed: - Issue forms rather than markdown templates, so a bug report arrives with the version, OS and cloud already structured. Both forms lead with a warning that questions, answers and query results can contain the reporter's own data — LakeSpeak redacts credentials but cannot know which table names are sensitive. - The feature form quotes the project's promise and points at GOVERNANCE.md before the first field, because scope is the most common reason to decline a request and that is cheaper to learn before writing it up than after. - A pull request template whose evidence section asks for the revert-and-watch-it- fail proof this project uses, and a final prompt for what a reviewer should be sceptical of. - CODEOWNERS listing the security-relevant paths separately so a change to auth, redaction or the workflows is never skimmed as routine. - SUPPORT.md routing security reports away from public issues, and saying plainly that a question about why a Genie answer is wrong is a Databricks question. Deliberately not added: FUNDING.yml (no sponsorship) and CITATION.cff (this is a CLI, not something anyone cites). * Bump the remaining pinned actions, artifact pair together upload-artifact and download-artifact are a matched pair: an artifact written by one major version is not readable by a mismatched other, and the release workflow writes with one job and reads with another. Dependabot raised them as separate PRs (#19 and #15), which is the same split that made the CodeQL bump fail. They move together here. Also folded in: dependency-review-action v5, action-gh-release v3, gitleaks-action v3. All still pinned by commit SHA with the version in a trailing comment, so the pins stay auditable and Dependabot can keep finding them.
|
Superseded by #21, which bumps these together. upload-artifact and download-artifact are a matched pair — an artifact written by one major version is not readable by a mismatched other, and the release workflow writes in one job and reads in another — so splitting them across separate PRs risks the same version skew that made the CodeQL bump fail. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/upload-artifact from 4.6.2 to 7.0.1.
Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)