Repository navigation
ci: bump the actions group with 6 updates - #83
Conversation
Bumps the actions group with 6 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4` | `7` | | [pnpm/action-setup](https://github.com/pnpm/action-setup) | `4` | `6` | | [actions/setup-node](https://github.com/actions/setup-node) | `4` | `7` | | [actions/setup-python](https://github.com/actions/setup-python) | `5` | `7` | | [actions/github-script](https://github.com/actions/github-script) | `7` | `9` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4` | `7` | Updates `actions/checkout` from 4 to 7 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v4...v7) Updates `pnpm/action-setup` from 4 to 6 - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@v4...v6) Updates `actions/setup-node` from 4 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4...v7) Updates `actions/setup-python` from 5 to 7 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v7) Updates `actions/github-script` from 7 to 9 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](actions/github-script@v7...v9) Updates `actions/upload-artifact` from 4 to 7 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: pnpm/action-setup dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/github-script dependency-version: '9' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions - dependency-name: actions/upload-artifact dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
PR author is in the excluded authors list. |
There was a problem hiding this comment.
Sorry @dependabot[bot], you have reached your weekly rate limit of 500000 diff characters.
Please try again later or upgrade to continue using Sourcery
📝 WalkthroughWalkthroughThe pull request updates GitHub Actions versions across four workflows. It changes setup, scripting, checkout, pnpm, and artifact upload actions without changing workflow logic, build configuration, or artifact paths. ChangesWorkflow action updates
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 8✅ Passed checks (8 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/tauri-build.yml:
- Line 19: Replace every mutable action tag with the corresponding immutable
commit SHA: pin actions/checkout@v7, actions/setup-node@v7,
pnpm/action-setup@v6, both NSIS and MSI actions/upload-artifact@v7 references in
.github/workflows/tauri-build.yml (lines 19, 22, 27, 54, and 61),
actions/setup-python@v7 in .github/workflows/ci.yml (line 110),
actions/github-script@v9 in .github/workflows/dependabot-auto-merge.yml (line
25), and actions/setup-python@v7 plus actions/upload-artifact@v7 in
.github/workflows/kb-update.yml (lines 24 and 45). Preserve each action version
while replacing only the mutable tag with its full commit SHA.
🪄 Autofix (Beta)
❌ Autofix failed (check again to retry)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 23aa26ad-cfe8-472d-a252-238a23f77ecd
📒 Files selected for processing (4)
.github/workflows/ci.yml.github/workflows/dependabot-auto-merge.yml.github/workflows/kb-update.yml.github/workflows/tauri-build.yml
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (2)
- GitHub Check: docker-build
- GitHub Check: python-tests
🧰 Additional context used
🪛 zizmor (1.28.0)
.github/workflows/dependabot-auto-merge.yml
[error] 25-25: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/kb-update.yml
[error] 24-24: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 45-45: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/tauri-build.yml
[warning] 19-19: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 19-19: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 27-27: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 22-22: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 54-54: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 61-61: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/ci.yml
[error] 110-110: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🔍 Remote MCP Context7, GitHub Copilot
Relevant review context
- All target action tags use the
node24runtime: checkout v7, pnpm/action-setup v6, setup-node v7, setup-python v7, github-script v9, and upload-artifact v7. Verify any self-hosted runners support this runtime. - The upgraded metadata retains the workflow inputs used in the supplied changes:
persist-credentials, pnpm caching,python-version/cache: pip, and artifactname/path. - upload-artifact v7 supports direct, unarchived single-file uploads via
archive: false; otherwise artifacts remain archived by default. Existing multi-file paths should therefore retain the default behavior. - Analogous Olive-Studio PRs successfully applied the same upgrades while preserving
setup-nodepnpm caching, Python 3.12 pip caching, and artifact name/path configuration. - The target Babel-Player repository could not be accessed through GitHub tooling (404), so the actual workflow contents and checks could not be independently verified.
🔇 Additional comments (1)
.github/workflows/tauri-build.yml (1)
19-19: 🔒 Security & PrivacyDo not flag untrusted pull-request credential exposure. This workflow runs only on
pushtags matchingv*andworkflow_dispatch; it does not execute pull-request code.persist-credentials: falseis optional hardening, not a required fix here.> Likely an incorrect or invalid review comment.
| runs-on: windows-latest | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| - uses: actions/checkout@v7 |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
Pin every upgraded GitHub Action to an immutable commit SHA.
All changed action references use mutable major-version tags. This violates the repository’s blanket zizmor policy and leaves CI behavior dependent on tag movement.
.github/workflows/tauri-build.yml#L19-L19: pinactions/checkout@v7..github/workflows/tauri-build.yml#L22-L22: pinactions/setup-node@v7..github/workflows/tauri-build.yml#L27-L27: pinpnpm/action-setup@v6..github/workflows/tauri-build.yml#L54-L54: pin the NSISactions/upload-artifact@v7..github/workflows/tauri-build.yml#L61-L61: pin the MSIactions/upload-artifact@v7..github/workflows/ci.yml#L110-L110: pinactions/setup-python@v7..github/workflows/dependabot-auto-merge.yml#L25-L25: pinactions/github-script@v9..github/workflows/kb-update.yml#L24-L24: pinactions/setup-python@v7..github/workflows/kb-update.yml#L45-L45: pinactions/upload-artifact@v7.
🧰 Tools
🪛 zizmor (1.28.0)
[warning] 19-19: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 19-19: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
📍 Affects 4 files
.github/workflows/tauri-build.yml#L19-L19(this comment).github/workflows/tauri-build.yml#L22-L22.github/workflows/tauri-build.yml#L27-L27.github/workflows/tauri-build.yml#L54-L54.github/workflows/tauri-build.yml#L61-L61.github/workflows/ci.yml#L110-L110.github/workflows/dependabot-auto-merge.yml#L25-L25.github/workflows/kb-update.yml#L24-L24.github/workflows/kb-update.yml#L45-L45
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/tauri-build.yml at line 19, Replace every mutable action
tag with the corresponding immutable commit SHA: pin actions/checkout@v7,
actions/setup-node@v7, pnpm/action-setup@v6, both NSIS and MSI
actions/upload-artifact@v7 references in .github/workflows/tauri-build.yml
(lines 19, 22, 27, 54, and 61), actions/setup-python@v7 in
.github/workflows/ci.yml (line 110), actions/github-script@v9 in
.github/workflows/dependabot-auto-merge.yml (line 25), and
actions/setup-python@v7 plus actions/upload-artifact@v7 in
.github/workflows/kb-update.yml (lines 24 and 45). Preserve each action version
while replacing only the mutable tag with its full commit SHA.
Source: Linters/SAST tools
|
Note Autofix is a beta feature. Expect some limitations and changes as we gather feedback and continue to improve it. The agent generated fixes only for
Lines 15–27 permissions:
contents: read
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: pnpm/action-setup@v6
+ - uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6
- - uses: actions/setup-node@v7
+ - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: "22"
cache: pnpmLines 79–85 contents: read
security-events: write
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: falseLines 103–113 run:
working-directory: olive-mcp-server
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: actions/setup-python@v7
+ - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.12"
cache: pipLines 125–131 contents: read
timeout-minutes: 5
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
Lines 22–28 steps:
- name: Check if PR can be merged
id: check
- uses: actions/github-script@v9
+ uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
with:
result-encoding: string
script: |
Lines 17–27 run:
working-directory: olive-mcp-server
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
persist-credentials: false
- - uses: actions/setup-python@v7
+ - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7
with:
python-version: "3.12"
cache: pipLines 42–48
- name: Upload report
if: ${{ !cancelled() }}
- uses: actions/upload-artifact@v7
+ uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: kb-update-report
path: |
Lines 16–30 build-windows:
runs-on: windows-latest
steps:
- - uses: actions/checkout@v7
+ - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Setup Node.js
- uses: actions/setup-node@v7
+ uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7
with:
node-version: 22
- name: Setup pnpm
- uses: pnpm/action-setup@v6
+ uses: pnpm/action-setup@0ebf47130e4866e96fce0953f49152a61190b271 # v6
with:
version: 11.17Lines 51–64 TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
- name: Upload NSIS artifact
- uses: actions/upload-artifact@v7
+ uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: olive-studio-nsis
path: src-tauri/target/x86_64-pc-windows-msvc/release/bundle/nsis/*.exe
if-no-files-found: error
- name: Upload MSI artifact
- uses: actions/upload-artifact@v7
+ uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: olive-studio-msi
path: src-tauri/target/x86_64-pc-windows-msvc/release/bundle/msi/*.msi |
Bumps the actions group with 6 updates:
474647577947Updates
actions/checkoutfrom 4 to 7Release notes
Sourced from actions/checkout's releases.
... (truncated)
Changelog
Sourced from actions/checkout's changelog.
... (truncated)
Commits
3d3c42eprep v7.0.1 release (#2531)2880268escape values passed to --unset (#2530)12cd223trim only ascii whitespace for branch (#2521)62661c4skip running unsafe pr check if input is default (#2518)e8d4307Bump the minor-actions-dependencies group with 2 updates (#2499)631c942eslint 9 (#2474)4f1f4aeBump actions/upload-artifact from 4 to 7 (#2476)ba09753Bump actions/checkout from 6 to 7 (#2488)b9e0990Bump docker/login-action from 3.3.0 to 4.2.0 (#2479)e8cb398Bump docker/build-push-action from 6.5.0 to 7.2.0 (#2478)Updates
pnpm/action-setupfrom 4 to 6Release notes
Sourced from pnpm/action-setup's releases.
Commits
0ebf471fix: update pnpm to v11.7.0 (#267)0e279bbfix: update pnpm to 11.1.1 (#248)3e83581fix: drop patchPnpmEnv so standalone+self-update works on Windows (#258)551b42edocs(README): fixcache_dependency_pathtype (#257)739bfe4fix: self-update bootstrap to packageManager-pinned version (#233) (#256)f61705dchore: add CODEOWNERS7a5507bfix: restore inputs from state in post (#255)1155470fix: honor devEngines.packageManager.onFail=error (#252) (#254)91ab88efix: bin_dest output points to self-updated pnpm, not bootstrap (#249)e578e19fix: update pnpm to 11.0.4Updates
actions/setup-nodefrom 4 to 7Release notes
Sourced from actions/setup-node's releases.
... (truncated)
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)Updates
actions/setup-pythonfrom 5 to 7Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
5fda3b9Pin SHA commits and update docs with latest versions (#1338)4ab7e95Merge pull request #1337 from actions/philip-gai/bump-actions-cache-6-2-00f3a009Remove the pip-install input (#1336)f8cf429Migrate to ESM and upgrade dependencies (#1330)54baeeaValidate and retry manifest fetch to prevent silent failures (#1332)c709277Annotation code fix (#1335)6849080remove EOL Python versions and Bumps numpy text fixture (#1333)0903b46Bump certifi from 2020.6.20 to 2024.7.4 in /tests/data (#1328)ece7cb0Fix pip cache error handling on Windows. (#1040)1d18d7aUpdate advanced-usage.md (#811)Updates
actions/github-scriptfrom 7 to 9Release notes
Sourced from actions/github-script's releases.
... (truncated)
Commits
3a2844bMerge pull request #700 from actions/salmanmkc/expose-getoctokit + prepare re...ca10bbdfix: use@octokit/core/types import for v7 compatibility86e48e2merge: incorporate main branch changesc108472chore: rebuild dist for v9 upgrade and getOctokit factoryafff112Merge pull request #712 from actions/salmanmkc/deployment-false + fix user-ag...ff8117eci: fix user-agent test to handle orchestration ID81c6b78ci: use deployment: false to suppress deployment noise from integration tests3953cafdocs: update README examples from@v8to@v9, add getOctokit docs and v9 brea...c17d55bci: add getOctokit integration test joba047196test: add getOctokit integration tests via callAsyncFunctionUpdates
actions/upload-artifactfrom 4 to 7Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsSummary by cubic
Update GitHub Actions in CI, Tauri build, KB update, and auto-merge workflows to latest majors for Node 24 and ESM support. No workflow logic changes.
Dependencies
actions/checkoutv4 → v7pnpm/action-setupv4 → v6actions/setup-nodev4 → v7actions/setup-pythonv5 → v7actions/github-scriptv7 → v9actions/upload-artifactv4 → v7Migration
actions/checkout@v7blocks fork PR checkout forpull_request_target/workflow_run. Setallow-unsafe-pr-checkout: trueonly if needed.actions/github-script@v9is ESM. Inline scripts must not userequire('@actions/github'); use the injectedgetOctokit.Written for commit 9b3fab2. Summary will update on new commits.