Skip to content

chore: bump actions/upload-artifact from 4.6.2 to 7.0.1 - #227

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps actions/upload-artifact from 4.6.2 to 7.0.1.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 15, 2026, 8:20 PM ET / September 16, 2026, 00:20 UTC (Revision 2).

ClawSweeper review

What this changes

Updates the pinned GitHub action that uploads runtime-install diagnostic evidence from v4.6.2 to v7.0.1.

Merge readiness

✅ Ready for maintainer review

The update is compatible with the existing workflow and has no actionable findings. Main still uses v4; the related workflow-removal PR remains unmerged, so this update is not yet obsolete.

Priority: P3
Reviewed head: db8e1fd1353a300392feb340464148bcf1c398f7

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, correctly pinned dependency update with compatible inputs and no concrete defects.
Proof confidence 🌊 off-meta tidepool Not applicable: The bot-authored update is exempt from contributor runtime proof; source inspection confirms compatible upload inputs, but ordinary PR checks do not exercise this manually triggered upload step.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The bot-authored update is exempt from contributor runtime proof; source inspection confirms compatible upload inputs, but ordinary PR checks do not exercise this manually triggered upload step.
Evidence reviewed 6 items Verified introduced change: The complete introduced delta changes only the upload-action SHA; artifact paths, permissions, triggers, retention, and error handling remain unchanged.
Current-main and release context: Current main retains the v4 upload pin. The workflow does not exist in the supplied latest release tag v0.2.46; this is development automation, not a shipped OCM runtime change.
Verified dependency release identity: GitHub resolves v7.0.1 directly to the proposed SHA, and its published release identifies that same commit.
Findings None None.
Security None None.

How this fits together

A dedicated GitHub Actions workflow compares current and historical OCM runtime installation behavior on an isolated Ubuntu runner. Its upload step preserves diagnostic files as a downloadable artifact.

flowchart LR
  A[Manual or reproduction branch trigger] --> B[Ubuntu runner]
  B --> C[Build current and historical OCM]
  C --> D[Run isolated comparison]
  D --> E[Upload diagnostic files]
  E --> F[Downloadable zipped artifact]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep artifact uploads compatible while the workflow exists; the proposed workflow retirement would eliminate this dependency-maintenance need.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this dependency-maintenance PR reports no product defect; compatibility was checked through the workflow and pinned action source.

Is this the best way to solve the issue?

Yes: changing only the immutable action pin is a narrow update, and the existing upload inputs retain their meaning.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against a87053dd608e.

Labels

Label justifications:

  • P3: This is a one-line dependency update to a diagnostic workflow with no OCM runtime behavior change.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The bot-authored update is exempt from contributor runtime proof; source inspection confirms compatible upload inputs, but ordinary PR checks do not exercise this manually triggered upload step.

Evidence

What I checked:

  • Verified introduced change: The complete introduced delta changes only the upload-action SHA; artifact paths, permissions, triggers, retention, and error handling remain unchanged. (.github/workflows/reproduce-ocm-98.yml:66, db8e1fd1353a)
  • Current-main and release context: Current main retains the v4 upload pin. The workflow does not exist in the supplied latest release tag v0.2.46; this is development automation, not a shipped OCM runtime change. (.github/workflows/reproduce-ocm-98.yml:66, a87053dd608e)
  • Verified dependency release identity: GitHub resolves v7.0.1 directly to the proposed SHA, and its published release identifies that same commit. (043fb46d1a93)
  • Applicable action contract: The target directly executes this dependency. Its action manifest uses Node 24, defaults archive to true and hidden-file inclusion to false, and retains the existing name, path, retention-days, and if-no-files-found inputs. The inspected upload implementation restricts multiple files only when archive is false; the target's hosted Ubuntu workflow keeps the zipped path. (action.yml:1, 043fb46d1a93)
  • Related removal remains open: chore: remove the standalone OCM-98 workflow #235 explicitly proposes deleting this workflow to eliminate its maintenance overhead while retaining regression tests and reproduction helpers. A live GitHub read confirms it is not merged.
  • Feature-history routing: GitHub path history associates the workflow with merged fix: isolate runtime install lifecycle state #131 and records MertBasar0 as commit author, with shakkernerd in its review context. Local follow-history encountered an unavailable promisor object; GitHub commit metadata and the workflow patch supplied the history fallback. (.github/workflows/reproduce-ocm-98.yml:1, 3cb61a7d1751)

Likely related people:

  • MertBasar0: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • shakkernerd: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-09-14T16:22:53.833Z sha 24780b2 :: needs maintainer review before merge. :: none

@dependabot dependabot Bot changed the title chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 chore: bump actions/upload-artifact from 4.6.2 to 7.0.1 Sep 16, 2026
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...043fb46)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.1 branch from 24780b2 to db8e1fd Compare September 16, 2026 00:16
@dependabot @github

dependabot Bot commented on behalf of github Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Looks like actions/upload-artifact is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 16, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/upload-artifact-7.0.1 branch September 16, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants