diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4398320ef..98c8b36d4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -771,14 +771,14 @@ jobs: # ignore — an empty annotation file (no flakes/failures) is normal. - name: Upload flake annotations if: always() && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: flake-annotations-unit-shard-${{ matrix.shard }} path: flake-annotations-unit-shard-*.txt if-no-files-found: ignore - name: Upload repository validation reports if: always() && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: repository-validation-unit-${{ matrix.os }}-${{ matrix.shard }} path: | @@ -970,7 +970,7 @@ jobs: bash scripts/ci/run-coverage-gate.sh - name: Upload shard coverage report if: always() && github.event_name == 'merge_group' && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-shard-${{ matrix.shard }} path: | @@ -990,7 +990,7 @@ jobs: # collide on extraction. - name: Upload coverage flake annotations if: always() && github.event_name == 'merge_group' && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: flake-annotations-coverage-shard-${{ matrix.shard }} path: flake-annotations-coverage-shard-${{ matrix.shard }}.txt @@ -1093,7 +1093,7 @@ jobs: echo "Coverage gate passed: ${coverage_value}% >= ${threshold}%" - name: Upload coverage report if: always() && github.event_name == 'merge_group' && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: coverage-report path: | @@ -1229,7 +1229,7 @@ jobs: exit $failed - name: Upload repository validation reports if: always() && github.event_name == 'merge_group' && needs.detect-release.outputs.is-release != 'true' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: repository-validation-integration path: .swarm/repository-validation/integration-*.json diff --git a/.github/workflows/drift-check.yml b/.github/workflows/drift-check.yml index dcbb724c4..92bc96907 100644 --- a/.github/workflows/drift-check.yml +++ b/.github/workflows/drift-check.yml @@ -68,7 +68,7 @@ jobs: run: node scripts/release-notes-fragments.mjs verify-retention - name: Preserve drift report for PR comment job if: ${{ always() }} - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: drift-check-report path: drift-report.md diff --git a/.github/workflows/flake-detection.yml b/.github/workflows/flake-detection.yml index 9720be486..4676e8bcb 100644 --- a/.github/workflows/flake-detection.yml +++ b/.github/workflows/flake-detection.yml @@ -86,7 +86,7 @@ jobs: - name: Upload flake suggestions if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: flake-suggestions path: | diff --git a/.github/workflows/release-and-publish.yml b/.github/workflows/release-and-publish.yml index 1dc65cc82..e79a479fb 100644 --- a/.github/workflows/release-and-publish.yml +++ b/.github/workflows/release-and-publish.yml @@ -88,7 +88,7 @@ jobs: ' - name: Upload runner artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: sandbox-runner-win32-${{ matrix.arch }} path: runners/swarm-sandbox-runner/target/${{ matrix.target }}/release/swarm-sandbox-runner.exe @@ -199,7 +199,7 @@ jobs: --apply - name: Upload exact-tag fragment cleanup plan - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: release-fragment-cleanup-plan path: .release-fragment-cleanup/plan.json diff --git a/docs/ci/required-check-evidence.json b/docs/ci/required-check-evidence.json index f5709a779..f0ac36fb5 100644 --- a/docs/ci/required-check-evidence.json +++ b/docs/ci/required-check-evidence.json @@ -72,15 +72,29 @@ } ], "workflowRunsByWorkflow": { - ".github/workflows/ci.yml": [34639685905], - ".github/workflows/pr-standards.yml": [34639685670], + ".github/workflows/ci.yml": [ + 34639685905 + ], + ".github/workflows/pr-standards.yml": [ + 34639685670 + ], ".github/workflows/drift-check.yml": [] } }, "workflowEvents": { - ".github/workflows/ci.yml": ["pull_request", "merge_group"], - ".github/workflows/pr-standards.yml": ["pull_request", "merge_group"], - ".github/workflows/drift-check.yml": ["workflow_dispatch", "pull_request", "push"] + ".github/workflows/ci.yml": [ + "pull_request", + "merge_group" + ], + ".github/workflows/pr-standards.yml": [ + "pull_request", + "merge_group" + ], + ".github/workflows/drift-check.yml": [ + "workflow_dispatch", + "pull_request", + "push" + ] }, "capturedWorkflowFiles": { ".github/workflows/ci.yml": { @@ -97,9 +111,9 @@ } }, "localWorkflowHashes": { - ".github/workflows/ci.yml": "2fc14fe568d147c7fd4dc73c4dd88c13d95c18ba70bbf97ce1f51a732d335d67", + ".github/workflows/ci.yml": "c0aa1321834f368fa73f1e8ea26b661347caf603c6915b719b0f8848cb69af77", ".github/workflows/pr-standards.yml": "e055a61a1d43c2c3c74f6b263b21fc4c8f80b62cc34669be59163cb7e492b5a1", - ".github/workflows/drift-check.yml": "4aaea9479278257aa715f1140bf24e0f92ef2cf9fe2a2b6873fb65fa6442ea78" + ".github/workflows/drift-check.yml": "b1ce25c5790245daab68b389812caf9b5588a4b5c9524a7b942c5690193bfa81" }, "capturedAt": "2026-09-11T21:30:25Z", "captureSha": "b21cdce17b8731143ed5fab7fdf32dd8ad5f7a7f", diff --git a/docs/releases/pending/3074-upload-artifact-v7.md b/docs/releases/pending/3074-upload-artifact-v7.md new file mode 100644 index 000000000..f8ab4b15f --- /dev/null +++ b/docs/releases/pending/3074-upload-artifact-v7.md @@ -0,0 +1,3 @@ +## chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 + +Dependabot bump of the `actions/upload-artifact` workflow action from v4.6.2 to v7.0.1 (pinned by SHA) across the CI, drift-check, flake-detection, and release-and-publish workflows. Maintainer-facing CI-only change; artifact upload behavior and inputs used by this repo are compatible.