From 273d80fec578593b71e6dcaeacf325442c053e07 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Sat, 10 Oct 2026 08:04:43 +0000 Subject: [PATCH 1/2] build(deps): bump the all-actions group with 4 updates Bumps the all-actions group with 4 updates: [actions/setup-node](https://github.com/actions/setup-node), [actions/upload-artifact](https://github.com/actions/upload-artifact), [jdx/mise-action](https://github.com/jdx/mise-action) and [actions/download-artifact](https://github.com/actions/download-artifact). Updates `actions/setup-node` from 7.0.0 to 7.1.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/820762786026740c76f36085b0efc47a31fe5020...949feb2413d6458794dcd2491c4babbbce0c15c1) Updates `actions/upload-artifact` from 7.0.1 to 7.0.2 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](https://github.com/actions/upload-artifact/compare/043fb46d1a93c77aae656e7c1c64a875d1fc6a0a...cf430e030ddbb5b0abf93d22962f4752f3646cd9) Updates `jdx/mise-action` from 5.0.1 to 5.1.1 - [Release notes](https://github.com/jdx/mise-action/releases) - [Changelog](https://github.com/jdx/mise-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/jdx/mise-action/compare/7a4e45a543138629540c9a1616d08632b893e492...2d8d4cafcbd33be2ea37d2b6f5ad595363d1f1ca) Updates `actions/download-artifact` from 7.0.0 to 8.0.2 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](https://github.com/actions/download-artifact/compare/37930b1c2abaa49bbe596cd826c3c89aef350131...9000827ccba6bdab643e8b6fd33ac0654aef8333) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: all-actions - dependency-name: jdx/mise-action dependency-version: 5.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: all-actions - dependency-name: actions/download-artifact dependency-version: 8.0.2 dependency-type: direct:production update-type: version-update:semver-major dependency-group: all-actions ... Signed-off-by: dependabot[bot] --- .github/workflows/_backend.yml | 8 ++++---- .github/workflows/_contract.yml | 2 +- .github/workflows/_docker.yml | 2 +- .github/workflows/_frontend.yml | 12 ++++++------ .github/workflows/docker-publish.yml | 8 ++++---- 5 files changed, 16 insertions(+), 16 deletions(-) diff --git a/.github/workflows/_backend.yml b/.github/workflows/_backend.yml index 19acc33632..38721073dc 100644 --- a/.github/workflows/_backend.yml +++ b/.github/workflows/_backend.yml @@ -24,7 +24,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: '22.x' @@ -131,7 +131,7 @@ jobs: - name: Upload test results on failure if: failure() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: test-results-backend path: | @@ -229,7 +229,7 @@ jobs: - name: Upload test results on failure if: failure() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: test-results-backend-features-${{ matrix.features }} path: | @@ -277,7 +277,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup mise for repository toolchain - uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1 + uses: jdx/mise-action@2d8d4cafcbd33be2ea37d2b6f5ad595363d1f1ca # v5.1.1 - name: Setup JDK 17 for registry contracts uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 diff --git a/.github/workflows/_contract.yml b/.github/workflows/_contract.yml index ee0649ff4b..72a1f744c6 100644 --- a/.github/workflows/_contract.yml +++ b/.github/workflows/_contract.yml @@ -209,7 +209,7 @@ jobs: - name: Upload japicmp reports if: ${{ always() && steps.baseline_contracts.outputs.has_standalone_contracts == 'true' && steps.baseline_contracts.outputs.breaking_release != 'true' }} - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: japicmp-reports path: | diff --git a/.github/workflows/_docker.yml b/.github/workflows/_docker.yml index 6a773826c6..dde54a3945 100644 --- a/.github/workflows/_docker.yml +++ b/.github/workflows/_docker.yml @@ -85,7 +85,7 @@ jobs: - name: Upload local Trivy report if: ${{ always() && steps.scan.outcome != 'skipped' && steps.scan.outcome != '' }} - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: trivy-verify-${{ matrix.service.name }} path: ${{ runner.temp }}/${{ matrix.service.name }}.trivy.json diff --git a/.github/workflows/_frontend.yml b/.github/workflows/_frontend.yml index 7a790749bc..a8c723875c 100644 --- a/.github/workflows/_frontend.yml +++ b/.github/workflows/_frontend.yml @@ -37,7 +37,7 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Setup Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} @@ -68,7 +68,7 @@ jobs: - name: Setup Node.js if: steps.should-run.outputs.run == 'true' - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} cache: 'pnpm' @@ -112,7 +112,7 @@ jobs: - name: Setup Node.js if: steps.should-run.outputs.run == 'true' - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} cache: 'pnpm' @@ -156,7 +156,7 @@ jobs: - name: Setup Node.js if: steps.should-run.outputs.run == 'true' - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} cache: 'pnpm' @@ -193,7 +193,7 @@ jobs: run: corepack enable && corepack prepare pnpm@${{ env.PNPM_VERSION }} --activate - name: Setup Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} cache: 'pnpm' @@ -221,7 +221,7 @@ jobs: run: corepack enable && corepack prepare pnpm@${{ env.PNPM_VERSION }} --activate - name: Setup Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + uses: actions/setup-node@949feb2413d6458794dcd2491c4babbbce0c15c1 # v7.1.0 with: node-version: ${{ env.NODE_VERSION }} cache: 'pnpm' diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 0b09e1945f..9aa5ddc590 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -113,7 +113,7 @@ jobs: version: v0.74.0 - name: Upload candidate scan report if: ${{ always() && steps.scan.outcome != 'skipped' && steps.scan.outcome != '' }} - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: trivy-${{ matrix.service.name }} path: ${{ runner.temp }}/${{ matrix.service.name }}.trivy.json @@ -165,7 +165,7 @@ jobs: printf '%s\n' "$SOURCE_SHA" > "$out/$SERVICE.source-commit" jq -n --arg service "$SERVICE" --arg image "$IMAGE_REF" '{service:$service,image_ref:$image}' > "$out/$SERVICE.release.json" - name: Upload candidate evidence - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: candidate-evidence-${{ matrix.service.name }} path: ${{ runner.temp }}/candidate-evidence-${{ matrix.service.name }}/ @@ -181,7 +181,7 @@ jobs: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Download this run's candidate evidence - uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v7 + uses: actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333 # v8.0.2 with: pattern: candidate-evidence-* path: ${{ runner.temp }}/candidate-evidence @@ -200,7 +200,7 @@ jobs: - name: Validate candidates and promote release tags run: scripts/runbooks/promote-release.sh "$RUNNER_TEMP/candidate-evidence" "${GITHUB_SHA}" ghcr.io/davidhlp/ulticode --execute - name: Upload complete release manifest and evidence - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 + uses: actions/upload-artifact@cf430e030ddbb5b0abf93d22962f4752f3646cd9 # v7 with: name: release-manifest path: | From 3d27910a333af7d9f656f695a2aaa43853f09a0a Mon Sep 17 00:00:00 2001 From: DavidHLP Date: Sat, 10 Oct 2026 22:19:57 -0700 Subject: [PATCH 2/2] fix(ci): align artifact download contract with pinned upgrade --- scripts/test/supply-chain-contract.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/test/supply-chain-contract.sh b/scripts/test/supply-chain-contract.sh index 9b4ba55c0e..cebdf06a67 100755 --- a/scripts/test/supply-chain-contract.sh +++ b/scripts/test/supply-chain-contract.sh @@ -149,7 +149,7 @@ for service in owner_services: owner_properties = ET.parse(owner_pom).getroot().find('m:properties', ns) owner_version = owner_properties.findtext(f'm:{prop}', namespaces=ns) assert root_version == owner_version == '1.0.1', f'{service["name"]}: release version mismatch ({root_version!r} != {owner_version!r})' -assert 'actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131' in workflow +assert 'actions/download-artifact@9000827ccba6bdab643e8b6fd33ac0654aef8333' in workflow print('digest-only candidates, common normalized repo and all-service promote gate: PASS') scan = workflow.split(' - name: Scan pushed candidate\n', 1)[1].split(' - name:', 1)[0] assert "exit-code: '1'" in scan and 'continue-on-error' not in scan