Repository navigation
Update GitHub Actions (major) - #75
Open
renovate-bot wants to merge 1 commit into
Open
renovate-bot wants to merge 1 commit into
renovate-bot wants to merge 1 commit into
Conversation
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
August 21, 2025 04:30
ec28de4 to
19e156b
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
October 1, 2025 21:55
19e156b to
822b8ce
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
November 20, 2025 16:52
a0135c3 to
5110d40
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
December 4, 2025 06:01
6ddbc7b to
8bf069c
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
3 times, most recently
from
January 28, 2026 21:47
2fc7de0 to
623de3b
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
February 24, 2026 00:46
623de3b to
9021dd2
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
March 24, 2026 17:05
c9f16ac to
ed39585
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
April 3, 2026 17:11
ed39585 to
b9be649
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
June 2, 2026 15:03
b9be649 to
d8931f9
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
3 times, most recently
from
June 16, 2026 18:03
43943a8 to
f51d8ee
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
June 25, 2026 16:13
fb4d855 to
6cc347e
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
July 8, 2026 01:27
6cc347e to
78bad43
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
July 21, 2026 02:11
684b077 to
8da6ca2
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
August 2, 2026 22:39
28c5a3a to
965bb82
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
August 25, 2026 13:39
965bb82 to
9a2414b
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
2 times, most recently
from
September 15, 2026 19:45
d9b7494 to
e07c68d
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
September 16, 2026 16:35
e07c68d to
d3068a2
Compare
renovate-bot
force-pushed
the
renovate/major-github-actions
branch
from
September 29, 2026 00:28
d3068a2 to
810d9c6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.2.2→v7.0.1v4.5.0→v6.0.1v4.1.0→v6.4.017→25Release Notes
actions/checkout (actions/checkout)
v7.0.1Compare Source
v7.0.0Compare Source
v6.1.0Compare Source
v6.0.3Compare Source
v6.0.2Compare Source
v6.0.1Compare Source
v6.0.0Compare Source
v5.1.0Compare Source
v5.0.1Compare Source
v5.0.0Compare Source
v4.4.0Compare Source
v4.3.1Compare Source
v4.3.0Compare Source
actions/setup-java (actions/setup-java)
v6.0.1Compare Source
v6.0.0Compare Source
v5.7.0Compare Source
v5.6.0Compare Source
What's Changed
Full Changelog: actions/setup-java@v5...v5.6.0
v5.5.0Compare Source
v5.4.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/setup-java@v5...v5.4.0
v5.3.0Compare Source
What's Changed
New Contributors
Full Changelog: actions/setup-java@v5...v5.3.0
v5.2.0Compare Source
What's Changed
Enhancement
Documentation Changes
Dependency Updates
New Contributors
Full Changelog: actions/setup-java@v5...v5.2.0
v5.1.0Compare Source
What's Changed
New Features
.sdkmanrcfile injava-version-fileparameter by @guicamest in #736Bug Fixes & Improvements
Documentation changes
Dependency updates
New Contributors
Full Changelog: actions/setup-java@v5...v5.1.0
v5.0.0Compare Source
What's Changed
Breaking Changes
Make sure your runner is updated to this version or newer to use this release. v2.327.1 Release Notes
Dependency Upgrades
Bug Fixes
New Contributors
Full Changelog: actions/setup-java@v4...v5.0.0
v4.9.1Compare Source
Adds a deprecation warning for setup-java v4.
v4.9.0Compare Source
v4.8.0Compare Source
What's Changed
Full Changelog: actions/setup-java@v4...v4.8.0
v4.7.1Compare Source
What's Changed
Documentation changes
Dependency updates:
Full Changelog: actions/setup-java@v4...v4.7.1
v4.7.0Compare Source
What's Changed
cachefrom version 3.2.4 to 4.0.0 by @aparnajyothi-y in #724@actions/http-clientfrom 2.2.1 to 2.2.3 by @dependabot in #728actions/publish-immutable-actionfrom 0.0.3 to 0.0.4 by @dependabot in #727@types/jestfrom 29.5.12 to 29.5.14 by @dependabot in #729New Contributors
Full Changelog: actions/setup-java@v4...v4.7.0
v4.6.0Compare Source
What's Changed
Add-ons:
Bug fixes:
New Contributors
Full Changelog: actions/setup-java@v4...v4.6.0
gradle/actions (gradle/actions)
v6.4.0Compare Source
Highlights
Gradle version support status in the Job Summary
The actions now report the support status of every Gradle version used in a workflow, as job
annotations and in the Job Summary (#1057). Thanks to @ov7a for the contribution.
Deliberately not reported: patch releases (being on
9.7.0when9.7.1exists is not flagged) andpre-releases (release candidates, milestones and snapshots never produce annotations). The latest
Gradle release is determined from the wrapper checksum data already bundled with the action, so no
network access is required.
Note that these annotations are emitted independently of the
add-job-summarysetting: settingadd-job-summary: 'never'suppresses the Job Summary itself, but the warning and notice annotationsremain.
Gradle itself is now reported in the dependency graph
The
dependency-submissionaction now applies v1.5.0 of theGitHub Dependency Graph Gradle Plugin
(up from v1.4.2) (#1069).
The headline change is that the Gradle Build Tool running the build is now reported as an
org.gradle:gradle-coredependency, so that GitHub can surface known vulnerabilities in the versionof Gradle used to run your build. These are the coordinates that GitHub advisories for the Gradle
Build Tool are published against.
Details worth knowing:
that filter aggressively.
A new Gradle signing key, if you use dependency verification
github-dependency-graph-gradle-plugin1.5.0is signed with a new Gradle signing subkey, and thekey previously documented in our setup guide has been revoked upstream:
org.gradle:github-dependency-graph-gradle-plugin1.5.0and laterE2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA(new)org.gradleplugin versions before the rotation7B79ADD11F8A779FE90FD3D0893A028475557671(old, revoked)com.gradleDevelocity Gradle plugin, including4.5.07B79ADD11F8A779FE90FD3D0893A028475557671(old, revoked)Because the Develocity Gradle plugin is still signed with the old key, you should trust both keys
rather than swapping one for the other — replacing the old key outright will break Develocity
injection. The documented snippet in
docs/setup-gradle.md
has been updated accordingly (#1071):
cache-provider: externalfor externally managed Gradle User HomeBuilds that save and restore Gradle User Home by some other mechanism (Develocity Artifact Cache, for
example) previously had to set
cache-disabled: true, which was misleading: caching wasn't disabled,it just wasn't managed by this action, and the Job Summary reported it as "Disabled".
cache-provider: externalskips Gradle User Home restore/save exactly ascache-disableddoes, butreports a distinct External status in the Job Summary explaining that caching is handled by
another provider (#1059).
Develocity access keys containing OIDC tokens now work
Short-lived-token handling validated the
server=key[;server=key]*access key format with a regexwhose
keyportion was too strict, so an access key holding an OIDC token value was rejectedoutright. Worse, had it passed the regex, parsing split each entry on
=and kept only the secondfield — silently truncating any key containing
=(as JWT padding does) and sending the mangledkey to the server. Both problems are fixed (#1061).
Job Summary attribution
Job summaries produced by
setup-gradleanddependency-submissionnow carry a top-level headingnaming the action, so the block stays attributable when another action's summary content lands in the
same job (#1058).
Updated defaults
wrapper-validation(368 → 373 entries)What's Changed
:wrappertask by @cobexer in #1064New Contributors
Full Changelog: gradle/actions@v6.3.0...v6.4.0
v6.3.0Compare Source
Highlights
Enhanced Caching: Windows fixes and a cache-protocol bump
This release updates
gradle-actions-cachingto v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:Cache entries failed to store at all on Windows.. Every entry failed
with
Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, soevery downstream job ran against an empty Gradle User Home. The cause was a nested,
unpatched copy of
@actions/globcombined with a silently swallowedrequire()inthe bundle, which left Windows path separators unnormalized.
Cache cleanup deleted instrumented jars that were in use. A bug in key
hashing for paths shorter than 64 characters made cleanup judge freshly created
caches/jars-9entries as unused and remove them, so theinstrumented-jarsentrywas never saved and every job re-instrumented its classpaths.
Also included: cache entry names are now consistent between the save and restore
reports — restore previously fell back to showing the raw glob pattern (e.g.
/home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead ofdependencies.Basic caching warns instead of failing silently
The basic (open-source) caching provider now emits a warning and reports
(Entry not saved: save failed)in the Job Summary when a cache save fails, ratherthan reporting success (#1028).
Dependency submission works with Isolated Projects
dependency-submissionnow disables Isolated Projects via a promoted property, sodependency graph generation works on builds that enable it (#1025). Thanks to @reinsch82 for the contribution.
Updated defaults
wrapper-validationWhat's Changed
New Contributors
Full Changelog: gradle/actions@v6.2.0...v6.3.0
v6.2.0Compare Source
Highlights
This release brings significant behaviour improvements to Enhanced caching, improvements to the generated Job Summary, and a number of correctness and security fixes.
What's Changed
New Contributors
Full Changelog: gradle/actions@v6.1.1...v6.2.0
v6.1.1Compare Source
This release updates various dependency versions, resolving several reported security vulnerabilities.
No functional changes are included
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.