Skip to content

Update GitHub Actions (major) - #75

Open
renovate-bot wants to merge 1 commit into
mihonapp:mainfrom
renovate-bot:renovate/major-github-actions
Open

renovate-bot wants to merge 1 commit into
mihonapp:mainfrom
renovate-bot:renovate/major-github-actions

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Aug 11, 2025 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
actions/checkout action major v4.2.2 → v7.0.1
actions/setup-java action major v4.5.0 → v6.0.1
gradle/actions action major v4.1.0 → v6.4.0
java-jdk uses-with major 17 → 25

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

v6.1.0

Compare Source

v6.0.3

Compare Source

v6.0.2

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

v5.1.0

Compare Source

v5.0.1

Compare Source

v5.0.0

Compare Source

v4.4.0

Compare Source

v4.3.1

Compare Source

v4.3.0

Compare Source

actions/setup-java (actions/setup-java)

v6.0.1

Compare Source

v6.0.0

Compare Source

v5.7.0

Compare Source

v5.6.0

Compare Source

What's Changed

Full Changelog: actions/setup-java@v5...v5.6.0

v5.5.0

Compare Source

v5.4.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v5...v5.4.0

v5.3.0

Compare Source

What's Changed
New Contributors

Full Changelog: actions/setup-java@v5...v5.3.0

v5.2.0

Compare Source

What's Changed
Enhancement
Documentation Changes
Dependency Updates
New Contributors

Full Changelog: actions/setup-java@v5...v5.2.0

v5.1.0

Compare Source

What's Changed
New Features
Bug Fixes & Improvements
Documentation changes
Dependency updates
New Contributors

Full Changelog: actions/setup-java@v5...v5.1.0

v5.0.0

Compare Source

What's Changed
Breaking Changes

Make sure your runner is updated to this version or newer to use this release. v2.327.1 Release Notes

Dependency Upgrades
Bug Fixes
New Contributors

Full Changelog: actions/setup-java@v4...v5.0.0

v4.9.1

Compare Source

Adds a deprecation warning for setup-java v4.

v4.9.0

Compare Source

v4.8.0

Compare Source

What's Changed

Full Changelog: actions/setup-java@v4...v4.8.0

v4.7.1

Compare Source

What's Changed

Documentation changes
Dependency updates:

Full Changelog: actions/setup-java@v4...v4.7.1

v4.7.0

Compare Source

What's Changed

New Contributors

Full Changelog: actions/setup-java@v4...v4.7.0

v4.6.0

Compare Source

What's Changed

Add-ons:

 - name: Checkout
   uses: actions/checkout@v4
 - name: Setup-java
   uses: actions/setup-java@v4
   with:
     distribution: ‘jetbrains’
     java-version: '21'

Bug fixes:

New Contributors

Full Changelog: actions/setup-java@v4...v4.6.0

gradle/actions (gradle/actions)

v6.4.0

Compare Source

Highlights

Gradle version support status in the Job Summary

The actions now report the support status of every Gradle version used in a workflow, as job
annotations and in the Job Summary (#​1057). Thanks to @​ov7a for the contribution.

version kind job annotation version table below the table
End-of-life — two or more major versions behind the latest release warning ⚠️ expandable section naming the affected release lines, pointing at the Gradle Security Subscription
Out of date — one major behind, or more than two minors behind on the current major notice ℹ️ one-line legend pointing at the Gradle release lifecycle docs
Current none — —

Deliberately not reported: patch releases (being on 9.7.0 when 9.7.1 exists is not flagged) and
pre-releases (release candidates, milestones and snapshots never produce annotations). The latest
Gradle release is determined from the wrapper checksum data already bundled with the action, so no
network access is required.

Note that these annotations are emitted independently of the add-job-summary setting: setting
add-job-summary: 'never' suppresses the Job Summary itself, but the warning and notice annotations
remain.

Gradle itself is now reported in the dependency graph

The dependency-submission action now applies v1.5.0 of the
GitHub Dependency Graph Gradle Plugin
(up from v1.4.2) (#​1069).

The headline change is that the Gradle Build Tool running the build is now reported as an
org.gradle:gradle-core dependency, so that GitHub can surface known vulnerabilities in the version
of Gradle used to run your build
. These are the coordinates that GitHub advisories for the Gradle
Build Tool are published against.

Details worth knowing:

  • The entry is always reported as a direct dependency with development scope.
  • It is not affected by the project, configuration or scope filters, so it appears even in graphs
    that filter aggressively.
  • Expect dependency graphs to gain this one new entry the first time a build runs after upgrading.
A new Gradle signing key, if you use dependency verification

[!IMPORTANT]
If your build has dependency verification
enabled, you must add a second trusted key before upgrading, or Dependency Graph generation will
fail signature verification.

github-dependency-graph-gradle-plugin 1.5.0 is signed with a new Gradle signing subkey, and the
key previously documented in our setup guide has been revoked upstream:

Artifact Signing key
org.gradle:github-dependency-graph-gradle-plugin 1.5.0 and later E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA (new)
org.gradle plugin versions before the rotation 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)
com.gradle Develocity Gradle plugin, including 4.5.0 7B79ADD11F8A779FE90FD3D0893A028475557671 (old, revoked)

Because the Develocity Gradle plugin is still signed with the old key, you should trust both keys
rather than swapping one for the other — replacing the old key outright will break Develocity
injection. The documented snippet in
docs/setup-gradle.md
has been updated accordingly (#​1071):

<trusted-keys>
   <trusted-key id="7B79ADD11F8A779FE90FD3D0893A028475557671">
      <trusting group="com.gradle"/>
      <trusting group="org.gradle"/>
   </trusted-key>
   <trusted-key id="E2879931BCA1A42E55F2D64DD9B2DFBD9F3298BA">
      <trusting group="org.gradle"/>
   </trusted-key>
</trusted-keys>
cache-provider: external for externally managed Gradle User Home

Builds that save and restore Gradle User Home by some other mechanism (Develocity Artifact Cache, for
example) previously had to set cache-disabled: true, which was misleading: caching wasn't disabled,
it just wasn't managed by this action, and the Job Summary reported it as "Disabled".

cache-provider: external skips Gradle User Home restore/save exactly as cache-disabled does, but
reports a distinct External status in the Job Summary explaining that caching is handled by
another provider (#​1059).

- uses: gradle/actions/setup-gradle@v6
  with:
    cache-provider: 'external'
Develocity access keys containing OIDC tokens now work

Short-lived-token handling validated the server=key[;server=key]* access key format with a regex
whose key portion was too strict, so an access key holding an OIDC token value was rejected
outright. Worse, had it passed the regex, parsing split each entry on = and kept only the second
field — silently truncating any key containing = (as JWT padding does) and sending the mangled
key to the server. Both problems are fixed (#​1061).

Job Summary attribution

Job summaries produced by setup-gradle and dependency-submission now carry a top-level heading
naming the action, so the block stays attributable when another action's summary content lands in the
same job (#​1058).

Updated defaults
  • GitHub Dependency Graph Gradle Plugin: 1.4.2 → 1.5.0
  • 5 new known-good wrapper checksums for wrapper-validation (368 → 373 entries)

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.3.0...v6.4.0

v6.3.0

Compare Source

Highlights

Enhanced Caching: Windows fixes and a cache-protocol bump

This release updates gradle-actions-caching to v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:

  • Cache entries failed to store at all on Windows.. Every entry failed
    with Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, so
    every downstream job ran against an empty Gradle User Home. The cause was a nested,
    unpatched copy of @actions/glob combined with a silently swallowed require() in
    the bundle, which left Windows path separators unnormalized.

  • Cache cleanup deleted instrumented jars that were in use. A bug in key
    hashing for paths shorter than 64 characters made cleanup judge freshly created
    caches/jars-9 entries as unused and remove them, so the instrumented-jars entry
    was never saved and every job re-instrumented its classpaths.

    Also included: cache entry names are now consistent between the save and restore
    reports — restore previously fell back to showing the raw glob pattern (e.g.
    /home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead of dependencies.

[!IMPORTANT]
Existing cache entries are invalidated by this release. The cache protocol
version was bumped to v2, so the first run after upgrading will be a cache miss
and will repopulate the cache. No configuration changes are required.

Basic caching warns instead of failing silently

The basic (open-source) caching provider now emits a warning and reports
(Entry not saved: save failed) in the Job Summary when a cache save fails, rather
than reporting success (#​1028).

Dependency submission works with Isolated Projects

dependency-submission now disables Isolated Projects via a promoted property, so
dependency graph generation works on builds that enable it (#​1025). Thanks to @​reinsch82 for the contribution.

Updated defaults
  • Injected Develocity Gradle plugin: 4.4.2 → 4.5.0
  • 36 new known-good wrapper checksums added for wrapper-validation

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.2.0...v6.3.0

v6.2.0

Compare Source

Highlights

This release brings significant behaviour improvements to Enhanced caching, improvements to the generated Job Summary, and a number of correctness and security fixes.

  1. Improved cache-cleanup mechanism. Cleanup of stale files from the Gradle User Home is now faster, and no longer depends on Gradle or a JVM. It works by inspecting the local file state directly, removing the Gradle invocation from the post-build step.
  2. More granular, more stable caching. The local build cache is stored as a separate cache entry, so it can be restored and invalidated independently of the main Gradle User Home entry. Transient Gradle housekeeping files are excluded from the cache, reducing its size and improving stability.
  3. Hide obsolete Job summaries in PR commments: When a new Job summary comment is added to a PR, previous outdated Job summaries are now hidden.
  4. Improved caching report in the job summary. The cache report now uses a single, consistent layout across all cache states and providers. Provider information is integrated directly into the report, and per-entry details are available in an expandable section. (#​985)
  5. Correctness and security fixes. A unique cache key is now used per run attempt, so re-runs no longer collide; the job summary shows the cache key string rather than an internal id; and bundled dependencies have been updated, including a ReDoS fix and a fast-xml CVE fix.
What's Changed
New Contributors

Full Changelog: gradle/actions@v6.1.1...v6.2.0

v6.1.1

Compare Source

This release updates various dependency versions, resolving several reported security vulnerabilities.
No functional changes are included

What's Changed

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot changed the title Update actions/checkout action to v5 Update GitHub Actions to v5 (major) Aug 21, 2025
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from ec28de4 to 19e156b Compare August 21, 2025 04:30
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from 19e156b to 822b8ce Compare October 1, 2025 21:55
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from a0135c3 to 5110d40 Compare November 20, 2025 16:52
@renovate-bot renovate-bot changed the title Update GitHub Actions to v5 (major) Update GitHub Actions (major) Nov 20, 2025
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from 6ddbc7b to 8bf069c Compare December 4, 2025 06:01
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 3 times, most recently from 2fc7de0 to 623de3b Compare January 28, 2026 21:47
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from 623de3b to 9021dd2 Compare February 24, 2026 00:46
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from c9f16ac to ed39585 Compare March 24, 2026 17:05
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from ed39585 to b9be649 Compare April 3, 2026 17:11
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from b9be649 to d8931f9 Compare June 2, 2026 15:03
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 3 times, most recently from 43943a8 to f51d8ee Compare June 16, 2026 18:03
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from fb4d855 to 6cc347e Compare June 25, 2026 16:13
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from 6cc347e to 78bad43 Compare July 8, 2026 01:27
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from 684b077 to 8da6ca2 Compare July 21, 2026 02:11
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from 28c5a3a to 965bb82 Compare August 2, 2026 22:39
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from 965bb82 to 9a2414b Compare August 25, 2026 13:39
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch 2 times, most recently from d9b7494 to e07c68d Compare September 15, 2026 19:45
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from e07c68d to d3068a2 Compare September 16, 2026 16:35
@renovate-bot
renovate-bot force-pushed the renovate/major-github-actions branch from d3068a2 to 810d9c6 Compare September 29, 2026 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant