build(deps): bump actions/setup-python from 5 to 7 - #204
Conversation
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 7. - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v5...v7) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Reconstruction of Dependabot's #204, #205, #206 and #207 on main: checkout 4 → 7, setup-python 5 → 7, upload-artifact 4 → 7, download-artifact 4 → 8. Their branches were not merged, not checked out and not run locally — under ADR-009 a bot's bytes get the same treatment as anyone else's. The four land in one commit rather than four merges because two of them are coupled. From upload v7 / download v8 the artifact actions share a direct upload contract: upload can skip zipping via `archive: false`, and download decides whether to decompress by sniffing Content-Type. Neither option is used here, but bumping one side alone leaves a producer and a consumer of that contract straddling it for as long as the other change sits unmerged. The rule is recorded beside the steps, since a later session bumping one of them is precisely who needs it. The jumps look worse than they are. Three of the four crossed a major only to move to Node 24 — a change the publishers themselves describe as "not a breaking change per-se but we're treating it as such". Every real break across the seven majors is gated behind an input this project does not set or a trigger it does not use: download-artifact v5 changed the path layout for artifacts fetched by ID and we fetch by name; setup-python v7 dropped `pip-install`, never passed here; checkout v7 refuses to check out a fork PR under `pull_request_target` or `workflow_run`, and neither workflow uses either trigger. setup-python v7 also carries a commit called "remove EOL Python versions", which is the one plausible way this breaks a five-version matrix — reading its file list, it touches only that action's own CI matrices and test fixtures, and nothing about which interpreters it installs. download-artifact v8 promotes a digest mismatch from a warning to an error. Taken deliberately rather than by omission: this is the one path that feeds PyPI, and a corrupted dist should stop there. checkout@v7 and setup-python@v7 are proven, not assumed — they touch ci.yml, so the upstream PRs' own sandboxed runs exercised them green across Python 3.10 through 3.14. The artifact pair is not: it appears only in publish.yml, which fires on `release: published`, so the green checks on #205 and #207 ran the unchanged ci.yml and say nothing about it. The next release is its first real exercise. Accepted because the usage is entirely default-shaped and the failure would be a failed release job before PyPI receives anything. Suite 805 green.
|
Superseded by #218, merged as This bump ( All four Actions majors were audited together and landed in a single commit, because Two follow-ups came out of it: #219 (pin actions to full SHAs rather than mutable major tags) and #220 (this ecosystem's grouping and PR-limit behaviour). Closing as superseded — thanks, Dependabot. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/setup-python from 5 to 7.
Release notes
Sourced from actions/setup-python's releases.
... (truncated)
Commits
5fda3b9Pin SHA commits and update docs with latest versions (#1338)4ab7e95Merge pull request #1337 from actions/philip-gai/bump-actions-cache-6-2-00f3a009Remove the pip-install input (#1336)f8cf429Migrate to ESM and upgrade dependencies (#1330)54baeeaValidate and retry manifest fetch to prevent silent failures (#1332)c709277Annotation code fix (#1335)6849080remove EOL Python versions and Bumps numpy text fixture (#1333)0903b46Bump certifi from 2020.6.20 to 2024.7.4 in /tests/data (#1328)ece7cb0Fix pip cache error handling on Windows. (#1040)1d18d7aUpdate advanced-usage.md (#811)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)