Skip to content

build(deps): bump actions/setup-python from 5 to 7 - #204

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-python-7
Closed

build(deps): bump actions/setup-python from 5 to 7#204
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-python-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown

Bumps actions/setup-python from 5 to 7.

Release notes

Sourced from actions/setup-python's releases.

v7.0.0

What's Changed

Enhancements

Bug Fix

Dependency Upgrade

New Contributors

Full Changelog: actions/setup-python@v6...v7.0.0

v6.3.0

What's Changed

Enhancement

Dependency update

Documentation

New Contributors

Full Changelog: actions/setup-python@v6.2.0...v6.3.0

v6.2.0

What's Changed

Dependency Upgrades

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@v5...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 8, 2026
Jason-Vaughan added a commit that referenced this pull request Sep 8, 2026
Reconstruction of Dependabot's #204, #205, #206 and #207 on main: checkout
4 → 7, setup-python 5 → 7, upload-artifact 4 → 7, download-artifact 4 → 8.
Their branches were not merged, not checked out and not run locally — under
ADR-009 a bot's bytes get the same treatment as anyone else's.

The four land in one commit rather than four merges because two of them are
coupled. From upload v7 / download v8 the artifact actions share a direct
upload contract: upload can skip zipping via `archive: false`, and download
decides whether to decompress by sniffing Content-Type. Neither option is
used here, but bumping one side alone leaves a producer and a consumer of
that contract straddling it for as long as the other change sits unmerged.
The rule is recorded beside the steps, since a later session bumping one of
them is precisely who needs it.

The jumps look worse than they are. Three of the four crossed a major only
to move to Node 24 — a change the publishers themselves describe as "not a
breaking change per-se but we're treating it as such". Every real break
across the seven majors is gated behind an input this project does not set
or a trigger it does not use: download-artifact v5 changed the path layout
for artifacts fetched by ID and we fetch by name; setup-python v7 dropped
`pip-install`, never passed here; checkout v7 refuses to check out a fork PR
under `pull_request_target` or `workflow_run`, and neither workflow uses
either trigger. setup-python v7 also carries a commit called "remove EOL
Python versions", which is the one plausible way this breaks a five-version
matrix — reading its file list, it touches only that action's own CI
matrices and test fixtures, and nothing about which interpreters it installs.

download-artifact v8 promotes a digest mismatch from a warning to an error.
Taken deliberately rather than by omission: this is the one path that feeds
PyPI, and a corrupted dist should stop there.

checkout@v7 and setup-python@v7 are proven, not assumed — they touch ci.yml,
so the upstream PRs' own sandboxed runs exercised them green across Python
3.10 through 3.14. The artifact pair is not: it appears only in publish.yml,
which fires on `release: published`, so the green checks on #205 and #207 ran
the unchanged ci.yml and say nothing about it. The next release is its first
real exercise. Accepted because the usage is entirely default-shaped and the
failure would be a failed release job before PyPI receives anything.

Suite 805 green.
@Jason-Vaughan

Copy link
Copy Markdown
Owner

Superseded by #218, merged as 2ddb0f3.

This bump (actions/setup-python 5 → 7) has shipped — re-implemented on main rather than merged from this branch, per the clean room standard in CONTRIBUTING.md. The version change is exactly the one proposed here; only the authorship of the bytes differs.

All four Actions majors were audited together and landed in a single commit, because upload-artifact v7 and download-artifact v8 share a direct-upload contract and merging them separately would have straddled it. The audit is summarised in #218.

Two follow-ups came out of it: #219 (pin actions to full SHAs rather than mutable major tags) and #220 (this ecosystem's grouping and PR-limit behaviour).

Closing as superseded — thanks, Dependabot.

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/setup-python-7 branch September 8, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant