build(deps): bump actions/download-artifact from 4 to 8 - #207
build(deps): bump actions/download-artifact from 4 to 8#207dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v4...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Reconstruction of Dependabot's #204, #205, #206 and #207 on main: checkout 4 → 7, setup-python 5 → 7, upload-artifact 4 → 7, download-artifact 4 → 8. Their branches were not merged, not checked out and not run locally — under ADR-009 a bot's bytes get the same treatment as anyone else's. The four land in one commit rather than four merges because two of them are coupled. From upload v7 / download v8 the artifact actions share a direct upload contract: upload can skip zipping via `archive: false`, and download decides whether to decompress by sniffing Content-Type. Neither option is used here, but bumping one side alone leaves a producer and a consumer of that contract straddling it for as long as the other change sits unmerged. The rule is recorded beside the steps, since a later session bumping one of them is precisely who needs it. The jumps look worse than they are. Three of the four crossed a major only to move to Node 24 — a change the publishers themselves describe as "not a breaking change per-se but we're treating it as such". Every real break across the seven majors is gated behind an input this project does not set or a trigger it does not use: download-artifact v5 changed the path layout for artifacts fetched by ID and we fetch by name; setup-python v7 dropped `pip-install`, never passed here; checkout v7 refuses to check out a fork PR under `pull_request_target` or `workflow_run`, and neither workflow uses either trigger. setup-python v7 also carries a commit called "remove EOL Python versions", which is the one plausible way this breaks a five-version matrix — reading its file list, it touches only that action's own CI matrices and test fixtures, and nothing about which interpreters it installs. download-artifact v8 promotes a digest mismatch from a warning to an error. Taken deliberately rather than by omission: this is the one path that feeds PyPI, and a corrupted dist should stop there. checkout@v7 and setup-python@v7 are proven, not assumed — they touch ci.yml, so the upstream PRs' own sandboxed runs exercised them green across Python 3.10 through 3.14. The artifact pair is not: it appears only in publish.yml, which fires on `release: published`, so the green checks on #205 and #207 ran the unchanged ci.yml and say nothing about it. The next release is its first real exercise. Accepted because the usage is entirely default-shaped and the failure would be a failed release job before PyPI receives anything. Suite 805 green.
|
Superseded by #218, merged as This bump ( All four Actions majors were audited together and landed in a single commit, because Two follow-ups came out of it: #219 (pin actions to full SHAs rather than mutable major tags) and #220 (this ecosystem's grouping and PR-limit behaviour). Closing as superseded — thanks, Dependabot. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/download-artifact from 4 to 8.
Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they doDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)