Skip to content

build(deps): bump actions/download-artifact from 4 to 8 - #207

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8
Closed

build(deps): bump actions/download-artifact from 4 to 8#207
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown

Bumps actions/download-artifact from 4 to 8.

Release notes

Sourced from actions/download-artifact's releases.

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v7.0.0

v7 - What's new

[!IMPORTANT] actions/download-artifact@v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

New Contributors

Full Changelog: actions/download-artifact@v6.0.0...v7.0.0

v6.0.0

... (truncated)

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4 to 8.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@v4...v8)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: '8'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 8, 2026
Jason-Vaughan added a commit that referenced this pull request Sep 8, 2026
Reconstruction of Dependabot's #204, #205, #206 and #207 on main: checkout
4 → 7, setup-python 5 → 7, upload-artifact 4 → 7, download-artifact 4 → 8.
Their branches were not merged, not checked out and not run locally — under
ADR-009 a bot's bytes get the same treatment as anyone else's.

The four land in one commit rather than four merges because two of them are
coupled. From upload v7 / download v8 the artifact actions share a direct
upload contract: upload can skip zipping via `archive: false`, and download
decides whether to decompress by sniffing Content-Type. Neither option is
used here, but bumping one side alone leaves a producer and a consumer of
that contract straddling it for as long as the other change sits unmerged.
The rule is recorded beside the steps, since a later session bumping one of
them is precisely who needs it.

The jumps look worse than they are. Three of the four crossed a major only
to move to Node 24 — a change the publishers themselves describe as "not a
breaking change per-se but we're treating it as such". Every real break
across the seven majors is gated behind an input this project does not set
or a trigger it does not use: download-artifact v5 changed the path layout
for artifacts fetched by ID and we fetch by name; setup-python v7 dropped
`pip-install`, never passed here; checkout v7 refuses to check out a fork PR
under `pull_request_target` or `workflow_run`, and neither workflow uses
either trigger. setup-python v7 also carries a commit called "remove EOL
Python versions", which is the one plausible way this breaks a five-version
matrix — reading its file list, it touches only that action's own CI
matrices and test fixtures, and nothing about which interpreters it installs.

download-artifact v8 promotes a digest mismatch from a warning to an error.
Taken deliberately rather than by omission: this is the one path that feeds
PyPI, and a corrupted dist should stop there.

checkout@v7 and setup-python@v7 are proven, not assumed — they touch ci.yml,
so the upstream PRs' own sandboxed runs exercised them green across Python
3.10 through 3.14. The artifact pair is not: it appears only in publish.yml,
which fires on `release: published`, so the green checks on #205 and #207 ran
the unchanged ci.yml and say nothing about it. The next release is its first
real exercise. Accepted because the usage is entirely default-shaped and the
failure would be a failed release job before PyPI receives anything.

Suite 805 green.
@Jason-Vaughan

Copy link
Copy Markdown
Owner

Superseded by #218, merged as 2ddb0f3.

This bump (actions/download-artifact 4 → 8) has shipped — re-implemented on main rather than merged from this branch, per the clean room standard in CONTRIBUTING.md. The version change is exactly the one proposed here; only the authorship of the bytes differs.

All four Actions majors were audited together and landed in a single commit, because upload-artifact v7 and download-artifact v8 share a direct-upload contract and merging them separately would have straddled it. The audit is summarised in #218.

Two follow-ups came out of it: #219 (pin actions to full SHAs rather than mutable major tags) and #220 (this ecosystem's grouping and PR-limit behaviour).

Closing as superseded — thanks, Dependabot.

@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/download-artifact-8 branch September 8, 2026 23:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant