chore(deps): Bump actions/download-artifact from 4.3.0 to 8.0.1 - #4
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): Bump actions/download-artifact from 4.3.0 to 8.0.1#4dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Author
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions/download-artifact-8
branch
from
June 10, 2026 20:31
3180145 to
7d15313
Compare
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 4.3.0 to 8.0.1. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@d3f86a1...3e5f45b) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/github_actions/actions/download-artifact-8
branch
from
June 13, 2026 14:13
7d15313 to
a9e5d20
Compare
Author
|
Superseded by #14. |
dependabot
Bot
deleted the
dependabot/github_actions/actions/download-artifact-8
branch
June 13, 2026 14:32
leocelis
added a commit
that referenced
this pull request
Jul 19, 2026
Follow-up pass specifically hunting for regulatory regimes not covered in the prior legal review, per an explicit "extend the research, check if I'm 100% protected" request. Same standard as before: primary sources, real citations, no invented text. OFAC sanctions (docs/EXPORT_COMPLIANCE.md): - A distinct regime from EAR export control — Treasury/OFAC governs *who* you transact with, separate from Commerce/BIS governing *what* crosses borders. - Documents the "informational materials" exemption published source code generally qualifies for (OFAC FAQ #4: ofac.treasury.gov/faqs/4), and why it's narrower than it sounds for a project that accepts external contributions: the exemption clearly covers one-way receipt of existing code, not clearly two-way PR review/discussion. - Real precedent, not hypothetical: the Linux kernel removed several Russia-affiliated maintainers in October 2024 over sanctions concerns, which is what prompted the Linux Foundation's OFAC guidance this section is modeled on. - Resulting policy: no two-way technical review of a contribution from an OFAC SDN-listed account or a comprehensively sanctioned jurisdiction until the transaction is confirmed exempt or licensed. Not a statement about any past contributor — none has raised this. EU Cyber Resilience Act (new: docs/EU_CRA_STATUS.md): - A different legal domain than export/sanctions law — ongoing manufacturer obligations (vulnerability reporting, CE marking) rather than cross-border movement restrictions. - Current status documented: out of scope. Individual maintainers cannot hold the Act's "open-source steward" category (requires a legal person), and non-monetized OSS is generally exempt from manufacturer obligations outright — both conditions currently true for Blindkey. - Names the exact trigger that would require re-running this analysis BEFORE acting, not after: monetization (a paid tier, commercial support, or a legal entity forming around the project) — relevant given the project's enterprise-adoption positioning, and reporting deadlines (11 September 2026 for in-scope actors) that start running once triggered. Also independently verified (not just re-documented) the "zero network, zero telemetry" claim against the actual codebase — grepped for reqwest/hyper/TcpStream/known telemetry SDKs across every crate. Confirmed backed by an enforced test (constraint_policy.rs, C23 — scans both Cargo.toml deps and source for network-call patterns), not just asserted in prose. No gap found; recorded as a verified claim, not a documentation change. Linked both docs from README.md, docs/README.md, and SECURITY.md alongside the existing export-compliance entry. Verification: cargo test --workspace --all-features (48 suites, 0 failures — docs-only change, confirms nothing broke); fmt clean; all markdown links resolve. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
leocelis
added a commit
that referenced
this pull request
Jul 20, 2026
Follow-up pass specifically hunting for regulatory regimes not covered in the prior legal review, per an explicit "extend the research, check if I'm 100% protected" request. Same standard as before: primary sources, real citations, no invented text. OFAC sanctions (docs/EXPORT_COMPLIANCE.md): - A distinct regime from EAR export control — Treasury/OFAC governs *who* you transact with, separate from Commerce/BIS governing *what* crosses borders. - Documents the "informational materials" exemption published source code generally qualifies for (OFAC FAQ #4: ofac.treasury.gov/faqs/4), and why it's narrower than it sounds for a project that accepts external contributions: the exemption clearly covers one-way receipt of existing code, not clearly two-way PR review/discussion. - Real precedent, not hypothetical: the Linux kernel removed several Russia-affiliated maintainers in October 2024 over sanctions concerns, which is what prompted the Linux Foundation's OFAC guidance this section is modeled on. - Resulting policy: no two-way technical review of a contribution from an OFAC SDN-listed account or a comprehensively sanctioned jurisdiction until the transaction is confirmed exempt or licensed. Not a statement about any past contributor — none has raised this. EU Cyber Resilience Act (new: docs/EU_CRA_STATUS.md): - A different legal domain than export/sanctions law — ongoing manufacturer obligations (vulnerability reporting, CE marking) rather than cross-border movement restrictions. - Current status documented: out of scope. Individual maintainers cannot hold the Act's "open-source steward" category (requires a legal person), and non-monetized OSS is generally exempt from manufacturer obligations outright — both conditions currently true for Blindkey. - Names the exact trigger that would require re-running this analysis BEFORE acting, not after: monetization (a paid tier, commercial support, or a legal entity forming around the project) — relevant given the project's enterprise-adoption positioning, and reporting deadlines (11 September 2026 for in-scope actors) that start running once triggered. Also independently verified (not just re-documented) the "zero network, zero telemetry" claim against the actual codebase — grepped for reqwest/hyper/TcpStream/known telemetry SDKs across every crate. Confirmed backed by an enforced test (constraint_policy.rs, C23 — scans both Cargo.toml deps and source for network-call patterns), not just asserted in prose. No gap found; recorded as a verified claim, not a documentation change. Linked both docs from README.md, docs/README.md, and SECURITY.md alongside the existing export-compliance entry. Verification: cargo test --workspace --all-features (48 suites, 0 failures — docs-only change, confirms nothing broke); fmt clean; all markdown links resolve. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps actions/download-artifact from 4.3.0 to 8.0.1.
Release notes
Sourced from actions/download-artifact's releases.
... (truncated)
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they do