chore(deps): bump actions/download-artifact from 7 to 8 in /.github/actions/build-custom-image-with-apko#5796
Conversation
|
@dependabot rebase |
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 7 to 8. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@v7...v8) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: '8' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
b98d4de to
797bc4e
Compare
|
@dependabot rebase |
|
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request |
|
Closing in favor of a combined PR with all remaining GitHub Actions bumps. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
- actions/upload-artifact v6 → v7 - actions/download-artifact v7 → v8 - actions/cache v4 → v5 - goreleaser/goreleaser-action v6 → v7 - chainguard-images/actions v1.0.16 → v1.0.20 - chainguard-dev/actions v1.5.6 → v1.6.4 Replaces individual Dependabot PRs: #5805, #5803, #5802, #5799, #5798, #5797, #5796, #5718 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
Combined into #5825. |
* chore(deps): bump GitHub Actions dependencies - actions/upload-artifact v6 → v7 - actions/download-artifact v7 → v8 - actions/cache v4 → v5 - goreleaser/goreleaser-action v6 → v7 - chainguard-images/actions v1.0.16 → v1.0.20 - chainguard-dev/actions v1.5.6 → v1.6.4 Replaces individual Dependabot PRs: #5805, #5803, #5802, #5799, #5798, #5797, #5796, #5718 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * ci: trigger fresh CI run * fix: bump chainguard-dev/actions to v1.6.10 v1.6.4 fails on arm64 runners due to missing AppArmor directory. Bumping to latest v1.6.10 which may resolve the issue. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: use chainguard-dev/actions v1.5.16 instead of v1.6.x v1.6.x requires AppArmor which is not available on the arm64 self-hosted runners. Staying on latest v1.5.x (v1.5.16) until the runner environment supports AppArmor. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * revert: keep chainguard-dev/actions at v1.5.6 and chainguard-images/actions at v1.0.16 The newer versions require AppArmor which is not available on the arm64 self-hosted runners. These bumps need to be handled separately with runner environment changes. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: remove duplicate SARIF uploads in alpha workflow The scan-image action already uploads SARIF with a consistent category (image-scan-<image-name>). The duplicate upload-sarif steps in alpha.yaml uploaded the same results without a category, creating a separate set of code scanning alerts that never got replaced by newer scans — causing stale CVE alerts to persist on the security page even after images were rebuilt with patched packages. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Revert "fix: remove duplicate SARIF uploads in alpha workflow" This reverts commit f194234. --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Bumps actions/download-artifact from 7 to 8.
Release notes
Sourced from actions/download-artifact's releases.
Commits
70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they do96bf374One more test fixb8c4819Fix skip decompress testDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)