Skip to content

build(deps): bump the actions group with 6 updates - #68

Merged
hyperpolymath merged 2 commits into
mainfrom
dependabot/github_actions/actions-badd06bef0
Sep 25, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
dependabot/github_actions/actions-badd06bef0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown

Bumps the actions group with 6 updates:

Package From To
actions/checkout 4.4.0 7.0.1
julia-actions/setup-julia 2.7.0 3.0.2
julia-actions/cache 2.1.0 3.3.0
actions/cache/restore 4.3.0 6.1.0
actions/cache/save 4.3.0 6.1.0
actions/upload-artifact 4.6.2 7.0.1

Updates actions/checkout from 4.4.0 to 7.0.1

Release notes

Sourced from actions/checkout's releases.

v7.0.1

What's Changed

Full Changelog: actions/checkout@v7...v7.0.1

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.1.0

What's Changed

https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/ for more details about this breaking change

Full Changelog: actions/checkout@v6.0.3...v6.1.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.1

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates julia-actions/setup-julia from 2.7.0 to 3.0.2

Release notes

Sourced from julia-actions/setup-julia's releases.

v3.0.2

What's Changed

We fixed a bug (#389).

We also updated our documentation, and we updated a CI dependency.

New Contributors

Full Changelog

Full Changelog: julia-actions/setup-julia@v3.0.1...v3.0.2

v3.0.1

What's Changed

This is a bugfix release that fixes an error seen when using min-minor or min-patch.

Full Changelog

Full Changelog: julia-actions/setup-julia@v3.0.0...v3.0.1

v3.0.0

⚠️ Breaking Changes, and Migration Guide for v2 ⟶ v3

  1. v3 requires Node 24 (compared to v2, which required Node 20).
  2. The behavior of version: min has changed between v2 and v3.
    • In v2, version: min would resolve to the minimum major/minor/patch, e.g. 1.10.0.
    • In v3, version: min resolves to the minimum major/minor but the latest patch, e.g. 1.10.11.
    • If you specifically want the minimum major/minor/patch under v3, you should specify version: min-patch. Note: v3 also adds the alias version: min-minor, which is equivalent to version: min.
  3. v3 will throw an error if x86_64 Julia binaries are requested on Apple Silicon macOS. (Under v2, this was a warning.) Under v3, if you specifically want to run x86_64 Julia binaries on Apple Silicon (under Rosetta 2), you must now opt-in by specifying the force-arch: true input.

Other Changes

We updated some dependencies, and we improved and updated the CI tooling on this repo.

Full Changelog

Full Changelog: julia-actions/setup-julia@v2.7.0...v3.0.0

Commits
  • fa02766 Bug fix: Validate cached julia binary exists and check PATH resolution (#389)
  • ff78161 Bump julia-actions/setup-julia from 2.7.0 to 3.0.1 in the all-github-actions ...
  • fe02cb7 README: Add a link to the v2-to-v3 release notes (#388)
  • f6f565d Bugfix: Fix an error seen when using min-minor or min-patch (#387)
  • 4a12c5f Breaking: Change min to return the latest patch (but still the minimum majo...
  • a8c65a2 Bump the all-github-actions group across 1 directory with 2 updates (#381)
  • 92d77f5 Bump picomatch from 2.3.1 to 2.3.2 (#379)
  • 679f144 Bump handlebars from 4.7.8 to 4.7.9 (#377)
  • 7c976c8 Add workflow to run make everything-from-scratch (#378)
  • 101e139 Breaking: Migrate from Node 20 to Node 24 (#374)
  • Additional commits viewable in compare view

Updates julia-actions/cache from 2.1.0 to 3.3.0

Release notes

Sourced from julia-actions/cache's releases.

v3.3.0

What's Changed

We migrated this action from JavaScript to TypeScript. Users should not notice any difference.

We also updated some dependencies.

Full Changelog

Full Changelog: julia-actions/cache@v3.2.0...v3.3.0

v3.2.0

New Features

Other changes

  • We updated some dependencies (JavaScript and CI).
  • We implemented a 7-day dependency cooldown for our dependencies.
  • We updated our docs.

New Contributors

Full Changelog

Full Changelog: julia-actions/cache@v3.1.0...v3.2.0

v3.1.0

What's Changed

New feature: We added support for Google Cloud Platform (julia-actions/cache#204).

We also updated some dependencies.

New Contributors

Full Changelog

Full Changelog: julia-actions/cache@v3.0.2...v3.1.0

v3.0.2

What's Changed

... (truncated)

Commits
  • a7bed9d Update some NPM dependencies (#257)
  • 56d8125 Migrate from JavaScript to TypeScript (#248)
  • fcb41b5 Bump brace-expansion from 1.1.13 to 1.1.18 (#256)
  • 592ca37 .gitattributes: Hide generated JS code from diffs and language stats (#253)
  • eb70237 Bump actions/checkout from 7.0.0 to 7.0.1 (#249)
  • d3af421 Bump actions/setup-node from 6.4.0 to 7.0.0 (#250)
  • b7788ab Add optional prefix for uploads (#246)
  • 3208dfc Add option to use (multithreaded) zstd for gcp (#244)
  • f6f2182 Stream tar archives directly to/from GCP storage without intermediate files (...
  • 8020c5e Bump @​google-cloud/storage from 7.19.0 to 7.21.0 (#240)
  • Additional commits viewable in compare view

Updates actions/cache/restore from 4.3.0 to 6.1.0

Release notes

Sourced from actions/cache/restore's releases.

v6.1.0

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

... (truncated)

Changelog

Sourced from actions/cache/restore's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Updates actions/cache/save from 4.3.0 to 6.1.0

Release notes

Sourced from actions/cache/save's releases.

v6.1.0

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

... (truncated)

Changelog

Sourced from actions/cache/save's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Updates actions/upload-artifact from 4.6.2 to 7.0.1

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.1

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout) | `4.4.0` | `7.0.1` |
| [julia-actions/setup-julia](https://github.com/julia-actions/setup-julia) | `2.7.0` | `3.0.2` |
| [julia-actions/cache](https://github.com/julia-actions/cache) | `2.1.0` | `3.3.0` |
| [actions/cache/restore](https://github.com/actions/cache) | `4.3.0` | `6.1.0` |
| [actions/cache/save](https://github.com/actions/cache) | `4.3.0` | `6.1.0` |
| [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` |


Updates `actions/checkout` from 4.4.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@11d5960...3d3c42e)

Updates `julia-actions/setup-julia` from 2.7.0 to 3.0.2
- [Release notes](https://github.com/julia-actions/setup-julia/releases)
- [Commits](julia-actions/setup-julia@4c0cb0f...fa02766)

Updates `julia-actions/cache` from 2.1.0 to 3.3.0
- [Release notes](https://github.com/julia-actions/cache/releases)
- [Commits](julia-actions/cache@d10a6fd...a7bed9d)

Updates `actions/cache/restore` from 4.3.0 to 6.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@0057852...55cc834)

Updates `actions/cache/save` from 4.3.0 to 6.1.0
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@0057852...55cc834)

Updates `actions/upload-artifact` from 4.6.2 to 7.0.1
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@ea165f8...043fb46)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: julia-actions/setup-julia
  dependency-version: 3.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: julia-actions/cache
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/cache/restore
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/cache/save
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner September 25, 2026 22:21
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a9602513-e305-474e-b9ea-21e2382870c7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 99db936 into main Sep 25, 2026
4 of 6 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-badd06bef0 branch September 25, 2026 22:26
hyperpolymath added a commit that referenced this pull request Sep 27, 2026
…venance probe visibility) (#85)

## Why

Every workflow run on this repository since **2026-09-25 22:19 UTC** has
failed with `startup_failure` and **zero jobs** — CI has produced no
verdict on anything since (the refreshed audit in
`docs/audit/2026-09-26-memory-numerics-warning-audit.md` records the
same observation). The run annotations name the cause; two rules,
neither reportable by a job that never starts:

> The actions `julia-actions/setup-julia@…`, `julia-actions/cache@…`,
and `julia-actions/julia-processcoverage@…` are **not allowed** in
hyperpolymath/MetaManifold-WebUI because all actions must be from a
repository owned by hyperpolymath, created by GitHub, verified in the
GitHub Marketplace, or match the pattern: `arena-ai-coding-agent[bot]`.
**All actions must also be pinned to a full-length commit SHA.**

- `ci.yml`, `ui.yml`, `doi.yml` used the three disallowed
`julia-actions/*` actions;
- `proofs.yml` used tag refs (`@v4`/`@v5`) instead of full SHAs (its
annotation from run 36293672919).

Dependabot PR #68 (merged 2026-09-25 22:26) was **not** the cause — it
only changed which ref each disallowed action used; the enforcement
itself turned on at 22:19 and broke the arena-branch run five minutes
before #68 merged.

## What changed (behaviour preserved)

| workflow | was | now |
|---|---|---|
| ci/ui/doi | `julia-actions/setup-julia` | inline install of official
1.12.5 binaries, **verified against the official checksum file** before
use; `JULIA_VERSION` keeps the pin cross-checked by `test_install_pins`
|
| ci/ui/doi | `julia-actions/cache` | `actions/cache@55cc834` (v6.1.0)
over the same depot dirs, keyed on each workflow's own Manifest/Project
|
| ci | `julia-actions/julia-processcoverage` | equivalent
`CoverageTools` run step (same default dirs, same `lcov.info`) |
| proofs | `checkout/setup-python/cache/upload-artifact@v4/@v5` | same
tags' **commits** — no version change |

Plus **two guards** so this cannot regress silently:

- `test/unit/test_install_pins.jl` now locates the Julia pin by step
name (`JULIA_VERSION=` in `Set up Julia`) and gains a new testset that
walks **every workflow** and fails on any action that is not
full-SHA-pinned or not allow-listed — a future dependabot bump to a tag
reddens `Pkg.test` instead of silencing Actions;
- the provenance probe fallbacks in `src/analysis/Execution.jl` (the
second commit) now `@warn` before writing
`version=unknown`/`hostname=unknown` placeholders — the manifest schema
and all existing assertions over it are untouched.

## Validation done offline

- YAML parse + duplicate-key scan of all four workflows;
- policy self-check mirroring the new testset (every `uses:` full-SHA +
allow-listed owner);
- `bash -n` on **every** `run:` block;
- `JULIA_VERSION` regex against `config/defaults/tool_versions.yml`
(1.12.5 = 1.12.5);
- `sha256sum -c` and `/usr/local/bin/<tool>` strings the pin tests
assert on are still present.

## Known remaining (settings-side, not fixable from workflow files)

A run on this branch also reported **`Actor is not allowed to trigger
Actions workflows`** (run 36295388349) — the repository's actor
allow-list appears to glob `arena-ai-coding-agent[bot]` (the `[bot]`
read as a character class), so pushes made by the Arena bot may still be
refused even with compliant workflow files. An admin needs to fix that
pattern; runs triggered by `hyperpolymath` should proceed once this
merges.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant