Update GitHub Artifact Actions (major) - #1003
Conversation
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
AI Dependency Impact AnalysisRisk Level: MEDIUMSummary of Dependency ChangesThe GitHub Actions Affected CodeNo Go code is directly affected. The impact is limited to GitHub Actions workflow files (typically located in
Breaking Change AssessmentSeveral breaking changes are introduced across these major versions:
Security AssessmentNo security advisories were reported in this update. However, defaulting digest mismatches to Supply-Chain AssessmentNo supply-chain concerns detected. Recommended ActionReview specific areas: Medium risk. A reviewer should check the
|
There was a problem hiding this comment.
Risk Level: MEDIUM
Summary of Dependency Changes
The GitHub Actions actions/download-artifact and actions/upload-artifact are being upgraded to major versions v8.0.1 and v7.0.1 respectively. These updates migrate the actions to Node.js 24 (requiring runner version 2.327.1+), upgrade internal packages to ESM modules, set download digest mismatches to error/fail by default, and change directory path extraction behavior when downloading a single artifact by ID.
Affected Code
No Go code is directly affected. The impact is limited to GitHub Actions workflow files (typically located in .github/workflows/):
- Workflows utilizing
actions/download-artifact: Workflows that download artifacts by ID (artifact-ids) will see changes in output directories. - Workflows utilizing
actions/upload-artifact: Workflows uploading files may benefit from the new direct/unzipped upload feature if configured. - Self-hosted runners: Any workflow running on self-hosted runner infrastructure may fail if the runner version is outdated.
Breaking Change Assessment
Several breaking changes are introduced across these major versions:
- Node.js 24 Runtime: Both actions now run on Node.js 24, requiring a minimum runner version of
2.327.1. Self-hosted runners below this version will fail to execute these actions. - Path Behavior Change (v5.0.0): If
actions/download-artifactis configured to download a single artifact by ID (using theartifact-idsparameter), the files are now extracted directly into the destinationpath/instead of nesting them insidepath/my-artifact/. Any subsequent steps relying on the nested folder structure will break. - Digest Mismatch Strictness (v8.0.0): Hash mismatches on download now default to
error(failing the build) instead ofwarn.
Security Assessment
No security advisories were reported in this update. However, defaulting digest mismatches to error in actions/download-artifact v8.0.0 improves the overall security and integrity of the build pipeline by preventing corrupted or tampered artifacts from being silently processed.
Supply-Chain Assessment
No supply-chain concerns detected.
Recommended Action
Review specific areas: Medium risk. A reviewer should check the .github/workflows/ configuration files to:
- Ensure no workflows download single artifacts by ID (
artifact-ids) and expect a nested output directory structure. - Confirm that all self-hosted runners (if any are used in the repository) have been upgraded to runner version
2.327.1or higher to support the Node.js 24 requirement.
|
🤖 Finished Review · ✅ Success · Started 7:50 PM UTC · Completed 8:03 PM UTC |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1003 +/- ##
==========================================
+ Coverage 76.74% 76.92% +0.17%
==========================================
Files 26 26
Lines 2817 2817
==========================================
+ Hits 2162 2167 +5
+ Misses 456 452 -4
+ Partials 199 198 -1
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
ReviewFindingsHigh
Labels: PR modifies GitHub Actions workflow files for artifact handling Next steps:
|
This PR contains the following updates:
v4.3.0→v8.0.1v4.6.2→v7.0.1Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
actions/download-artifact (actions/download-artifact)
v8.0.1Compare Source
What's Changed
Full Changelog: actions/download-artifact@v8...v8.0.1
v8.0.0Compare Source
v8 - What's new
Direct downloads
To support direct uploads in
actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks theContent-Typeheader ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the newskip-decompressparameter totrue.Enforced checks (breaking)
A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the
digest-mismatchparameter. To be secure by default, we are now defaulting the behavior toerrorwhich will fail the workflow run.ESM
To support new versions of the @actions/* packages, we've upgraded the package to ESM.
What's Changed
errorby @danwkennedy in #461Full Changelog: actions/download-artifact@v7...v8.0.0
v8Compare Source
v7.0.0Compare Source
v7 - What's new
Node.js 24
This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
New Contributors
Full Changelog: actions/download-artifact@v6.0.0...v7.0.0
v7Compare Source
v6.0.0Compare Source
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.@actions/artifacttov4.0.0v6.0.0by @danwkennedy in #438New Contributors
Full Changelog: actions/download-artifact@v5...v6.0.0
v6Compare Source
v5.0.0Compare Source
What's Changed
v5.0.0
🚨 Breaking Change
This release fixes an inconsistency in path behavior for single artifact downloads by ID. If you're downloading single artifacts by ID, the output path may change.
What Changed
Previously, single artifact downloads behaved differently depending on how you specified the artifact:
name: my-artifact→ extracted topath/(direct)artifact-ids: 12345→ extracted topath/my-artifact/(nested)Now both methods are consistent:
name: my-artifact→ extracted topath/(unchanged)artifact-ids: 12345→ extracted topath/(fixed - now direct)Migration Guide
✅ No Action Needed If:
merge-multiple: trueas a workaroundYou download single artifacts by ID and your workflows expect the nested directory structure.
Before v5 (nested structure):
To maintain old behavior (if needed):
New Contributors
Full Changelog: actions/download-artifact@v4...v5.0.0
v5Compare Source
actions/upload-artifact (actions/upload-artifact)
v7.0.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v7...v7.0.1
v7.0.0Compare Source
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new
archiveparameter tofalseto skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. Thenameparameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.ESM
To support new versions of the
@actions/*packages, we've upgraded the package to ESM.What's Changed
New Contributors
Full Changelog: actions/upload-artifact@v6...v7.0.0
v7Compare Source
v6.0.0Compare Source
v6 - What's new
Node.js 24
This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0
v6Compare Source
v5.0.0Compare Source
What's Changed
BREAKING CHANGE: this update supports Node
v24.x. This is not a breaking change per-se but we're treating it as such.@actions/artifacttov4.0.0v5.0.0by @danwkennedy in #734New Contributors
Full Changelog: actions/upload-artifact@v4...v5.0.0
v5Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
To execute skipped test pipelines write comment
/ok-to-test.Documentation
Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.