Skip to content

Update GitHub Artifact Actions (major) - #1003

Open
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/major-github-artifact-actions
Open

Update GitHub Artifact Actions (major)#1003
red-hat-konflux[bot] wants to merge 1 commit into
mainfrom
konflux/mintmaker/main/major-github-artifact-actions

Conversation

@red-hat-konflux

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/download-artifact action major v4.3.0v8.0.1
actions/upload-artifact action major v4.6.2v7.0.1

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

actions/download-artifact (actions/download-artifact)

v8.0.1

Compare Source

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

Compare Source

v8 - What's new

[!IMPORTANT]
actions/download-artifact@​v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT]
Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @​actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

v8

Compare Source

v7.0.0

Compare Source

v7 - What's new

[!IMPORTANT]
actions/download-artifact@​v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

New Contributors

Full Changelog: actions/download-artifact@v6.0.0...v7.0.0

v7

Compare Source

v6.0.0

Compare Source

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

New Contributors

Full Changelog: actions/download-artifact@v5...v6.0.0

v6

Compare Source

v5.0.0

Compare Source

What's Changed
v5.0.0
🚨 Breaking Change

This release fixes an inconsistency in path behavior for single artifact downloads by ID. If you're downloading single artifacts by ID, the output path may change.

What Changed

Previously, single artifact downloads behaved differently depending on how you specified the artifact:

  • By name: name: my-artifact → extracted to path/ (direct)
  • By ID: artifact-ids: 12345 → extracted to path/my-artifact/ (nested)

Now both methods are consistent:

  • By name: name: my-artifact → extracted to path/ (unchanged)
  • By ID: artifact-ids: 12345 → extracted to path/ (fixed - now direct)
Migration Guide
✅ No Action Needed If:
  • You download artifacts by name
  • You download multiple artifacts by ID
  • You already use merge-multiple: true as a workaround
⚠️ Action Required If:

You download single artifacts by ID and your workflows expect the nested directory structure.

Before v5 (nested structure):

- uses: actions/download-artifact@v4
  with:
    artifact-ids: 12345
    path: dist

# Files were in: dist/my-artifact/

Where my-artifact is the name of the artifact you previously uploaded

To maintain old behavior (if needed):

- uses: actions/download-artifact@v5
  with:
    artifact-ids: 12345
    path: dist/my-artifact  # Explicitly specify the nested path
New Contributors

Full Changelog: actions/download-artifact@v4...v5.0.0

v5

Compare Source

actions/upload-artifact (actions/upload-artifact)

v7.0.1

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1

v7.0.0

Compare Source

v7 What's new
Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed
New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v7

Compare Source

v6.0.0

Compare Source

v6 - What's new

[!IMPORTANT]
actions/upload-artifact@​v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v6

Compare Source

v5.0.0

Compare Source

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

New Contributors

Full Changelog: actions/upload-artifact@v4...v5.0.0

v5

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@github-actions github-actions Bot added the semver/major Semver major version bump label Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

AI Dependency Impact Analysis

Risk Level: MEDIUM

Summary of Dependency Changes

The GitHub Actions actions/download-artifact and actions/upload-artifact are being upgraded to major versions v8.0.1 and v7.0.1 respectively. These updates migrate the actions to Node.js 24 (requiring runner version 2.327.1+), upgrade internal packages to ESM modules, set download digest mismatches to error/fail by default, and change directory path extraction behavior when downloading a single artifact by ID.

Affected Code

No Go code is directly affected. The impact is limited to GitHub Actions workflow files (typically located in .github/workflows/):

  • Workflows utilizing actions/download-artifact: Workflows that download artifacts by ID (artifact-ids) will see changes in output directories.
  • Workflows utilizing actions/upload-artifact: Workflows uploading files may benefit from the new direct/unzipped upload feature if configured.
  • Self-hosted runners: Any workflow running on self-hosted runner infrastructure may fail if the runner version is outdated.

Breaking Change Assessment

Several breaking changes are introduced across these major versions:

  • Node.js 24 Runtime: Both actions now run on Node.js 24, requiring a minimum runner version of 2.327.1. Self-hosted runners below this version will fail to execute these actions.
  • Path Behavior Change (v5.0.0): If actions/download-artifact is configured to download a single artifact by ID (using the artifact-ids parameter), the files are now extracted directly into the destination path/ instead of nesting them inside path/my-artifact/. Any subsequent steps relying on the nested folder structure will break.
  • Digest Mismatch Strictness (v8.0.0): Hash mismatches on download now default to error (failing the build) instead of warn.

Security Assessment

No security advisories were reported in this update. However, defaulting digest mismatches to error in actions/download-artifact v8.0.0 improves the overall security and integrity of the build pipeline by preventing corrupted or tampered artifacts from being silently processed.

Supply-Chain Assessment

No supply-chain concerns detected.

Recommended Action

Review specific areas: Medium risk. A reviewer should check the .github/workflows/ configuration files to:

  1. Ensure no workflows download single artifacts by ID (artifact-ids) and expect a nested output directory structure.
  2. Confirm that all self-hosted runners (if any are used in the repository) have been upgraded to runner version 2.327.1 or higher to support the Node.js 24 requirement.

@github-actions github-actions Bot added the risk/medium AI-assessed medium risk dependency update label Aug 4, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk Level: MEDIUM

Summary of Dependency Changes

The GitHub Actions actions/download-artifact and actions/upload-artifact are being upgraded to major versions v8.0.1 and v7.0.1 respectively. These updates migrate the actions to Node.js 24 (requiring runner version 2.327.1+), upgrade internal packages to ESM modules, set download digest mismatches to error/fail by default, and change directory path extraction behavior when downloading a single artifact by ID.

Affected Code

No Go code is directly affected. The impact is limited to GitHub Actions workflow files (typically located in .github/workflows/):

  • Workflows utilizing actions/download-artifact: Workflows that download artifacts by ID (artifact-ids) will see changes in output directories.
  • Workflows utilizing actions/upload-artifact: Workflows uploading files may benefit from the new direct/unzipped upload feature if configured.
  • Self-hosted runners: Any workflow running on self-hosted runner infrastructure may fail if the runner version is outdated.

Breaking Change Assessment

Several breaking changes are introduced across these major versions:

  • Node.js 24 Runtime: Both actions now run on Node.js 24, requiring a minimum runner version of 2.327.1. Self-hosted runners below this version will fail to execute these actions.
  • Path Behavior Change (v5.0.0): If actions/download-artifact is configured to download a single artifact by ID (using the artifact-ids parameter), the files are now extracted directly into the destination path/ instead of nesting them inside path/my-artifact/. Any subsequent steps relying on the nested folder structure will break.
  • Digest Mismatch Strictness (v8.0.0): Hash mismatches on download now default to error (failing the build) instead of warn.

Security Assessment

No security advisories were reported in this update. However, defaulting digest mismatches to error in actions/download-artifact v8.0.0 improves the overall security and integrity of the build pipeline by preventing corrupted or tampered artifacts from being silently processed.

Supply-Chain Assessment

No supply-chain concerns detected.

Recommended Action

Review specific areas: Medium risk. A reviewer should check the .github/workflows/ configuration files to:

  1. Ensure no workflows download single artifacts by ID (artifact-ids) and expect a nested output directory structure.
  2. Confirm that all self-hosted runners (if any are used in the repository) have been upgraded to runner version 2.327.1 or higher to support the Node.js 24 requirement.

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 4, 2026

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:50 PM UTC · Completed 8:03 PM UTC
Commit: 701e62a · View workflow run →

@codecov-commenter

codecov-commenter commented Aug 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.92%. Comparing base (842645f) to head (7424b21).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #1003      +/-   ##
==========================================
+ Coverage   76.74%   76.92%   +0.17%     
==========================================
  Files          26       26              
  Lines        2817     2817              
==========================================
+ Hits         2162     2167       +5     
+ Misses        456      452       -4     
+ Partials      199      198       -1     
Flag Coverage Δ
e2e-tests 30.28% <ø> (+0.03%) ⬆️
unit-tests 73.98% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 1 file with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 842645f...7424b21. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@fullsend-ai-review

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] .github/workflows/agent-files-detect.yaml, .github/workflows/agent-files-enforce.yaml — This PR modifies files under protected paths (.github/). The PR has no linked issue providing authorization for changes to governance/infrastructure files. Human approval is always required for protected-path changes.
    Remediation: An infra-team reviewer should verify the major version bumps (upload-artifact v4.6.2→v7.0.1, download-artifact v4.3.0→v8.0.1) are compatible with current workflow usage and remove the agent-config-review-required label. Note: automated review found the version bump itself to be technically sound — the continue-on-error: true on the download step handles v8's new default-error-on-hash-mismatch behavior safely (fail-closed), and no workflow permissions are changed.

Labels: PR modifies GitHub Actions workflow files for artifact handling


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

@fullsend-ai-review fullsend-ai-review Bot added the github_actions Pull requests that update GitHub Actions code label Aug 4, 2026
@red-hat-konflux red-hat-konflux Bot changed the title chore(deps): update github artifact actions (major) Update GitHub Artifact Actions (major) Aug 7, 2026

@meyrevived meyrevived left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code risk/medium AI-assessed medium risk dependency update semver/major Semver major version bump

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants