Skip to content

build(deps): Bump actions/upload-artifact from 4.6.2 to 7.0.0#3117

Merged
julienrbrt merged 2 commits intomainfrom
dependabot/github_actions/main/actions/upload-artifact-7.0.0
Mar 3, 2026
Merged

build(deps): Bump actions/upload-artifact from 4.6.2 to 7.0.0#3117
julienrbrt merged 2 commits intomainfrom
dependabot/github_actions/main/actions/upload-artifact-7.0.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Mar 2, 2026

Bumps actions/upload-artifact from 4.6.2 to 7.0.0.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

... (truncated)

Commits
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • ddc45ed docs: update README to correct action name for Node.js 24 support
  • 615b319 chore: release v6.0.0 for Node.js 24 support
  • 017748b Merge pull request #744 from actions/fix-storage-blob
  • 38d4c79 chore: rebuild dist
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4.6.2...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Performance Alert ⚠️

Possible performance regression was detected for benchmark 'Spamoor Trace Benchmarks'.
Benchmark result of this commit is worse than the previous benchmark result exceeding threshold 1.50.

Benchmark suite Current: dc62b13 Previous: 9af0f90 Ratio
SpamoorSmoke - evm_for_ctx (avg) 91.73333333333333 us 34.20161290322581 us 2.68

This comment was automatically generated by workflow using github-action-benchmark.

@github-actions
Copy link
Contributor

github-actions bot commented Mar 3, 2026

The latest Buf updates on your PR. Results from workflow CI / buf-check (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed⏩ skipped✅ passed✅ passedMar 3, 2026, 8:25 AM

@claude
Copy link
Contributor

claude bot commented Mar 3, 2026

Claude finished @julienrbrt's task in 2m 17s —— View job


Code Review: actions/upload-artifact v4.6.2 → v7.0.0

  • Read changed workflow files
  • Assess breaking changes across versions
  • Review benchmark regression alert
  • Provide final review

Summary

This is a routine Dependabot bump of actions/upload-artifact across two workflow files. The changes are minimal, backward-compatible, and safe to merge.


What Actually Changed

benchmark.yml (2 lines):

# Before (SHA-pinned)
actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
# After
actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0

test.yml (2 lines):

# Before (floating tag — was already at v6, not v4.6.2)
actions/upload-artifact@v6
# After
actions/upload-artifact@v7.0.0

Note: test.yml was already at @v6 while the PR title says "from 4.6.2 to 7.0.0" — Dependabot tracks the effective version per-file, so this is expected.


Version Changelog Assessment (v4 → v7)

Version Key Change Impact
v5 Node.js 24 preliminary support None for existing usage
v6 Default Node.js 24, min runner v2.327.1 GitHub-hosted runners auto-update; self-hosted runners may need attention
v7 ESM upgrade, new archive: false direct upload Additive only — no breaking changes for name+path patterns used here

All existing usages in this repo use the standard name + path pattern, which is fully compatible with v7.


Observations

Minor: SHA pinning inconsistency (pre-existing)

benchmark.yml uses SHA-pinned references with tag comments (security best practice), while test.yml uses floating tags (@v7.0.0, @v8.0.0). This inconsistency predates this PR.

# benchmark.yml (secure ✓)
uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0

# test.yml (less secure)
uses: actions/upload-artifact@v7.0.0

For stronger supply chain security, test.yml should also pin to commit SHAs. Fix this →


Benchmark Regression Alert

The performance alert (SpamoorSmoke - evm_for_ctx: 2.68x regression) is unrelated to this PR. This is a GitHub Actions workflow-only change with no impact on application logic or benchmark behavior. The regression likely reflects CI runner variance or was present in the base commit.


Verdict

Safe to merge. The usage patterns in this repo are fully compatible with v7.0.0. No action required.

@codecov
Copy link

codecov bot commented Mar 3, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.75%. Comparing base (cfb479a) to head (f32109a).

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #3117      +/-   ##
==========================================
- Coverage   60.78%   60.75%   -0.04%     
==========================================
  Files         113      113              
  Lines       11675    11675              
==========================================
- Hits         7097     7093       -4     
- Misses       3775     3779       +4     
  Partials      803      803              
Flag Coverage Δ
combined 60.75% <ø> (-0.04%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@julienrbrt julienrbrt merged commit a698fcd into main Mar 3, 2026
28 of 29 checks passed
@julienrbrt julienrbrt deleted the dependabot/github_actions/main/actions/upload-artifact-7.0.0 branch March 3, 2026 08:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant