chore(deps): bump actions/upload-artifact from 4.5.0 to 7.0.1 - #147
chore(deps): bump actions/upload-artifact from 4.5.0 to 7.0.1#147dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.5.0 to 7.0.1. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@6f51ac0...043fb46) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
This is a major version bump for No security advisories or deprecation warnings are called out in the Dependabot PR body for this update. Generated by Claude Code |
FrancesCoronel
left a comment
There was a problem hiding this comment.
This is a major version bump (actions/upload-artifact 4.5.0 → 7.0.1, spanning three major versions), so flagging for manual review before merge per policy.
No security advisories or deprecation warnings noted in the PR body. Note that actions/upload-artifact v5+ dropped Node 16 support and changed some default behaviors around artifact retention/compression — worth a quick check that any workflows consuming these artifacts (e.g. Playwright reports, Lighthouse output) still work as expected.
Generated by Claude Code
Dependabot PR ReviewSummary: Major version bump — CI Status
Not auto-approving/enabling auto-merge given the major version bump and the failing security-audit gate. Recommend manual review. Generated by Claude Code |
Dependabot PR ReviewSummary:
|
Dependabot PR ReviewSummary:
Two major versions (v5 removed download-in-workflow behaviors tied to the old artifact backend, v6/v7 continue on the new backend). This repo's CI StatusAlso not clean: Not approving or enabling auto-merge — requesting manual review given the major version bump. Generated by Claude Code |
📸 Visual snapshotsScreenshots captured for this PR — view all artifacts.
|
|
🤖 Automated dependency review: major version bump ( Generated by Claude Code |
Bumps actions/upload-artifact from 4.5.0 to 7.0.1.
Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)