Uh oh!
There was an error while loading. Please reload this page.
build(deps): bump actions/setup-node from 6.3.0 to 7.0.0 - #114
build(deps): bump actions/setup-node from 6.3.0 to 7.0.0#114dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.3.0 to 7.0.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v6.3.0...v7.0.0) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Pi Dependabot assessmentDependency and version movement
Authoritative changelog / advisory links
Application usage and potentially disruptive effects
Validation
Conversation state / unresolved concerns
Change risk: 5/10 — A semver-major CI action changes its internal ESM runtime, bundled toolkit graph, cache outputs, and registry authentication fallback, and it is used in the release publishing workflow. Risk is bounded because the application diff is only two action references, node24 was already required by v6.3.0, no inputs are removed, and all CI/tests pass. Remediation importance: 6/10 — This is reachable CI/CD supply-chain and npm release-publishing infrastructure, and v7 removes older action dependency findings, but it does not change application runtime code or production package dependencies and is not itself an application vulnerability fix. Final exact head SHA: Dev deployment evidence
Status: blocked check_after: not set (exact deployment not confirmed) Residual risks / blocking reason
|
Bumps actions/setup-node from 6.3.0 to 7.0.0.
Release notes
Sourced from actions/setup-node's releases.
Commits
8207627Migrate to ESM and upgrade dependencies (#1574)04be95cAdd cache-primary-key and cache-matched-key as outputs (#1577)7c2c68ddocs: Update caching recommendations to mitigate cache poisoning risks (#1567)6a61c03Merge pull request #1569 from jasongin/update-actions-cache-5.1.030eb73bResolve high-severity audit issues4e1a87aUpdate dist360237fStrict equality4f8aac5Bump@actions/cacheto 5.1.0, log cache write deniedf4a67bbOnly usemirrorTokeningetManifestif it's provided (#1548)0355742Remove dummy NODE_AUTH_TOKEN export (#1558)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)