Skip to content

Migrate to ESM and upgrade dependencies - #1574

Merged
HarithaVattikuti merged 6 commits into
actions:mainfrom
gowridurgad:esm-migration-node
Jul 14, 2026
Merged

Migrate to ESM and upgrade dependencies#1574
HarithaVattikuti merged 6 commits into
actions:mainfrom
gowridurgad:esm-migration-node

Conversation

@gowridurgad

Copy link
Copy Markdown
Contributor

Description:
Migrates setup-node from CommonJS to ECMAScript Modules (ESM)

Related issue:
Add link to the related issue.

Check list:

  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

@gowridurgad
gowridurgad requested a review from a team as a code ownerJune 26, 2026 08:33
CopilotAI review requested due to automatic review settings June 26, 2026 08:33

CopilotAI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR migrates the setup-node codebase and tooling from CommonJS to ESM, aligning runtime behavior (NodeNext resolution + import.meta.url) with updated dependencies and ESM-compatible lint/test configuration.

Changes:

  • Switch TypeScript compilation to module: NodeNext and update internal relative imports to include .js extensions.
  • Migrate Jest and ESLint configuration to ESM-friendly setups (flat ESLint config + TS Jest config + ESM mocking patterns).
  • Upgrade Actions/toolkit and related dependencies, and refresh licensed metadata accordingly.

Reviewed changes

Copilot reviewed 73 out of 85 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
tsconfig.jsonSwitch TS module output to NodeNext and exclude jest config from compilation.
src/util.tsUpdate catch clause style while keeping behavior unchanged.
src/setup-node.tsUpdate entrypoint import to ESM-friendly .js specifier.
src/main.tsConvert internal imports to .js and replace __dirname usage with import.meta.url resolution.
src/distributions/v8-canary/canary_builds.tsUpdate internal imports to .js specifiers.
src/distributions/rc/rc_builds.tsUpdate internal imports to .js specifiers.
src/distributions/official_builds/official_builds.tsUpdate internal imports to .js specifiers.
src/distributions/nightly/nightly_builds.tsUpdate internal imports to .js specifiers.
src/distributions/installer-factory.tsUpdate internal imports to .js specifiers.
src/distributions/base-distribution.tsUpdate imports for ESM and replace __dirname usage with import.meta.url resolution.
src/distributions/base-distribution-prerelease.tsUpdate internal imports to .js specifiers.
src/cache-utils.tsUpdate internal import to .js and fix async command output usage (await).
src/cache-save.tsUpdate internal imports to .js specifiers.
src/cache-restore.tsUpdate internal imports to .js specifiers.
package.jsonMark package as ESM, update scripts, and upgrade dependencies/tooling.
jest.config.tsAdd ESM-compatible Jest configuration using ts-jest with useESM.
jest.config.jsRemove legacy CommonJS Jest configuration.
eslint.config.mjsAdd flat ESLint config in ESM format.
dist/setup/package.jsonAdd package boundary metadata for the bundled setup entrypoint.
dist/cache-save/package.jsonAdd package boundary metadata for the bundled post-action entrypoint.
.prettierrc.jsonAdd Prettier configuration in JSON format.
.prettierrc.jsRemove legacy CommonJS Prettier configuration.
.licensed.ymlUpdate allowed/reviewed licenses and normalize indentation for reviewed packages.
.eslintrc.jsRemove legacy ESLint config (replaced by flat config).
.eslintignoreRemove legacy ignore file (handled via flat config ignores).
tests/rc-installer.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/problem-matcher.test.tsUpdate tests to use ESM JSON import attributes and Jest globals.
tests/official-installer.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/nightly-installer.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/mock/glob-mock.test.tsUpdate internal test import to .js specifier and Jest globals.
tests/main.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/canary-installer.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/cache-utils.test.tsUpdate tests to mock @actions/exec.getExecOutput and align with async command execution.
tests/cache-save.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/cache-restore.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
tests/authutil.test.tsUpdate tests for ESM execution + ESM-safe mocking/import patterns.
.licenses/npm/xml-naming.dep.ymlNormalize license metadata formatting (homepage field).
.licenses/npm/wrappy.dep.ymlRemove license metadata entry (dependency resolution changed).
.licenses/npm/universal-user-agent.dep.ymlUpdate license metadata to match upgraded dependency version/content.
.licenses/npm/strnum.dep.ymlUpdate license metadata formatting/version alignment.
.licenses/npm/semver.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/semver-6.3.1.dep.ymlRemove old semver v6 license metadata entry.
.licenses/npm/once.dep.ymlRemove license metadata entry (dependency resolution changed).
.licenses/npm/minimatch-3.1.5.dep.ymlAdd license metadata for additional minimatch version present in resolution.
.licenses/npm/minimatch-10.2.5.dep.ymlAdd license metadata for upgraded minimatch version present in resolution.
.licenses/npm/json-with-bigint.dep.ymlUpdate license metadata to match dependency name/version/copyright.
.licenses/npm/fast-xml-parser.dep.ymlUpdate license metadata formatting/version alignment.
.licenses/npm/fast-content-type-parse.dep.ymlUpdate license metadata to match new dependency and reviewed status.
.licenses/npm/deprecation.dep.ymlRemove license metadata entry (dependency resolution changed).
.licenses/npm/brace-expansion-5.0.6.dep.ymlUpdate license metadata to match resolved dependency content.
.licenses/npm/brace-expansion-1.1.13.dep.ymlAdd license metadata for additional brace-expansion version present in resolution.
.licenses/npm/before-after-hook.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/balanced-match-4.0.4.dep.ymlAdd license metadata for additional balanced-match version present in resolution.
.licenses/npm/balanced-match-1.0.2.dep.ymlAdd license metadata for additional balanced-match version present in resolution.
.licenses/npm/@typespec/ts-http-runtime.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/types.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/types-13.10.0.dep.ymlRemove old @octokit/types license metadata entry.
.licenses/npm/@octokit/request.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/request-error.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/plugin-rest-endpoint-methods.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/plugin-paginate-rest.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/openapi-types.dep.ymlUpdate license metadata to match upgraded dependency version/content.
.licenses/npm/@octokit/graphql.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/endpoint.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/core.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@octokit/auth-token.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@nodable/entities.dep.ymlUpdate license metadata formatting/version alignment.
.licenses/npm/@azure/storage-common.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@azure/storage-blob.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@azure/core-xml.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@azure/core-rest-pipeline.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@azure/core-http-compat.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@azure/abort-controller.dep.ymlAdd license metadata for newly present dependency in resolution.
.licenses/npm/@actions/tool-cache.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/io.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/http-client-4.0.1.dep.ymlUpdate license metadata to match upgraded dependency version/content.
.licenses/npm/@actions/glob-0.7.0.dep.ymlUpdate license metadata to match upgraded dependency version/content.
.licenses/npm/@actions/glob-0.6.1.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/github.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/exec.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/core.dep.ymlUpdate license metadata to match upgraded dependency version.
.licenses/npm/@actions/cache.dep.ymlUpdate license metadata to match upgraded dependency version.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment threadpackage.json Outdated
@gowridurgadgowridurgad self-assigned this Jul 6, 2026
priyagupta108
priyagupta108 previously approved these changes Jul 9, 2026
@HarithaVattikuti
HarithaVattikuti merged commit 8207627 into actions:mainJul 14, 2026
231 checks passed
ajgon pushed a commit to deedee-ops/schemas that referenced this pull request Jul 14, 2026
#11)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6.4.0` → `v7.0.0` |
---
### Release Notes
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0)
[Compare Source](actions/setup-node@v6.5.0...v7.0.0)
#### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#8203;deiga](https://github.com/deiga) in [#&#8203;1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1569](actions/setup-node#1569)
#### New Contributors
- [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#&#8203;1536](actions/setup-node#1536)
- [@&#8203;deiga](https://github.com/deiga) made their first contribution in [#&#8203;1548](actions/setup-node#1548)
- [@&#8203;jasongin](https://github.com/jasongin) made their first contribution in [#&#8203;1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0)
[Compare Source](actions/setup-node@v6.4.0...v6.5.0)
#### What's Changed
- Update [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@&#8203;HarithaVattikuti](https://github.com/HarithaVattikuti) in [#&#8203;1579](actions/setup-node#1579)
**Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
</details>
---
### Configuration
📅 **Schedule**: (in timezone Europe/Warsaw)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI2MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbXX0=-->
Reviewed-on: https://git.ajgon.casa/deedee/schemas/pulls/11
@matkoniecz

matkoniecz commented Jul 17, 2026

Copy link
Copy Markdown

this got listed as breaking change in https://github.com/actions/setup-node#breaking-changes-in-v7 - any idea what is the proper way to check is it a breaking change in openstreetmap/id-tagging-schema#2574 and potentially mitigate it?

https://github.com/actions/setup-node#breaking-changes-in-v7 does not have much info or migration steps

hypekostas pushed a commit to stellar/stellar-disbursement-platform-frontend that referenced this pull request Jul 20, 2026
…roup (#558)
Bumps the all-actions group with 1 update: [actions/setup-node](https://github.com/actions/setup-node).
Updates `actions/setup-node` from **6** to **7**
## Release notes
*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*
> ## v7.0.0
>
> ## What's Changed
>
> ### Enhancements
> - Add `cache-primary-key` and `cache-matched-key` as outputs by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1577](actions/setup-node#1577)
> - Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1574](actions/setup-node#1574)
>
> ### Bug fixes
> - Remove dummy `NODE_AUTH_TOKEN` export by [@gowridurgad](https://github.com/gowridurgad) in [actions/setup-node#1558](actions/setup-node#1558)
> - Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [actions/setup-node#1548](actions/setup-node#1548)
>
> ### Documentation updates
> - Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1536](actions/setup-node#1536)
> - Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [actions/setup-node#1550](actions/setup-node#1550)
> - Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [actions/setup-node#1567](actions/setup-node#1567)
>
> ### Dependency update
> - Upgrade `@actions/cache` to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [actions/setup-node#1569](actions/setup-node#1569)
>
> ### New Contributors
> - @chiranjib-swain (#1536)
> - @deiga (#1548)
> - @jasongin (#1569)
>
> **Full Changelog:** actions/setup-node@v6...v7.0.0
>
> ## v6.5.0
> - Update `@actions/cache` to 5.1.0 and add security overrides for `undici` and `fast-xml-parser`.
>
> **Full Changelog:** actions/setup-node@v6.4.0...v6.5.0
>
> ## v6.4.0
> - Upgrade `@actions` dependencies.
> - Update Node.js versions in `versions.yml` and bump package to v6.4.0.
>
> ## v6.3.0
> - Support parsing `devEngines` field.
>
> ... (remaining release notes truncated exactly as in the original)
## Commits
- `8207627` Migrate to ESM and upgrade dependencies (#1574)
- `04be95c` Add cache-primary-key and cache-matched-key as outputs (#1577)
- `7c2c68d` Update caching recommendations to mitigate cache poisoning risks (#1567)
- `6a61c03` Merge pull request #1569
- `30eb73b` Resolve high-severity audit issues
- `4e1a87a` Update dist
- `360237f` Strict equality
- `4f8aac5` Bump `@actions/cache` to 5.1.0
- `f4a67bb` Only use `mirrorToken` in `getManifest` if it's provided (#1548)
- `0355742` Remove dummy `NODE_AUTH_TOKEN` export (#1558)
- Additional commits viewable in the compare view.
---
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
## Dependabot commands and options
- `@dependabot rebase`
- `@dependabot recreate`
- `@dependabot show <dependency name> ignore conditions`
- `@dependabot ignore <dependency name> major version`
- `@dependabot ignore <dependency name> minor version`
- `@dependabot ignore <dependency name>`
- `@dependabot unignore <dependency name>`
- `@dependabot unignore <dependency name> <ignore condition>`
Sirherobrine23 pushed a commit to Sirherobrine23/gitea-runner that referenced this pull request Jul 21, 2026
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` |
---
### Release Notes
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0)
[Compare Source](actions/setup-node@v7.0.0...v7.0.0)
#### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#8203;deiga](https://github.com/deiga) in [#&#8203;1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1569](actions/setup-node#1569)
#### New Contributors
- [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#&#8203;1536](actions/setup-node#1536)
- [@&#8203;deiga](https://github.com/deiga) made their first contribution in [#&#8203;1548](actions/setup-node#1548)
- [@&#8203;jasongin](https://github.com/jasongin) made their first contribution in [#&#8203;1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
### [`v7`](actions/setup-node@v6.5.0...v7.0.0)
[Compare Source](actions/setup-node@v6.5.0...v7.0.0)
### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0)
[Compare Source](actions/setup-node@v6.4.0...v6.5.0)
#### What's Changed
- Update [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@&#8203;HarithaVattikuti](https://github.com/HarithaVattikuti) in [#&#8203;1579](actions/setup-node#1579)
**Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0)
[Compare Source](actions/setup-node@v6.3.0...v6.4.0)
#### What's Changed
##### Dependency updates:
- Upgrade [@&#8203;actions](https://github.com/actions) dependencies by [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;1525](actions/setup-node#1525)
- Update Node.js versions in versions.yml and bump package to v6.4.0 by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1533](actions/setup-node#1533)
#### New Contributors
- [@&#8203;Copilot](https://github.com/Copilot) made their first contribution in [#&#8203;1525](actions/setup-node#1525)
**Full Changelog**: <actions/setup-node@v6...v6.4.0>
### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0)
[Compare Source](actions/setup-node@v6.2.0...v6.3.0)
#### What's Changed
##### Enhancements:
- Support parsing `devEngines` field by [@&#8203;susnux](https://github.com/susnux) in [#&#8203;1283](actions/setup-node#1283)
> When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.
##### Dependency updates:
- Fix npm audit issues by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1491](actions/setup-node#1491)
- Replace uuid with crypto.randomUUID() by [@&#8203;trivikr](https://github.com/trivikr) in [#&#8203;1378](actions/setup-node#1378)
- Upgrade minimatch from 3.1.2 to 3.1.5 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;1498](actions/setup-node#1498)
##### Bug fixes:
- Remove hardcoded bearer for mirror-url [@&#8203;marco-ippolito](https://github.com/marco-ippolito) in [#&#8203;1467](actions/setup-node#1467)
- Scope test lockfiles by package manager and update cache tests by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1495](actions/setup-node#1495)
#### New Contributors
- [@&#8203;susnux](https://github.com/susnux) made their first contribution in [#&#8203;1283](actions/setup-node#1283)
**Full Changelog**: <actions/setup-node@v6...v6.3.0>
### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0)
[Compare Source](actions/setup-node@v6.1.0...v6.2.0)
#### What's Changed
##### Documentation
- Documentation update related to absence of Lockfile by [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) in [#&#8203;1454](actions/setup-node#1454)
- Correct mirror option typos by [@&#8203;MikeMcC399](https://github.com/MikeMcC399) in [#&#8203;1442](actions/setup-node#1442)
- Readme update on checkout version v6 by [@&#8203;deining](https://github.com/deining) in [#&#8203;1446](actions/setup-node#1446)
- Readme typo fixes [@&#8203;munyari](https://github.com/munyari) in [#&#8203;1226](actions/setup-node#1226)
- Advanced document update on checkout version v6 by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1468](actions/setup-node#1468)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to v5.0.1 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1449](actions/setup-node#1449)
#### New Contributors
- [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#&#8203;1454](actions/setup-node#1454)
- [@&#8203;MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#&#8203;1442](actions/setup-node#1442)
- [@&#8203;deining](https://github.com/deining) made their first contribution in [#&#8203;1446](actions/setup-node#1446)
- [@&#8203;munyari](https://github.com/munyari) made their first contribution in [#&#8203;1226](actions/setup-node#1226)
**Full Changelog**: <actions/setup-node@v6...v6.2.0>
### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0)
[Compare Source](actions/setup-node@v6...v6.1.0)
#### What's Changed
##### Enhancement:
- Remove always-auth configuration handling by [@&#8203;priyagupta108](https://github.com/priyagupta108) in [#&#8203;1436](actions/setup-node#1436)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1384](actions/setup-node#1384)
- Upgrade actions/checkout from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1439](actions/setup-node#1439)
- Upgrade js-yaml from 3.14.1 to 3.14.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1435](actions/setup-node#1435)
##### Documentation update:
- Add example for restore-only cache in documentation by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1419](actions/setup-node#1419)
**Full Changelog**: <actions/setup-node@v6...v6.1.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/runner/pulls/1094
Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
yamz8 pushed a commit to forgente/docs that referenced this pull request Jul 21, 2026
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` |
---
### Release Notes
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0)
[Compare Source](actions/setup-node@v7.0.0...v7.0.0)
##### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#8203;deiga](https://github.com/deiga) in [#&#8203;1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1569](actions/setup-node#1569)
##### New Contributors
- [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#&#8203;1536](actions/setup-node#1536)
- [@&#8203;deiga](https://github.com/deiga) made their first contribution in [#&#8203;1548](actions/setup-node#1548)
- [@&#8203;jasongin](https://github.com/jasongin) made their first contribution in [#&#8203;1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
### [`v7`](actions/setup-node@v6.5.0...v7.0.0)
[Compare Source](actions/setup-node@v6.5.0...v7.0.0)
### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0)
[Compare Source](actions/setup-node@v6.4.0...v6.5.0)
##### What's Changed
- Update [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@&#8203;HarithaVattikuti](https://github.com/HarithaVattikuti) in [#&#8203;1579](actions/setup-node#1579)
**Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0)
[Compare Source](actions/setup-node@v6.3.0...v6.4.0)
##### What's Changed
##### Dependency updates:
- Upgrade [@&#8203;actions](https://github.com/actions) dependencies by [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;1525](actions/setup-node#1525)
- Update Node.js versions in versions.yml and bump package to v6.4.0 by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1533](actions/setup-node#1533)
##### New Contributors
- [@&#8203;Copilot](https://github.com/Copilot) made their first contribution in [#&#8203;1525](actions/setup-node#1525)
**Full Changelog**: <actions/setup-node@v6...v6.4.0>
### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0)
[Compare Source](actions/setup-node@v6.2.0...v6.3.0)
##### What's Changed
##### Enhancements:
- Support parsing `devEngines` field by [@&#8203;susnux](https://github.com/susnux) in [#&#8203;1283](actions/setup-node#1283)
> When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.
##### Dependency updates:
- Fix npm audit issues by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1491](actions/setup-node#1491)
- Replace uuid with crypto.randomUUID() by [@&#8203;trivikr](https://github.com/trivikr) in [#&#8203;1378](actions/setup-node#1378)
- Upgrade minimatch from 3.1.2 to 3.1.5 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;1498](actions/setup-node#1498)
##### Bug fixes:
- Remove hardcoded bearer for mirror-url [@&#8203;marco-ippolito](https://github.com/marco-ippolito) in [#&#8203;1467](actions/setup-node#1467)
- Scope test lockfiles by package manager and update cache tests by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1495](actions/setup-node#1495)
##### New Contributors
- [@&#8203;susnux](https://github.com/susnux) made their first contribution in [#&#8203;1283](actions/setup-node#1283)
**Full Changelog**: <actions/setup-node@v6...v6.3.0>
### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0)
[Compare Source](actions/setup-node@v6.1.0...v6.2.0)
##### What's Changed
##### Documentation
- Documentation update related to absence of Lockfile by [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) in [#&#8203;1454](actions/setup-node#1454)
- Correct mirror option typos by [@&#8203;MikeMcC399](https://github.com/MikeMcC399) in [#&#8203;1442](actions/setup-node#1442)
- Readme update on checkout version v6 by [@&#8203;deining](https://github.com/deining) in [#&#8203;1446](actions/setup-node#1446)
- Readme typo fixes [@&#8203;munyari](https://github.com/munyari) in [#&#8203;1226](actions/setup-node#1226)
- Advanced document update on checkout version v6 by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1468](actions/setup-node#1468)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to v5.0.1 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1449](actions/setup-node#1449)
##### New Contributors
- [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#&#8203;1454](actions/setup-node#1454)
- [@&#8203;MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#&#8203;1442](actions/setup-node#1442)
- [@&#8203;deining](https://github.com/deining) made their first contribution in [#&#8203;1446](actions/setup-node#1446)
- [@&#8203;munyari](https://github.com/munyari) made their first contribution in [#&#8203;1226](actions/setup-node#1226)
**Full Changelog**: <actions/setup-node@v6...v6.2.0>
### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0)
[Compare Source](actions/setup-node@v6...v6.1.0)
#### What's Changed
##### Enhancement:
- Remove always-auth configuration handling by [@&#8203;priyagupta108](https://github.com/priyagupta108) in [#&#8203;1436](actions/setup-node#1436)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1384](actions/setup-node#1384)
- Upgrade actions/checkout from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1439](actions/setup-node#1439)
- Upgrade js-yaml from 3.14.1 to 3.14.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1435](actions/setup-node#1435)
##### Documentation update:
- Add example for restore-only cache in documentation by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1419](actions/setup-node#1419)
**Full Changelog**: <actions/setup-node@v6...v6.1.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/docs/pulls/467
Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
yamz8 pushed a commit to forgente/blog that referenced this pull request Jul 21, 2026
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/setup-node](https://github.com/actions/setup-node) | action | major | `v6` → `v7` |
---
### Release Notes
<details>
<summary>actions/setup-node (actions/setup-node)</summary>
### [`v7.0.0`](https://github.com/actions/setup-node/releases/tag/v7.0.0)
[Compare Source](actions/setup-node@v7.0.0...v7.0.0)
##### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@&#8203;deiga](https://github.com/deiga) in [#&#8203;1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) in [#&#8203;1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1569](actions/setup-node#1569)
##### New Contributors
- [@&#8203;chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#&#8203;1536](actions/setup-node#1536)
- [@&#8203;deiga](https://github.com/deiga) made their first contribution in [#&#8203;1548](actions/setup-node#1548)
- [@&#8203;jasongin](https://github.com/jasongin) made their first contribution in [#&#8203;1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
### [`v7`](actions/setup-node@v6.5.0...v7.0.0)
[Compare Source](actions/setup-node@v6.5.0...v7.0.0)
### [`v6.5.0`](https://github.com/actions/setup-node/releases/tag/v6.5.0)
[Compare Source](actions/setup-node@v6.4.0...v6.5.0)
##### What's Changed
- Update [@&#8203;actions/cache](https://github.com/actions/cache) to 5.1.0 and add security overrides for undici and fast-xml-parser by [@&#8203;HarithaVattikuti](https://github.com/HarithaVattikuti) in [#&#8203;1579](actions/setup-node#1579)
**Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
### [`v6.4.0`](https://github.com/actions/setup-node/releases/tag/v6.4.0)
[Compare Source](actions/setup-node@v6.3.0...v6.4.0)
##### What's Changed
##### Dependency updates:
- Upgrade [@&#8203;actions](https://github.com/actions) dependencies by [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;1525](actions/setup-node#1525)
- Update Node.js versions in versions.yml and bump package to v6.4.0 by [@&#8203;priya-kinthali](https://github.com/priya-kinthali) in [#&#8203;1533](actions/setup-node#1533)
##### New Contributors
- [@&#8203;Copilot](https://github.com/Copilot) made their first contribution in [#&#8203;1525](actions/setup-node#1525)
**Full Changelog**: <actions/setup-node@v6...v6.4.0>
### [`v6.3.0`](https://github.com/actions/setup-node/releases/tag/v6.3.0)
[Compare Source](actions/setup-node@v6.2.0...v6.3.0)
##### What's Changed
##### Enhancements:
- Support parsing `devEngines` field by [@&#8203;susnux](https://github.com/susnux) in [#&#8203;1283](actions/setup-node#1283)
> When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.
##### Dependency updates:
- Fix npm audit issues by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1491](actions/setup-node#1491)
- Replace uuid with crypto.randomUUID() by [@&#8203;trivikr](https://github.com/trivikr) in [#&#8203;1378](actions/setup-node#1378)
- Upgrade minimatch from 3.1.2 to 3.1.5 by [@&#8203;dependabot](https://github.com/dependabot) in [#&#8203;1498](actions/setup-node#1498)
##### Bug fixes:
- Remove hardcoded bearer for mirror-url [@&#8203;marco-ippolito](https://github.com/marco-ippolito) in [#&#8203;1467](actions/setup-node#1467)
- Scope test lockfiles by package manager and update cache tests by [@&#8203;gowridurgad](https://github.com/gowridurgad) in [#&#8203;1495](actions/setup-node#1495)
##### New Contributors
- [@&#8203;susnux](https://github.com/susnux) made their first contribution in [#&#8203;1283](actions/setup-node#1283)
**Full Changelog**: <actions/setup-node@v6...v6.3.0>
### [`v6.2.0`](https://github.com/actions/setup-node/releases/tag/v6.2.0)
[Compare Source](actions/setup-node@v6.1.0...v6.2.0)
##### What's Changed
##### Documentation
- Documentation update related to absence of Lockfile by [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) in [#&#8203;1454](actions/setup-node#1454)
- Correct mirror option typos by [@&#8203;MikeMcC399](https://github.com/MikeMcC399) in [#&#8203;1442](actions/setup-node#1442)
- Readme update on checkout version v6 by [@&#8203;deining](https://github.com/deining) in [#&#8203;1446](actions/setup-node#1446)
- Readme typo fixes [@&#8203;munyari](https://github.com/munyari) in [#&#8203;1226](actions/setup-node#1226)
- Advanced document update on checkout version v6 by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1468](actions/setup-node#1468)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) to v5.0.1 by [@&#8203;salmanmkc](https://github.com/salmanmkc) in [#&#8203;1449](actions/setup-node#1449)
##### New Contributors
- [@&#8203;mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#&#8203;1454](actions/setup-node#1454)
- [@&#8203;MikeMcC399](https://github.com/MikeMcC399) made their first contribution in [#&#8203;1442](actions/setup-node#1442)
- [@&#8203;deining](https://github.com/deining) made their first contribution in [#&#8203;1446](actions/setup-node#1446)
- [@&#8203;munyari](https://github.com/munyari) made their first contribution in [#&#8203;1226](actions/setup-node#1226)
**Full Changelog**: <actions/setup-node@v6...v6.2.0>
### [`v6.1.0`](https://github.com/actions/setup-node/releases/tag/v6.1.0)
[Compare Source](actions/setup-node@v6...v6.1.0)
##### What's Changed
##### Enhancement:
- Remove always-auth configuration handling by [@&#8203;priyagupta108](https://github.com/priyagupta108) in [#&#8203;1436](actions/setup-node#1436)
##### Dependency updates:
- Upgrade [@&#8203;actions/cache](https://github.com/actions/cache) from 4.0.3 to 4.1.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1384](actions/setup-node#1384)
- Upgrade actions/checkout from 5 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1439](actions/setup-node#1439)
- Upgrade js-yaml from 3.14.1 to 3.14.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;1435](actions/setup-node#1435)
##### Documentation update:
- Add example for restore-only cache in documentation by [@&#8203;aparnajyothi-y](https://github.com/aparnajyothi-y) in [#&#8203;1419](actions/setup-node#1419)
**Full Changelog**: <actions/setup-node@v6...v6.1.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->Reviewed-on: https://gitea.com/gitea/blog/pulls/546
Reviewed-by: silverwind <2021+silverwind@noreply.gitea.com>
Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
@gowridurgad

Copy link
Copy Markdown
ContributorAuthor

Hi @matkoniecz, thanks for calling this out. We've updated the README in PR #1593 to clarify this. The ESM migration in V7 is an internal change only and does not affect action inputs, outputs, or behavior for consuming workflows, so it should not affect openstreetmap/id-tagging-schema. No migration steps are needed for this change

mergifyBot added a commit to ArcadeData/arcadedb-usecases that referenced this pull request Jul 26, 2026
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
Release notes
*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*
> v7.0.0
> ------
>
> What's Changed
> --------------
>
> ### Enhancements:
>
> * Add cache-primary-key and cache-matched-key as outputs by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577)
> * Migrate to ESM and upgrade dependencies by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574)
>
> ### Bug fixes:
>
> * Remove dummy NODE\_AUTH\_TOKEN export by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558)
> * Only use `mirrorToken` in `getManifest` if it's provided by [`@​deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
>
> ### Documentation updates:
>
> * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * docs: Update restore-only cache documentation by [`@​priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550)
> * docs: Update caching recommendations to mitigate cache poisoning risks by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567)
>
> ### Dependency update:
>
> * Upgrade `@​actions/cache` to 5.1.0, log cache write denied by [`@​jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> New Contributors
> ----------------
>
> * [`@​chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * [`@​deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
> * [`@​jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> **Full Changelog**: <actions/setup-node@v6...v7.0.0>
>
> v6.5.0
> ------
>
> What's Changed
> --------------
>
> * Update `@​actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@​HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579)
>
> **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
Commits
* [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574))
* [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577))
* [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567))
* [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0
* [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues
* [`4e1a87a`](actions/setup-node@4e1a87a) Update dist
* [`360237f`](actions/setup-node@360237f) Strict equality
* [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@​actions/cache` to 5.1.0, log cache write denied
* [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548))
* [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558))
* Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627)
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-node&package-manager=github\_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Comment thread.licensed.yml
- mit
- cc0-1.0
- unlicense
- blueoak-1.0.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread.eslintrc.js
@@ -1,51 +0,0 @@
// This is a reusable configuration file copied from https://github.com/actions/reusable-workflows/tree/main/reusable-configurations. Please don't make changes to this file as it's the subject of an automatic update.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

automativ

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • ```
    autonoma

Comment thread.eslintrc.js
@@ -1,51 +0,0 @@
// This is a reusable configuration file copied from https://github.com/actions/reusable-workflows/tree/main/reusable-configurations. Please don't make changes to this file as it's the subject of an automatic update.
module.exports={
extends: [

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@SJuarezVazquez

Comment thread.eslintrc.js
@@ -1,51 +0,0 @@
// This is a reusable configuration file copied from https://github.com/actions/reusable-workflows/tree/main/reusable-configurations. Please don't make changes to this file as it's the subject of an automatic update.
module.exports={

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

operacional

Comment thread.licensed.yml
reviewed:
npm:
- "@actions/http-client" No newline at end of file
- "@actions/http-client"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tools

mergifyBot added a commit to robfrank/linklift that referenced this pull request Jul 27, 2026
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
Release notes
*Sourced from [actions/setup-node's releases](https://github.com/actions/setup-node/releases).*
> v7.0.0
> ------
>
> What's Changed
> --------------
>
> ### Enhancements:
>
> * Add cache-primary-key and cache-matched-key as outputs by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1577](https://redirect.github.com/actions/setup-node/pull/1577)
> * Migrate to ESM and upgrade dependencies by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1574](https://redirect.github.com/actions/setup-node/pull/1574)
>
> ### Bug fixes:
>
> * Remove dummy NODE\_AUTH\_TOKEN export by [`@​gowridurgad`](https://github.com/gowridurgad) in [actions/setup-node#1558](https://redirect.github.com/actions/setup-node/pull/1558)
> * Only use `mirrorToken` in `getManifest` if it's provided by [`@​deiga`](https://github.com/deiga) in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
>
> ### Documentation updates:
>
> * Add documentation for publishing to npm with Trusted Publisher (OIDC) by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * docs: Update restore-only cache documentation by [`@​priya-kinthali`](https://github.com/priya-kinthali) in [actions/setup-node#1550](https://redirect.github.com/actions/setup-node/pull/1550)
> * docs: Update caching recommendations to mitigate cache poisoning risks by [`@​chiranjib-swain`](https://github.com/chiranjib-swain) in [actions/setup-node#1567](https://redirect.github.com/actions/setup-node/pull/1567)
>
> ### Dependency update:
>
> * Upgrade `@​actions/cache` to 5.1.0, log cache write denied by [`@​jasongin`](https://github.com/jasongin) in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> New Contributors
> ----------------
>
> * [`@​chiranjib-swain`](https://github.com/chiranjib-swain) made their first contribution in [actions/setup-node#1536](https://redirect.github.com/actions/setup-node/pull/1536)
> * [`@​deiga`](https://github.com/deiga) made their first contribution in [actions/setup-node#1548](https://redirect.github.com/actions/setup-node/pull/1548)
> * [`@​jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-node#1569](https://redirect.github.com/actions/setup-node/pull/1569)
>
> **Full Changelog**: <actions/setup-node@v6...v7.0.0>
>
> v6.5.0
> ------
>
> What's Changed
> --------------
>
> * Update `@​actions/cache` to 5.1.0 and add security overrides for undici and fast-xml-parser by [`@​HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-node#1579](https://redirect.github.com/actions/setup-node/pull/1579)
>
> **Full Changelog**: <actions/setup-node@v6.4.0...v6.5.0>
Commits
* [`8207627`](actions/setup-node@8207627) Migrate to ESM and upgrade dependencies ([#1574](https://redirect.github.com/actions/setup-node/issues/1574))
* [`04be95c`](actions/setup-node@04be95c) Add cache-primary-key and cache-matched-key as outputs ([#1577](https://redirect.github.com/actions/setup-node/issues/1577))
* [`7c2c68d`](actions/setup-node@7c2c68d) docs: Update caching recommendations to mitigate cache poisoning risks ([#1567](https://redirect.github.com/actions/setup-node/issues/1567))
* [`6a61c03`](actions/setup-node@6a61c03) Merge pull request [#1569](https://redirect.github.com/actions/setup-node/issues/1569) from jasongin/update-actions-cache-5.1.0
* [`30eb73b`](actions/setup-node@30eb73b) Resolve high-severity audit issues
* [`4e1a87a`](actions/setup-node@4e1a87a) Update dist
* [`360237f`](actions/setup-node@360237f) Strict equality
* [`4f8aac5`](actions/setup-node@4f8aac5) Bump `@​actions/cache` to 5.1.0, log cache write denied
* [`f4a67bb`](actions/setup-node@f4a67bb) Only use `mirrorToken` in `getManifest` if it's provided ([#1548](https://redirect.github.com/actions/setup-node/issues/1548))
* [`0355742`](actions/setup-node@0355742) Remove dummy NODE\_AUTH\_TOKEN export ([#1558](https://redirect.github.com/actions/setup-node/issues/1558))
* Additional commits viewable in [compare view](actions/setup-node@48b55a0...8207627)
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility\_score?dependency-name=actions/setup-node&package-manager=github\_actions&previous-version=6.4.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
@chybisovchybisov mentioned this pull request Jul 27, 2026
3 tasks
h1431532403240 pushed a commit to GET-Technology-Inc/jamf-docs-mcp-server that referenced this pull request Aug 3, 2026
Updates all 8 call sites: ci.yml (4 jobs), license-check.yml,
publish-gpr.yml, release.yml, upstream-contract.yml.
v6 and v7 declare identical inputs and both run on node24; outputs are
additive only. The ESM migration (actions/setup-node#1574) also bumped every
bundled @actions/* toolkit across major boundaries, and added a missing
`await` in cache-utils.ts that makes the previously-dead "Could not get npm
cache folder path" guard live.
No job on the PR exercises setup-node — they are all path-skipped — so the
first real execution is the Release run on main.
renovateBot added a commit to cigaleapp/cigale that referenced this pull request Aug 3, 2026
##### [vv7.0.0](https://github.com/actions/setup-node/releases/tag/v7.0.0)
##### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@gowridurgad](https://github.com/gowridurgad) in [#1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [#1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@gowridurgad](https://github.com/gowridurgad) in [#1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [#1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [#1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [#1569](actions/setup-node#1569)
##### New Contributors
- [@chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#1536](actions/setup-node#1536)
- [@deiga](https://github.com/deiga) made their first contribution in [#1548](actions/setup-node#1548)
- [@jasongin](https://github.com/jasongin) made their first contribution in [#1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
##### [vv7](actions/setup-node@v6.5.0...v7.0.0)
gwennlbh pushed a commit to cigaleapp/cigale that referenced this pull request Aug 3, 2026
##### [vv7.0.0](https://github.com/actions/setup-node/releases/tag/v7.0.0)
##### What's Changed
##### Enhancements:
- Add cache-primary-key and cache-matched-key as outputs by [@gowridurgad](https://github.com/gowridurgad) in [#1577](actions/setup-node#1577)
- Migrate to ESM and upgrade dependencies by [@gowridurgad](https://github.com/gowridurgad) in [#1574](actions/setup-node#1574)
##### Bug fixes:
- Remove dummy NODE\_AUTH\_TOKEN export by [@gowridurgad](https://github.com/gowridurgad) in [#1558](actions/setup-node#1558)
- Only use `mirrorToken` in `getManifest` if it's provided by [@deiga](https://github.com/deiga) in [#1548](actions/setup-node#1548)
##### Documentation updates:
- Add documentation for publishing to npm with Trusted Publisher (OIDC) by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1536](actions/setup-node#1536)
- docs: Update restore-only cache documentation by [@priya-kinthali](https://github.com/priya-kinthali) in [#1550](actions/setup-node#1550)
- docs: Update caching recommendations to mitigate cache poisoning risks by [@chiranjib-swain](https://github.com/chiranjib-swain) in [#1567](actions/setup-node#1567)
##### Dependency update:
- Upgrade [@actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@jasongin](https://github.com/jasongin) in [#1569](actions/setup-node#1569)
##### New Contributors
- [@chiranjib-swain](https://github.com/chiranjib-swain) made their first contribution in [#1536](actions/setup-node#1536)
- [@deiga](https://github.com/deiga) made their first contribution in [#1548](actions/setup-node#1548)
- [@jasongin](https://github.com/jasongin) made their first contribution in [#1569](actions/setup-node#1569)
**Full Changelog**: <actions/setup-node@v6...v7.0.0>
##### [vv7](actions/setup-node@v6.5.0...v7.0.0)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@gowridurgad@matkoniecz@HarithaVattikuti@priya-kinthali@priyagupta108@pelonducks25-crypto