Skip to content

chore: bump GitHub Actions(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0#87

Open
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/github_actions/actions/upload-artifact-7.0.0
Open

chore: bump GitHub Actions(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0#87
dependabot[bot] wants to merge 2 commits intomainfrom
dependabot/github_actions/actions/upload-artifact-7.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 1, 2026

Bumps actions/upload-artifact from 6.0.0 to 7.0.0.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

Commits

@dependabot dependabot bot added the security A security or dependency related update label Mar 1, 2026
@agriyakhetarpal
Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 6.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@b7c566a...bbbca2d)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/upload-artifact-7.0.0 branch from ca1faa7 to 29a77d3 Compare April 2, 2026 02:02
Copy link
Copy Markdown
Member

@agriyakhetarpal agriyakhetarpal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Interesting, the SHA moved and the tag comment did not change? This is not the first time I've seen this kind of problem with Dependabot updates (we've previously encountered this with cibuildwheel/scikit-learn once). I think we should set up https://docs.zizmor.sh/audits/#ref-version-mismatch at some point. For now, I'm going to manually correct the SHA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security A security or dependency related update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant