ci(deps): bump checkout/upload-artifact/download-artifact majors

Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the
pinned-SHA contract stays consistent in one commit.

actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and
actions/download-artifact v4 -> v8 across every workflow. docker.yml moves
from checkout v6 to v7 with the rest.

publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated
there and in the packaging policy tests that assert them
(snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs,
release-snap-assets.test.mjs). Each SHA was checked against the upstream tag
refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1,
download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the
unpinned bumps in build-and-make.yaml.

download-artifact v8 changes two behaviours that matter for the Snap publish
path, both in our favour: an artifact digest mismatch now fails the run
instead of logging a warning, and the action only unzips responses whose
Content-Type says zip. The publish job downloads a normal upload-artifact
artifact by name, so decompression is unchanged, and it re-verifies the
receipt digest itself regardless.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Opus 5 committed 2026-07-26 02:24:52 +02:00
1 parent 7e8c2ccce1
commit 319a0404aa
10 files changed
+39 -39

No files matched your search

+12 -12
View File
@@ -56,7 +56,7 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Setup Node.js
uses: actions/setup-node@v4
@@ -322,7 +322,7 @@ jobs:
test -s "${RUNTIME_ROOT}/source-archive-binding.json"
- name: Upload staged Linux runtime
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-embedded-mpv-runtime
path: vendor/embedded-mpv/linux-x64
@@ -330,7 +330,7 @@ jobs:
retention-days: 7
- name: Upload Linux runtime source compliance
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-frame-copy-runtime-sources
path: dist/compliance/linux-frame-copy-runtime-sources.tar.xz
@@ -370,7 +370,7 @@ jobs:
steps: &electron-build-steps
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install pnpm
uses: pnpm/action-setup@v4
@@ -424,7 +424,7 @@ jobs:
- name: Download pinned Linux Embedded MPV runtime
if: matrix.os == 'linux'
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: linux-embedded-mpv-runtime
path: vendor/embedded-mpv/linux-x64
@@ -1187,7 +1187,7 @@ jobs:
- name: Upload artifacts (macOS)
if: matrix.os == 'macos'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: macos-${{ matrix.arch }}-artifacts
path: |
@@ -1199,7 +1199,7 @@ jobs:
- name: Upload system-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'system'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-system-artifacts
path: |
@@ -1211,7 +1211,7 @@ jobs:
- name: Upload portable-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'portable'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-portable-artifacts
path: |
@@ -1223,7 +1223,7 @@ jobs:
- name: Upload Flatpak-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'flatpak'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-flatpak-artifacts
path: |
@@ -1232,7 +1232,7 @@ jobs:
- name: Upload artifacts (Windows)
if: matrix.os == 'windows'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: windows-artifacts
path: |
@@ -1294,10 +1294,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Download all artifacts
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
path: artifacts