ci(deps): bump checkout/upload-artifact/download-artifact majors

Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the
pinned-SHA contract stays consistent in one commit.

actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and
actions/download-artifact v4 -> v8 across every workflow. docker.yml moves
from checkout v6 to v7 with the rest.

publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated
there and in the packaging policy tests that assert them
(snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs,
release-snap-assets.test.mjs). Each SHA was checked against the upstream tag
refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1,
download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the
unpinned bumps in build-and-make.yaml.

download-artifact v8 changes two behaviours that matter for the Snap publish
path, both in our favour: an artifact digest mismatch now fails the run
instead of logging a warning, and the action only unzips responses whose
Content-Type says zip. The publish job downloads a normal upload-artifact
artifact by name, so decompression is unchanged, and it re-verifies the
receipt digest itself regardless.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Opus 5 committed 2026-07-26 02:24:52 +02:00
1 parent 7e8c2ccce1
commit 319a0404aa
10 files changed
+39 -39

No files matched your search

@@ -174,13 +174,13 @@ test('isolates released verification from the fresh credentialed upload runner',
assert.deepEqual(
verifyJob.steps.filter((step) => step.uses).map((step) => step.uses),
[
'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5',
'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02',
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1',
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a',
]
);
assert.deepEqual(
publishJob.steps.filter((step) => step.uses).map((step) => step.uses),
['actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093']
['actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c']
);
const bindingStep = verifyJob.steps.find(