mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 02:46:16 -08:00
ci(deps): bump checkout/upload-artifact/download-artifact majors
Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the pinned-SHA contract stays consistent in one commit. actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and actions/download-artifact v4 -> v8 across every workflow. docker.yml moves from checkout v6 to v7 with the rest. publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated there and in the packaging policy tests that assert them (snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs, release-snap-assets.test.mjs). Each SHA was checked against the upstream tag refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1, download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the unpinned bumps in build-and-make.yaml. download-artifact v8 changes two behaviours that matter for the Snap publish path, both in our favour: an artifact digest mismatch now fails the run instead of logging a warning, and the action only unzips responses whose Content-Type says zip. The publish job downloads a normal upload-artifact artifact by name, so decompression is unchanged, and it re-verifies the receipt digest itself regardless. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
7e8c2ccce1
commit
319a0404aa
10 files changed
+39
-39
No files matched your search
@@ -174,13 +174,13 @@ test('isolates released verification from the fresh credentialed upload runner',
|
||||
assert.deepEqual(
|
||||
verifyJob.steps.filter((step) => step.uses).map((step) => step.uses),
|
||||
[
|
||||
'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5',
|
||||
'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02',
|
||||
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1',
|
||||
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a',
|
||||
]
|
||||
);
|
||||
assert.deepEqual(
|
||||
publishJob.steps.filter((step) => step.uses).map((step) => step.uses),
|
||||
['actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093']
|
||||
['actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c']
|
||||
);
|
||||
|
||||
const bindingStep = verifyJob.steps.find(
|
||||
|
||||
Reference in new issue
Block a user