From 553f45dedce672b843b927ee20a6f45328eca127 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 28 Jul 2026 08:12:18 +0200 Subject: [PATCH] chore(deps): bump actions/cache from 4 to 6 (#1281) * chore(deps): bump actions/cache from 4 to 6 Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](https://github.com/actions/cache/compare/v4...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] * chore(ci): allow actions/cache v6 in the Snap workflow policy The Snap supply-chain policy test pins the exact major of every action the build workflow may use, so bumping actions/cache in the workflow without updating BUILD_ACTION_ALLOWLIST fails publish-snap-workflow.test.mjs. Co-Authored-By: Claude Opus 5 --------- Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: 4gray Co-authored-by: Claude Opus 5 --- .github/workflows/build-and-make.yaml | 6 +++--- tools/packaging/snap-workflow-policy.test-helpers.mjs | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/.github/workflows/build-and-make.yaml b/.github/workflows/build-and-make.yaml index efc62626e..3fcb30ebb 100644 --- a/.github/workflows/build-and-make.yaml +++ b/.github/workflows/build-and-make.yaml @@ -86,7 +86,7 @@ jobs: - name: Restore pinned Linux runtime and immutable source inputs id: linux-runtime-cache - uses: actions/cache@v4 + uses: actions/cache@v6 with: path: | vendor/embedded-mpv/linux-x64/include @@ -525,7 +525,7 @@ jobs: # after the macOS Embedded MPV artifacts are built and manually tested. if: matrix.embedded_mpv_platform && matrix.os != 'linux' && !startsWith(github.ref, 'refs/tags/v') && (github.event_name == 'pull_request' || github.ref == 'refs/heads/master') id: embedded-mpv-runtime-cache - uses: actions/cache/restore@v4 + uses: actions/cache/restore@v6 with: path: | vendor/embedded-mpv/${{ matrix.embedded_mpv_platform }}-${{ matrix.embedded_mpv_arch }}/include @@ -1119,7 +1119,7 @@ jobs: # TEMPORARY ARTIFACT TEST: remove `|| github.ref == 'refs/heads/master'` # after the macOS Embedded MPV artifacts are built and manually tested. if: matrix.embedded_mpv_platform && matrix.os != 'linux' && !startsWith(github.ref, 'refs/tags/v') && github.repository == '4gray/iptvnator' && github.event_name != 'pull_request' && github.ref == 'refs/heads/master' && steps.embedded-mpv-runtime-cache.outputs.cache-hit != 'true' - uses: actions/cache/save@v4 + uses: actions/cache/save@v6 with: path: | vendor/embedded-mpv/${{ matrix.embedded_mpv_platform }}-${{ matrix.embedded_mpv_arch }}/include diff --git a/tools/packaging/snap-workflow-policy.test-helpers.mjs b/tools/packaging/snap-workflow-policy.test-helpers.mjs index 5fc55b065..1d1020c80 100644 --- a/tools/packaging/snap-workflow-policy.test-helpers.mjs +++ b/tools/packaging/snap-workflow-policy.test-helpers.mjs @@ -13,9 +13,9 @@ const PUBLISH_ACTION_ALLOWLIST = Object.freeze([ PINNED_UPLOAD_ARTIFACT_ACTION, ]); const BUILD_ACTION_ALLOWLIST = Object.freeze([ - 'actions/cache/restore@v4', - 'actions/cache/save@v4', - 'actions/cache@v4', + 'actions/cache/restore@v6', + 'actions/cache/save@v6', + 'actions/cache@v6', 'actions/checkout@v7', 'actions/download-artifact@v8', 'actions/setup-node@v4',