ci(deps): bump checkout/upload-artifact/download-artifact majors (#1264)

Supersedes #1249, #1245 and #1247, which each rewrote the full-commit pins in
publish-snap.yaml while the same SHAs are asserted in three packaging test
files — merged separately, every one of them left those tests red.

actions/checkout v4 -> v7 (docker.yml from v6), actions/upload-artifact
v4 -> v7, actions/download-artifact v4 -> v8. New pins verified against the
upstream tag refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d =
v7.0.1, download-artifact 3e5f45b2 = v8.0.1.

download-artifact v8 changes two things on the Snap publish path, both in our
favour: a digest mismatch now fails the run instead of logging a warning, and
decompression is skipped for non-zip Content-Types (our artifact is a normal
upload-artifact zip, so unchanged). checkout v7's fork-PR block only applies to
pull_request_target/workflow_run, neither of which exists here.
This commit is contained in:
4gray authored and GitHub committed 2026-07-26 19:54:39 +02:00
1 parent d5f5beab38
commit f193232dab
10 files changed
+39 -39

No files matched your search

+12 -12
View File
@@ -56,7 +56,7 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Setup Node.js
uses: actions/setup-node@v4
@@ -322,7 +322,7 @@ jobs:
test -s "${RUNTIME_ROOT}/source-archive-binding.json"
- name: Upload staged Linux runtime
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-embedded-mpv-runtime
path: vendor/embedded-mpv/linux-x64
@@ -330,7 +330,7 @@ jobs:
retention-days: 7
- name: Upload Linux runtime source compliance
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-frame-copy-runtime-sources
path: dist/compliance/linux-frame-copy-runtime-sources.tar.xz
@@ -370,7 +370,7 @@ jobs:
steps: &electron-build-steps
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install pnpm
uses: pnpm/action-setup@v4
@@ -424,7 +424,7 @@ jobs:
- name: Download pinned Linux Embedded MPV runtime
if: matrix.os == 'linux'
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
name: linux-embedded-mpv-runtime
path: vendor/embedded-mpv/linux-x64
@@ -1187,7 +1187,7 @@ jobs:
- name: Upload artifacts (macOS)
if: matrix.os == 'macos'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: macos-${{ matrix.arch }}-artifacts
path: |
@@ -1199,7 +1199,7 @@ jobs:
- name: Upload system-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'system'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-system-artifacts
path: |
@@ -1211,7 +1211,7 @@ jobs:
- name: Upload portable-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'portable'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-portable-artifacts
path: |
@@ -1223,7 +1223,7 @@ jobs:
- name: Upload Flatpak-runtime Linux artifacts
if: matrix.os == 'linux' && matrix.linux_profile == 'flatpak'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: linux-flatpak-artifacts
path: |
@@ -1232,7 +1232,7 @@ jobs:
- name: Upload artifacts (Windows)
if: matrix.os == 'windows'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: windows-artifacts
path: |
@@ -1294,10 +1294,10 @@ jobs:
steps:
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Download all artifacts
uses: actions/download-artifact@v4
uses: actions/download-artifact@v8
with:
path: artifacts