ci(deps): bump checkout/upload-artifact/download-artifact majors (#1264)

Supersedes #1249, #1245 and #1247, which each rewrote the full-commit pins in
publish-snap.yaml while the same SHAs are asserted in three packaging test
files — merged separately, every one of them left those tests red.

actions/checkout v4 -> v7 (docker.yml from v6), actions/upload-artifact
v4 -> v7, actions/download-artifact v4 -> v8. New pins verified against the
upstream tag refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d =
v7.0.1, download-artifact 3e5f45b2 = v8.0.1.

download-artifact v8 changes two things on the Snap publish path, both in our
favour: a digest mismatch now fails the run instead of logging a warning, and
decompression is skipped for non-zip Content-Types (our artifact is a normal
upload-artifact zip, so unchanged). checkout v7's fork-PR block only applies to
pull_request_target/workflow_run, neither of which exists here.
This commit is contained in:
4gray authored and GitHub committed 2026-07-26 19:54:39 +02:00
1 parent d5f5beab38
commit f193232dab
10 files changed
+39 -39

No files matched your search

@@ -174,13 +174,13 @@ test('isolates released verification from the fresh credentialed upload runner',
assert.deepEqual(
verifyJob.steps.filter((step) => step.uses).map((step) => step.uses),
[
'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5',
'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02',
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1',
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a',
]
);
assert.deepEqual(
publishJob.steps.filter((step) => step.uses).map((step) => step.uses),
['actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093']
['actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c']
);
const bindingStep = verifyJob.steps.find(
+3 -3
View File
@@ -1563,7 +1563,7 @@ test('publish workflow installs the source verifier and binds the release tag re
);
assert.equal(
checkoutStep.uses,
'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5'
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
);
assert.equal(snapcraftStep.uses, undefined);
assert.match(
@@ -1594,11 +1594,11 @@ test('publish workflow installs the source verifier and binds the release tag re
);
assert.equal(
transferStep.uses,
'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02'
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
);
assert.equal(
artifactDownloadStep.uses,
'actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093'
'actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
);
assert.ok(
publishJob.steps.indexOf(artifactDownloadStep) <
@@ -2,11 +2,11 @@ import assert from 'node:assert/strict';
import { parse } from 'yaml';
const PINNED_CHECKOUT_ACTION =
'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5';
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1';
const PINNED_UPLOAD_ARTIFACT_ACTION =
'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02';
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a';
const PINNED_DOWNLOAD_ARTIFACT_ACTION =
'actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093';
'actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c';
const PUBLISH_ACTION_ALLOWLIST = Object.freeze([
PINNED_CHECKOUT_ACTION,
PINNED_DOWNLOAD_ARTIFACT_ACTION,
@@ -16,10 +16,10 @@ const BUILD_ACTION_ALLOWLIST = Object.freeze([
'actions/cache/restore@v4',
'actions/cache/save@v4',
'actions/cache@v4',
'actions/checkout@v4',
'actions/download-artifact@v4',
'actions/checkout@v7',
'actions/download-artifact@v8',
'actions/setup-node@v4',
'actions/upload-artifact@v4',
'actions/upload-artifact@v7',
'pnpm/action-setup@v4',
'softprops/action-gh-release@v2',
]);