mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 02:46:16 -08:00
Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the pinned-SHA contract stays consistent in one commit. actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and actions/download-artifact v4 -> v8 across every workflow. docker.yml moves from checkout v6 to v7 with the rest. publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated there and in the packaging policy tests that assert them (snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs, release-snap-assets.test.mjs). Each SHA was checked against the upstream tag refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1, download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the unpinned bumps in build-and-make.yaml. download-artifact v8 changes two behaviours that matter for the Snap publish path, both in our favour: an artifact digest mismatch now fails the run instead of logging a warning, and the action only unzips responses whose Content-Type says zip. The publish job downloads a normal upload-artifact artifact by name, so decompression is unchanged, and it re-verifies the receipt digest itself regardless. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>