Files
iptvnator/tools
4grayandClaude Opus 5 319a0404aa ci(deps): bump checkout/upload-artifact/download-artifact majors
Supersedes the three individual Dependabot PRs (#1249, #1245, #1247) so the
pinned-SHA contract stays consistent in one commit.

actions/checkout v4 -> v7, actions/upload-artifact v4 -> v7 and
actions/download-artifact v4 -> v8 across every workflow. docker.yml moves
from checkout v6 to v7 with the rest.

publish-snap.yaml keeps full-commit pins, so the three new SHAs are updated
there and in the packaging policy tests that assert them
(snap-workflow-policy.test-helpers.mjs, publish-snap-workflow.test.mjs,
release-snap-assets.test.mjs). Each SHA was checked against the upstream tag
refs: checkout 3d3c42e5 = v7.0.1, upload-artifact 043fb46d = v7.0.1,
download-artifact 3e5f45b2 = v8.0.1. BUILD_ACTION_ALLOWLIST follows the
unpinned bumps in build-and-make.yaml.

download-artifact v8 changes two behaviours that matter for the Snap publish
path, both in our favour: an artifact digest mismatch now fails the run
instead of logging a warning, and the action only unzips responses whose
Content-Type says zip. The publish job downloads a normal upload-artifact
artifact by name, so decompression is unchanged, and it re-verifies the
receipt digest itself regardless.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 02:24:52 +02:00
..