chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1 - #13
chore(deps): bump actions/upload-artifact from 4.6.2 to 7.0.1#13dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.6.2 to 7.0.1. - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) --- updated-dependencies: - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM, straightforward version bump.
What was reviewed: the single-line change updating actions/upload-artifact from the pinned SHA for v4.6.2 to the pinned SHA for v7.0.1 in the "Upload freshness diagnostics" step. Confirmed the SHA and version comment match (ea165f8d... v4.6.2 to 043fb46d... v7.0.1) and that no other lines in the workflow changed — the with: block (name/path) is untouched.
Extended reasoning...
Overview
The PR is a Dependabot-authored one-line change to .github/workflows/documentation-freshness.yml, updating the pinned commit SHA (and accompanying version comment) for actions/upload-artifact from v4.6.2 to v7.0.1 in a single artifact-upload step. No other workflow logic, inputs, or steps are modified.
Security risks
The action is still pinned to a full commit SHA (not a mutable tag), which is the recommended supply-chain-security practice, so there is no reduction in pinning rigor. The new SHA (043fb46d1a93c77aae656e7c1c64a875d1fc6a0a) corresponds to the official actions/upload-artifact repository per the PR's commit links, and it's a well-known, first-party GitHub Action. There is no change to permissions, secrets, or inputs in this workflow step (name and path under with: are unchanged), so there's no meaningful new security surface introduced by this diff itself. The v7 release does include a major internal rewrite (ESM, new direct-upload feature flag) but since this workflow doesn't use the new archive parameter, behavior for this specific usage should be unaffected.
Level of scrutiny
This warrants minimal scrutiny: it is a routine automated dependency bump limited to a CI workflow file, doesn't touch application/plugin code, and only affects a diagnostics-upload step gated behind if: always() in what appears to be a non-critical documentation-freshness check job.
Other factors
No CODEOWNERS restrictions were found for workflow files, no prior review comments or CHANGES_REQUESTED states exist on this PR, and the bug-hunting pass reported zero findings. The change is minimal, mechanical, and self-contained, matching the standard criteria for auto-approval of dependency bumps.
Bumps actions/upload-artifact from 4.6.2 to 7.0.1.
Release notes
Sourced from actions/upload-artifact's releases.
... (truncated)
Commits
043fb46Merge pull request #797 from actions/yacaovsnc/update-dependency634250cInclude changes in typespec/ts-http-runtime 0.3.5e454baaReadme: bump all the example versions to v7 (#796)74fad66Update the readme with direct upload details (#795)bbbca2dSupport direct file uploads (#764)589182cUpgrade the module to ESM and bump dependencies (#762)47309c9Merge pull request #754 from actions/Link-/add-proxy-integration-tests02a8460Add proxy integration testb7c566aMerge pull request #745 from actions/upload-artifact-v6-releasee516bc8docs: correct description of Node.js 24 support in READMEDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)