Skip to content

chore: Cherry-picked changes from upstream - #45

Merged
Raj-StepSecurity merged 13 commits into
mainfrom
auto-cherry-pick
Oct 1, 2026
Merged

Raj-StepSecurity merged 13 commits into
mainfrom
auto-cherry-pick

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Cherry-picked changes from upstream.

jfrog/setup-jfrog-cli@v5.1.0...v5.2.0

* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
* Document that latest plus download-repository can return a stale CLI.

Log an info line for that combination so CI can pin a version instead of relying on generic [RELEASE].

* Clarify non-failing latest repository guidance

* Explain the cached [RELEASE] path behavior

* Soften version guidance and cite Artifactory cache behavior

* Drop metadata wording from latest+download-repository docs

* Pin Go 1.24 for Auto-Build and skip macOS Artifactory bootstrap

* Skip macOS Auto-Build cells the way jfrog-cli does (JGC-413)

* Exclude macOS from Auto-Build and match latest+download-repository wording.

* Test latest [RELEASE] download URLs and drop unused lint.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

🚀 PR Updated!

The PR has been updated with the latest cherry-picked commits.

@step-security/maintained-actions-dev Please review and approve the changes.

📦 Target Release Version: v5.2.0
📋 Previous Release Version: v5.1.0

⚠️ Completely Skipped Commits Due to only modifying files in: package.json, package-lock.json, yarn.lock, node_modules/, dist/, or .gitignore

  • 1641575d87647fb969c0545f0b6a76873e328b7c
  • deda456d982fc5e9a7a020b63eb0d2968aedd33e

❗ Missing Files:

  • lib/main.js
  • lib/utils.js
  • lib/cleanup.js
  • lib/utils.js

🛑 Workflow Files (Cannot be auto-applied by GitHub Actions):

  • .github/workflows/release.yml from commit b14f2d45ff4f61644304113a5f595c29d85002a8
  • .github/workflows/auto-build-publish.yml from commit 06e4295338235bb1d794a1529a12aed3023fc067
  • .github/workflows/frogbot-scan-repository.yml from commit 06e4295338235bb1d794a1529a12aed3023fc067

❌ Conflicting Files:

  • README.md from commit fd83e886ae9f3eb231639555770350520afcb9c3
  • README.md from commit 9ae8744290394e74dfcca36ea5d6d957687e5c63
  • action.yml from commit 9ae8744290394e74dfcca36ea5d6d957687e5c63
  • src/main.ts from commit 9ae8744290394e74dfcca36ea5d6d957687e5c63
  • src/utils.ts from commit 9ae8744290394e74dfcca36ea5d6d957687e5c63
  • test/main.spec.ts from commit 9ae8744290394e74dfcca36ea5d6d957687e5c63

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v5.1.0...v5.2.0

📋 File-by-File Analysis:

.github/workflows/auto-build-publish.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 2 deletions)

.github/workflows/frogbot-scan-repository.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 2 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+11 -1)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+3 -3)

lib/cleanup.js

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 2 deletions)

lib/utils.js

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 16 additions, 3 deletions)

src/cleanup.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+4 -2)

src/evidence-collection.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+0 -1)

src/job-summary.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+0 -3)

src/utils.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+15 -0)

test/main.spec.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+135 -0)

📊 Summary:

  • Total files changed upstream: 11
  • Files present in PR: 7/11
  • Files with matching changes: 7/11

❌ Overall Status: 🔴 INCOMPLETE - Missing files or changes

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v5.1.0...v5.2.0

📋 File-by-File Analysis:

.github/workflows/auto-build-publish.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 2 deletions)

.github/workflows/frogbot-scan-repository.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 2 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+11 -1)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+3 -3)

lib/cleanup.js

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 2 deletions)

lib/utils.js

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 16 additions, 3 deletions)

src/cleanup.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+4 -2)

src/evidence-collection.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+0 -1)

src/job-summary.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+0 -3)

src/utils.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+15 -0)

test/main.spec.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+135 -0)

📊 Summary:

  • Total files changed upstream: 11
  • Files present in PR: 7/11
  • Files with matching changes: 7/11

❌ Overall Status: 🔴 INCOMPLETE - Missing files or changes

@Raj-StepSecurity
Raj-StepSecurity merged commit 9aea594 into main Oct 1, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants