Commit b788266
authored
chore(deps): update actions/download-artifact action to v8 (#812)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
|
[actions/download-artifact](https://redirect.github.com/actions/download-artifact)
| action | major | `v5` → `v8` |
---
### Release Notes
<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>
###
[`v8.0.1`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.1)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8.0.1)
##### What's Changed
- Support for CJK characters in the artifact name by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​471](https://redirect.github.com/actions/download-artifact/pull/471)
- Add a regression test for artifact name + content-type mismatches by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​472](https://redirect.github.com/actions/download-artifact/pull/472)
**Full Changelog**:
<actions/download-artifact@v8...v8.0.1>
###
[`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8)
##### v8 - What's new
##### Direct downloads
To support direct uploads in `actions/upload-artifact`, the action will
no longer attempt to unzip all downloaded files. Instead, the action
checks the `Content-Type` header ahead of unzipping and skips non-zipped
files. Callers wishing to download a zipped file as-is can also set the
new `skip-decompress` parameter to `false`.
##### Enforced checks (breaking)
A previous release introduced digest checks on the download. If a
download hash didn't match the expected hash from the server, the action
would log a warning. Callers can now configure the behavior on mismatch
with the `digest-mismatch` parameter. To be secure by default, we are
now defaulting the behavior to `error` which will fail the workflow run.
##### ESM
To support new versions of the @​actions/\* packages, we've
upgraded the package to ESM.
##### What's Changed
- Don't attempt to un-zip non-zipped downloads by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to
`error` by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​461](https://redirect.github.com/actions/download-artifact/pull/461)
**Full Changelog**:
<actions/download-artifact@v7...v8.0.0>
###
[`v8`](https://redirect.github.com/actions/download-artifact/compare/v7...v8)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)
###
[`v7.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v7.0.0)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v7.0.0)
##### v7 - What's new
> \[!IMPORTANT]
> actions/download-artifact\@​v7 now runs on Node.js 24
(`runs.using: node24`) and requires a minimum Actions Runner version of
2.327.1. If you are using self-hosted runners, ensure they are updated
before upgrading.
##### Node.js 24
This release updates the runtime to Node.js 24. v6 had preliminary
support for Node 24, however this action was by default still running on
Node.js 20. Now this action by default will run on Node.js 24.
##### What's Changed
- Update GHES guidance to include reference to Node 20 version by
[@​patrikpolyak](https://redirect.github.com/patrikpolyak) in
[#​440](https://redirect.github.com/actions/download-artifact/pull/440)
- Download Artifact Node24 support by
[@​salmanmkc](https://redirect.github.com/salmanmkc) in
[#​415](https://redirect.github.com/actions/download-artifact/pull/415)
- fix: update
[@​actions/artifact](https://redirect.github.com/actions/artifact)
to fix Node.js 24 punycode deprecation by
[@​salmanmkc](https://redirect.github.com/salmanmkc) in
[#​451](https://redirect.github.com/actions/download-artifact/pull/451)
- prepare release v7.0.0 for Node.js 24 support by
[@​salmanmkc](https://redirect.github.com/salmanmkc) in
[#​452](https://redirect.github.com/actions/download-artifact/pull/452)
##### New Contributors
- [@​patrikpolyak](https://redirect.github.com/patrikpolyak) made
their first contribution in
[#​440](https://redirect.github.com/actions/download-artifact/pull/440)
- [@​salmanmkc](https://redirect.github.com/salmanmkc) made their
first contribution in
[#​415](https://redirect.github.com/actions/download-artifact/pull/415)
**Full Changelog**:
<actions/download-artifact@v6.0.0...v7.0.0>
###
[`v7`](https://redirect.github.com/actions/download-artifact/compare/v6...v7)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)
###
[`v6.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v6.0.0)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v6.0.0)
#### What's Changed
**BREAKING CHANGE:** this update supports Node `v24.x`. This is not a
breaking change per-se but we're treating it as such.
- Update README for download-artifact v5 changes by
[@​yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#​417](https://redirect.github.com/actions/download-artifact/pull/417)
- Update README with artifact extraction details by
[@​yacaovsnc](https://redirect.github.com/yacaovsnc) in
[#​424](https://redirect.github.com/actions/download-artifact/pull/424)
- Readme: spell out the first use of GHES by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​431](https://redirect.github.com/actions/download-artifact/pull/431)
- Bump `@actions/artifact` to `v4.0.0`
- Prepare `v6.0.0` by
[@​danwkennedy](https://redirect.github.com/danwkennedy) in
[#​438](https://redirect.github.com/actions/download-artifact/pull/438)
#### New Contributors
- [@​danwkennedy](https://redirect.github.com/danwkennedy) made
their first contribution in
[#​431](https://redirect.github.com/actions/download-artifact/pull/431)
**Full Changelog**:
<actions/download-artifact@v5...v6.0.0>
###
[`v6`](https://redirect.github.com/actions/download-artifact/compare/v5...v6)
[Compare
Source](https://redirect.github.com/actions/download-artifact/compare/v5.0.0...v6.0.0)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/EmergeTools/hackernews).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xODUuMSIsInVwZGF0ZWRJblZlciI6IjQzLjE4NS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent ba07e32 commit b788266
1 file changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
140 | | - | |
| 140 | + | |
141 | 141 | | |
142 | 142 | | |
143 | 143 | | |
| |||
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
194 | | - | |
| 194 | + | |
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
| |||
0 commit comments