Skip to content

chore(deps-actions): update github-actions (major) - #287

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-github-actions
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-github-actions

Conversation

@renovate

@renovate renovate Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Pending Age Confidence
actions/cache action major v4.3.0 → v6.1.0 age confidence
actions/checkout action major v6 → v7 age confidence
actions/checkout action major v6.0.3 → v7.0.1 age confidence
actions/checkout action major v4 → v7 age confidence
actions/github-script action major v7 → v9 age confidence
actions/setup-node action major v6.4.0 → v7.0.0 v7.1.0 age confidence
codecov/codecov-action action major v6 → v7 age confidence
node uses-with major 22 → 24 age confidence
pnpm (source) uses-with major 11.11.0 → 12.10.0 12.10.1 age confidence

Release Notes

actions/cache (actions/cache)

v6.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

Compare Source

What's Changed
New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

Compare Source

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v5.0.2: v.5.0.2

Compare Source

v5.0.2
What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

v5.0.1

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


v5.0.1
What's Changed
v5.0.0
What's Changed

Full Changelog: actions/cache@v5...v5.0.1

v5.0.0

Compare Source

[!IMPORTANT]
actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


What's Changed

Full Changelog: actions/cache@v4.3.0...v5.0.0

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

  • Block checking out fork PR for pull_request_target and workflow_run by @​aiqiaoy in #​2454
  • Various dependency updates
actions/github-script (actions/github-script)

v9.0.0

Compare Source

New features:

  • getOctokit factory function — Available directly in the script context. Create additional authenticated Octokit clients with different tokens for multi-token workflows, GitHub App tokens, and cross-org access. See Creating additional clients with getOctokit for details and examples.
  • Orchestration ID in user-agent — The ACTIONS_ORCHESTRATION_ID environment variable is automatically appended to the user-agent string for request tracing.

Breaking changes:

  • require('@actions/github') no longer works in scripts. The upgrade to @actions/github v9 (ESM-only) means require('@actions/github') will fail at runtime. If you previously used patterns like const { getOctokit } = require('@actions/github') to create secondary clients, use the new injected getOctokit function instead — it's available directly in the script context with no imports needed.
  • getOctokit is now an injected function parameter. Scripts that declare const getOctokit = ... or let getOctokit = ... will get a SyntaxError because JavaScript does not allow const/let redeclaration of function parameters. Use the injected getOctokit directly, or use var getOctokit = ... if you need to redeclare it.
  • If your script accesses other @actions/github internals beyond the standard github/octokit client, you may need to update those references for v9 compatibility.

What's Changed

New Contributors

Full Changelog: actions/github-script@v8.0.0...v9.0.0

v8.0.0

Compare Source

actions/setup-node (actions/setup-node)

v7.0.0

Compare Source

What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency update:
New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

codecov/codecov-action (codecov/codecov-action)

v7.1.1

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

Compare Source

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

v7.0.0

Compare Source

⚠️ Due to migration issues with keybase, we are unable to update our keys under the codecovsecurity account. We have deleted the account and are using codecovsecops with the original gpg key

What's Changed

Full Changelog: codecov/codecov-action@v6.0.1...v7.0.0

actions/node-versions (node)

v24.21.0: 24.21.0

Compare Source

Node.js 24.21.0

v24.20.0: 24.20.0

Compare Source

Node.js 24.20.0

v24.19.0: 24.19.0

Compare Source

Node.js 24.19.0

v24.18.1: 24.18.1

Compare Source

Node.js 24.18.1

v24.18.0: 24.18.0

Compare Source

Node.js 24.18.0

v24.17.0: 24.17.0

Compare Source

Node.js 24.17.0

v24.16.0: 24.16.0

Compare Source

Node.js 24.16.0

v24.15.0: 24.15.0

Compare Source

Node.js 24.15.0

v24.14.1: 24.14.1

Compare Source

Node.js 24.14.1

v24.14.0: 24.14.0

Compare Source

Node.js 24.14.0

v24.13.1: 24.13.1

Compare Source

Node.js 24.13.1

v24.13.0: 24.13.0

Compare Source

Node.js 24.13.0

v24.12.0: 24.12.0

Compare Source

Node.js 24.12.0

v24.11.1: 24.11.1

Compare Source

Node.js 24.11.1

v24.11.0: 24.11.0

Compare Source

Node.js 24.11.0

v24.10.0: 24.10.0

Compare Source

Node.js 24.10.0

v24.9.0: 24.9.0

Compare Source

Node.js 24.9.0

v24.8.0: 24.8.0

Compare Source

Node.js 24.8.0

v24.7.0: 24.7.0

Compare Source

Node.js 24.7.0

v24.6.0: 24.6.0

Compare Source

Node.js 24.6.0

v24.5.0: 24.5.0

Compare Source

Node.js 24.5.0

v24.4.1: 24.4.1

Compare Source

Node.js 24.4.1

v24.4.0: 24.4.0

Compare Source

Node.js 24.4.0

v24.3.0: 24.3.0

Compare Source

Node.js 24.3.0

v24.2.0: 24.2.0

Compare Source

Node.js 24.2.0

v24.1.0: 24.1.0

Compare Source

Node.js 24.1.0

v24.0.2: 24.0.2

Compare Source

Node.js 24.0.2

v24.0.1: 24.0.1

Compare Source

Node.js 24.0.1

v24.0.0: 24.0.0

Compare Source

Node.js 24.0.0

pnpm/pnpm (pnpm)

v12.10.0: pnpm 12.10.0

Compare Source

This release adds an experimental loaded node linker, lets pnpm-lock.yaml record resolution settings, and reads cached registry metadata faster. It also carries several security fixes, including one that stops a dependency version from writing files outside the global virtual store.

Minor Changes
  • Added experimental nodeLinker: { type: loaded } installation. Compatible dependencies load directly from the content-addressable store through an automatically registered Node.js loader. nodeLinker.excluded selects packages and their dependency trees to install in the global virtual store.

  • lockfile.includeResolutionSettings: true makes pnpm-lock.yaml record autoDedupe, dedupeInjectedDeps, dedupePeerDependents and linkWorkspacePackages. Installs then treat a lockfile that records other values as outdated. A lockfile that records autoDedupe is reused by later installs on any machine, so pnpm run after pnpm install --frozen-lockfile no longer starts another install #​16583.

Patch Changes
Security
  • pnpm install now prevents dependency versions with path traversal from writing files outside the global virtual store.

  • pnpm now verifies locked config dependencies against their registry before installing them. Config dependencies must come from an npm registry. The lockfile can no longer replace the integrity of a config dependency pinned with version+integrity.

  • Lockfile verification now checks the tarballs inside a variations resolution against the registry. A name@version lockfile entry with an empty variations resolution is now rejected.

  • pnpm audit signatures now verifies signatures against the integrity recorded in the lockfile. Packages without a recorded integrity cannot pass signature verification.

  • pnpm install and pnpm publish now reject archive metadata larger than 64 MiB before reading it into memory. Publishing a pre-built tarball also rejects manifests and README files larger than 64 MiB.

  • Two URL or local path dependencies no longer share a virtual store directory when one URL has +, #, :, or ? where the other has /. Such dependencies, including git dependencies pinned with #, now get a hash suffix on their directory name.

  • The warning about an ignored project .npmrc registry setting no longer prints the username and password of a URL-scoped key such as //user:password@registry.example.com/${PATH}/:_authToken.

Installing and resolving dependencies
  • pnpm install now fails with ERR_PNPM_UNSUPPORTED_PROTOCOL when a dependency uses a specifier with a protocol pnpm does not support, such as Yarn's patch:. On Windows, such a specifier failed with os error 123. On other platforms, pnpm linked it to a directory that does not exist. Reading a package.json that fails now names the file #​16590.

  • pnpm install now fails with ERR_PNPM_PACKAGE_MANIFEST_INVALID_ATTRIBUTE when a project declares a dependency whose specifier is not a string, such as "is-positive": 42. Before, the dependency was silently left out of the lockfile. A readPackage hook can still correct the specifier.

  • Fixed pnpm install failing with ERR_PNPM_CMD_SHIM_RESOLVE_PATH when an executable's parent directory contains a dangling symlink.

  • pnpm install --frozen-lockfile no longer fails with ERR_PNPM_RESOLUTION_SHAPE_MISMATCH when a name@version lockfile entry has a resolution served by a custom fetcher pnpm/tasks#108.

  • pnpm install --fix-lockfile repairs a lockfile whose importer references a package that has no snapshot entry, as left by a badly merged lockfile. It failed with ERR_PNPM_LOCKFILE_MISSING_DEPENDENCY since 12.8.0 #​16618.

  • When a dependency moves an exact dependency of its own to an older version, a peer dependency that pnpm installed automatically now moves with it. Before, pnpm install and pnpm dedupe kept the newer locked version of the peer, so the lockfile held two copies of it, for example two copies of vue pnpm/tasks#61.

  • pnpm dedupe now reads registry metadata for a dependency pinned to an exact version, as pnpm install does. If the registry metadata disagreed with the package's package.json, the lockfile it wrote depended on whether minimumReleaseAge was set #​16615.

Speed and size
  • Dependency resolution reads cached registry metadata faster. The metadata cache moved to <cache-dir>/v12/, so the first install after upgrading downloads registry metadata again. A damaged cache entry is downloaded again, or reported as an error when --offline is set. pnpm cache prune also removes the metadata cache that older pnpm versions wrote under <cache-dir>/v11/ #​13512.

  • Package metadata requests no longer wait behind queued tarball downloads when maxSockets or a proxy limits the connections to a registry. Large installs resolve faster and print fewer Request took warnings.

  • Sped up installs in large workspaces on macOS when the dependency links already exist. pnpm now keeps a link that already points at the right package without trying to create it first. Relinking the direct dependencies of 1,000 workspace projects took 45 ms, down from 116 ms pnpm/tasks#65.

  • Commands in a project that pins a different pnpm version start about 13 ms faster on macOS. pnpm now runs the pinned version's binary directly, without the shell script in front of it pnpm/tasks#66.

  • The pnpm binary is about 0.9 MB smaller, and the arm64 Linux binary is about 1 MB smaller still.

Running scripts and commands
  • pnpm run no longer prints [ELIFECYCLE] Command failed ... after Ctrl+C ends the script. pnpm still exits the way the script's shell did: on Windows with the shell's exit code (cmd reports -1073741510, PowerShell 1), on Unix by re-raising SIGINT #​16579.

  • pnpm run "/<regex>/" now accepts JavaScript regular expression syntax such as lookahead and lookbehind. A selector like "/^hello:(?!b).*$/" failed with ERR_PNPM_NO_SCRIPT #​16604.

  • pnpm run and pnpm exec now forward --config.* command-line flags to the install started by verifyDepsBeforeRun pnpm/tasks#60.

  • On Windows, a process started by pnpm run or pnpm exec can again start a child with CREATE_BREAKAWAY_FROM_JOB. That child keeps running after pnpm exits, even if the command fails #​16628.

  • Empty nodeOptions values from command-line flags and environment variables now override lower-priority settings. Scripts retain NODE_OPTIONS from the parent environment or extraEnv when nodeOptions is empty.

  • pnpm now reads the failIfNoMatch setting from pnpm-workspace.yaml, so a filter that matches no workspace project exits with code 1 when the setting is true. The new --no-fail-if-no-match flag turns the setting off for one command #​16577.

Configuration, setup, and pnpm versions
  • pnpm config get --global and pnpm config list --global now show only the global configuration, also when run inside a project. Settings from the project's pnpm-workspace.yaml and .npmrc were included before. The same applies to --location=global #​16598.

  • pnpm now prints config warnings, such as an unset environment variable in .npmrc, when loading the config fails.

  • pnpm 11 releases older than 11.28.4 can run pnpm 12 again when the packageManager field pins it. Since 12.9.0 they failed with SyntaxError: Invalid or unexpected token #​16594.

  • On Windows, pnpm self-update no longer runs the update a second time when it replaces a pnpm.cmd linked by pnpm 12.8 or older. cmd.exe read on in the replaced pnpm.cmd, printed an error about a command that is not recognized, and ran the new pnpm once more #​16573.

  • pnpm setup now puts $PNPM_HOME/bin first on PATH in login shells that inherited it further down, such as the VS Code terminal on macOS. Before, another node took precedence over the one installed by pnpm runtime set node -g. Run pnpm setup again to update the block in your shell config #​16635.

  • pnpm setup now names the shell config file even if it is already up to date #​16608.

Updating, auditing, and publishing
  • pnpm update --latest now applies the savePrefix setting when it rewrites a dependency whose range has no operator of its own, such as <2.0.0.

  • The interactive pnpm audit --fix picker now shows each patched version with the saveExact and savePrefix style that the override is written with #​13209.

  • pnpm unpublish <pkg>@<version> now deletes the tarball under the registry's path when the registry is served under one, such as Gitea's npm registry. It used to send the delete to the host root and report success without removing the version #​16568. It also no longer mistakes a sibling path such as /npm-mirror/ for the registry path /npm/ pnpm/tasks#94.

Output and messages
  • A warning about a project's devEngines or packageManager pin is now printed to stderr. A command such as pnpm cache path or pnpm list --json keeps only its own output on stdout #​16584.

  • pnpm list now reports the correct package paths when nodeLinker is hoisted #​9593.

  • Resolution errors now name the failing dependency and its parent packages. Fatal errors appear as structured error records with their error codes when using --reporter=ndjson.

  • The error for an invalid git repository in the lockfile now has the code ERR_PNPM_INVALID_GIT_REPOSITORY. Its message now lists every rejected form of the value.

  • pnpm runtime --help and pnpm help runtime now name the set subcommand and the runtimes it accepts #​16580.

Platinum Sponsors
Bit OpenAI Notion
CodeRabbit
Gold Sponsors
Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.9.1: pnpm 12.9.1

Compare Source

This release moves the WebContainer build into a separate @pnpm/wasm package, shrinks the pnpm package back to about 4 MB, and fixes pnpm publish with provenance from GitLab CI.

Patch Changes
  • The WebAssembly build for StackBlitz WebContainers now ships as a separate @pnpm/wasm package. The pnpm and @pnpm/exe packages no longer include it, which brings their unpacked size back from about 55 MB to about 4 MB. In a WebContainer, install @pnpm/wasm with npm to get the pnpm command.

  • pnpm publish with provenance from GitLab CI is no longer rejected by the npm registry with a 422 error. The provenance statement now includes the GitLab CI variables in invocation.parameters, as npm does #​16551.

  • pnpm audit signatures now uses the TLS settings of the redirect target when a registry redirects its signing-keys request, for example to registry.npmjs.org. A cafile scoped to a private registry no longer makes the redirected request fail #​16541.

  • Fixed pnpm install --frozen-lockfile rejecting an up-to-date lockfile when an injected workspace package uses a catalog entry in peerDependencies #​16557.

  • The [<since>] filter selector works again with Git 2.24 through 2.27 #​16561. With Git older than 2.24, the selector now fails with an error that names the required Git version.

    It also detects changes in projects whose directory names contain non-ASCII characters. Such a change used to be credited to the parent project. changedFilesIgnorePattern and testPattern now match changed files whose names contain non-ASCII characters.

  • The pnpm executable is about 10% smaller. On macOS arm64 it went from 45.1 MB to 40.3 MB.

  • Sped up trust downgrade checks for packages with long release histories.

  • With optimisticRepeatInstall: false, pnpm install now runs the projects' own lifecycle scripts, such as prepare, even when node_modules is already up to date #​16545.

  • pnpm self-update now fails for Homebrew-installed pnpm and prints the brew upgrade command for the installed formula, such as brew upgrade pnpm or brew upgrade pnpm@11. It used to install a second copy of pnpm that the Homebrew one kept shadowing #​16547.

Platinum Sponsors

Bit OpenAI Notion
CodeRabbit

Gold Sponsors

Sanity Discord Vite
SerpApi Stackblitz Workleap
Nx Latitude

v12.9.0: pnpm 12.9

Compare Source

This release runs pnpm in StackBlitz WebContainers, adds a per-registry networkConcurrency setting, and records every installed project in the store. It also carries a security fix for pnpm login.

Minor Changes
  • pnpm now automatically uses WebAssembly in StackBlitz WebContainers, including when installation scripts are disabled. Native installations continue to use the native executable when installation scripts are enabled.

  • A registries entry can now set networkConcurrency, the most requests pnpm keeps in flight to that registry's origin. Requests to other registries keep the overall limit. The setting may live in pnpm-workspace.yaml or the global config.yaml.

    registries:
      https://npm.corp.example.com/:
        scopes: ["@acme"]
        networkConcurrency: 4
  • pnpm install now records every project it installs in the store's projects directory, as a symlink to the project directory. A --frozen-store install without the global virtual store still records nothing. Only projects that used the global virtual store were recorded before #​6929.

Patch Changes
  • pnpm login no longer forwards credentials in its request body to another origin during redirects.
Installing packages
  • Fixed pnpm install failing on Android with ERR_PNPM_STORE_DIR_ACQUIRE_OPERATION_LOCK #​16508.

  • pnpm install --frozen-lockfile again succeeds when a workspace project recorded in pnpm-lock.yaml has no directory, such as a project left out of a Docker build context. It still fails if the project's directory exists without a package.json #​16453.

  • pnpm install --frozen-lockfile no longer requires a pnpm-lock.yaml in a project that has no dependencies. It also succeeds when pnpm-lock.yaml records only the pinned pnpm version, as other commands write it when they run before the first install #​16477.

  • Fixed pnpm install --frozen-lockfile rejecting a fresh lockfile when an injected workspace dependency has an optional peer supplied by another workspace project #​16428.

  • With nodeLinker: hoisted, a filtered install now keeps the packages of the workspace projects an earlier install put in node_modules. This also covers the install that pnpm --filter <selector> run and pnpm --filter <selector> exec start before the command. Before, these installs removed every package that only the unselected projects needed #​16483.

  • pnpm install with nodeLinker: hoisted now refreshes directories supplied by custom fetchers when reinstalling. pnpm also keeps the symlinks inside those directories.

  • With enableGlobalVirtualStore on, scripts can run entry points that a CommonJS require hook loads again, such as ts-node index.ts. They failed with ERR_UNKNOWN_FILE_EXTENSION on Node.js versions without built-in TypeScript support #​16436.

  • pnpm now keeps each project's current lockfile and hidden hoisted dependencies in its own node_modules/.pnpm when virtualStoreDir points at a shared global virtual store. --virtual-store-dir now sets the global virtual store's location too pnpm/tasks#47.

  • pnpm clean no longer deletes the project when virtualStoreDir or globalVirtualStoreDir is set to the project directory. It also leaves a directory outside the project alone when the setting reaches it through a symlink. It now removes a global virtual store that globalVirtualStoreDir places inside the project, as it does for virtualStoreDir.

Optional dependencies
  • pnpm install no longer fails when a dependency of an optional dependency is missing from the registry. Like npm, pnpm now leaves out the nearest optional dependency above it, together with its subtree #​16511.

  • When an optional dependency fails to build, pnpm now removes its link from node_modules. A repeat pnpm install then reports "Already up to date" and no longer reruns the failing build #​16468.

  • pnpm install now prints a warning with the error when an optional dependency cannot be fetched and is skipped. The skipped package is no longer counted in the Packages: +N summary. The pnpm:skipped-optional-dependency log reports the skip with the fetch_failure reason #​16514.

Resolving dependencies
  • Fixed pnpm install changing an unchanged project's direct dependency to a sibling

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (in timezone America/Havana)

  • Branch creation
    • At 05:00 PM through 11:59 PM and 12:00 AM through 06:59 AM, Monday through Friday (* 17-23,0-6 * * 1-5)
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested review from a team and yacosta738 October 8, 2026 05:01
@github-actions github-actions Bot added the area/ci CI, tooling, and automation label Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 73c7ba10-a293-460d-b0ee-454dc491c037

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Oct 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@renovate
renovate Bot force-pushed the renovate/major-github-actions branch from ad2398b to 89bcaee Compare October 8, 2026 08:09
@github-actions github-actions Bot added product/shared Cortex-wide tooling, shared infrastructure and cross-product work area/release Packaging, versioning, publishing and distribution labels Oct 8, 2026
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 5 times, most recently from 9ef0e85 to ef8edf3 Compare October 8, 2026 15:40
yacosta738
yacosta738 previously approved these changes Oct 8, 2026
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch from ef8edf3 to 313afa4 Compare October 8, 2026 15:46
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch 7 times, most recently from bf08ed6 to 2706dd9 Compare October 9, 2026 10:40
@renovate
renovate Bot force-pushed the renovate/major-github-actions branch from 2706dd9 to 0a242db Compare October 9, 2026 11:29
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci CI, tooling, and automation area/release Packaging, versioning, publishing and distribution dependencies github-actions product/shared Cortex-wide tooling, shared infrastructure and cross-product work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant