Skip to content

Update GitHub Action Versions#48

Closed
morisil wants to merge 1 commit intomainfrom
gh-actions-update-1771892724
Closed

Update GitHub Action Versions#48
morisil wants to merge 1 commit intomainfrom
gh-actions-update-1771892724

Conversation

@morisil
Copy link
Member

@morisil morisil commented Feb 24, 2026

GitHub Actions Version Updates

@claude
Copy link

claude bot commented Feb 24, 2026

Code Review

This PR updates gradle/actions/setup-gradle from v5.0.1 to v5.0.2 in the reusable build-gradle.yml workflow.

Summary

This is a straightforward, low-risk dependency update. The v5.0.2 release (published 2026-02-23) is a maintenance release with no functional changes — it updates npm and Jackson dependencies, converts the project to ESM modules, and refreshes known Gradle wrapper checksums.

Assessment

Code quality: The change is minimal and correct — a single version pin bump with no other modifications.

Security: Pinning to a tagged version (@v5.0.2) rather than a commit SHA is a mild supply-chain consideration, but this is consistent with how the rest of the workflow references actions and is acceptable for a trusted action from the gradle org.

Potential improvement (non-blocking): For stronger supply-chain security, actions can be pinned to a full commit SHA (e.g. gradle/actions/setup-gradle@<sha> # v5.0.2). This protects against tag mutation. Worth considering as a future practice if the organization prioritizes it, but it is not required here.

No issues found. This update is safe to merge.

@morisil morisil closed this Feb 26, 2026
@morisil morisil deleted the gh-actions-update-1771892724 branch February 26, 2026 15:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant