Skip to content

chore(deps): bump actions/upload-artifact from 4 to 7 - #855

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-artifact-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown

Bumps actions/upload-artifact from 4 to 7.

Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: actions/upload-artifact@v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: actions/upload-artifact@v5.0.0...v6.0.0

v5.0.0

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

... (truncated)

Commits
  • 043fb46 Merge pull request #797 from actions/yacaovsnc/update-dependency
  • 634250c Include changes in typespec/ts-http-runtime 0.3.5
  • e454baa Readme: bump all the example versions to v7 (#796)
  • 74fad66 Update the readme with direct upload details (#795)
  • bbbca2d Support direct file uploads (#764)
  • 589182c Upgrade the module to ESM and bump dependencies (#762)
  • 47309c9 Merge pull request #754 from actions/Link-/add-proxy-integration-tests
  • 02a8460 Add proxy integration test
  • b7c566a Merge pull request #745 from actions/upload-artifact-v6-release
  • e516bc8 docs: correct description of Node.js 24 support in README
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](actions/upload-artifact@v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/upload-artifact-7 branch from 457196b to 9e83257 Compare October 4, 2026 12:29
@dependabot
dependabot Bot deployed to staging October 4, 2026 12:29 Active
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🛡️ Frontend Security Scan

npm audit
# npm audit report

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
# npm audit report

@vitest/mocker  2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix --force`
Will install storybook@10.6.1, which is a breaking change
node_modules/@vitest/mocker
  storybook  9.1.0-alpha.0 - 10.1.0-beta.6
  Depends on vulnerable versions of @vitest/mocker
  node_modules/storybook
    @storybook/addon-docs  <=0.0.0-pr-35259-sha-153697da || 9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/csf-plugin
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-docs
    @storybook/addon-links  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-links
    @storybook/builder-webpack5  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of fork-ts-checker-webpack-plugin
    Depends on vulnerable versions of storybook
    Depends on vulnerable versions of webpack-dev-middleware
    node_modules/@storybook/builder-webpack5
      @storybook/nextjs  *
      Depends on vulnerable versions of @storybook/builder-webpack5
      Depends on vulnerable versions of @storybook/preset-react-webpack
      Depends on vulnerable versions of @storybook/react
      Depends on vulnerable versions of node-polyfill-webpack-plugin
      Depends on vulnerable versions of storybook
      node_modules/@storybook/nextjs
    @storybook/core-webpack  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/core-webpack
    @storybook/csf-plugin  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/csf-plugin
    @storybook/preset-react-webpack  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of @storybook/react-docgen-typescript-plugin
    Depends on vulnerable versions of storybook
    node_modules/@storybook/preset-react-webpack
    @storybook/react  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react
    @storybook/react-dom-shim  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react-dom-shim

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/braces
  chokidar  2.0.0 - 3.6.0
  Depends on vulnerable versions of braces
  node_modules/chokidar
    fork-ts-checker-webpack-plugin  0.4.7 - 4.0.0-beta.5 || 6.0.0-alpha.1 - 9.0.3
    Depends on vulnerable versions of chokidar
    node_modules/fork-ts-checker-webpack-plugin
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    @storybook/react-docgen-typescript-plugin  *
    Depends on vulnerable versions of micromatch
    node_modules/@storybook/react-docgen-typescript-plugin
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/@shadcn/registry/node_modules/fast-glob
    node_modules/@ts-morph/common/node_modules/fast-glob
    node_modules/fast-glob
    node_modules/shadcn/node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
      @shadcn/registry  0.0.0-beta-20261001093212 || >=0.1.0
      Depends on vulnerable versions of fast-glob
      Depends on vulnerable versions of ts-morph
      node_modules/@shadcn/registry
        shadcn  <=0.0.0-beta-20261001093212 || >=2.0.0
        Depends on vulnerable versions of @shadcn/registry
        Depends on vulnerable versions of fast-glob
        Depends on vulnerable versions of ts-morph
        node_modules/shadcn
      @ts-morph/common  0.2.0 - 0.24.0 || 0.26.0 - 0.27.0
      Depends on vulnerable versions of fast-glob
      node_modules/@ts-morph/common
        ts-morph  6.0.1 - 23.0.0 || 25.0.0 - 26.0.0
        Depends on vulnerable versions of @ts-morph/common
        node_modules/ts-morph

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/elliptic
  browserify-sign  >=2.4.0
  Depends on vulnerable versions of elliptic
  node_modules/browserify-sign
    crypto-browserify  >=3.4.0
    Depends on vulnerable versions of browserify-sign
    Depends on vulnerable versions of create-ecdh
    node_modules/crypto-browserify
      node-polyfill-webpack-plugin  <=4.0.0
      Depends on vulnerable versions of crypto-browserify
      node_modules/node-polyfill-webpack-plugin
  create-ecdh  *
  Depends on vulnerable versions of elliptic
  node_modules/create-ecdh

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

webpack-dev-middleware  <7.4.5
Severity: high
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath - https://github.com/advisories/GHSA-g84c-rxfj-3j2c
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/webpack-dev-middleware

31 vulnerabilities (5 low, 11 moderate, 15 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force
ESLint
> flowstar@0.1.0 lint
> eslint .


/home/runner/work/FlowStar/FlowStar/next.config.mjs
  15:5  warning  Unexpected console statement  no-console

/home/runner/work/FlowStar/FlowStar/scripts/check-secrets.mjs
  28:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
  31:16  warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  47:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  52:9   warning  Unexpected console statement                                               no-console
  60:3   warning  Unexpected console statement                                               no-console
  63:3   warning  Unexpected console statement                                               no-console

/home/runner/work/FlowStar/FlowStar/scripts/soroban-security-check.mjs
   14:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
   16:9   warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  135:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  142:7   warning  Unexpected console statement                                               no-console
  150:3   warning  Unexpected console statement                                               no-console
  154:3   warning  Unexpected console statement                                               no-console
  159:3   warning  Unexpected console statement                                               no-console

✖ 14 problems (0 errors, 14 warnings)
Hardcoded secrets check
✅ No hardcoded secrets found.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1290 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

This branch was successfully deployed

1 active deployment
staging — 9e832577 Deployed Oct 4, 2026 by dependabot[bot] via deploy-staging #303
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants