diff --git a/.github/workflows/containers.yml b/.github/workflows/containers.yml index 8467876de..2e2d650a3 100644 --- a/.github/workflows/containers.yml +++ b/.github/workflows/containers.yml @@ -678,7 +678,7 @@ jobs: - name: "Upload the digest-bound SBOM as a CI artifact (#3321)" if: matrix.sbom == true && github.event_name != 'pull_request' - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: # Keyed by the digest, not the run: two builds of the same commit # produce the same name, and a digest-keyed name is the one an diff --git a/.github/workflows/frontend-testing-pilot.yml b/.github/workflows/frontend-testing-pilot.yml index c2f693773..a214408ac 100644 --- a/.github/workflows/frontend-testing-pilot.yml +++ b/.github/workflows/frontend-testing-pilot.yml @@ -196,7 +196,7 @@ jobs: # keeps for generated evidence. - name: Upload the mutation report if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-mutation-report path: | diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml index 102124702..445f0e0d7 100644 --- a/.github/workflows/quality.yml +++ b/.github/workflows/quality.yml @@ -597,7 +597,7 @@ jobs: # per-run suffix costs no consumer. - name: Upload unit test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-unit-junit-${{ github.run_id }}-${{ github.run_attempt }} # The file is named explicitly rather than uploading its directory: @@ -669,7 +669,7 @@ jobs: # files the coverage reporter wrote, from the run above, can land here. - name: Upload unit test coverage if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-coverage-${{ github.run_id }}-${{ github.run_attempt }} path: arcane/home/honeypot-dashboard/frontend-next/coverage/ @@ -758,7 +758,7 @@ jobs: # gone and why the path is not the `.ci-artifacts/` directory. - name: Upload unit test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-unit-junit-${{ github.run_id }}-${{ github.run_attempt }} path: .ci-artifacts/frontend-next-unit-junit.xml @@ -782,7 +782,7 @@ jobs: run: npm run test:discovery - name: Upload unit test coverage if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-coverage-${{ github.run_id }}-${{ github.run_attempt }} path: arcane/home/honeypot-dashboard/frontend-next/coverage/ @@ -878,7 +878,7 @@ jobs: # upload above. - name: Upload browser test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-browser-junit-${{ github.run_id }}-${{ github.run_attempt }} path: .ci-artifacts/playwright-junit.xml @@ -889,7 +889,7 @@ jobs: # run it holds nothing worth storing. - name: Upload Playwright report and traces if: failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-browser-report-${{ github.run_id }}-${{ github.run_attempt }} # Both directories are named, not the frontend-next tree around @@ -949,7 +949,7 @@ jobs: # names, same explicit paths, no `overwrite: true`. - name: Upload browser test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-browser-junit-${{ github.run_id }}-${{ github.run_attempt }} path: .ci-artifacts/playwright-junit.xml @@ -957,7 +957,7 @@ jobs: retention-days: 7 - name: Upload Playwright report and traces if: failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: frontend-next-browser-report-${{ github.run_id }}-${{ github.run_attempt }} path: | @@ -1225,7 +1225,7 @@ jobs: # twin's upload for the full argument. - name: Upload test log if: failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: backend-service-cargo-test-log-${{ github.run_id }}-${{ github.run_attempt }} path: .ci-artifacts/cargo-test.log @@ -1322,7 +1322,7 @@ jobs: # same named-file path, no `overwrite: true`. - name: Upload test log if: failure() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: backend-service-cargo-test-log-${{ github.run_id }}-${{ github.run_attempt }} path: .ci-artifacts/cargo-test.log @@ -2515,7 +2515,7 @@ jobs: # sanitise a free-text field, so fixing that means renaming the row. - name: Upload test results if: always() - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: scripts-${{ matrix.name }}-results-${{ github.run_id }}-${{ github.run_attempt }} path: | diff --git a/.github/workflows/weekly-schemathesis.yml b/.github/workflows/weekly-schemathesis.yml index 8cf0b297a..975c01436 100644 --- a/.github/workflows/weekly-schemathesis.yml +++ b/.github/workflows/weekly-schemathesis.yml @@ -280,7 +280,7 @@ jobs: # what this job was last tested against, so the comment is corrected to # match the code rather than the code bumped to match the comment -- # changing the major would be a build-logic change, not a pin fix. - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: schemathesis-reports path: |