Skip to content

ci(deps): bump actions/setup-node from 4 to 7 - #30

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7
Open

ci(deps): bump actions/setup-node from 4 to 7#30
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown

Bumps actions/setup-node from 4 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown

bulwark

  • scan — 2 semgrep findings
error output
typescript: using ambient node 22.23.2 (no version declared by this repo)
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
The `json` and `json-pretty` reporters are experimental and may change in patch releases.
From https://github.com/wardnet/wardnet-status
 * branch            main       -> FETCH_HEAD
e9206f428a184ff01f1e7993d2e718ac16c18e12
creating virtual environment...
installing semgrep from spec 'semgrep==1.168.0'...
done! ✨ 🌟 ✨
  installed package semgrep 1.168.0, installed using Python 3.12.3
  These apps are now available
    - pysemgrep
    - semgrep
               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 3 files tracked by git with 1074 Code rules:
                                                                                                                        
  Language      Rules   Files          Origin      Rules                                                                
 ─────────────────────────────        ───────────────────                                                               
  <multilang>      47       3          Community    1074                                                                
  yaml             35       3                                                                                           
                                                                                                                        
  Current version has 6 findings.

Creating git worktree from 'e9206f428a184ff01f1e7993d2e718ac16c18e12' to scan baseline.
  Will report findings introduced by these commits (may be incomplete for shallow checkouts):
    * 2dc7c03 Merge 66dd9587be9ffbba7b6c07fa05b8a4307087995e into e9206f428a184ff01f1e7993d2e718ac16c18e12
    * 66dd958 ci(deps): bump actions/setup-node from 4 to 7

               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 1 file tracked by git with 1 Code rule:
  Scanning 1 file.
                   
                   
┌─────────────────┐
│ 2 Code Findings │
└─────────────────┘
                                
    .github/workflows/deploy.yml
    ❯❱ yaml.github-actions.security.github-actions-mutable-action-tag.github-actions-mutable-action-tag
          ❰❰ Blocking ❱❱
          GitHub Actions step uses a mutable tag or branch reference. Tags and branch names can be silently   
          repointed by the action owner, enabling supply-chain attacks — as seen in the trivy-action and kics-
          github-action compromises. Pin the reference to a full 40-character commit SHA instead, e.g. `uses: 
          actions/checkout@8ade135a41bc03ea155e62e844d188df1ea18608`.                                         
          Details: https://sg.run/2LgAL                                                                       
                                                                                                              
           29┆ - uses: actions/setup-node@v7
            ⋮┆----------------------------------------
           49┆ - uses: actions/setup-node@v7

                
                
┌──────────────┐
│ Scan Summary │
└──────────────┘
✅ Scan completed successfully.
 • Findings: 2 (2 blocking)
 • Rules run: 82
 • Targets scanned: 3
 • Parsed lines: ~100.0%
 • Scan was limited to files changed since baseline commit.
 • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
Ran 82 rules on 3 files: 2 findings.
[PASS] biome(.)
[PASS] biome(./page)
[PASS] biome(./worker)
[FAIL] semgrep
Error: 1 check(s) failed
bulwark: 1 check(s) failed
  • coverage — see error output below

📦 Full bulwark output — complete scan and coverage logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants