Skip to content

Update external GitHub workflows - #1

Open
rybesh wants to merge 1 commit into
v1.0-DEVfrom
github-workflows-update/2026-05-29
Open

rybesh wants to merge 1 commit into
v1.0-DEVfrom
github-workflows-update/2026-05-29

Conversation

@rybesh

@rybesh rybesh commented May 29, 2026

Copy link
Copy Markdown
Member

Updates from gh-external-audit update:

  • actions/checkout: v2 → v6 (major tag)
  • actions/checkout: v4 → v6 (major tag)
  • actions/setup-java: v3 → v5 (major tag) — v3→v5 is Node 24 runtime; distribution/java-version/server-id/server-username/server-password all still supported
  • actions/setup-java: v4 → v5 (major tag) — v4→v5 is Node 24 runtime; distribution: temurin + java-version + cache: maven all still supported
  • actions/upload-artifact: v3 → v7 (major tag) — v3→v7. v4 was a major storage-architecture rewrite, but this workflow only uploads (no paired download in the same workflow), so no pairing concern. name/path inputs unchanged.
  • docker/build-push-action: 3b5e8027fcad23fda98b2e3ac259d8d67585f671 → f9f3042f (SHA) — preserving SHA pin; bumping to current v7.2.0 SHA
  • docker/login-action: f4ef78c080cd8ba55a85445d5b36e214a81df20a → 650006c6 (SHA) — preserving SHA pin (don't downgrade security); bumping to current v4.2.0 SHA
  • docker/metadata-action: 9ec57ed1fcdbf14dcef7dfbe97b2010124a938b7 → 80c7e94d (SHA) — preserving SHA pin; bumping to current v6.1.0 SHA
  • github/codeql-action: v2 → v4 (major tag) — v2 deprecated; v4 runs on Node 24. languages input unchanged
  • shrink/actions-docker-extract: v3 → v4 (major tag) — v3→v4 is just Node 24 runtime
  • softprops/action-gh-release: v1 → v3 (major tag) — v1→v3: v2 was Node 20, v3 is Node 24; files input unchanged

Not updated:

  • actions/setup-java: v1 (kept) — setup-java@v2+ made distribution a required input; this workflow only sets java-version: 17 so bumping would fail at runtime. Add distribution: temurin before re-running
  • enridaga/auto-release-milestone: master (kept) — audit reported no_release — the action has no GitHub releases to pin to; combined with @master branch pin (security flag), this requires upstream remediation

Updates from `gh-external-audit update`:

- actions/checkout: v2 → v6 (major tag)
- actions/checkout: v4 → v6 (major tag)
- actions/setup-java: v3 → v5 (major tag) — v3→v5 is Node 24 runtime; distribution/java-version/server-id/server-username/server-password all still supported
- actions/setup-java: v4 → v5 (major tag) — v4→v5 is Node 24 runtime; distribution: temurin + java-version + cache: maven all still supported
- actions/upload-artifact: v3 → v7 (major tag) — v3→v7. v4 was a major storage-architecture rewrite, but this workflow only uploads (no paired download in the same workflow), so no pairing concern. name/path inputs unchanged.
- docker/build-push-action: 3b5e8027fcad23fda98b2e3ac259d8d67585f671 → f9f3042f (SHA) — preserving SHA pin; bumping to current v7.2.0 SHA
- docker/login-action: f4ef78c080cd8ba55a85445d5b36e214a81df20a → 650006c6 (SHA) — preserving SHA pin (don't downgrade security); bumping to current v4.2.0 SHA
- docker/metadata-action: 9ec57ed1fcdbf14dcef7dfbe97b2010124a938b7 → 80c7e94d (SHA) — preserving SHA pin; bumping to current v6.1.0 SHA
- github/codeql-action: v2 → v4 (major tag) — v2 deprecated; v4 runs on Node 24. `languages` input unchanged
- shrink/actions-docker-extract: v3 → v4 (major tag) — v3→v4 is just Node 24 runtime
- softprops/action-gh-release: v1 → v3 (major tag) — v1→v3: v2 was Node 20, v3 is Node 24; `files` input unchanged

Not updated:

- actions/setup-java: v1 (kept) — setup-java@v2+ made `distribution` a required input; this workflow only sets `java-version: 17` so bumping would fail at runtime. Add `distribution: temurin` before re-running
- enridaga/auto-release-milestone: master (kept) — audit reported `no_release` — the action has no GitHub releases to pin to; combined with @master branch pin (security flag), this requires upstream remediation
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant