chore(deps): update actions/setup-node action to v7 - #67
Merged
Merged
Conversation
|
Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net |
renovate
Bot
force-pushed
the
renovate/actions-setup-node-7.x
branch
from
September 3, 2026 12:23
87b8caf to
ad96f7a
Compare
|
Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net |
renovate
Bot
force-pushed
the
renovate/actions-setup-node-7.x
branch
from
September 7, 2026 22:03
ad96f7a to
63b9828
Compare
|
Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net |
This was referenced Sep 8, 2026
renovate
Bot
force-pushed
the
renovate/actions-setup-node-7.x
branch
from
September 8, 2026 09:39
63b9828 to
160997f
Compare
|
Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net |
renovate
Bot
force-pushed
the
renovate/actions-setup-node-7.x
branch
from
September 8, 2026 10:15
160997f to
e0b7d88
Compare
… bump
Renovate maintains workflow pins and their version comments together; it
does not touch SECURITY-PIPELINE.md. check-supply-chain reported the gap on
this branch:
[register] actions/setup-node: workflow pins 820762786026… (v7.0.0) but
SECURITY-PIPELINE.md records only 49933ea5288c… (v4.4.0)
note: SECURITY-PIPELINE.md lists actions/setup-node at 49933ea5288c…
(v4.4.0), which no workflow currently uses
Pin truth passed — the digest resolves to the version its comment claims.
Only the register was stale.
Second exercise of the habit recorded under "Keeping this register true":
the register moves on the bump's branch, before merging, so the check is
green on the pull request rather than only on acc afterwards.
Unlike the checkout bump in #66, nothing in the surrounding prose went
stale with it. Two passages were checked and both still hold:
- "Version currency" discusses the node-version INPUT ('22' backend, '20'
frontend), not the action pin, so this bump does not touch it.
- The zizmor.yml comment on the config-validator step says it reuses the
setup-node pin this repository already carries, so Renovate maintains one
digest rather than two. All five references move together, so that
remains true.
Worth stating because it marks the check's limit: it verifies the table,
and nothing verifies the prose around it. #66 needed a human to notice
three stale passages. This one genuinely did not.
|
Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net |
This was referenced Sep 8, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.4.0→v7.0.0Release Notes
actions/setup-node (actions/setup-node)
v7.0.0Compare Source
What's Changed
Enhancements:
Bug fixes:
mirrorTokeningetManifestif it's provided by @deiga in #1548Documentation updates:
Dependency update:
New Contributors
Full Changelog: actions/setup-node@v6...v7.0.0
v6.5.0Compare Source
What's Changed
Full Changelog: actions/setup-node@v6.4.0...v6.5.0
v6.4.0Compare Source
What's Changed
Dependency updates:
New Contributors
Full Changelog: actions/setup-node@v6...v6.4.0
v6.3.0Compare Source
What's Changed
Enhancements:
devEnginesfield by @susnux in #1283Dependency updates:
Bug fixes:
New Contributors
Full Changelog: actions/setup-node@v6...v6.3.0
v6.2.0Compare Source
What's Changed
Documentation
Dependency updates:
New Contributors
Full Changelog: actions/setup-node@v6...v6.2.0
v6.1.0Compare Source
What's Changed
Enhancement:
Dependency updates:
Documentation update:
Full Changelog: actions/setup-node@v6...v6.1.0
v6.0.0Compare Source
What's Changed
Breaking Changes
Dependency Upgrades
Full Changelog: actions/setup-node@v5...v6.0.0
v5.0.0Compare Source
What's Changed
Breaking Changes
This update, introduces automatic caching when a valid
packageManagerfield is present in yourpackage.json. This aims to improve workflow performance and make dependency management more seamless.To disable this automatic caching, set
package-manager-cache: falseMake sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes
Dependency Upgrades
New Contributors
Full Changelog: actions/setup-node@v4...v5.0.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.