Skip to content

chore(deps): update actions/setup-node action to v7 - #67

Merged
sgort merged 2 commits into
accfrom
renovate/actions-setup-node-7.x
Sep 8, 2026
Merged

sgort merged 2 commits into
accfrom
renovate/actions-setup-node-7.x

Conversation

@renovate

@renovate renovate Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/setup-node action major v4.4.0v7.0.0

Release Notes

actions/setup-node (actions/setup-node)

v7.0.0

Compare Source

What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency update:
New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

Compare Source

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

Compare Source

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

Compare Source

What's Changed

Enhancements:

When using node-version-file: package.json, setup-node now prefers devEngines.runtime over engines.node.

Dependency updates:
Bug fixes:

New Contributors

Full Changelog: actions/setup-node@v6...v6.3.0

v6.2.0

Compare Source

What's Changed

Documentation
Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.2.0

v6.1.0

Compare Source

What's Changed

Enhancement:
Dependency updates:
Documentation update:

Full Changelog: actions/setup-node@v6...v6.1.0

v6.0.0

Compare Source

What's Changed

Breaking Changes

Dependency Upgrades

Full Changelog: actions/setup-node@v5...v6.0.0

v5.0.0

Compare Source

What's Changed

Breaking Changes

This update, introduces automatic caching when a valid packageManager field is present in your package.json. This aims to improve workflow performance and make dependency management more seamless.
To disable this automatic caching, set package-manager-cache: false

steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v5
  with:
    package-manager-cache: false

Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. See Release Notes

Dependency Upgrades

New Contributors

Full Changelog: actions/setup-node@v4...v5.0.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net

@renovate
renovate Bot force-pushed the renovate/actions-setup-node-7.x branch from 87b8caf to ad96f7a Compare September 3, 2026 12:23
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net

@renovate
renovate Bot force-pushed the renovate/actions-setup-node-7.x branch from ad96f7a to 63b9828 Compare September 7, 2026 22:03
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net

@renovate
renovate Bot force-pushed the renovate/actions-setup-node-7.x branch from 160997f to e0b7d88 Compare September 8, 2026 10:15
… bump

Renovate maintains workflow pins and their version comments together; it
does not touch SECURITY-PIPELINE.md. check-supply-chain reported the gap on
this branch:

  [register] actions/setup-node: workflow pins 820762786026… (v7.0.0) but
             SECURITY-PIPELINE.md records only 49933ea5288c… (v4.4.0)

  note: SECURITY-PIPELINE.md lists actions/setup-node at 49933ea5288c…
        (v4.4.0), which no workflow currently uses

Pin truth passed — the digest resolves to the version its comment claims.
Only the register was stale.

Second exercise of the habit recorded under "Keeping this register true":
the register moves on the bump's branch, before merging, so the check is
green on the pull request rather than only on acc afterwards.

Unlike the checkout bump in #66, nothing in the surrounding prose went
stale with it. Two passages were checked and both still hold:

- "Version currency" discusses the node-version INPUT ('22' backend, '20'
  frontend), not the action pin, so this bump does not touch it.
- The zizmor.yml comment on the config-validator step says it reuses the
  setup-node pin this repository already carries, so Renovate maintains one
  digest rather than two. All five references move together, so that
  remains true.

Worth stating because it marks the check's limit: it verifies the table,
and nothing verifies the prose around it. #66 needed a human to notice
three stale passages. This one genuinely did not.
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

Azure Static Web Apps: Your stage site is ready! Visit it here: https://brave-bay-04f351e03-67.westeurope.4.azurestaticapps.net

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant