Repository navigation
Bump actions/cache from 5 to 6 - #1444
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6. - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](actions/cache@v5...v6) --- updated-dependencies: - dependency-name: actions/cache dependency-version: '6' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
bgentry
left a comment
There was a problem hiding this comment.
🤖 Codex review: Security review is clear for River's current hosted configuration; this PR is superseded and should remain unmerged.
Upgrade
actions/cache:v5→v6- Reviewed River head:
55443f3de1ba51e5a432e6750f48048836c593a5 - Target action tag resolves to canonical upstream commit
55cc8345863c7cc4c66a329aec7e433d2d1c52a9.
Security review
- Action TypeScript and inputs/outputs are unchanged versus the current v5 ref; Node 24 remains the runtime. Reviewed the ESM/toolkit migration, graph churn, cache policy handling and generated restore/save bundles. The embedded 38,407-byte CRC64 WASM matches the verified Azure storage npm artifact byte-for-byte and has no direct networking or filesystem-open imports.
- Independently verified 33 relevant published npm tarballs across the Actions group against registry/upstream-lock SHA512 integrity. No same-version integrity rewrites or non-registry sources were found. Toolkit provenance subject digests match the inspected artifacts; signature/transparency chains were not independently verified. Target release commits have GitHub-valid signatures.
- No action-specific public advisory found. This does not establish that bundled dependencies are advisory-free.
Compatibility verification
- Master
81c96bfe8167ab90a5009dad6098195b9857cb62already contains every requested reference update through #1459, including additional workflows added since this stale PR. No remaining upgrade from this PR needs merging. - No action entrypoint was executed locally. Hosted checkout/cache/toolchain semantics require GitHub runners; stale failing checks, where present, are not treated as a passing gate. This is a comment-only supersession decision.
Residual risk
- Bundled brace-expansion advisories are bypassed by the action glob path's
nobrace: true; River supplies trusted fixed Cargo paths. Undici advisories affect APIs not used by these action paths. Large generated bundles and WASM were statically inspected, not rebuilt or exhaustively audited. Major tags and the target release remain mutable.
|
@dependabot rebase |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
Superseded by #1459: master already contains this exact Actions upgrade. Dependabot cannot rebase this older PR because its configuration entry changed, so closing it as redundant. The dependency security review is recorded above. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/cache from 5 to 6.
Release notes
Sourced from actions/cache's releases.
... (truncated)
Changelog
Sourced from actions/cache's changelog.
... (truncated)
Commits
55cc834Merge pull request #1768 from jasongin/readonly-cached8cd72fBump@actions/cacheto v6.1.0 - handle cache write error due to RO token2c8a9bdMerge pull request #1760 from actions/samirat/esm_migration_and_package_updatee9b91fdPrettier fixese4884b8Rebuild dist10baf01Fixed licensese39b386Fix test mock return orderb692820PR feedback6074912Rebuild dist bundles as ESM to match type:module5a912e8Fix lint and jest issuesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)