Skip to content

chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.1 - #300

Merged
EVWorth merged 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8.0.1
Aug 1, 2026
Merged

chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.1#300
EVWorth merged 1 commit into
mainfrom
dependabot/github_actions/actions/download-artifact-8.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/download-artifact from 7.0.0 to 8.0.1.

Release notes

Sourced from actions/download-artifact's releases.

v8.0.1

What's Changed

Full Changelog: actions/download-artifact@v8...v8.0.1

v8.0.0

v8 - What's new

[!IMPORTANT] actions/download-artifact@v8 has been migrated to an ESM module. This should be transparent to the caller but forks might need to make significant changes.

[!IMPORTANT] Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Direct downloads

To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to true.

Enforced checks (breaking)

A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

Full Changelog: actions/download-artifact@v7...v8.0.0

Commits
  • 3e5f45b Add regression tests for CJK characters (#471)
  • e6d03f6 Add a regression test for artifact name + content-type mismatches (#472)
  • 70fc10c Merge pull request #461 from actions/danwkennedy/digest-mismatch-behavior
  • f258da9 Add change docs
  • ccc058e Fix linting issues
  • bd7976b Add a setting to specify what to do on hash mismatch and default it to error
  • ac21fcf Merge pull request #460 from actions/danwkennedy/download-no-unzip
  • 15999bf Add note about package bumps
  • 974686e Bump the version to v8 and add release notes
  • fbe48b1 Update test names to make it clearer what they do
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 7.0.0 to 8.0.1.
- [Release notes](https://github.com/actions/download-artifact/releases)
- [Commits](actions/download-artifact@37930b1...3e5f45b)

---
updated-dependencies:
- dependency-name: actions/download-artifact
  dependency-version: 8.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates github-actions GitHub Actions updates labels Jul 26, 2026

@EVWorth EVWorth left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: release.yml will likely break at the artifact download step.

actions/download-artifact@v8.0.1 introduces strict hash mismatch handling — v8 release notes (Hash mismatches will now error by default.). But the workflow still uses upload-artifact@v7.0.1 at release.yml:148 and ci.yml:244, 334. Cross-major uploader/downloader pairs can mismatch the embedded hash protocol.

Per https://github.com/actions/download-artifact/releases/tag/v8.0.0:

Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).

Options to fix this PR:

  1. Add an upload-artifact@v8 bump in this same PR so uploader and downloader match — and re-run a release dry-run to validate hash compatibility.
  2. Set with: digest-mismatch: 'warn' on the download step (release.yml:164) to preserve the v7 fail-open behavior.

Recommend option 1 — bumping upload-artifact in lockstep is the cleaner long-term path and prevents the same drift in the next dependabot cycle.

CI didn't run the relevant matrix jobs because of path filters (actions-only), so the artifact-download hash mismatch won't be caught until the next release cut. Catching it now avoids a broken release.

@EVWorth EVWorth left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reconsidering after digging into the actual artifact package behavior — approving.

I was overcautious. The upload-artifact side has not shipped v8 yet (latest is v7.0.1, same SHA already on main). The hash-mismatch validation in download-artifact@v8 is a runtime corruption check, not a version-pair check: the @actions/artifact package uses the same manifest format across v7 upload and v8 download, and the README explicitly mentions reading v7 zipped uploads.

What v8 download actually changes:

  • ESM-only bundle (transparent to caller unless you require() it from a fork action — we don't)
  • Default digest-mismatch: 'error' (was warning). Mitigations if this ever fires: set with: digest-mismatch: 'warn' on release.yml:164 (one line).

CI's path-filter skipped the matrix jobs for this PR (actions-only change), so runtime confirmation needs a release-cut smoke. Recommend merging and watching the next make bump release dry-run for download step.

Summary after the original review: the artifact backend is shared between upload-artifact v7 and download-artifact v8; mixed versions are explicitly supported in the upstream README.

@EVWorth
EVWorth merged commit 46080f5 into main Aug 1, 2026
10 checks passed
@EVWorth
EVWorth deleted the dependabot/github_actions/actions/download-artifact-8.0.1 branch August 1, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates github-actions GitHub Actions updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant