chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.1 - #300
Conversation
Bumps [actions/download-artifact](https://github.com/actions/download-artifact) from 7.0.0 to 8.0.1. - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@37930b1...3e5f45b) --- updated-dependencies: - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
EVWorth
left a comment
There was a problem hiding this comment.
Requesting changes: release.yml will likely break at the artifact download step.
actions/download-artifact@v8.0.1 introduces strict hash mismatch handling — v8 release notes (Hash mismatches will now error by default.). But the workflow still uses upload-artifact@v7.0.1 at release.yml:148 and ci.yml:244, 334. Cross-major uploader/downloader pairs can mismatch the embedded hash protocol.
Per https://github.com/actions/download-artifact/releases/tag/v8.0.0:
Hash mismatches will now error by default. Users can override this behavior with a setting change (see below).
Options to fix this PR:
- Add an upload-artifact@v8 bump in this same PR so uploader and downloader match — and re-run a release dry-run to validate hash compatibility.
- Set
with: digest-mismatch: 'warn'on the download step (release.yml:164) to preserve the v7 fail-open behavior.
Recommend option 1 — bumping upload-artifact in lockstep is the cleaner long-term path and prevents the same drift in the next dependabot cycle.
CI didn't run the relevant matrix jobs because of path filters (actions-only), so the artifact-download hash mismatch won't be caught until the next release cut. Catching it now avoids a broken release.
EVWorth
left a comment
There was a problem hiding this comment.
Reconsidering after digging into the actual artifact package behavior — approving.
I was overcautious. The upload-artifact side has not shipped v8 yet (latest is v7.0.1, same SHA already on main). The hash-mismatch validation in download-artifact@v8 is a runtime corruption check, not a version-pair check: the @actions/artifact package uses the same manifest format across v7 upload and v8 download, and the README explicitly mentions reading v7 zipped uploads.
What v8 download actually changes:
- ESM-only bundle (transparent to caller unless you
require()it from a fork action — we don't) - Default
digest-mismatch: 'error'(was warning). Mitigations if this ever fires: setwith: digest-mismatch: 'warn'on release.yml:164 (one line).
CI's path-filter skipped the matrix jobs for this PR (actions-only change), so runtime confirmation needs a release-cut smoke. Recommend merging and watching the next make bump release dry-run for download step.
Summary after the original review: the artifact backend is shared between upload-artifact v7 and download-artifact v8; mixed versions are explicitly supported in the upstream README.
Bumps actions/download-artifact from 7.0.0 to 8.0.1.
Release notes
Sourced from actions/download-artifact's releases.
Commits
3e5f45bAdd regression tests for CJK characters (#471)e6d03f6Add a regression test for artifact name + content-type mismatches (#472)70fc10cMerge pull request #461 from actions/danwkennedy/digest-mismatch-behaviorf258da9Add change docsccc058eFix linting issuesbd7976bAdd a setting to specify what to do on hash mismatch and default it toerrorac21fcfMerge pull request #460 from actions/danwkennedy/download-no-unzip15999bfAdd note about package bumps974686eBump the version tov8and add release notesfbe48b1Update test names to make it clearer what they doDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)