Skip to content

chore(deps): bump dawidd6/action-download-artifact from 24 to 27 in the actions group - #552

Merged
fank merged 1 commit into
mainfrom
dependabot/github_actions/actions-85ecf4c6e7
Oct 2, 2026
Merged

fank merged 1 commit into
mainfrom
dependabot/github_actions/actions-85ecf4c6e7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: dawidd6/action-download-artifact.

Updates dawidd6/action-download-artifact from 24 to 27

Release notes

Sourced from dawidd6/action-download-artifact's releases.

v27

What's Changed

Full Changelog: dawidd6/action-download-artifact@v26...v27

v26

Full Changelog: dawidd6/action-download-artifact@v25...v26

v25

What's Changed

Full Changelog: dawidd6/action-download-artifact@v24...v25

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact).


Updates `dawidd6/action-download-artifact` from 24 to 27
- [Release notes](https://github.com/dawidd6/action-download-artifact/releases)
- [Commits](dawidd6/action-download-artifact@v24...v27)

---
updated-dependencies:
- dependency-name: dawidd6/action-download-artifact
  dependency-version: '27'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Coverage Report for ui

Status Category Percentage Covered / Total
🔵 Lines 98.96%
🟰 ±0%
5542 / 5600
🔵 Statements 98.31%
🟰 ±0%
7831 / 7965
🔵 Functions 97.8%
🟰 ±0%
2233 / 2283
🔵 Branches 89.62%
🟰 ±0%
2480 / 2767
File CoverageNo changed files found.
Generated in workflow #21 for commit 3136fd4 by the Vitest Coverage Report Action

@fank
fank self-requested a review October 2, 2026 21:53
@fank

fank commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Ratatoskr reviewed this pull request.

Approved on 3136fd48. See the review.

Finished 2026-10-02 21:55 UTC.

@fank fank left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve: no findings. The bump is a drop-in upgrade, and CI on this head shows v27 picking the correct latest main artifact in both workflows.

Review details

Verdict: approve. I'd be comfortable as the only reviewer on this one. It changes two uses: lines and leaves inputs, outputs and permissions alone.

Scope

  • .github/workflows/go.yml:88 and .github/workflows/ui.yml:69 move from dawidd6/action-download-artifact@v24 to @v27. Nothing else in either workflow changes.

Upstream v24 → v27 diff (checked against the action repo, not just the release notes)

  • action.yml: the only change adds default: false to dry_run. In main.js, dry_run is now read with getBooleanInput. We don't set dry_run, so the default applies and nothing can throw. The inputs we use (branch, workflow_conclusion, name, path, if_no_artifact_found) and the found_artifact output that go.yml:104 reads are unchanged.
  • Run selection in main.js changed in two ways:
    • Candidate runs are now sorted newest-first in the action instead of trusting the API's order.
    • When a filter is set, the action also fetches the latest 100 runs without the filter and matches them locally, then merges them in. That covers our branch: main case and costs one extra API call per invocation.
  • Expired artifacts are now filtered out, but only on the check_artifacts/search_artifacts path, which we don't use.
  • The rest of the diff is adm-zip 0.6.0 → 0.6.1 in the vendored node_modules, plus upstream's own workflows and README. I saw no new network endpoints or token handling.

Evidence that the fix matters here

  • The PR's Go run (37029387194) selected main run 36157036743 (2026-09-25). Its head_sha 38cf17b5e0f19052fe9f795ab56e83cfca03d80d is the current tip of main.
  • The PR's UI run (37029387256) selected 36157025862, which is the latest successful UI run on main.
  • For comparison, a branch-filtered listing of the Go workflow (gh run list --workflow go.yml --branch main) currently returns only runs from 2026-07-24. Querying the same workflow's runs without the branch filter shows the 2026-09-25 run. This looks like the flaky search-index behaviour v27 works around, so the old version may have been diffing coverage against stale baselines.

Safety

  • No permission changes. Both jobs already have contents: write, and the action uses the default github.token.
  • v27 resolved to eab87c9830c39eff17e5a6eadb20bfb4bc880477 in the run logs, which matches the upstream tag and the commit Dependabot listed.
  • The action is pinned to a mutable major tag rather than a SHA. Every other action in .github/workflows/ is pinned the same way, so this follows repository convention and isn't a finding against this PR.

Tests / checks

  • Go test, Code coverage report and UI check all pass on head 3136fd487522b08ca8280d78050266468d165982. Changing ui.yml means the UI workflow (normally limited to ui/** paths) also ran.
  • In both runs the download step actually ran and found an artifact, so this was exercised, not skipped.
  • I didn't exercise the if_no_artifact_found: warn path (no artifact found) on v27. Its code is unchanged between the two versions.

Earlier discussions

  • None. There are no review threads (checked via GraphQL) and no prior reviews.

@fank
fank merged commit ddb4e25 into main Oct 2, 2026
3 checks passed
@fank
fank deleted the dependabot/github_actions/actions-85ecf4c6e7 branch October 2, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant