chore(deps): bump dawidd6/action-download-artifact from 24 to 27 in the actions group - #552
Merged
Merged
Conversation
Bumps the actions group with 1 update: [dawidd6/action-download-artifact](https://github.com/dawidd6/action-download-artifact). Updates `dawidd6/action-download-artifact` from 24 to 27 - [Release notes](https://github.com/dawidd6/action-download-artifact/releases) - [Commits](dawidd6/action-download-artifact@v24...v27) --- updated-dependencies: - dependency-name: dawidd6/action-download-artifact dependency-version: '27' dependency-type: direct:production update-type: version-update:semver-major dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Coverage Report for ui
File CoverageNo changed files found. |
fank
self-requested a review
October 2, 2026 21:53
Member
|
Ratatoskr reviewed this pull request. Approved on Finished 2026-10-02 21:55 UTC. |
fank
approved these changes
Oct 2, 2026
fank
left a comment
Member
There was a problem hiding this comment.
Approve: no findings. The bump is a drop-in upgrade, and CI on this head shows v27 picking the correct latest main artifact in both workflows.
Review details
Verdict: approve. I'd be comfortable as the only reviewer on this one. It changes two uses: lines and leaves inputs, outputs and permissions alone.
Scope
.github/workflows/go.yml:88and.github/workflows/ui.yml:69move fromdawidd6/action-download-artifact@v24to@v27. Nothing else in either workflow changes.
Upstream v24 → v27 diff (checked against the action repo, not just the release notes)
action.yml: the only change addsdefault: falsetodry_run. Inmain.js,dry_runis now read withgetBooleanInput. We don't setdry_run, so the default applies and nothing can throw. The inputs we use (branch,workflow_conclusion,name,path,if_no_artifact_found) and thefound_artifactoutput thatgo.yml:104reads are unchanged.- Run selection in
main.jschanged in two ways:- Candidate runs are now sorted newest-first in the action instead of trusting the API's order.
- When a filter is set, the action also fetches the latest 100 runs without the filter and matches them locally, then merges them in. That covers our
branch: maincase and costs one extra API call per invocation.
- Expired artifacts are now filtered out, but only on the
check_artifacts/search_artifactspath, which we don't use. - The rest of the diff is
adm-zip0.6.0 → 0.6.1 in the vendorednode_modules, plus upstream's own workflows and README. I saw no new network endpoints or token handling.
Evidence that the fix matters here
- The PR's Go run (37029387194) selected main run 36157036743 (2026-09-25). Its
head_sha38cf17b5e0f19052fe9f795ab56e83cfca03d80dis the current tip ofmain. - The PR's UI run (37029387256) selected 36157025862, which is the latest successful UI run on
main. - For comparison, a branch-filtered listing of the Go workflow (
gh run list --workflow go.yml --branch main) currently returns only runs from 2026-07-24. Querying the same workflow's runs without the branch filter shows the 2026-09-25 run. This looks like the flaky search-index behaviour v27 works around, so the old version may have been diffing coverage against stale baselines.
Safety
- No permission changes. Both jobs already have
contents: write, and the action uses the defaultgithub.token. v27resolved toeab87c9830c39eff17e5a6eadb20bfb4bc880477in the run logs, which matches the upstream tag and the commit Dependabot listed.- The action is pinned to a mutable major tag rather than a SHA. Every other action in
.github/workflows/is pinned the same way, so this follows repository convention and isn't a finding against this PR.
Tests / checks
- Go
test,Code coverage reportand UIcheckall pass on head3136fd487522b08ca8280d78050266468d165982. Changingui.ymlmeans the UI workflow (normally limited toui/**paths) also ran. - In both runs the download step actually ran and found an artifact, so this was exercised, not skipped.
- I didn't exercise the
if_no_artifact_found: warnpath (no artifact found) on v27. Its code is unchanged between the two versions.
Earlier discussions
- None. There are no review threads (checked via GraphQL) and no prior reviews.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 1 update: dawidd6/action-download-artifact.
Updates
dawidd6/action-download-artifactfrom 24 to 27Release notes
Sourced from dawidd6/action-download-artifact's releases.
Commits
eab87c9fix: merge unfiltered runs into filtered run search (#432)27e4ae6feat: log skipped workflow runs in debug mode634d83bworkflows: update0b3820anode_modules: update (#430)398d90bfix: do not rely on API workflow run ordering (#429)b9a309fbuild(deps): bump adm-zip from 0.6.0 to 0.6.1 (#427)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions