Skip to content

build(deps): bump the github-actions group across 1 directory with 4 updates - #2

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-b0477e0607
Closed

build(deps): bump the github-actions group across 1 directory with 4 updates#2
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/github-actions-b0477e0607

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 10, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 4 updates in the / directory: actions/checkout, actions/configure-pages, actions/upload-pages-artifact and actions/deploy-pages.

Updates actions/checkout from 4 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

v6.0.0

What's Changed

... (truncated)

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/configure-pages from 5 to 6

Release notes

Sourced from actions/configure-pages's releases.

v6.0.0

Changelog

See details of all code changes since previous release.

Commits
  • 45bfe01 Merge pull request #186 from salmanmkc/node24
  • d8770c2 Update Node version from 20 to 24 in action.yml
  • cb8a1a3 upgrade to node 24
  • d560657 Merge pull request #165 from actions/Jcambass-patch-1
  • 35e0ac4 Upgrade IA Publish
  • 1dfbcbf Merge pull request #163 from actions/Jcambass-patch-1
  • 2f4f988 Add workflow file for publishing releases to immutable action package
  • 0d7570c Merge pull request #162 from actions/pin-draft-release-verssion
  • 3ea1966 pin draft release version
  • aabcbc4 Merge pull request #160 from actions/dependabot/npm_and_yarn/espree-10.1.0
  • Additional commits viewable in compare view

Updates actions/upload-pages-artifact from 3 to 5

Release notes

Sourced from actions/upload-pages-artifact's releases.

v5.0.0

Changelog

See details of all code changes since previous release.

v4.0.0

What's Changed

Full Changelog: actions/upload-pages-artifact@v3.0.1...v4.0.0

v3.0.1

Changelog

See details of all code changes since previous release.

Commits
  • fc324d3 Merge pull request #139 from Tom-van-Woudenberg/patch-1
  • fe9d4b7 Merge branch 'main' into patch-1
  • 0ca1617 Merge pull request #137 from jonchurch/include-hidden-files
  • 57f0e84 Update action.yml
  • 4a90348 v7 --> hash
  • 56f665a Update upload-artifact action to version 7
  • f7615f5 Add include-hidden-files input
  • 7b1f4a7 Merge pull request #127 from heavymachinery/pin-sha
  • 4cc19c7 Pin actions/upload-artifact to SHA
  • 2d163be Merge pull request #107 from KittyChiu/main
  • Additional commits viewable in compare view

Updates actions/deploy-pages from 4 to 5

Release notes

Sourced from actions/deploy-pages's releases.

v5.0.0

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.5

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.4

Changelog


See details of all code changes since previous release.

⚠️ For use with products other than GitHub.com, such as GitHub Enterprise Server, please consult the compatibility table.

v4.0.3

Changelog

... (truncated)

Commits
  • cd2ce8f Merge pull request #404 from salmanmkc/node24
  • bbe2a95 Update Node.js version to 24.x
  • 854d7aa Merge pull request #374 from actions/Jcambass-patch-1
  • 306bb81 Add workflow file for publishing releases to immutable action package
  • b742728 Merge pull request #360 from actions/dependabot/npm_and_yarn/npm_and_yarn-513...
  • 7273294 Bump braces in the npm_and_yarn group across 1 directory
  • 963791f Merge pull request #361 from actions/dependabot-friendly
  • 51bb29d Make the rebuild dist workflow safer for Dependabot
  • 89f3d10 Merge pull request #358 from actions/dependabot/npm_and_yarn/non-breaking-cha...
  • bce7355 Merge branch 'main' into dependabot/npm_and_yarn/non-breaking-changes-99c12deb21
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jul 10, 2026
…updates

Bumps the github-actions group with 4 updates in the / directory: [actions/checkout](https://github.com/actions/checkout), [actions/configure-pages](https://github.com/actions/configure-pages), [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) and [actions/deploy-pages](https://github.com/actions/deploy-pages).


Updates `actions/checkout` from 4 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v4...v7)

Updates `actions/configure-pages` from 5 to 6
- [Release notes](https://github.com/actions/configure-pages/releases)
- [Commits](actions/configure-pages@v5...v6)

Updates `actions/upload-pages-artifact` from 3 to 5
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](actions/upload-pages-artifact@v3...v5)

Updates `actions/deploy-pages` from 4 to 5
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@v4...v5)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/configure-pages
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/deploy-pages
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: actions/upload-pages-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump the github-actions group with 4 updates build(deps): bump the github-actions group across 1 directory with 4 updates Jul 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/github-actions-b0477e0607 branch from 3e36a77 to f14dbd1 Compare July 15, 2026 08:54
@dependabot @github

dependabot Bot commented on behalf of github Jul 16, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 16, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-b0477e0607 branch July 16, 2026 07:47
thomas-mangin added a commit that referenced this pull request Aug 22, 2026
Phase 6 of spec-record-answers-2-only-encoding, first of three. A
record
line's payload becomes a counted text: the three-letter kind, a space,
the byte count of the payload, and then that many bytes. A reader slices
the payload by arithmetic and never looks for the end of the line, which
was the last scan left on the line that repeats.

The owner's directive put the length after the token and before the
content, and the shape is the counted text every other variable field
already uses. `#2:42 row {"peer":"10.0.0.1"}` becomes
`#2:42 row 2:19:{"peer":"10.0.0.1"}`, and the fault line follows it.
appendAnswerRecordPrefix is the one writer of everything in front of the
payload, and AnswerRecordLineSize measures a line by calling it, so a
measured line and a written one cannot drift.

answerRecordPrefixMax becomes answerRecordPrefixWidth and it is EXACT
rather than a maximum: the id field at its widest, the kind token, the
space that closes it, the counted number stating the payload's byte
count, and the colon that closes that count. 51 bytes, arithmetic from
five parts that each state their own bound.
TestAnswerRecordLineSizeExact states EQUALITY against the widest prefix
the writer can produce, which is what phase 5 could not do: a LOOSER
constant costs nothing a running test can see, so a bound would have
left the loose direction unproven.

cutCountedBytes is cutCountedText for a value held as bytes, and it
exists for the reason appendCountedBytes does: a record's payload
reaches and leaves the wire without being copied into a string, on the
line that repeats. countedDigits carries the refusals both readers
share,
so a malformed length is refused in one place. parseAnswerRecord then
requires the line to END where the payload ends, which is the check the
stated count buys and which the next commit turns into the frame's own
guarantee.

Two other speakers of this wire follow. test/scripts/ze_api.py writes
the
counted payload from _respond_answer and reads it through the new public
answer_record_payload, which refuses a line carrying bytes past its
payload. internal/exabgp/bridge needs no change here: it dispatches on
the kind and decodes no record payload.

test/plugin/answer-first-bounds-long-walk.ci is new. It proves the pipe
still bounds a walk of 407 records to 10 after the reframe, and that the
bound reaches the ENCODER rather than the rendering: the unbounded walk
passes the 256-record threshold and `| ndjson` writes one line per
record, while the same walk bounded to ten fits the threshold, is
answered as one document, and writes that one line. It then compares the
ten records against the walk's own records byte for byte.

Mutation-verified, one mutation per guard. Writing the payload without
its count reddens TestAppendAnswerRecordNoKey and
TestAnswerRecordLineSizeExact, and reddens answer-many-records and
answer-unconditional over the wire. A constant one byte loose reddens
TestAnswerRecordLineSizeExact and leaves
TestAnswerRecordLineSizeAllocatesNothing green, which is the direction
phase 5 named as undiscriminated. A size that forgets the counted header
reddens TestAnswerRecordLineSizeExact. Dropping parseAnswerRecord's
trailing-byte refusal reddens TestAppendAnswerRecordNoKey. Making the
`first` pipe pass its records through reddens
answer-first-bounds-long-walk. In the Python harness, writing the record
uncounted reddens plugin-pipe-alias-help.

AC-18 and TestEnvelopeKeyOverLimitRefused are retired rather than
implemented. They cap the envelope key and the error code at 35 bytes,
and that cap existed only because the spec assumed a short length form.
A counted text states its byte count as a counted number, so it carries
a value of any length and nothing is capped by its own encoding. Neither
was ever implemented: `grep -rn "envelopeKeyMax" --include=*.go .`
returns nothing.

replaceNewlines still rewrites a newline inside a value here. Deleting
it needs the frame to stop splitting on a newline it does not own, which
is the third commit. The second drops the id's length prefix, which the
owner ruled on mid-phase after measuring it slower and two bytes wider
than the plain `#42 ` a fused loop reads.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants