Skip to content

chore(deps): bump actions/setup-node from 6 to 7 - #380

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7
Open

chore(deps): bump actions/setup-node from 6 to 7#380
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 14, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 6 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note

Low Risk
Workflow-only dependency bump with no application or secret-handling changes; existing inputs are unchanged.

Overview
Upgrades actions/setup-node from v6 to v7 in the CI workflows that install Node for pnpm.

release-on-merge.yml and test-on-pull-request.yml still use Node 16 and cache: 'pnpm'; only the action major version changes.

Reviewed by Cursor Bugbot for commit 01ab8d6. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code labels Jul 14, 2026
with:
version: 7.6.0
- uses: actions/setup-node@v6
- uses: actions/setup-node@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses mutable tag v7 which can be silently repointed by the action owner, enabling supply-chain attacks through malicious code injection into CI/CD pipelines.

More details about this

The workflow step actions/setup-node@v7 uses a mutable version tag (v7) instead of a pinned commit SHA. This allows the action owner to silently update what code runs in your CI/CD pipeline without your knowledge.

Here's how an attacker could exploit this:

  1. Compromise the action repository: An attacker gains access to the actions/setup-node repository on GitHub.
  2. Repoint the tag: They force-push to the v7 tag, pointing it to a malicious commit that includes backdoored Node.js setup code or credentials theft.
  3. Automatic execution: The next time your workflow runs (on any pull request), GitHub automatically pulls the latest commit at v7, which is now the attacker's malicious code.
  4. Silent compromise: Your node-version and cache settings execute against the attacker's modified action, potentially exposing secrets in ${{ secrets }} or injecting malware into your build artifacts.

This mirrors real supply-chain attacks like the Trivy and KICS GitHub Action compromises, where legitimate actions were weaponized through tag manipulation.

To prevent this, replace the mutable tag with a full 40-character commit SHA so your workflow always runs the exact same code.

To resolve this comment:

✨ Commit fix suggestion
  1. Replace the mutable action reference actions/setup-node@v7 with a full 40-character commit SHA for the exact release you want to keep using, for example uses: actions/setup-node@<full-commit-sha>.
  2. Keep the existing with: block unchanged so the workflow behavior stays the same, for example node-version: '16' and cache: 'pnpm' do not need to change.
  3. Get the correct SHA from the actions/setup-node release you intend to use, then paste that SHA directly into the uses: line instead of the version tag. Pinning to a commit SHA prevents the action owner from moving v7 to different code later.

Alternatively, if you need easier version updates, pin to the commit SHA that corresponds to the current v7 release and track upgrades separately by updating that SHA when you intentionally adopt a newer release.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

Need help? Review go/semgrep-playbook or Reach out in #security-vulnerabilities on Slack.

You can view more details about this finding in the Semgrep AppSec Platform.

with:
version: 7.6.0
- uses: actions/setup-node@v6
- uses: actions/setup-node@v7

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses mutable version tag v7 which can be repointed by the action owner to inject malicious code into your workflow. Pin to a full commit SHA instead.

More details about this

The step uses: actions/setup-node@v7 references the action using a mutable version tag (v7) instead of pinning to a specific commit SHA. Version tags can be moved or repointed by the action owner after release, allowing them to silently inject malicious code into your workflow.

Here's how an attacker could exploit this:

  1. Compromise the action repository: An attacker gains control of the actions/setup-node repository (via credential theft, internal access, or social engineering).
  2. Repoint the v7 tag: The attacker moves the v7 tag to a malicious commit they've created that contains backdoored Node.js setup logic.
  3. Your workflow pulls the malicious version: Next time your CI/CD pipeline runs, actions/setup-node@v7 resolves to the attacker's malicious commit instead of the legitimate one.
  4. Execute payload: The backdoor code runs with full access to your repository secrets (GITHUB_TOKEN), environment variables, and build artifacts. The attacker can steal credentials, modify your package contents, or compromise downstream users.

This same attack vector was used in the real-world compromises of trivy-action and kics-github-action, where attackers gained the ability to exfiltrate credentials and manipulate build outputs.

To resolve this comment:

✨ Commit fix suggestion
  1. Replace the mutable GitHub Action reference with a full 40-character commit SHA instead of the v7 tag.
    Change uses: actions/setup-node@v7 to uses: actions/setup-node@<full-commit-sha>.

  2. Resolve the SHA from the exact action version you intend to trust.
    For example, open the actions/setup-node release or tag page, find the commit behind v7, and copy the full SHA rather than a branch or tag name.

  3. Keep the existing with: block unchanged after pinning the action.
    The step should look like - uses: actions/setup-node@8ade135a41bc03ea155e62e844d188df1ea18608 followed by the current node-version and cache settings. Pinning to a commit SHA prevents the action owner from silently moving the version reference later.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

Need help? Review go/semgrep-playbook or Reach out in #security-vulnerabilities on Slack.

You can view more details about this finding in the Semgrep AppSec Platform.

@scribdbot scribdbot added the 30+ days open PR has been open for 30+ days label Aug 18, 2026
@scribdbot

Copy link
Copy Markdown
Collaborator

⚠️ PR Age Notice: This pull request was opened over 30 days ago and has been labeled for visibility. If there's no activity for 7 days after this label is applied, it will be automatically closed.

To keep it open, please leave a comment or push an update. You can also label it as 'pinned' to prevent auto-closure.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

30+ days open PR has been open for 30+ days dependencies Pull requests that update a dependency file github_actions Pull requests that update Github_actions code

Development

Successfully merging this pull request may close these issues.

1 participant