Skip to content

chore: bump actions/setup-node from 6 to 7 - #73

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/main/actions/setup-node-7
Open

chore: bump actions/setup-node from 6 to 7#73
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/main/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 6 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependencies github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 1, 2026 21:45
@dependabot dependabot Bot added dependencies Dependencies github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Zizmor found Critical or High severity GitHub Actions workflow security issues:

Summary

Severity Count
High 24
Total 24

Details

Grouped by audit rule and file. Line/column refer to the workflow or action YAML on the scanned branch.

template-injection — High

code injection via template expansion

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#template-injection

Locations:

  • Line 67–80 (cols 8–60) — this step
  • Line 72 (cols 27–42) — expression github.workflow — may expand into attacker-controllable code
  • Line 69 (cols 8–11) — this run block

unpinned-uses — High (10 similar finding(s))

unpinned action reference

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#unpinned-uses

Locations:

  • Line 19 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 22 (cols 14–35) — expression actions/setup-node@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 40 (cols 14–41) — expression docker/setup-qemu-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 44 (cols 14–43) — expression docker/setup-buildx-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 48 (cols 14–36) — expression docker/login-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 57 (cols 14–41) — expression docker/build-push-action@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 65 (cols 14–42) — expression sigstore/cosign-installer@v3 — action is not pinned to a hash (required by blanket policy)
  • Line 89 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • …and 2 more location(s) in this file.

cache-poisoning — High

runtime artifacts potentially vulnerable to a cache poisoning attack

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#cache-poisoning

Locations:

  • Line 57 (cols 8–41) — runtime artifacts usually published here
  • Line 22 (cols 8–35) — enables caching by default
  • Line 21–24 (cols 8–47) — this step

unpinned-uses — High (12 similar finding(s))

unpinned action reference

File: .github/workflows/test.yaml

Fix guidance: https://docs.zizmor.sh/audits/#unpinned-uses

Locations:

  • Line 36 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 38 (cols 14–33) — expression actions/setup-go@v6 — action is not pinned to a hash (required by blanket policy)
  • Line 53 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 55 (cols 14–33) — expression actions/setup-go@v6 — action is not pinned to a hash (required by blanket policy)
  • Line 61 (cols 14–50) — expression golangci/golangci-lint-action@v9.3.0 — action is not pinned to a hash (required by blanket policy)
  • Line 74 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 80 (cols 14–35) — expression actions/setup-node@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 88 (cols 14–45) — expression tj-actions/coverage-badge-go@v3 — action is not pinned to a hash (required by blanket policy)
  • …and 4 more location(s) in this file.

Please review these findings before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Zizmor found Critical or High severity GitHub Actions workflow security issues:

Summary

Severity Count
High 24
Total 24

Details

Grouped by audit rule and file. Line/column refer to the workflow or action YAML on the scanned branch.

template-injection — High

code injection via template expansion

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#template-injection

Locations:

  • Line 67–80 (cols 8–60) — this step
  • Line 72 (cols 27–42) — expression github.workflow — may expand into attacker-controllable code
  • Line 69 (cols 8–11) — this run block

unpinned-uses — High (10 similar finding(s))

unpinned action reference

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#unpinned-uses

Locations:

  • Line 19 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 22 (cols 14–35) — expression actions/setup-node@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 40 (cols 14–41) — expression docker/setup-qemu-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 44 (cols 14–43) — expression docker/setup-buildx-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 48 (cols 14–36) — expression docker/login-action@v4 — action is not pinned to a hash (required by blanket policy)
  • Line 57 (cols 14–41) — expression docker/build-push-action@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 65 (cols 14–42) — expression sigstore/cosign-installer@v3 — action is not pinned to a hash (required by blanket policy)
  • Line 89 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • …and 2 more location(s) in this file.

cache-poisoning — High

runtime artifacts potentially vulnerable to a cache poisoning attack

File: .github/workflows/release.yaml

Fix guidance: https://docs.zizmor.sh/audits/#cache-poisoning

Locations:

  • Line 57 (cols 8–41) — runtime artifacts usually published here
  • Line 22 (cols 8–35) — enables caching by default
  • Line 21–24 (cols 8–47) — this step

unpinned-uses — High (12 similar finding(s))

unpinned action reference

File: .github/workflows/test.yaml

Fix guidance: https://docs.zizmor.sh/audits/#unpinned-uses

Locations:

  • Line 36 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 38 (cols 14–33) — expression actions/setup-go@v6 — action is not pinned to a hash (required by blanket policy)
  • Line 53 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 55 (cols 14–33) — expression actions/setup-go@v6 — action is not pinned to a hash (required by blanket policy)
  • Line 61 (cols 14–50) — expression golangci/golangci-lint-action@v9.3.0 — action is not pinned to a hash (required by blanket policy)
  • Line 74 (cols 14–33) — expression actions/checkout@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 80 (cols 14–35) — expression actions/setup-node@v7 — action is not pinned to a hash (required by blanket policy)
  • Line 88 (cols 14–45) — expression tj-actions/coverage-badge-go@v3 — action is not pinned to a hash (required by blanket policy)
  • …and 4 more location(s) in this file.

Please review these findings before merging.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants