Skip to content

build(deps): bump actions/cache from 4 to 6 - #118

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/cache-6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/cache-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/cache from 4 to 6.

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/cache](https://github.com/actions/cache) from 4 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, github-actions. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@kryptt

kryptt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Superseded by #128 — this bump is included there after individual verification: action.yml inputs are byte-identical between v4.3.0 and v6.1.0 (only the node20→node24 runtime line differs), all 18 usages pass exactly {path, key, restore-keys}, and @v6 resolves to v6.1.0, which adds graceful read-only-cache-token handling on fork PRs.

@kryptt kryptt closed this Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/cache-6 branch October 2, 2026 16:40
kryptt added a commit that referenced this pull request Oct 2, 2026
The cache bump landed as a hand-edit of the generated ci.yml (mirroring
Dependabot's #118 diff), which githubWorkflowCheck rightly flags: ci.yml
is generator-owned (CONTRIBUTING.md: never hand-edit it). This pairs the
edit with its source of truth — UseRef.Public("actions", "cache", "v6")
in the setup-java cache patch. githubWorkflowGenerate now emits zero
workflow drift, so the committed ci.yml is exactly generated output, and
githubWorkflowCheck passes.
kryptt added a commit that referenced this pull request Oct 2, 2026
… stryker blocker (#115) (#128)

* build(deps): bump actions/cache from v4 to v6

Supersedes #118. Drop-in verified: action.yml inputs are byte-identical
between v4.3.0 and v6.1.0 (only the node20 -> node24 runtime line
differs); all 18 steps pass exactly {path, key, restore-keys}; @v6
resolves to v6.1.0, which adds graceful handling of read-only cache
tokens (the accurate 'cache write denied' warning on fork PRs instead
of the bogus 'another job may be creating this cache').

* build(deps): bump droste-core from 0.9.0-M3 to 0.10.0

Supersedes #124. Benchmark-only dependency (never published downstream).
0.10.0 is dependency maintenance upstream (cats update,
scala-collection-compat 2.13.0, Scala.js 1.18.2); our droste surface
(Fix, scheme.{cata,ana,hylo}, Algebra/Coalgebra) compiles unchanged and
all nine SchemesBench benchmarks execute on the new version.

* build(deps): bump sbt-stryker4s from 0.20.4 to 1.1.1

Supersedes #126. No removed or renamed features reach this build: the
setting keys used in build.sbt (strykerReporters, strykerExcludedMutations,
strykerThresholdsBreak) are unchanged, the borrowed-tests wiring still
resolves, and 1.x requires sbt >= 1.11.2 (we run 1.13.0). Verified with a
schemes smoke run (48/58 killed, 0 NoCoverage) and a full avroIntegration
run (481 killed / 51 survived / 58 known-macro NoCoverage, no crash).

Decisive for issue #115: 1.1.1 fixes stryker4s' rollback invariant crash
('cases should be non-empty') that killed avro's mutation run on main —
0.20.4's mutant removal could empty a Term.Match by deleting its default
Pat.Wildcard case; 1.1.1 filters it. Also refreshes the invocation-doctrine
comment: the module-scoped <m>/stryker form works again since 0.20.4.

* fix(avro): keep AvroWalk's null-narrowing outside stryker's reach

Addresses #115 blocker 1. The flow-typed 'val here = if index != null
then index else ...' loses its narrowing the moment stryker4s' mutator
rewrites the condition, so two mutants died as compile errors instead of
being exercised (and on 0.20.4 that rollback crashed the whole run).

Express the narrowing as a match on the null sentinel with an explicit
JMap[String, Integer] type: a match has no condition to mutate, so the
narrowing is structural rather than flow-based. (The ascribe + 'index.nn'
spelling from the issue does not compile here — the guard already narrows,
E216 fires, and -Werror rejects the warning.) Applied at both occurrences
(totalNominalIndex and recordSlots); AvroCompileError mutants from
AvroWalk go to zero.

* docs: refresh version pins and the stryker invocation doctrine

CLAUDE.md said Scala 3.8.3 / sbt 1.12.9; the project builds Scala 3.9.0
(build.sbt scala3Version) on sbt 1.13.0 (project/build.properties).
CONTRIBUTING.md's bootstrap list pointed Scala at build.properties and
omitted the JDK 25 requirement for kyo + the docs site.

The 'invoke as project <m>; stryker, NOT <m>/stryker' claim stopped being
true in 0.20.4 (module-scoped task resolution was fixed upstream); state
the history instead of forbidding the working form. The mutationAll alias
also covers zio and kyo now, not just the original eight modules.
quality-assurance.md's scoverage path follows the Scala version.

* build(ci): bump the workflow generator's actions/cache ref to v6

The cache bump landed as a hand-edit of the generated ci.yml (mirroring
Dependabot's #118 diff), which githubWorkflowCheck rightly flags: ci.yml
is generator-owned (CONTRIBUTING.md: never hand-edit it). This pairs the
edit with its source of truth — UseRef.Public("actions", "cache", "v6")
in the setup-java cache patch. githubWorkflowGenerate now emits zero
workflow drift, so the committed ci.yml is exactly generated output, and
githubWorkflowCheck passes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant