Skip to content

SCANDOCKER-87 Update build workflow dependencies - #323

Merged
alban-auzeill merged 1 commit into
masterfrom
alban/SCANDOCKER-87
Sep 17, 2026
Merged

alban-auzeill merged 1 commit into
masterfrom
alban/SCANDOCKER-87

Conversation

@alban-auzeill

@alban-auzeill alban-auzeill commented Sep 16, 2026 •

Copy link
Copy Markdown
Member

The version changes are sufficient. No dependency in this PR requires a new or removed parameter.
All 10 checks pass, and the one genuine breaking change (skipSignatureVerification) is already exercised by the passing scan job.

Reference links and migration requirements

Dependency Reference Migration requirement Status
actions/checkout v5.0.0→v7.0.1 v6.0.0, v7.0.0, v7.0.1 v6: Node 24 + creds persisted to a separate file. v7: blocks fork-PR checkout for pull_request_target/workflow_run N/A — our triggers are pull_request/push
jdx/mise-action v3.2.0→v4.3.0 v4.0.0, v4.3.0 Only Node 20→24 runtime; notes say "no configuration changes needed" version/cache_save still valid
mise 2025.7.12→2026.9.9 releases — breaking in 2026.4.16, 2026.7.14, 2026.8.14, 2026.9.7 Breaking items are npm/node-gyp, brew casks, task shell args, python symlinks None touch .tool-versions or bats; mise ls-remote bats lists 1.14.0
ci-github-actions v1→v2 2.0.0, Git References README permissions: contents: write for get-build-number; remove cross-job BUILD_NUMBER passthrough Present at build.yml:21; no passthrough to remove
vault-action-wrapper 3.1.0→3.6.1 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.5.1, 3.6.1 No new inputs. Behaviour note: 3.2.0 auto-selects the Vault role from GITHUB_REF secrets is our only input
docker/login-action v3.5.0→v4.6.0 v4.0.0 Requires Actions Runner v2.327.1+ (Node 24 default) Satisfied — both jobs using it passed
sonarqube-scan-action v6→v8 v7.0.0, v8.0.0, README §skipSignatureVerification Breaking: default flips true→false, so the runner needs gpg + dirmngr, else set it back to true Scan job passed in 42s → both present
hadolint → v2.15.1 v2.15.1 None Same digest as :latest; local run exits 0
bats-core v1.12.0+12→v1.14.0 v1.13.0, v1.14.0 Two breaking: run now honors set -e (#1118); errors when no tests found, --allow-empty-suite to revert (#1211) N/A — no set -e in qa.bats; 5 tests found; --tap still works
bats-assert v2.2.0+1→v2.2.4 v2.2.4 None Test job passed

The old bats pin was v1.12.0-12-g855844b, so this crosses two releases — that's where the only breaking changes in the PR outside sonarqube-scan-action live.

@alban-auzeill
alban-auzeill requested a review from a team as a code owner September 16, 2026 07:25
@hashicorp-vault-sonar-prod

Copy link
Copy Markdown

SCANDOCKER-87

@sonarqube-next

Copy link
Copy Markdown

@gitar-bot

gitar-bot Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Code Review ✅ Approved

Build workflow dependencies updated. No issues found.

Review coverage

Functional validation 1 of 1 objectives covered

Rules No rules evaluated

Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ SCANDOCKER-87 - 1 of 1 objectives covered

This PR covers the objective to update build workflow dependencies.

✅ 1 covered here
  • ✅ Update build workflow dependencies
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@alban-auzeill
alban-auzeill requested review from antoine-vinot-sonarsource and removed request for a team September 16, 2026 08:19
@alban-auzeill
alban-auzeill merged commit d030b21 into master Sep 17, 2026
12 checks passed
@alban-auzeill
alban-auzeill deleted the alban/SCANDOCKER-87 branch September 17, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants