From 7136fdb676f3c600d3f4101fe9b29a2b6d114607 Mon Sep 17 00:00:00 2001 From: Stanislav Zhuk Date: Thu, 10 Sep 2026 22:00:17 +0300 Subject: [PATCH] chore: bump actions, remove setup-sandbox ## The Issue The pinned actions are behind, and `Homebrew/actions/setup-homebrew` no longer has a `setup-sandbox` input. ## How This PR Solves The Issue Bump `actions/checkout` to v7.0.1 and `Homebrew/actions/setup-homebrew` to its latest commit, bump `actions/upload-artifact` to v7 in the README example, and drop `setup-sandbox: true`. Homebrew's Linux sandbox uses Landlock now, so the Bubblewrap logic and that input are gone upstream. Every other action is already at its latest major. ## Manual Testing Instructions Run the add-ons test workflow, the Homebrew steps should behave as before. ## Automated Testing Overview Covered by the existing workflows, which use the bumped actions themselves. ## Release/Deployment Notes `CHANGELOG.md` has these entries in the v2.6.0 section, its PR links need the real number. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/add-on-disable-checkout-test.yml | 4 ++-- .github/workflows/add-ons-test.yml | 2 +- .github/workflows/doc-links.yml | 2 +- .github/workflows/release.yml | 4 ++-- CHANGELOG.md | 5 +++++ README.md | 2 +- action.yaml | 6 ++---- 7 files changed, 14 insertions(+), 11 deletions(-) diff --git a/.github/workflows/add-on-disable-checkout-test.yml b/.github/workflows/add-on-disable-checkout-test.yml index addfa77..b5dbe0d 100644 --- a/.github/workflows/add-on-disable-checkout-test.yml +++ b/.github/workflows/add-on-disable-checkout-test.yml @@ -29,10 +29,10 @@ jobs: steps: - name: Clone current repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: repository: ${{ env.ADD_ON }} ref: ${{ env.ADD_ON_REF }} diff --git a/.github/workflows/add-ons-test.yml b/.github/workflows/add-ons-test.yml index a68b709..d4be825 100644 --- a/.github/workflows/add-ons-test.yml +++ b/.github/workflows/add-ons-test.yml @@ -55,7 +55,7 @@ jobs: steps: - name: Clone current repository - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Retrieve last tag of add-on id: last_tag diff --git a/.github/workflows/doc-links.yml b/.github/workflows/doc-links.yml index 0f3350d..39ec35d 100644 --- a/.github/workflows/doc-links.yml +++ b/.github/workflows/doc-links.yml @@ -25,7 +25,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Clone sources - uses: actions/checkout@v6 + uses: actions/checkout@v7 with: path: sources diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4856685..7d45e10 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -47,7 +47,7 @@ jobs: echo "major_tag=$(echo ${{ steps.set-version-number.outputs.version_number }} | cut -d. -f1)" >> $GITHUB_OUTPUT - name: Clone sources - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: Check version consistency in CHANGELOG and README run: | @@ -134,7 +134,7 @@ jobs: contents: write steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 with: fetch-depth: 0 diff --git a/CHANGELOG.md b/CHANGELOG.md index e460337..d0ebc9d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -24,6 +24,11 @@ The [public API](https://semver.org/spec/v2.0.0.html#spec-item-1) of this projec - Install `ddev_version: HEAD` by downloading the latest `main` build with `ddev utility download-ddev` instead of building it from source with `brew install --HEAD`, which is much faster. If the download fails, for example when nightly.link is down, the Homebrew source build is used as a fallback ([PR #68](https://github.com/ddev/github-action-add-on-test/pull/68)) - Download the Docker images with `ddev utility download-images`, falling back to `ddev debug download-images` for DDEV older than v1.24.9 ([PR #68](https://github.com/ddev/github-action-add-on-test/pull/68)) +- Bump `actions/checkout` to v7.0.1 and `Homebrew/actions/setup-homebrew` ([PR #69](https://github.com/ddev/github-action-add-on-test/pull/69)) + +### Removed + +- Remove `setup-sandbox: true` from `Homebrew/actions/setup-homebrew`, the input is gone now that Homebrew's Linux sandbox uses Landlock instead of Bubblewrap ([PR #69](https://github.com/ddev/github-action-add-on-test/pull/69)) --- diff --git a/README.md b/README.md index 4311ced..2fb5964 100644 --- a/README.md +++ b/README.md @@ -245,7 +245,7 @@ jobs: - name: Upload artifacts if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: artifact-${{ matrix.ddev_version }} path: | diff --git a/action.yaml b/action.yaml index 99f5572..266d784 100644 --- a/action.yaml +++ b/action.yaml @@ -45,9 +45,7 @@ inputs: runs: using: "composite" steps: - - uses: Homebrew/actions/setup-homebrew@54f3c3de99e48b2646ca31230c9b6e9717dac4d4 # https://github.com/Homebrew/actions/commits/main/setup-homebrew/ - with: - setup-sandbox: true + - uses: Homebrew/actions/setup-homebrew@23156a3d9674d7f52f74f1a58979ec4d77847166 # https://github.com/Homebrew/actions/commits/main/setup-homebrew/ - name: Environment setup shell: bash @@ -56,7 +54,7 @@ runs: brew install bats-core bats-core/bats-core/bats-assert bats-core/bats-core/bats-file bats-core/bats-core/bats-support jq mkcert yq >/dev/null mkcert -install - - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # https://github.com/actions/checkout/commits/v6.0.3/ + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # https://github.com/actions/checkout/commits/v7.0.1/ if: inputs.disable_checkout_action == 'false' with: repository: ${{ inputs.addon_repository }}