Skip to content

Bump actions/setup-go from 6 to 7 - #1446

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-go-7
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/setup-go-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-go from 6 to 7.

Release notes

Sourced from actions/setup-go's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/setup-go@v6...v7.0.0

v6.5.0

What's Changed

Dependency update

New Contributors

Full Changelog: actions/setup-go@v6...v6.5.0

v6.4.0

What's Changed

Enhancement

Dependency update

Documentation update

New Contributors

Full Changelog: actions/setup-go@v6...v6.4.0

v6.3.0

What's Changed

Full Changelog: actions/setup-go@v6...v6.3.0

v6.2.0

What's Changed

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7.
- [Release notes](https://github.com/actions/setup-go/releases)
- [Commits](actions/setup-go@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-go
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026

@bgentry bgentry left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Codex review: Security review is clear for River's current hosted configuration; this PR is superseded and should remain unmerged.

Upgrade

  • actions/setup-go: v6 → v7
  • Reviewed River head: 0c4f0a9e554efd5ea4f395982afaa0c98155321c
  • Target action tag resolves to canonical upstream commit b7ad1dad31e06c5925ef5d2fc7ad053ef454303e.

Security review

  • Inputs/outputs and Node 24 remain unchanged. Reviewed ESM/toolkit migration, downloader behavior and cache-key SHA256 use (the action does not add Go-distribution checksum verification), cache read/write policy handling, graph churn and setup/post-job bundles. New native resolver hooks are development-only and absent from shipped bundles. Embedded CRC64 WASM matches the verified Azure storage npm artifact; no external WASM download is introduced.
  • Independently verified 33 relevant published npm tarballs across the Actions group against registry/upstream-lock SHA512 integrity. No same-version integrity rewrites or non-registry sources were found. Toolkit provenance subject digests match the inspected artifacts; signature/transparency chains were not independently verified. Target release commits have GitHub-valid signatures.
  • No action-specific public advisory found. This does not establish that bundled dependencies are advisory-free.

Compatibility verification

  • Master 81c96bfe8167ab90a5009dad6098195b9857cb62 already contains every requested reference update through #1459, including additional workflows added since this stale PR. No remaining upgrade from this PR needs merging.
  • No action entrypoint was executed locally. Hosted checkout/cache/toolchain semantics require GitHub runners; stale failing checks, where present, are not treated as a passing gate. This is a comment-only supersession decision.

Residual risk

  • New bundled fast-xml-parser 5.9.3 is affected by GHSA-8r6m-32jq-jx6q, fixed in 5.10.1. Azure response parsing enables entities. In River's default hosted configuration, XML comes from GitHub/Azure cache-service responses; no attacker-controlled source/module/cache-archive XML path was found. This reachability assessment is an inference, not a fix or a vulnerability-free claim; reassess for custom endpoints/proxies. Brace-expansion is bypassed by nobrace: true; vulnerable undici APIs are unused. Generated bundles/WASM were not rebuilt or exhaustively audited; the major tag remains mutable although the exact v7.0.0 release is immutable.

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml.

@bgentry

bgentry commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Superseded by #1459: master already contains this exact Actions upgrade. Dependabot cannot rebase this older PR because its configuration entry changed, so closing it as redundant. The dependency security review is recorded above.

@bgentry bgentry closed this Oct 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/setup-go-7 branch October 8, 2026 01:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant