Repository navigation
Bump actions/setup-go from 6 to 7 - #1446
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6 to 7. - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](actions/setup-go@v6...v7) --- updated-dependencies: - dependency-name: actions/setup-go dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
🤖 Codex review: Security review is clear for River's current hosted configuration; this PR is superseded and should remain unmerged.
Upgrade
actions/setup-go:v6→v7- Reviewed River head:
0c4f0a9e554efd5ea4f395982afaa0c98155321c - Target action tag resolves to canonical upstream commit
b7ad1dad31e06c5925ef5d2fc7ad053ef454303e.
Security review
- Inputs/outputs and Node 24 remain unchanged. Reviewed ESM/toolkit migration, downloader behavior and cache-key SHA256 use (the action does not add Go-distribution checksum verification), cache read/write policy handling, graph churn and setup/post-job bundles. New native resolver hooks are development-only and absent from shipped bundles. Embedded CRC64 WASM matches the verified Azure storage npm artifact; no external WASM download is introduced.
- Independently verified 33 relevant published npm tarballs across the Actions group against registry/upstream-lock SHA512 integrity. No same-version integrity rewrites or non-registry sources were found. Toolkit provenance subject digests match the inspected artifacts; signature/transparency chains were not independently verified. Target release commits have GitHub-valid signatures.
- No action-specific public advisory found. This does not establish that bundled dependencies are advisory-free.
Compatibility verification
- Master
81c96bfe8167ab90a5009dad6098195b9857cb62already contains every requested reference update through #1459, including additional workflows added since this stale PR. No remaining upgrade from this PR needs merging. - No action entrypoint was executed locally. Hosted checkout/cache/toolchain semantics require GitHub runners; stale failing checks, where present, are not treated as a passing gate. This is a comment-only supersession decision.
Residual risk
- New bundled
fast-xml-parser 5.9.3is affected by GHSA-8r6m-32jq-jx6q, fixed in 5.10.1. Azure response parsing enables entities. In River's default hosted configuration, XML comes from GitHub/Azure cache-service responses; no attacker-controlled source/module/cache-archive XML path was found. This reachability assessment is an inference, not a fix or a vulnerability-free claim; reassess for custom endpoints/proxies. Brace-expansion is bypassed bynobrace: true; vulnerable undici APIs are unused. Generated bundles/WASM were not rebuilt or exhaustively audited; the major tag remains mutable although the exact v7.0.0 release is immutable.
|
@dependabot rebase |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
Superseded by #1459: master already contains this exact Actions upgrade. Dependabot cannot rebase this older PR because its configuration entry changed, so closing it as redundant. The dependency security review is recorded above. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps actions/setup-go from 6 to 7.
Release notes
Sourced from actions/setup-go's releases.
... (truncated)
Commits
b7ad1dachore(deps): bump@actions/cacheto 6.2.0 (#771)0778a10Migrate to ESM and upgrade dependencies (#763)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)