build(deps): update github actions (main) (major)
Metadata
Current evaluation
Merged Renovate PR updating four GitHub Actions to major versions: download-artifact v8, upload-artifact v7, setup-uv v8.1.0, and action-gh-release v3. Approved by two reviewers. CI type warnings were non-blocking.
Suggested action: —
No scores available.
Issue body
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [actions/download-artifact](https://redirect.github.com/actions/download-artifact) | action | major | `v6` → `v8` |
| [actions/upload-artifact](https://redirect.github.com/actions/upload-artifact) | action | major | `v5` → `v7` |
| [astral-sh/setup-uv](https://redirect.github.com/astral-sh/setup-uv) | action | major | `v7` → `v8.1.0` |
| [softprops/action-gh-release](https://redirect.github.com/softprops/action-gh-release) | action | major | `v2` → `v3` |
---
### Release Notes
<details>
<summary>actions/download-artifact (actions/download-artifact)</summary>
### [`v8.0.1`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.1)
[Compare Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8.0.1)
##### What's Changed
- Support for CJK characters in the artifact name by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​471](https://redirect.github.com/actions/download-artifact/pull/471)
- Add a regression test for artifact name + content-type mismatches by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​472](https://redirect.github.com/actions/download-artifact/pull/472)
**Full Changelog**: <https://github.com/actions/download-artifact/compare/v8...v8.0.1>
### [`v8.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v8.0.0)
[Compare Source](https://redirect.github.com/actions/download-artifact/compare/v8...v8)
##### v8 - What's new
##### Direct downloads
To support direct uploads in `actions/upload-artifact`, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the `Content-Type` header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new `skip-decompress` parameter to `false`.
##### Enforced checks (breaking)
A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the `digest-mismatch` parameter. To be secure by default, we are now defaulting the behavior to `error` which will fail the workflow run.
##### ESM
To support new versions of the @​actions/\* packages, we've upgraded the package to ESM.
##### What's Changed
- Don't attempt to un-zip non-zipped downloads by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​460](https://redirect.github.com/actions/download-artifact/pull/460)
- Add a setting to specify what to do on hash mismatch and default it to `error` by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​461](https://redirect.github.com/actions/download-artifact/pull/461)
**Full Changelog**: <https://github.com/actions/download-artifact/compare/v7...v8.0.0>
### [`v8`](https://redirect.github.com/actions/download-artifact/compare/v7...v8)
[Compare Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v8)
### [`v7.0.0`](https://redirect.github.com/actions/download-artifact/releases/tag/v7.0.0)
[Compare Source](https://redirect.github.com/actions/download-artifact/compare/v7.0.0...v7.0.0)
##### v7 - What's new
> \[!IMPORTANT]
> actions/download-artifact\@​v7 now runs on Node.js 24 (`runs.using: node24`) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.
##### Node.js 24
This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
##### What's Changed
- Update GHES guidance to include reference to Node 20 version by [@​patrikpolyak](https://redirect.github.com/patrikpolyak) in [#​440](https://redirect.github.com/actions/download-artifact/pull/440)
- Download Artifact Node24 support by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​415](https://redirect.github.com/actions/download-artifact/pull/415)
- fix: update [@​actions/artifact](https://redirect.github.com/actions/artifact) to fix Node.js 24 punycode deprecation by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​451](https://redirect.github.com/actions/download-artifact/pull/451)
- prepare release v7.0.0 for Node.js 24 support by [@​salmanmkc](https://redirect.github.com/salmanmkc) in [#​452](https://redirect.github.com/actions/download-artifact/pull/452)
##### New Contributors
- [@​patrikpolyak](https://redirect.github.com/patrikpolyak) made their first contribution in [#​440](https://redirect.github.com/actions/download-artifact/pull/440)
- [@​salmanmkc](https://redirect.github.com/salmanmkc) made their first contribution in [#​415](https://redirect.github.com/actions/download-artifact/pull/415)
**Full Changelog**: <https://github.com/actions/download-artifact/compare/v6.0.0...v7.0.0>
### [`v7`](https://redirect.github.com/actions/download-artifact/compare/v6...v7)
[Compare Source](https://redirect.github.com/actions/download-artifact/compare/v6.0.0...v7.0.0)
</details>
<details>
<summary>actions/upload-artifact (actions/upload-artifact)</summary>
### [`v7.0.1`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.1)
[Compare Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7.0.1)
##### What's Changed
- Update the readme with direct upload details by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​795](https://redirect.github.com/actions/upload-artifact/pull/795)
- Readme: bump all the example versions to v7 by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​796](https://redirect.github.com/actions/upload-artifact/pull/796)
- Include changes in typespec/ts-http-runtime 0.3.5 by [@​yacaovsnc](https://redirect.github.com/yacaovsnc) in [#​797](https://redirect.github.com/actions/upload-artifact/pull/797)
**Full Changelog**: <https://github.com/actions/upload-artifact/compare/v7...v7.0.1>
### [`v7.0.0`](https://redirect.github.com/actions/upload-artifact/releases/tag/v7.0.0)
[Compare Source](https://redirect.github.com/actions/upload-artifact/compare/v7...v7)
#### v7 What's new
##### Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new `archive` parameter to `false` to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The `name` parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.
##### ESM
To support new versions of the `@actions/*` packages, we've upgraded the package to ESM.
#### What's Changed
- Add proxy integration test by [@​Link-](https://redirect.github.com/Link-) in [#​754](https://redirect.github.com/actions/upload-artifact/pull/754)
- Upgrade the module to ESM and bump dependencies by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​762](https://redirect.github.com/actions/upload-artifact/pull/762)
- Support direct file uploads by [@​danwkennedy](https://redirect.github.com/danwkennedy) in [#​764](https://redirect.github.com/actions/upload-artifact/pull/764)
#### New Contributors
- [@​Link-](https://redirect.github.com/Link-) made their first contribution in [#​754](https://redirect.github.com/actions/upload-artifact/pull/754)
**Full Changelog**: <https://github.com/actions/upload-artifact/compare/v6...v7.0.0>
### [`v7`](https://redirect.github.com/actions/upload-artifact/compare/v6...v7)
[Compare Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v7)
### [`v6.0.0`](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)
[Compare Source](https://redirect.github.com/actions/upload-artifact/compare/v6.0.0...v6.0.0)
### [`v6`](https://redirect.github.com/actions/upload-artifact/compare/v5...v6)
[Compare Source](https://redirect.github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0)
</details>
<details>
<summary>astral-sh/setup-uv (astral-sh/setup-uv)</summary>
### [`v8.1.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.1.0): 🌈 New input `no-project`
[Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v8.0.0...v8.1.0)
#### Changes
This add the a new boolean input `no-project`.
It only makes sense to use in combination with `activate-environment: true` and will append `--no project` to the `uv venv` call. This is for example useful [if you have a pyproject.toml file with parts unparseable by uv](https://redirect.github.com/astral-sh/setup-uv/issues/854)
#### 🚀 Enhancements
- Add input no-project in combination with activate-environment [@​eifinger](https://redirect.github.com/eifinger) ([#​856](https://redirect.github.com/astral-sh/setup-uv/issues/856))
#### 🧰 Maintenance
- fix: grant contents:write to validate-release job [@​eifinger](https://redirect.github.com/eifinger) ([#​860](https://redirect.github.com/astral-sh/setup-uv/issues/860))
- Add a release-gate step to the release workflow [@​zanieb](https://redirect.github.com/zanieb) ([#​859](https://redirect.github.com/astral-sh/setup-uv/issues/859))
- Draft commitish releases [@​eifinger](https://redirect.github.com/eifinger) ([#​858](https://redirect.github.com/astral-sh/setup-uv/issues/858))
- Add action-types.yml to instructions [@​eifinger](https://redirect.github.com/eifinger) ([#​857](https://redirect.github.com/astral-sh/setup-uv/issues/857))
- chore: update known checksums for 0.11.7 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​853](https://redirect.github.com/astral-sh/setup-uv/issues/853))
- Refactor version resolving [@​eifinger](https://redirect.github.com/eifinger) ([#​852](https://redirect.github.com/astral-sh/setup-uv/issues/852))
- chore: update known checksums for 0.11.6 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​850](https://redirect.github.com/astral-sh/setup-uv/issues/850))
- chore: update known checksums for 0.11.5 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​845](https://redirect.github.com/astral-sh/setup-uv/issues/845))
- chore: update known checksums for 0.11.4 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​843](https://redirect.github.com/astral-sh/setup-uv/issues/843))
- Add a release workflow [@​zanieb](https://redirect.github.com/zanieb) ([#​839](https://redirect.github.com/astral-sh/setup-uv/issues/839))
- chore: update known checksums for 0.11.3 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​836](https://redirect.github.com/astral-sh/setup-uv/issues/836))
#### 📚 Documentation
- Update ignore-nothing-to-cache documentation [@​eifinger](https://redirect.github.com/eifinger) ([#​833](https://redirect.github.com/astral-sh/setup-uv/issues/833))
- Pin setup-uv docs to v8 [@​eifinger](https://redirect.github.com/eifinger) ([#​829](https://redirect.github.com/astral-sh/setup-uv/issues/829))
#### ⬆️ Dependency updates
- chore(deps): bump release-drafter/release-drafter from 7.1.1 to 7.2.0 @​[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) ([#​855](https://redirect.github.com/astral-sh/setup-uv/issues/855))
### [`v8.0.0`](https://redirect.github.com/astral-sh/setup-uv/releases/tag/v8.0.0): 🌈 Immutable releases and secure tags
[Compare Source](https://redirect.github.com/astral-sh/setup-uv/compare/v7.6.0...v8.0.0)
##### This is the first immutable release of `setup-uv` 🥳
All future releases are also immutable, if you want to know more about what this means checkout [the docs](https://docs.github.com/en/code-security/concepts/supply-chain-security/immutable-releases).
This release also has two breaking changes
##### New format for `manifest-file`
The previously deprecated way of defining a custom version manifest to control which `uv` versions are available and where to download them from got removed. The functionality is still there but you have to use the [new format](https://redirect.github.com/astral-sh/setup-uv/blob/main/docs/customization.md#format).
##### No more major and minor tags
To increase **security** even more we will **stop publishing minor tags**. You won't be able to use `@v8` or `@v8.0` any longer. We do this because pinning to major releases opens up users to supply chain attacks like what happened to [tj-actions](https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/).
> \[!TIP]
> Use the immutable tag as a version `astral-sh/setup-uv@v8.0.0`
> Or even better the githash `astral-sh/setup-uv@cec208311dfd045dd5311c1add060b2062131d57`
##### 🚨 Breaking changes
- Remove update-major-minor-tags workflow [@​eifinger](https://redirect.github.com/eifinger) ([#​826](https://redirect.github.com/astral-sh/setup-uv/issues/826))
- Remove deprecrated custom manifest [@​eifinger](https://redirect.github.com/eifinger) ([#​813](https://redirect.github.com/astral-sh/setup-uv/issues/813))
##### 🧰 Maintenance
- Shortcircuit latest version from manifest [@​eifinger](https://redirect.github.com/eifinger) ([#​828](https://redirect.github.com/astral-sh/setup-uv/issues/828))
- Simplify inputs.ts [@​eifinger](https://redirect.github.com/eifinger) ([#​827](https://redirect.github.com/astral-sh/setup-uv/issues/827))
- Bump release-drafter to v7.1.1 [@​eifinger](https://redirect.github.com/eifinger) ([#​825](https://redirect.github.com/astral-sh/setup-uv/issues/825))
- Refactor inputs [@​eifinger](https://redirect.github.com/eifinger) ([#​823](https://redirect.github.com/astral-sh/setup-uv/issues/823))
- Replace inline compile args with tsconfig [@​eifinger](https://redirect.github.com/eifinger) ([#​824](https://redirect.github.com/astral-sh/setup-uv/issues/824))
- chore: update known checksums for 0.11.2 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​821](https://redirect.github.com/astral-sh/setup-uv/issues/821))
- chore: update known checksums for 0.11.1 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​817](https://redirect.github.com/astral-sh/setup-uv/issues/817))
- chore: update known checksums for 0.11.0 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​815](https://redirect.github.com/astral-sh/setup-uv/issues/815))
- Fix latest-version workflow check [@​eifinger](https://redirect.github.com/eifinger) ([#​812](https://redirect.github.com/astral-sh/setup-uv/issues/812))
- chore: update known checksums for 0.10.11/0.10.12 @​[github-actions\[bot\]](https://redirect.github.com/apps/github-actions) ([#​811](https://redirect.github.com/astral-sh/setup-uv/issues/811))
</details>
<details>
<summary>softprops/action-gh-release (softprops/action-gh-release)</summary>
### [`v3.0.0`](https://redirect.github.com/softprops/action-gh-release/releases/tag/v3.0.0)
[Compare Source](https://redirect.github.com/softprops/action-gh-release/compare/v3.0.0...v3.0.0)
`3.0.0` is a major release that moves the action runtime from Node 20 to Node 24.
Use `v3` on GitHub-hosted runners and self-hosted fleets that already support the
Node 24 Actions runtime. If you still need the last Node 20-compatible line, stay on
`v2.6.2`.
#### What's Changed
##### Other Changes 🔄
- Move the action runtime and bundle target to Node 24
- Update `@types/node` to the Node 24 line and allow future Dependabot updates
- Keep the floating major tag on `v3`; `v2` remains pinned to the latest `2.x` release
### [`v3`](https://redirect.github.com/softprops/action-gh-release/compare/v2...v3)
[Compare Source](https://redirect.github.com/softprops/action-gh-release/compare/v2.6.2...v3.0.0)
</details>
---
### Configuration
📅 **Schedule**: (in timezone Etc/UTC)
- Branch creation
- "every weekend"
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/charmcraft).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzkuMyIsInVwZGF0ZWRJblZlciI6IjQzLjIwOS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJQUjogRGVwZW5kZW5jaWVzIl19-->
Evaluation history
| Date | Model | Scores | Action | Summary |
|---|---|---|---|---|
| qwen/qwen3.6-35b-a3b | — | — | Merged Renovate PR updating four GitHub Actions to major versions: download-artifact v8, upload-artifact v7, setup-uv v8.1.0, and action-gh-release v3. Approved by two reviewers. CI type warnings were non-blocking. | |
| qwen3.6-35b-a3b-mtp-q6 | — | — | Renovate automerged major GitHub Actions updates for download-artifact, upload-artifact, setup-uv, and action-gh-release. Type check warnings were noted as non-blocking. Changes were successfully merged into main. | |
| qwen3.6-35b-a3b-mtp-q6 |
Staleness:
20
Complexity:
10
Confidence:
85
|
needs review | Updates major versions of GitHub Actions including download-artifact, upload-artifact, setup-uv, and action-gh-release. The PR remains open and pending merge, with recurring CI type-checking failures flagged but marked as non-actionable. |
Update history
No update history recorded yet.
Related issues
No related issues found above the similarity threshold.