Update github actions - #548
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
This PR updates pinned GitHub Actions to newer patch versions across CI, release, lint, and security scanning workflows.
Changes:
- Bump
actions/setup-javafrom v5.6.0 to v5.7.0 in multiple workflows. - Bump
gradle/actions/*from v6.2.0 to v6.3.0 (setup + wrapper validation). - Bump
github/codeql-action/*from v4.37.3 to v4.37.5 andjdx/mise-actionfrom v4.2.3 to v4.2.4.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/reusable-lint-check.yml | Updates jdx/mise-action pin for lint workflow tooling setup. |
| .github/workflows/release.yml | Updates Java/Gradle setup actions used for building and publishing releases. |
| .github/workflows/ossf-scorecard.yml | Updates CodeQL SARIF upload action used by Scorecard workflow. |
| .github/workflows/gradle-wrapper-validation.yml | Updates Gradle wrapper validation action pin. |
| .github/workflows/codeql.yml | Updates Java/Gradle setup and CodeQL init/analyze action pins. |
| .github/workflows/build-common.yml | Updates Java/Gradle setup pins used by shared build workflow. |
| .github/workflows/auto-update-semconv.yml | Updates Java/Gradle setup pins used by semantic convention auto-update automation. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
trask
approved these changes
Aug 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v5.6.0→v5.7.0v4.37.3→v4.37.5v6.2.0→v6.3.0v4.2.3→v4.2.4Release Notes
actions/setup-java (actions/setup-java)
v5.7.0Compare Source
github/codeql-action (github/codeql-action)
v4.37.5Compare Source
v4.37.4Compare Source
gradle/actions (gradle/actions)
v6.3.0Compare Source
Highlights
Enhanced Caching: Windows fixes and a cache-protocol bump
This release updates
gradle-actions-cachingto v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:Cache entries failed to store at all on Windows.. Every entry failed
with
Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, soevery downstream job ran against an empty Gradle User Home. The cause was a nested,
unpatched copy of
@actions/globcombined with a silently swallowedrequire()inthe bundle, which left Windows path separators unnormalized.
Cache cleanup deleted instrumented jars that were in use. A bug in key
hashing for paths shorter than 64 characters made cleanup judge freshly created
caches/jars-9entries as unused and remove them, so theinstrumented-jarsentrywas never saved and every job re-instrumented its classpaths.
Also included: cache entry names are now consistent between the save and restore
reports — restore previously fell back to showing the raw glob pattern (e.g.
/home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead ofdependencies.Basic caching warns instead of failing silently
The basic (open-source) caching provider now emits a warning and reports
(Entry not saved: save failed)in the Job Summary when a cache save fails, ratherthan reporting success (#1028).
Dependency submission works with Isolated Projects
dependency-submissionnow disables Isolated Projects via a promoted property, sodependency graph generation works on builds that enable it (#1025). Thanks to @reinsch82 for the contribution.
Updated defaults
wrapper-validationWhat's Changed
New Contributors
Full Changelog: gradle/actions@v6.2.0...v6.3.0
jdx/mise-action (jdx/mise-action)
v4.2.4: : Reliable locking detection under forced colorCompare Source
A small patch release that fixes locking-support detection when workflows force colored output.
Fixed
Detect
mise install --lockedreliably under forced color (#580 by @scop)When colored output was forced globally (for example via
CLICOLOR_FORCE=1), ANSI escape codes inmise install --helpprevented the action from matching--lockedin the help text, so locking support was reported as unavailable even on versions of mise that supported it.The help probe now runs with
NO_COLOR=1in its environment, which overridesCLICOLOR_FORCEand guarantees plain-text output for the feature detection — regardless of the surrounding workflow's color settings.Full Changelog: jdx/mise-action@v4.2.3...v4.2.4
Configuration
📅 Schedule: (UTC)
* 0-7 * * 2)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.