Skip to content

Update github actions - #548

Merged
trask merged 1 commit into
mainfrom
renovate/github-actions
Aug 4, 2026
Merged

Update github actions#548
trask merged 1 commit into
mainfrom
renovate/github-actions

Conversation

@renovate

@renovate renovate Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/setup-java action minor v5.6.0v5.7.0
github/codeql-action action patch v4.37.3v4.37.5
gradle/actions action minor v6.2.0v6.3.0
jdx/mise-action action patch v4.2.3v4.2.4

Release Notes

actions/setup-java (actions/setup-java)

v5.7.0

Compare Source

github/codeql-action (github/codeql-action)

v4.37.5

Compare Source

v4.37.4

Compare Source

gradle/actions (gradle/actions)

v6.3.0

Compare Source

Highlights

Enhanced Caching: Windows fixes and a cache-protocol bump

This release updates gradle-actions-caching to v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:

  • Cache entries failed to store at all on Windows.. Every entry failed
    with Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, so
    every downstream job ran against an empty Gradle User Home. The cause was a nested,
    unpatched copy of @actions/glob combined with a silently swallowed require() in
    the bundle, which left Windows path separators unnormalized.

  • Cache cleanup deleted instrumented jars that were in use. A bug in key
    hashing for paths shorter than 64 characters made cleanup judge freshly created
    caches/jars-9 entries as unused and remove them, so the instrumented-jars entry
    was never saved and every job re-instrumented its classpaths.

    Also included: cache entry names are now consistent between the save and restore
    reports — restore previously fell back to showing the raw glob pattern (e.g.
    /home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead of dependencies.

[!IMPORTANT]
Existing cache entries are invalidated by this release. The cache protocol
version was bumped to v2, so the first run after upgrading will be a cache miss
and will repopulate the cache. No configuration changes are required.

Basic caching warns instead of failing silently

The basic (open-source) caching provider now emits a warning and reports
(Entry not saved: save failed) in the Job Summary when a cache save fails, rather
than reporting success (#​1028).

Dependency submission works with Isolated Projects

dependency-submission now disables Isolated Projects via a promoted property, so
dependency graph generation works on builds that enable it (#​1025). Thanks to @​reinsch82 for the contribution.

Updated defaults
  • Injected Develocity Gradle plugin: 4.4.2 → 4.5.0
  • 36 new known-good wrapper checksums added for wrapper-validation

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.2.0...v6.3.0

jdx/mise-action (jdx/mise-action)

v4.2.4: : Reliable locking detection under forced color

Compare Source

A small patch release that fixes locking-support detection when workflows force colored output.

Fixed
Detect mise install --locked reliably under forced color (#​580 by @​scop)

When colored output was forced globally (for example via CLICOLOR_FORCE=1), ANSI escape codes in mise install --help prevented the action from matching --locked in the help text, so locking support was reported as unavailable even on versions of mise that supported it.

The help probe now runs with NO_COLOR=1 in its environment, which overrides CLICOLOR_FORCE and guarantees plain-text output for the feature detection — regardless of the surrounding workflow's color settings.

Full Changelog: jdx/mise-action@v4.2.3...v4.2.4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 07:59 AM, only on Tuesday (* 0-7 * * 2)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copilot AI review requested due to automatic review settings August 4, 2026 00:24
@renovate
renovate Bot requested review from a team as code owners August 4, 2026 00:24

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.

This PR updates pinned GitHub Actions to newer patch versions across CI, release, lint, and security scanning workflows.

Changes:

  • Bump actions/setup-java from v5.6.0 to v5.7.0 in multiple workflows.
  • Bump gradle/actions/* from v6.2.0 to v6.3.0 (setup + wrapper validation).
  • Bump github/codeql-action/* from v4.37.3 to v4.37.5 and jdx/mise-action from v4.2.3 to v4.2.4.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
.github/workflows/reusable-lint-check.yml Updates jdx/mise-action pin for lint workflow tooling setup.
.github/workflows/release.yml Updates Java/Gradle setup actions used for building and publishing releases.
.github/workflows/ossf-scorecard.yml Updates CodeQL SARIF upload action used by Scorecard workflow.
.github/workflows/gradle-wrapper-validation.yml Updates Gradle wrapper validation action pin.
.github/workflows/codeql.yml Updates Java/Gradle setup and CodeQL init/analyze action pins.
.github/workflows/build-common.yml Updates Java/Gradle setup pins used by shared build workflow.
.github/workflows/auto-update-semconv.yml Updates Java/Gradle setup pins used by semantic convention auto-update automation.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@trask
trask merged commit e2e8f24 into main Aug 4, 2026
18 checks passed
@trask
trask deleted the renovate/github-actions branch August 4, 2026 00:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants