chore(deps): bump actions/upload-artifact from 4 to 7 (#2444)

Bumps
[actions/upload-artifact](https://github.com/actions/upload-artifact)
from 4 to 7.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/actions/upload-artifact/releases">actions/upload-artifact's
releases</a>.</em></p>
<blockquote>
<h2>v7.0.0</h2>
<h2>v7 What's new</h2>
<h3>Direct Uploads</h3>
<p>Adds support for uploading single files directly (unzipped). Callers
can set the new <code>archive</code> parameter to <code>false</code> to
skip zipping the file during upload. Right now, we only support single
files. The action will fail if the glob passed resolves to multiple
files. The <code>name</code> parameter is also ignored with this
setting. Instead, the name of the artifact will be the name of the
uploaded file.</p>
<h3>ESM</h3>
<p>To support new versions of the <code>@actions/*</code> packages,
we've upgraded the package to ESM.</p>
<h2>What's Changed</h2>
<ul>
<li>Add proxy integration test by <a
href="https://github.com/Link"><code>@​Link</code></a>- in <a
href="https://redirect.github.com/actions/upload-artifact/pull/754">actions/upload-artifact#754</a></li>
<li>Upgrade the module to ESM and bump dependencies by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/762">actions/upload-artifact#762</a></li>
<li>Support direct file uploads by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/764">actions/upload-artifact#764</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/Link"><code>@​Link</code></a>- made
their first contribution in <a
href="https://redirect.github.com/actions/upload-artifact/pull/754">actions/upload-artifact#754</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v6...v7.0.0">https://github.com/actions/upload-artifact/compare/v6...v7.0.0</a></p>
<h2>v6.0.0</h2>
<h2>v6 - What's new</h2>
<blockquote>
<p>[!IMPORTANT]
actions/upload-artifact@v6 now runs on Node.js 24 (<code>runs.using:
node24</code>) and requires a minimum Actions Runner version of 2.327.1.
If you are using self-hosted runners, ensure they are updated before
upgrading.</p>
</blockquote>
<h3>Node.js 24</h3>
<p>This release updates the runtime to Node.js 24. v5 had preliminary
support for Node.js 24, however this action was by default still running
on Node.js 20. Now this action by default will run on Node.js 24.</p>
<h2>What's Changed</h2>
<ul>
<li>Upload Artifact Node 24 support by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/719">actions/upload-artifact#719</a></li>
<li>fix: update <code>@​actions/artifact</code> for Node.js 24 punycode
deprecation by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/744">actions/upload-artifact#744</a></li>
<li>prepare release v6.0.0 for Node.js 24 support by <a
href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/745">actions/upload-artifact#745</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0">https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0</a></p>
<h2>v5.0.0</h2>
<h2>What's Changed</h2>
<p><strong>BREAKING CHANGE:</strong> this update supports Node
<code>v24.x</code>. This is not a breaking change per-se but we're
treating it as such.</p>
<ul>
<li>Update README.md by <a
href="https://github.com/GhadimiR"><code>@​GhadimiR</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/681">actions/upload-artifact#681</a></li>
<li>Update README.md by <a
href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
href="https://redirect.github.com/actions/upload-artifact/pull/712">actions/upload-artifact#712</a></li>
<li>Readme: spell out the first use of GHES by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/727">actions/upload-artifact#727</a></li>
<li>Update GHES guidance to include reference to Node 20 version by <a
href="https://github.com/patrikpolyak"><code>@​patrikpolyak</code></a>
in <a
href="https://redirect.github.com/actions/upload-artifact/pull/725">actions/upload-artifact#725</a></li>
<li>Bump <code>@actions/artifact</code> to <code>v4.0.0</code></li>
<li>Prepare <code>v5.0.0</code> by <a
href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
<a
href="https://redirect.github.com/actions/upload-artifact/pull/734">actions/upload-artifact#734</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="043fb46d1a"><code>043fb46</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/797">#797</a>
from actions/yacaovsnc/update-dependency</li>
<li><a
href="634250c138"><code>634250c</code></a>
Include changes in typespec/ts-http-runtime 0.3.5</li>
<li><a
href="e454baaac2"><code>e454baa</code></a>
Readme: bump all the example versions to v7 (<a
href="https://redirect.github.com/actions/upload-artifact/issues/796">#796</a>)</li>
<li><a
href="74fad66b98"><code>74fad66</code></a>
Update the readme with direct upload details (<a
href="https://redirect.github.com/actions/upload-artifact/issues/795">#795</a>)</li>
<li><a
href="bbbca2ddaa"><code>bbbca2d</code></a>
Support direct file uploads (<a
href="https://redirect.github.com/actions/upload-artifact/issues/764">#764</a>)</li>
<li><a
href="589182c5a4"><code>589182c</code></a>
Upgrade the module to ESM and bump dependencies (<a
href="https://redirect.github.com/actions/upload-artifact/issues/762">#762</a>)</li>
<li><a
href="47309c993a"><code>47309c9</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/754">#754</a>
from actions/Link-/add-proxy-integration-tests</li>
<li><a
href="02a8460834"><code>02a8460</code></a>
Add proxy integration test</li>
<li><a
href="b7c566a772"><code>b7c566a</code></a>
Merge pull request <a
href="https://redirect.github.com/actions/upload-artifact/issues/745">#745</a>
from actions/upload-artifact-v6-release</li>
<li><a
href="e516bc8500"><code>e516bc8</code></a>
docs: correct description of Node.js 24 support in README</li>
<li>Additional commits viewable in <a
href="https://github.com/actions/upload-artifact/compare/v4...v7">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact&package-manager=github_actions&previous-version=4&new-version=7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: gsxdsm <gsxdsm@users.noreply.github.com>
This commit is contained in:
dependabot[bot]
2026-07-27 19:06:09 -07:00
committed by GitHub
parent b848a13509
commit 74d6513fae
7 changed files with 25 additions and 19 deletions

View File

@@ -53,7 +53,7 @@ jobs:
node -e "require('node:fs').writeFileSync(process.argv[1], process.argv[2] + '\n')" "$pack_dir/agent-browser-version.txt" "$agent_browser_version"
- name: Upload packed install fixture
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: agent-browser-install-pack
path: |

View File

@@ -215,7 +215,7 @@ jobs:
# Automated publish is intentionally deferred to FN-5593.
# Keep a single artifact; filenames include -x64 / -arm64 so both arches are captured.
- name: Upload Windows artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-desktop-windows
path: |

View File

@@ -126,7 +126,7 @@ jobs:
# snapshot automatically — refresh is manual/scheduled only.
- name: Upload per-shard test timings
if: always()
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: test-timings-shard-${{ matrix.shard }}
# Relative outputFile paths mean each package writes its own
@@ -138,10 +138,11 @@ jobs:
plugins/examples/*/.timings/timings-*.json
if-no-files-found: ignore
# FNXC:TestInfrastructure 2026-07-24-01:05:
# .timings/ is a dot-directory and upload-artifact@v4 excludes hidden
# .timings/ is a dot-directory and upload-artifact excludes hidden
# files by default, so this step silently uploaded NOTHING since it was
# added ("No files were found") and the timing snapshot could never be
# refreshed from CI. Hidden files must be included for the glob to match.
# FNXC:CI 2026-07-28-01:35: pin is actions/upload-artifact@v7 (Dependabot #2444).
include-hidden-files: true
retention-days: 14

View File

@@ -20,7 +20,7 @@ jobs:
run: pnpm --filter @fusion/dashboard build
- name: Upload dashboard dist artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: dashboard-dist-client
path: packages/dashboard/dist/client
@@ -93,7 +93,7 @@ jobs:
- name: Upload iOS artifact
if: steps.ios-check.outputs.exists == 'true'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-ios-ipa
path: ${{ runner.temp }}/ios-artifacts/fusion-ios.ipa
@@ -156,7 +156,7 @@ jobs:
- name: Upload Android artifact
if: steps.android-check.outputs.exists == 'true'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-android-apk
path: packages/mobile/android/app/build/outputs/apk/debug/*.apk

View File

@@ -155,7 +155,7 @@ jobs:
fi
- name: Upload artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: ${{ matrix.binary }}
path: |
@@ -227,7 +227,7 @@ jobs:
}
- name: Upload desktop Windows artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-desktop-windows
path: |
@@ -331,7 +331,7 @@ jobs:
done
- name: Upload desktop macOS artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-desktop-macos
path: |
@@ -422,7 +422,7 @@ jobs:
done
- name: Upload desktop Linux artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
# Single glob set covers both linux-x64 and linux-arm64 artifact filenames.
name: fusion-desktop-linux
@@ -581,7 +581,7 @@ jobs:
done
- name: Upload Android artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-android-apk
path: |

View File

@@ -103,7 +103,7 @@ jobs:
"$hash ${{ matrix.binary }}" | Out-File -Encoding ascii ${{ matrix.binary }}.sha256
- name: Upload artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: ${{ matrix.binary }}
path: |
@@ -162,7 +162,7 @@ jobs:
}
- name: Upload desktop Windows artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-desktop-windows
path: |
@@ -262,7 +262,7 @@ jobs:
done
- name: Upload desktop macOS artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-desktop-macos
path: |
@@ -347,7 +347,7 @@ jobs:
done
- name: Upload desktop Linux artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
# Single glob set covers both linux-x64 and linux-arm64 artifact filenames.
name: fusion-desktop-linux
@@ -504,7 +504,7 @@ jobs:
done
- name: Upload Android artifacts
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: fusion-android-apk
path: |
@@ -532,7 +532,7 @@ jobs:
ls -la combined/
- name: Upload combined archive
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v7
with:
name: all-binaries
path: combined/*

View File

@@ -858,7 +858,12 @@ describe("Cross-platform agent-browser install workflow", () => {
expect(content).toContain("pnpm pack --pack-destination");
expect(content).toContain('dependencies["agent-browser"]');
expect(content).toContain("agent-browser-version.txt");
expect(content).toContain("actions/upload-artifact@v4");
/*
FNXC:CI 2026-07-28-01:35:
Dependabot PR #2444 bumps actions/upload-artifact 4→7 on the agent-browser install workflow.
Gate pin must track the workflow pin; download-artifact stays at v4 until a paired bump.
*/
expect(content).toContain("actions/upload-artifact@v7");
expect(content).toContain("actions/download-artifact@v4");
expect(content).toContain("Packed Fusion manifest lost the exact agent-browser pin");
expect(content).toContain("Packed Fusion manifest lost the agent-browser bin");