From 74d6513fae227672e7444edb9f8eb825fd6b39cd Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 27 Jul 2026 19:06:09 -0700 Subject: [PATCH] chore(deps): bump actions/upload-artifact from 4 to 7 (#2444) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
Release notes

Sourced from actions/upload-artifact's releases.

v7.0.0

v7 What's new

Direct Uploads

Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.

ESM

To support new versions of the @actions/* packages, we've upgraded the package to ESM.

What's Changed

New Contributors

Full Changelog: https://github.com/actions/upload-artifact/compare/v6...v7.0.0

v6.0.0

v6 - What's new

[!IMPORTANT] actions/upload-artifact@v6 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

Node.js 24

This release updates the runtime to Node.js 24. v5 had preliminary support for Node.js 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.

What's Changed

Full Changelog: https://github.com/actions/upload-artifact/compare/v5.0.0...v6.0.0

v5.0.0

What's Changed

BREAKING CHANGE: this update supports Node v24.x. This is not a breaking change per-se but we're treating it as such.

... (truncated)

Commits

[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact&package-manager=github_actions&previous-version=4&new-version=7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
--------- Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: gsxdsm --- .github/workflows/agent-browser-install.yml | 2 +- .github/workflows/desktop-windows.yml | 2 +- .github/workflows/full-suite.yml | 5 +++-- .github/workflows/mobile.yml | 6 +++--- .github/workflows/release.yml | 10 +++++----- .github/workflows/test-release.yml | 12 ++++++------ packages/cli/src/__tests__/ci-workflow.test.ts | 7 ++++++- 7 files changed, 25 insertions(+), 19 deletions(-) diff --git a/.github/workflows/agent-browser-install.yml b/.github/workflows/agent-browser-install.yml index bbc5b1baa3..00f0b5f732 100644 --- a/.github/workflows/agent-browser-install.yml +++ b/.github/workflows/agent-browser-install.yml @@ -53,7 +53,7 @@ jobs: node -e "require('node:fs').writeFileSync(process.argv[1], process.argv[2] + '\n')" "$pack_dir/agent-browser-version.txt" "$agent_browser_version" - name: Upload packed install fixture - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: agent-browser-install-pack path: | diff --git a/.github/workflows/desktop-windows.yml b/.github/workflows/desktop-windows.yml index 1b8d0934f9..4c11e029a1 100644 --- a/.github/workflows/desktop-windows.yml +++ b/.github/workflows/desktop-windows.yml @@ -215,7 +215,7 @@ jobs: # Automated publish is intentionally deferred to FN-5593. # Keep a single artifact; filenames include -x64 / -arm64 so both arches are captured. - name: Upload Windows artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-desktop-windows path: | diff --git a/.github/workflows/full-suite.yml b/.github/workflows/full-suite.yml index 59fdddf823..aa43aa07ff 100644 --- a/.github/workflows/full-suite.yml +++ b/.github/workflows/full-suite.yml @@ -126,7 +126,7 @@ jobs: # snapshot automatically — refresh is manual/scheduled only. - name: Upload per-shard test timings if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: test-timings-shard-${{ matrix.shard }} # Relative outputFile paths mean each package writes its own @@ -138,10 +138,11 @@ jobs: plugins/examples/*/.timings/timings-*.json if-no-files-found: ignore # FNXC:TestInfrastructure 2026-07-24-01:05: - # .timings/ is a dot-directory and upload-artifact@v4 excludes hidden + # .timings/ is a dot-directory and upload-artifact excludes hidden # files by default, so this step silently uploaded NOTHING since it was # added ("No files were found") and the timing snapshot could never be # refreshed from CI. Hidden files must be included for the glob to match. + # FNXC:CI 2026-07-28-01:35: pin is actions/upload-artifact@v7 (Dependabot #2444). include-hidden-files: true retention-days: 14 diff --git a/.github/workflows/mobile.yml b/.github/workflows/mobile.yml index 397856e800..c24ef05ad6 100644 --- a/.github/workflows/mobile.yml +++ b/.github/workflows/mobile.yml @@ -20,7 +20,7 @@ jobs: run: pnpm --filter @fusion/dashboard build - name: Upload dashboard dist artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: dashboard-dist-client path: packages/dashboard/dist/client @@ -93,7 +93,7 @@ jobs: - name: Upload iOS artifact if: steps.ios-check.outputs.exists == 'true' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-ios-ipa path: ${{ runner.temp }}/ios-artifacts/fusion-ios.ipa @@ -156,7 +156,7 @@ jobs: - name: Upload Android artifact if: steps.android-check.outputs.exists == 'true' - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-android-apk path: packages/mobile/android/app/build/outputs/apk/debug/*.apk diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fc55914119..b6aa0fb6d1 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -155,7 +155,7 @@ jobs: fi - name: Upload artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ${{ matrix.binary }} path: | @@ -227,7 +227,7 @@ jobs: } - name: Upload desktop Windows artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-desktop-windows path: | @@ -331,7 +331,7 @@ jobs: done - name: Upload desktop macOS artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-desktop-macos path: | @@ -422,7 +422,7 @@ jobs: done - name: Upload desktop Linux artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: # Single glob set covers both linux-x64 and linux-arm64 artifact filenames. name: fusion-desktop-linux @@ -581,7 +581,7 @@ jobs: done - name: Upload Android artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-android-apk path: | diff --git a/.github/workflows/test-release.yml b/.github/workflows/test-release.yml index e791b2d117..a95ede8166 100644 --- a/.github/workflows/test-release.yml +++ b/.github/workflows/test-release.yml @@ -103,7 +103,7 @@ jobs: "$hash ${{ matrix.binary }}" | Out-File -Encoding ascii ${{ matrix.binary }}.sha256 - name: Upload artifact - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: ${{ matrix.binary }} path: | @@ -162,7 +162,7 @@ jobs: } - name: Upload desktop Windows artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-desktop-windows path: | @@ -262,7 +262,7 @@ jobs: done - name: Upload desktop macOS artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-desktop-macos path: | @@ -347,7 +347,7 @@ jobs: done - name: Upload desktop Linux artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: # Single glob set covers both linux-x64 and linux-arm64 artifact filenames. name: fusion-desktop-linux @@ -504,7 +504,7 @@ jobs: done - name: Upload Android artifacts - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: fusion-android-apk path: | @@ -532,7 +532,7 @@ jobs: ls -la combined/ - name: Upload combined archive - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: all-binaries path: combined/* diff --git a/packages/cli/src/__tests__/ci-workflow.test.ts b/packages/cli/src/__tests__/ci-workflow.test.ts index c5e08ce562..43b4c0ac2a 100644 --- a/packages/cli/src/__tests__/ci-workflow.test.ts +++ b/packages/cli/src/__tests__/ci-workflow.test.ts @@ -858,7 +858,12 @@ describe("Cross-platform agent-browser install workflow", () => { expect(content).toContain("pnpm pack --pack-destination"); expect(content).toContain('dependencies["agent-browser"]'); expect(content).toContain("agent-browser-version.txt"); - expect(content).toContain("actions/upload-artifact@v4"); + /* + FNXC:CI 2026-07-28-01:35: + Dependabot PR #2444 bumps actions/upload-artifact 4→7 on the agent-browser install workflow. + Gate pin must track the workflow pin; download-artifact stays at v4 until a paired bump. + */ + expect(content).toContain("actions/upload-artifact@v7"); expect(content).toContain("actions/download-artifact@v4"); expect(content).toContain("Packed Fusion manifest lost the exact agent-browser pin"); expect(content).toContain("Packed Fusion manifest lost the agent-browser bin");