Skip to content

ci: bump actions/cache from 4 to 5 in the github-actions group - #56

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-97f38a5d32
Jan 26, 2026
Merged

ci: bump actions/cache from 4 to 5 in the github-actions group#56
github-actions[bot] merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-97f38a5d32

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the github-actions group with 1 update: actions/cache.

Updates actions/cache from 4 to 5

Release notes

Sourced from actions/cache's releases.

v5.0.0

[!IMPORTANT] actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

If you are using self-hosted runners, ensure they are updated before upgrading.


What's Changed

Full Changelog: actions/cache@v4.3.0...v5.0.0

v4.3.0

What's Changed

New Contributors

Full Changelog: actions/cache@v4...v4.3.0

v4.2.4

What's Changed

New Contributors

Full Changelog: actions/cache@v4...v4.2.4

v4.2.3

What's Changed

  • Update to use @​actions/cache 4.0.3 package & prepare for new release by @​salmanmkc in actions/cache#1577 (SAS tokens for cache entries are now masked in debug logs)

New Contributors

Full Changelog: actions/cache@v4.2.2...v4.2.3

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

Changelog

5.0.2

  • Bump @actions/cache to v5.0.3 #1692

5.0.1

  • Update @azure/storage-blob to ^12.29.1 via @actions/cache@5.0.1 #1685

5.0.0

[!IMPORTANT] actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.

4.3.0

  • Bump @actions/cache to v4.1.0

4.2.4

  • Bump @actions/cache to v4.0.5

4.2.3

  • Bump @actions/cache to v4.0.3 (obfuscates SAS token in debug logs for cache entries)

4.2.2

  • Bump @actions/cache to v4.0.2

4.2.1

  • Bump @actions/cache to v4.0.1

4.2.0

TLDR; The cache backend service has been rewritten from the ground up for improved performance and reliability. actions/cache now integrates with the new cache service (v2) APIs.

The new service will gradually roll out as of February 1st, 2025. The legacy service will also be sunset on the same date. Changes in these release are fully backward compatible.

We are deprecating some versions of this action. We recommend upgrading to version v4 or v3 as soon as possible before February 1st, 2025. (Upgrade instructions below).

If you are using pinned SHAs, please use the SHAs of versions v4.2.0 or v3.4.0

If you do not upgrade, all workflow runs using any of the deprecated actions/cache will fail.

... (truncated)

Commits
  • 8b402f5 Merge pull request #1692 from GhadimiR/main
  • 304ab5a license for httpclient
  • 609fc19 Update licensed record for cache
  • b22231e Build
  • 93150cd Add PR link to releases
  • 9b8ca9f Bump actions/cache to 5.0.3
  • 9255dc7 Merge pull request #1686 from actions/cache-v5.0.1-release
  • 8ff5423 chore: release v5.0.1
  • 9233019 Merge pull request #1685 from salmanmkc/node24-storage-blob-fix
  • b975f2b fix: add peer property to package-lock.json for dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the github-actions group with 1 update: [actions/cache](https://github.com/actions/cache).


Updates `actions/cache` from 4 to 5
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v5)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jan 26, 2026
@github-actions
github-actions Bot merged commit 1546c1f into main Jan 26, 2026
5 of 8 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/github-actions-97f38a5d32 branch January 26, 2026 01:23
jeremy pushed a commit that referenced this pull request Feb 19, 2026
Bumps the github-actions group with 1 update: [actions/cache](https://github.com/actions/cache).


Updates `actions/cache` from 4 to 5
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v4...v5)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
jeremy added a commit that referenced this pull request Jul 28, 2026
* Bound the keyring probe on headless sessions (Refs #568)

Bumps github.com/basecamp/cli to the post-#56 credstore
(v0.2.2-0.20260728023309-04e401b12c6c), which adds
StoreOptions.ProbeTimeout: a bounded availability probe that kills the
hung `security` child on darwin and falls back to file storage as if
the probe had failed.

The CLI wires it interactivity-aware: when stderr is not a terminal
(CI, piped installers, ssh without a TTY) the probe is bounded at ten
seconds — a headless session can never answer a keychain unlock prompt,
so hanging forever in an uncancellable child was the only alternative
(the #568 incident class, previously mitigated only by lazy
construction and the BASECAMP_NO_KEYRING escape hatch). Interactive
sessions keep the unbounded probe: a locked keychain there raises an
unlock prompt, and cutting it off mid-answer would silently degrade the
user to plaintext file storage.

ForceFile is deliberately not wired: credstore's internal
timeout-to-file fallback covers the CLI's need, and the env-var path
already provides forced file mode.

* Treat only fully detached sessions as headless (Refs #568)

Stderr alone misclassified routine interactive use: `2>auth.log` from
a terminal would have bounded the probe and, on a >10s unlock answer,
silently degraded to plaintext file storage with the warning hidden in
the redirected log. Headless now requires stdin, stdout, and stderr to
all be non-terminals — any attached stream means a human can answer the
unlock prompt on the controlling terminal or the GUI. Review feedback
on #581.

* Recognize GUI sessions before bounding the probe (Refs #568)

All three stdio streams being non-terminals is not proof of
headlessness: a macOS app or IDE task runner launches the CLI fully
detached while the user can still answer the keychain unlock dialog on
the WindowServer. Headless now additionally requires no GUI session —
on darwin via `launchctl managername` != Aqua (bounded, cannot touch
the keychain, failures count as no GUI so true headless keeps the
bounded probe); elsewhere via DISPLAY/WAYLAND_DISPLAY, with Windows
always false since Credential Manager never prompts. Review feedback
on #581.

* Split the Windows GUI-session stub into its own file (Refs #568)

The !darwin implementation's claim that Windows is always non-GUI was
false — that build returned true on any platform with DISPLAY set. A
dedicated session_windows.go hard-codes false with the rationale, the
unix implementation drops the stale claim, and the env test gains the
Wayland-only branch. Review feedback on #581.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants