Skip to content

Build(deps): Bump the actions group with 2 updates - #262

Closed
dependabot[bot] wants to merge 5 commits into
mainfrom
dependabot/github_actions/actions-02325a8da5
Closed

Build(deps): Bump the actions group with 2 updates#262
dependabot[bot] wants to merge 5 commits into
mainfrom
dependabot/github_actions/actions-02325a8da5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 2 updates: actions/checkout and actions/cache.

Updates actions/checkout from 6 to 7

Release notes

Sourced from actions/checkout's releases.

v7.0.0

What's Changed

New Contributors

Full Changelog: actions/checkout@v6.0.3...v7.0.0

v6.0.3

What's Changed

New Contributors

Full Changelog: actions/checkout@v6...v6.0.3

v6.0.2

What's Changed

Full Changelog: actions/checkout@v6.0.1...v6.0.2

v6.0.1

What's Changed

Full Changelog: actions/checkout@v6...v6.0.1

Changelog

Sourced from actions/checkout's changelog.

Changelog

v7.0.0

v6.0.3

v6.0.2

v6.0.1

v6.0.0

v5.0.1

v5.0.0

v4.3.1

v4.3.0

v4.2.2

v4.2.1

... (truncated)

Commits

Updates actions/cache from 5 to 6

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

v5.0.1

[!IMPORTANT] actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

jlukic and others added 2 commits June 25, 2026 01:34
Bumps the actions group with 2 updates: [actions/checkout](https://github.com/actions/checkout) and [actions/cache](https://github.com/actions/cache).


Updates `actions/checkout` from 6 to 7
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

Updates `actions/cache` from 5 to 6
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 25, 2026
@vercel

vercel Bot commented Jun 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
semantic-next Ready Ready Preview, Comment Jun 26, 2026 3:13pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
mcp Ignored Ignored Preview Jun 26, 2026 3:13pm

Request Review

@semantic-performance-bot

semantic-performance-bot Bot commented Jun 25, 2026

Copy link
Copy Markdown

⚪ No Meaningful Change for 5e07611 on Benchmark Suite 📊

Base: main · Action: #28246892448 · Raw: bench-report.json

Build(deps): Bump the actions group with 2 updates

Note

This PR did not move any measured metrics.

✅ 0 faster · ❌ 0 slower · 🔍 39 unsure · ⚪ 34 no change


⚪ No Change (34)

Metrics where this PR measured within ±2% of main — no meaningful performance change detected.

metric Change
ast-walk-15k -0.4% – +1.6%
build-html-string-10k -0.9% – +0.7%
todo:bulk-add-500 -0.5% – +1.1%
krausest:clear-10k -0.4% – +1.4%
computed-chain-10x60k -0.8% – +0.7%
krausest:create-10k -0.9% – +0.2%
krausest:create-1k -1.5% – +0.6%
dom-walker-1000x15 -0.9% – +1.7%
each-100 -0.5% – +1.3%
each-100-mount -1.5% – +0.0%
template:each-mount-1000 -0.8% – +0.7%
todo:edit-start-10 -1.4% – +1.1%
todo:filter-cycle-20 -0.3% – +1.4%
flush-fanout-allocation-1000x500 -0.1% – +0.9%
helper-100-mount -0.8% – +0.9%
mutate-doc-nested-200k -0.2% – +0.7%
parse-cold-complex-200 -1.7% – +1.0%
parse-cold-normal-500 -1.4% – +1.9%
reaction-coalesce-400x100 -1.1% – +0.9%
reaction-dep-diff-45k -1.9% – +0.6%
reaction-flush-noop-5m -0.6% – +0.9%
reactive-fanout-500x1200 -0.7% – +0.6%
reactive-list-replace-1000x1000 -0.6% – +0.7%
reactive-multi-read-5x160k -1.1% – +0.3%
reactive-push-2000x20 -1.1% – +1.2%
reactive-stable-deps-3reads-5000x100 +0.0% – +0.8%
reactive-stable-fanout-5000x100 -0.1% – +0.5%
set-same-10m -1.0% – +0.8%
template:subtemplate-data-blob-100 -1.3% – +0.5%
template:subtemplate-helpers-heavy-100x500 -0.6% – +0.5%
template:subtemplate-helpers-light-100x500 -1.2% – +1.2%
template:subtemplate-reactive-data-100x500 -1.1% – +1.1%
krausest:swap-rows-20 -1.4% – +1.7%
todo:toggle-all-200 -0.4% – +0.8%
🔍 Unsure (39)

Too Fast to Measure Precisely (39)

On benches this short, OS jitter, GC, and JIT pauses drown out anything under 4%. Bigger changes than that still show up.

metric Change Test Time Expected Noise
template:active-indicator-200 -2.9% – +2.3% ~36ms ±10%
template:active-indicator-nested-200 -4.4% – +0.8% ~21ms ±8%
todo:add-20 -0.8% – +2.4% ~11ms ±5%
krausest:append-1k -3.5% – +2.8% ~90ms ±8%
todo:clear-completed-250 -0.1% – +2.2% ~38ms ±3%
computed-subscribe-unsubscribe-10k -1.8% – +3.5% ~15ms ±8%
computed-unobserved-200x500 -0.8% – +2.5% ~23ms ±5%
todo:edit-cycle-5 -3.8% – -0.3% ~68ms ±4%
expr-js-10k -2.1% – +0.5% ~19ms ±6%
expr-lisp-50k -0.0% – +3.0% ~41ms ±8%
expr-simple-100k -0.8% – +2.5% ~22ms ±8%
helper-100-state-change-1k -2.4% – +1.4% ~3ms ±9%
mutate-grid-row-edit-600 -3.1% – +1.9% ~3ms ±7%
reactive-list-filter-1000x300 -0.9% – +5.2% ~5ms ±9%
reactive-set-index-300 -3.5% – +7.9% ~2ms ±16%
reactive-set-property-by-id-200 -5.0% – +1.7% ~2ms ±10%
todo:remove-50-back -0.9% – +2.6% ~6ms ±5%
todo:remove-50-front -2.9% – +1.3% ~7ms ±5%
todo:remove-50-middle -1.4% – +5.3% ~7ms ±8%
todo:remove-first-100 -1.7% – +3.7% ~15ms ±6%
todo:remove-last-100 -2.2% – +0.9% ~14ms ±4%
todo:remove-middle-100 -2.3% – +6.1% ~13ms ±11%
krausest:remove-row-back-100 -2.4% – +3.2% ~27ms ±7%
krausest:remove-row-front-20 -4.6% – +3.5% ~9ms ±9%
krausest:remove-row-middle-20 -4.6% – +2.2% ~6ms ±8%
todo:rename-500 -6.1% – +3.4% ~19ms ±12%
krausest:replace-1k -2.2% – +1.8% ~95ms ±6%
krausest:select-40 -1.8% – +5.9% ~6ms ±10%
snippet-args-5k -2.1% – +0.2% ~53ms ±5%
template:snippet-args-per-key-100x500 -0.5% – +2.2% ~34ms ±4%
template:snippet-in-subtemplate-100x1k -2.9% – +1.0% ~24ms ±7%
template:stable-ref-mutate-500 -3.9% – +2.8% ~14ms ±11%
sub-unsub-100k -0.6% – +2.8% ~28ms ±5%
template:subtemplate-shorthand-props-100x500 -0.7% – +2.1% ~42ms ±5%
todo:toggle-100 -5.3% – +2.0% ~13ms ±9%
todo:toggle-first-100 -2.3% – +3.3% ~15ms ±7%
todo:toggle-last-100 -1.9% – +2.6% ~15ms ±6%
todo:toggle-middle-100 -2.5% – +1.1% ~13ms ±4%
krausest:update-10th-50 -3.2% – +1.2% ~26ms ±6%
📖 Bench glossary (40 metrics)
metric what it tests
krausest:append-1k Appends 1000 new rows onto an existing 1000-row table.
krausest:clear-10k Clears a 10000-row table back to empty in a single operation.
krausest:create-10k Renders a fresh 10000-row table into an empty parent at ten times the create-1k scale.
krausest:create-1k Renders a fresh 1000-row table into an empty parent.
krausest:remove-row-back-100 Removes the last row 100 times from a 1000-row table, with no other rows needing to move.
krausest:remove-row-front-20 Removes the first row 20 times from a 1000-row table, with all remaining rows sliding up each time.
krausest:remove-row-middle-20 Removes the middle row 20 times from a 1000-row table, with the rows below it sliding up each time.
krausest:replace-1k Replaces 1000 rows with a fresh 1000-row set, diffing the keyed list against a populated table.
krausest:select-40 Highlights one row at a time across 40 rows so only the previous and newly highlighted rows update.
krausest:swap-rows-20 Swaps the second and second-to-last rows in a 1000-row table, repeated 20 times.
krausest:update-10th-50 Updates the label on every tenth row of a 1000-row table, looped 50 times to lift the work above noise.
template:active-indicator-200 Cycles selectedId across 200 list items. Only the previously and newly active items update their class.
template:active-indicator-nested-200 Cycles currentUrl through 50 leaf urls in a 5×10×4 nav. Only the previously and newly active leaves should update their…
template:each-mount-1000 Mounts a fresh 1000-item each block with five-field items so per-record allocation cost dominates the wall clock.
template:snippet-args-per-key-100x500 Mutates one snippet arg's source across 100 invocations, 500 cycles. Adjacent no-signal expressions stay quiet.
template:snippet-in-subtemplate-100x1k Mutates one subtemplate prop's source across 25 cards each invoking 4 inner snippets, 1000 cycles. Snippet bodies shoul…
template:stable-ref-mutate-500 Replaces one item by index in a 500-item list across 100 cycles. Only that item's expressions re-render.
template:subtemplate-data-blob-100 Mutates one field inside data=expression on 100 children. Every child re-renders by design.
template:subtemplate-helpers-heavy-100x500 100 subtemplates, 4 inner bindings where three call helpers shaped like userland reality — Intl.NumberFormat, Array.fin…
template:subtemplate-helpers-light-100x500 100 subtemplates, 4 inner bindings each calling formatDate / classIf / capitalize, 500 cycles. Mutates one source signa…
template:subtemplate-reactive-data-100x500 Mutates one verbose reactiveData field across 100 child subtemplates, 500 cycles. Only the changed field re-evaluates.
template:subtemplate-shorthand-props-100x500 Mutates one shorthand prop's source across 100 child subtemplates, 500 cycles. Only that prop re-evaluates.
todo:add-20 Appends 20 todo items one at a time, like a user typing entries in a row.
todo:bulk-add-500 Renders 500 todo items added at once from a single data load.
todo:clear-completed-250 Clears 250 completed items from a 500-item list in one action, like clicking clear completed.
todo:edit-cycle-5 Runs 5 full edit-then-save cycles on different items, like editing a row and saving it.
todo:edit-start-10 Enters edit mode on 10 different items in a row, like double-clicking each one.
todo:filter-cycle-20 Cycles through active, completed, and all filters 20 times on a 100-item list.
todo:remove-50-back Deletes 50 items from the end of a 100-item list, one click at a time.
todo:remove-50-front Deletes 50 items from the front of a 100-item list, one click at a time.
todo:remove-50-middle Deletes 50 items from the middle of a 100-item list, one click at a time.
todo:remove-first-100 Deletes the first item 100 times from a 200-item list, with remaining items moving up each time.
todo:remove-last-100 Deletes the last item 100 times from a 200-item list, with no other items needing to move.
todo:remove-middle-100 Deletes the middle item 100 times from a 200-item list, walking halfway through to find each target.
todo:rename-500 Renames items in a 100-item list 500 times via single-field setProperty without editingId co-fires.
todo:toggle-100 Cycles through the first 10 items 10 times each, like a user toggling items repeatedly down a list.
todo:toggle-all-200 Toggles all 100 items completed and back across 200 cycles via the master checkbox.
todo:toggle-first-100 Toggles the first item in a 100-item list 100 times, alternating completed on and off.
todo:toggle-last-100 Toggles the last item in a 100-item list 100 times, alternating completed on and off.
todo:toggle-middle-100 Toggles a middle item in a 100-item list 100 times, alternating completed on and off.

Sample size: 80 floor / 270 max · Noise floor: ±2% · Timeout: 3min · Wall-clock: 12m19s

@dependabot @github

dependabot Bot commented on behalf of github Jun 27, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/github_actions/actions-02325a8da5 branch June 27, 2026 15:24
jlukic added a commit that referenced this pull request Jun 27, 2026
Download fork-built artifacts into runner.temp instead of the checkout tree, so
a crafted artifact can't land on the main-overlaid reporter. Bump checkout to v7
and cache to v6 across all workflows (supersedes #262); the workflow_run
reporters check out main, so checkout v7's fork-PR block does not apply.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CI modifies continuous integration dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant