Skip to content

Pin dependencies - gh-action_cache v1.5.0#263

Merged
julien-carsique-sonarsource merged 1 commit into
masterfrom
renovate/github-actions
May 20, 2026
Merged

Pin dependencies - gh-action_cache v1.5.0#263
julien-carsique-sonarsource merged 1 commit into
masterfrom
renovate/github-actions

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 20, 2026

This PR contains the following updates:

Package Type Update Change
SonarSource/gh-action_cache action minor v1.4.4v1.5.0

Release Notes

SonarSource/gh-action_cache (SonarSource/gh-action_cache)

v1.5.0

Compare Source

What's Changed
New Features
Bug Fixes

Full Changelog: SonarSource/gh-action_cache@v1.4.5...v1.5.0

v1.4.5

Compare Source

Improvements

Full Changelog: SonarSource/gh-action_cache@v1.4.4...v1.4.5


Configuration

📅 Schedule: (in timezone Europe/Paris)

  • Branch creation
    • "after 7am every weekday,before 8pm every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from a team as a code owner May 20, 2026 13:30
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 20, 2026

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: undefined
Post-upgrade command 'pre-commit autoupdate --freeze || true' has not been added to the allowed list in allowedCommands

@renovate renovate Bot temporarily deployed to sca-checking May 20, 2026 13:30 Inactive
@sonar-review-alpha
Copy link
Copy Markdown
Contributor

sonar-review-alpha Bot commented May 20, 2026

Summary

Renovate-generated dependency update pinning three GitHub Actions to specific commits. Primary change: gh-action_cache upgraded from v1.4.4 to v1.5.0 across 8 action files. The v1.5.0 release includes new cache metrics features and fixes a pre-commit regression. All changes are mechanical reference updates with consistent version comments.

What reviewers should know

Scope: Review the consistency of version updates across all 8 files—each should pin gh-action_cache to the same commit hash (bdecdb...).

What changed: Lines containing uses: SonarSource/gh-action_cache@ were updated. The comment suffix changed from # v1.4.4 to # v1.5.0, and the commit hash was updated to match that version tag.

Release highlights (from the description): v1.5.0 adds cache-size-bytes output for metrics, simplifies the CI_METRICS_ENABLED gate, and fixes a container self-reference regression from earlier patches. These are improvements, not breaking changes.

Note: No functional code changes—this is a dependency pinning update. The files being modified are all GitHub Actions configuration files (action.yml).


  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

@hashicorp-vault-sonar-prod
Copy link
Copy Markdown

hashicorp-vault-sonar-prod Bot commented May 20, 2026

Renovate Jira issue ID: BUILD-11421

Copy link
Copy Markdown
Contributor

@sonar-review-alpha sonar-review-alpha Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

Clean, mechanical Renovate PR with no issues found. All 8 gh-action_cache references use the identical v1.5.0 digest (bdecdb7…), and both workflow-level pins are consistent — every external uses: reference in the repo is now digest-pinned. The only unpinned references are local ./.actions/… paths, which correctly cannot and do not need digest pinning.

🗣️ Give feedback

@julien-carsique-sonarsource julien-carsique-sonarsource changed the title Pin dependencies Pin dependencies - gh-action_cache v1.5.0 May 20, 2026
@julien-carsique-sonarsource julien-carsique-sonarsource enabled auto-merge (rebase) May 20, 2026 13:42
@sonarqubecloud
Copy link
Copy Markdown

@julien-carsique-sonarsource julien-carsique-sonarsource merged commit 951552e into master May 20, 2026
13 of 14 checks passed
@julien-carsique-sonarsource julien-carsique-sonarsource deleted the renovate/github-actions branch May 20, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant