Skip to content

chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 - #87

Merged
lamemustafa merged 1 commit into
masterfrom
dependabot/github_actions/actions/setup-node-7.0.0
Aug 3, 2026
Merged

chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0#87
lamemustafa merged 1 commit into
masterfrom
dependabot/github_actions/actions/setup-node-7.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependabot major update for actions/setup-node from 6.4.0 to 7.0.0 across existing CI and release workflows.

Root Cause / Decision Record

  • The previous branch was stale and its old CI was blocked by a then-current dependency audit finding.
  • The current upstream major release changes only the setup action runtime used by existing workflows; it does not change extension runtime code or permissions.
  • This refreshed branch must pass the current GitHub checks and strict current-head review gate before merge.

Scope

  • Runtime: GitHub Actions workflow action pins only.
  • Tests: Existing CI verification only.
  • Docs/governance: PR readiness metadata only.
  • Explicitly out of scope: extension permissions, portal automation, downloads, storage, and public copy.

Pack Workflow Preflight

  • pnpm workflow:preflight is running in the current GitHub Actions validation.
  • This Dependabot PR is opened from its bot-owned update branch, not master.
  • Latest master Pack AGENTS guidance was reviewed before merge evaluation.
  • PR body keeps the required Pack privacy/review/verification checklist visible.

Sanchika Adoption Gate

  • This PR does not consume @sanchika/* packages or copied Sanchika guidance.
  • This PR does not import parent or Sanchika source paths.

Privacy And Data-Flow Impact

  • No new browser permissions, host permissions, network calls, analytics, or telemetry.
  • No credential, OTP, CAPTCHA, cookie, token, GST file, or taxpayer-data capture.
  • Public copy and privacy declarations are unchanged.

Sensitive Surface Review

  • Portal target binding and evidence-backed download completion are unchanged.
  • Service-worker durability and side-effect confirmation are unchanged.
  • No taxpayer data, local paths, raw URLs/referrers, or portal HTML are in the diff.

Chrome Web Store Impact

  • No Chrome Web Store listing scope or full-fiscal-year claim changes.
  • CI release evidence remains distinct from store-submission sign-off.
  • PR title follows Conventional Commits.

Verification

  • Current GitHub Actions: frozen install, dependency audit, WXT prepare, formatting, lint, TypeScript, Vitest, build, and package verification.
  • pnpm workflow:preflight and strict current-head review gate before merge.
  • git diff --check is covered by current Pack CI.

Artifact Evidence

  • CI run: pending on current Dependabot head.
  • ZIP artifact: not applicable until CI completes.
  • ZIP SHA-256: not applicable until CI completes.
  • Clean source/tag or head SHA: bot-owned refreshed head.

PR Review Follow-Up

  • GitHub Actions and latest-head automated review are pending.
  • Inline review threads will be inspected after checks complete.
  • No commits will be added after latest-head review without re-review.
Thread/comment Disposition Commit or evidence
Dependabot update accepted official v7.0.0 release notes; current CI pending

Screenshots

Not applicable: workflow-pin-only change.

DCO

  • Dependabot commit includes a Signed-off-by trailer.

@dependabot @github

dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from lamemustafa as a code owner July 21, 2026 00:24
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits.
Credits must be used to enable repository wide code reviews.

@lamemustafa

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-node-7.0.0 branch from 387dacd to 1f4691b Compare August 3, 2026 13:32
@lamemustafa

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@48b55a0...8207627)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-node-7.0.0 branch from 1f4691b to 43cd3d6 Compare August 3, 2026 13:41
@lamemustafa

Copy link
Copy Markdown
Owner

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: 43cd3d60b9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@lamemustafa
lamemustafa merged commit 3b8492e into master Aug 3, 2026
7 checks passed
@lamemustafa
lamemustafa deleted the dependabot/github_actions/actions/setup-node-7.0.0 branch August 3, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant