Skip to content

chore: Cherry-picked changes from upstream#262

Merged
Raj-StepSecurity merged 9 commits intomainfrom
auto-cherry-pick
Dec 12, 2025
Merged

chore: Cherry-picked changes from upstream#262
Raj-StepSecurity merged 9 commits intomainfrom
auto-cherry-pick

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

Cherry-picked changes from upstream.

In some cases(eg. if RUST_TOOLCHAIN is set and cargo
is managed by rustup) cargo metadata will behave
incorrectly if some environment variables are removed
@github-actions
Copy link
Copy Markdown
Contributor Author

🚀 PR Updated!

The PR has been updated with the latest cherry-picked commits.

@step-security/maintained-actions-dev Please review and approve the changes.

📦 Target Release Version: v2.8.2
📋 Previous Release Version: v2.8.1

⚠️ Completely Skipped Commits Due to only modifying files in: package.json, package-lock.json, yarn.lock, node_modules/, dist/, or .gitignore

  • 14cb63c99f59f3218434d76ea30a71214758bc74
  • 90fd0618bca3f95e8e028f7262b611077c54d1c6
  • eb57cd6af8d0b5c6aa28974150fc441e47b46fea
  • a1f94902a6a14bb816df36cf064a35883424b553
  • b08fc8f955570d8cdfa8887f2b9226c886d7b53d
  • 20d842343222d4c3b66d607d88b1ad564cb74826
  • 51dda28b917a50812be2827c6ba2930ce4df144a
  • 94162284cf9c7d6640f58b132f82f114d78d8ab0
  • 54f69366a5959e90a4c4eced34931f0a8c4a25e4
  • a84bfdc502f07db5a85dd9d7a30f91a931516cc5
  • 972b315a8225e8594dddc2b92e6333d1d1d3059c
  • c9119007a19252f0981aef1785db9b0dd6f373c0
  • f2a41b7c112cd43711cfd57f0a59eca88ec14a64
  • c071727fc96109277f0135b3f13503db23b6cc1b
  • 2ea64efb2551baf97fd9611d09c8af70b088ceae

❗ Missing Files:

  • CHANGELOG.md

🛑 Workflow Files (Cannot be auto-applied by GitHub Actions):

  • .github/workflows/buildjet.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/check-dist.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/coverage.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/dependabot.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/git-registry.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/install.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/simple.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/target-dir.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/workspaces.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/zizmor.yml from commit 7bd5339b5bb72c5e611e84cd9dc9889d368d97d1
  • .github/workflows/coverage.yml from commit 2a0d153b42e3d13eec68323e0cffc4bdfc0ca552
  • .github/workflows/coverage.yml from commit bf8c5948003802780c0a3fbf4b70a3b5274c19aa
  • .github/workflows/coverage.yml from commit 2245981121fc501aa75416a0fe803a874b11db29
  • .github/workflows/multi-job-cache.yml from commit 27f6075dd285ebdc3f2c42dec885140e5ac8bb11
  • .github/workflows/check-dist.yml from commit b28feea9c965a23a0ccab09aa03e61c1c58ed738
  • .github/workflows/coverage.yml from commit b28feea9c965a23a0ccab09aa03e61c1c58ed738
  • .github/workflows/dependabot.yml from commit b28feea9c965a23a0ccab09aa03e61c1c58ed738
  • .github/workflows/coverage.yml from commit 7ec422fc69200df613a80010a4233d8526df6fda
  • .github/workflows/coverage.yml from commit 07caf06f7a4b787ad36bd267269f3c0dfa29744b
  • .github/workflows/buildjet.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/check-dist.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/coverage.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/dependabot.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/git-registry.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/install.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/multi-job-cache.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/simple.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/target-dir.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/workspaces.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/zizmor.yml from commit 3aaed5547eb4ccbf48b9a4d7dd62a50e04f7019d
  • .github/workflows/buildjet.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/check-dist.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/coverage.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/dependabot.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/git-registry.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/install.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/multi-job-cache.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/simple.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/target-dir.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/workspaces.yml from commit 8930d9c33e314043c13794316986491e42a060d9
  • .github/workflows/zizmor.yml from commit 8930d9c33e314043c13794316986491e42a060d9

@github-actions
Copy link
Copy Markdown
Contributor Author

github-actions bot commented Dec 2, 2025

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.8.1...v2.8.2

📋 File-by-File Analysis:

.github/workflows/buildjet.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/check-dist.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+7 -3)

.github/workflows/coverage.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+8 -2)

.github/workflows/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 7 deletions)

.github/workflows/git-registry.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/install.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/multi-job-cache.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 74 additions, 0 deletions)

.github/workflows/simple.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/target-dir.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/workspaces.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - ❌ No PR patch available (+5 -1)

.github/workflows/zizmor.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 24 additions, 0 deletions)

CHANGELOG.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+17 -5)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+8 -0)

src/config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+89 -82)

src/workspace.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+1 -1)

📊 Summary:

  • Total files changed upstream: 16
  • Files present in PR: 4/16
  • Files with matching changes: 4/16

Overall Status: 🔴 INCOMPLETE - Missing files or changes

@github-actions
Copy link
Copy Markdown
Contributor Author

github-actions bot commented Dec 2, 2025

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.8.1...v2.8.2

📋 File-by-File Analysis:

.github/workflows/buildjet.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/check-dist.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+7 -3) | Missing 5 additions | Missing 3 deletions

.github/workflows/coverage.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+8 -2) | Missing 2 additions | Missing 2 deletions

.github/workflows/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 7 deletions)

.github/workflows/git-registry.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/install.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/multi-job-cache.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+74 -0) | Missing 4 additions

.github/workflows/simple.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/target-dir.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/workspaces.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/zizmor.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 24 additions, 0 deletions)

CHANGELOG.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+17 -5)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+8 -0)

src/config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+89 -82)

src/workspace.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+1 -1)

📊 Summary:

  • Total files changed upstream: 16
  • Files present in PR: 13/16
  • Files with matching changes: 4/16

Overall Status: 🔴 INCOMPLETE - Missing files or changes

Comment thread .github/workflows/check-dist.yml
Comment thread .github/workflows/multi-job-cache.yml
Comment thread .github/workflows/multi-job-cache.yml
Copy link
Copy Markdown
Contributor

@amanstep amanstep left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

make version changes in package.json file

@github-actions
Copy link
Copy Markdown
Contributor Author

github-actions bot commented Dec 4, 2025

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.8.1...v2.8.2

📋 File-by-File Analysis:

.github/workflows/buildjet.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/check-dist.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+7 -3) | Missing 5 additions | Missing 3 deletions

.github/workflows/coverage.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+8 -2) | Missing 2 additions | Missing 2 deletions

.github/workflows/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 7 deletions)

.github/workflows/git-registry.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/install.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/multi-job-cache.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+74 -0) | Missing 4 additions

.github/workflows/simple.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/target-dir.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/workspaces.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/zizmor.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 24 additions, 0 deletions)

CHANGELOG.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+17 -5)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+8 -0)

src/config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+89 -82)

src/workspace.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+1 -1)

📊 Summary:

  • Total files changed upstream: 16
  • Files present in PR: 13/16
  • Files with matching changes: 4/16

Overall Status: 🔴 INCOMPLETE - Missing files or changes

@github-actions
Copy link
Copy Markdown
Contributor Author

🔍 Cherry-Pick Verification Report

📦 Upstream Changes: v2.8.1...v2.8.2

📋 File-by-File Analysis:

.github/workflows/buildjet.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/check-dist.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+7 -3) | Missing 5 additions | Missing 3 deletions

.github/workflows/coverage.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+8 -2) | Missing 2 additions | Missing 2 deletions

.github/workflows/dependabot.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 9 additions, 7 deletions)

.github/workflows/git-registry.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/install.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/multi-job-cache.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+74 -0) | Missing 4 additions

.github/workflows/simple.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/target-dir.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/workspaces.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ❌ No
  • Status: 🟡 Partial - ❌ Cherry-pick incomplete (+5 -1) | Missing 1 additions | Missing 1 deletions

.github/workflows/zizmor.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 24 additions, 0 deletions)

CHANGELOG.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ❌ No
  • Status: 🔴 Missing - File missing in PR (upstream has 4 additions, 0 deletions)

README.md

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+17 -5)

action.yml

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+8 -0)

src/config.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+89 -82)

src/workspace.ts

  • Upstream has changes: ✅ Yes
  • File exists in PR: ✅ Yes
  • Changes match: ✅ Yes
  • Status: 🟢 Perfect - ✅ All changes applied correctly (+1 -1)

📊 Summary:

  • Total files changed upstream: 16
  • Files present in PR: 13/16
  • Files with matching changes: 4/16

Overall Status: 🔴 INCOMPLETE - Missing files or changes

@Raj-StepSecurity Raj-StepSecurity merged commit b0c7652 into main Dec 12, 2025
42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants