ci: bump artifact actions to v7 (upload + download together)#337
Merged
Conversation
Supersedes Dependabot #329, which bumped actions/upload-artifact 4→7 but left actions/download-artifact@v4 in release.yml's publish job. GitHub requires matching upload/download majors — a v7↔v4 pair breaks the release artifact merge (download-artifact can't read v7-format uploads). Bump all four refs together: upload-artifact in build.yml, mutation.yml, release.yml, and download-artifact in release.yml. CI/release-only; no CLI-binary change. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Contributor
|
👋 Heads-up — Code review queue is at 42 / 30 Above the WIP limit. The team convention is to review existing PRs before opening new work. Open PRs currently in Code review (oldest first):
Pull from review before opening new work. (This is a nudge from the kanban WIP check, not a block.) |
aptracebloc
approved these changes
Jul 15, 2026
saadqbal
added a commit
that referenced
this pull request
Jul 16, 2026
* chore(deps): bump softprops/action-gh-release from 2 to 3 Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3. - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@v2...v3) --- updated-dependencies: - dependency-name: softprops/action-gh-release dependency-version: '3' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * chore: back-merge main → develop after #323 promote (#335) * chore(deps): bump the k8s group with 3 updates (#331) Bumps the k8s group with 3 updates: [k8s.io/api](https://github.com/kubernetes/api), [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery) and [k8s.io/client-go](https://github.com/kubernetes/client-go). Updates `k8s.io/api` from 0.36.1 to 0.36.2 - [Commits](kubernetes/api@v0.36.1...v0.36.2) Updates `k8s.io/apimachinery` from 0.36.1 to 0.36.2 - [Commits](kubernetes/apimachinery@v0.36.1...v0.36.2) Updates `k8s.io/client-go` from 0.36.1 to 0.36.2 - [Changelog](https://github.com/kubernetes/client-go/blob/master/CHANGELOG.md) - [Commits](kubernetes/client-go@v0.36.1...v0.36.2) --- updated-dependencies: - dependency-name: k8s.io/api dependency-version: 0.36.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: k8s - dependency-name: k8s.io/apimachinery dependency-version: 0.36.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: k8s - dependency-name: k8s.io/client-go dependency-version: 0.36.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: k8s ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Asad Iqbal (Saadi) <asad.dsoft@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump github.com/schollz/progressbar/v3 (#333) Bumps [github.com/schollz/progressbar/v3](https://github.com/schollz/progressbar) from 3.19.0 to 3.19.1. - [Release notes](https://github.com/schollz/progressbar/releases) - [Commits](schollz/progressbar@v3.19.0...v3.19.1) --- updated-dependencies: - dependency-name: github.com/schollz/progressbar/v3 dependency-version: 3.19.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Asad Iqbal (Saadi) <asad.dsoft@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump helm/kind-action from 1.10.0 to 1.14.0 (#328) Bumps [helm/kind-action](https://github.com/helm/kind-action) from 1.10.0 to 1.14.0. - [Release notes](https://github.com/helm/kind-action/releases) - [Commits](helm/kind-action@v1.10.0...v1.14.0) --- updated-dependencies: - dependency-name: helm/kind-action dependency-version: 1.14.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Asad Iqbal (Saadi) <asad.dsoft@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/add-to-project from 1.0.2 to 2.0.0 (#327) Bumps [actions/add-to-project](https://github.com/actions/add-to-project) from 1.0.2 to 2.0.0. - [Release notes](https://github.com/actions/add-to-project/releases) - [Commits](actions/add-to-project@v1.0.2...v2.0.0) --- updated-dependencies: - dependency-name: actions/add-to-project dependency-version: 2.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Asad Iqbal (Saadi) <asad.dsoft@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/stale from 9 to 10 (#332) Bumps [actions/stale](https://github.com/actions/stale) from 9 to 10. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](actions/stale@v9...v10) --- updated-dependencies: - dependency-name: actions/stale dependency-version: '10' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Asad Iqbal (Saadi) <asad.dsoft@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(ci): point Dependabot at develop, not main (#336) All work in this repo flows feature → develop → main (promote PRs). Dependabot defaults to the repo default branch (main), so the first batch of bumps (#327–#334) targeted main directly — bypassing develop and set to regress on the next promote (develop carries the older deps). Set target-branch: "develop" on both ecosystems so bumps ride the normal review + promote path. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * ci: bump artifact actions to v7 (upload + download together) (#337) Supersedes Dependabot #329, which bumped actions/upload-artifact 4→7 but left actions/download-artifact@v4 in release.yml's publish job. GitHub requires matching upload/download majors — a v7↔v4 pair breaks the release artifact merge (download-artifact can't read v7-format uploads). Bump all four refs together: upload-artifact in build.yml, mutation.yml, release.yml, and download-artifact in release.yml. CI/release-only; no CLI-binary change. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> * Merge pull request #339 from tracebloc/fix/338-heartbeat-single-client fix(cli): home heartbeat fetches one client, not the whole account (#338) * chore(deps): bump github.com/spf13/cobra from 1.8.1 to 1.10.2 (#340) Bumps [github.com/spf13/cobra](https://github.com/spf13/cobra) from 1.8.1 to 1.10.2. - [Release notes](https://github.com/spf13/cobra/releases) - [Commits](spf13/cobra@v1.8.1...v1.10.2) --- updated-dependencies: - dependency-name: github.com/spf13/cobra dependency-version: 1.10.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #329. Dependabot bumped
actions/upload-artifact4→7 but leftactions/download-artifact@v4inrelease.yml's publish job — a mismatched upload/download major would break the release artifact merge. This bumps all four refs together (3× upload + 1× download). CI/release-only; no CLI change. Closes #329.🤖 Generated with Claude Code
Note
Low Risk
CI/release workflow dependency bumps only; no application or auth logic changes, though release publish depends on artifact compatibility across v7.
Overview
Aligns all GitHub Actions artifact steps on v7 so upload and download stay on the same major version.
actions/upload-artifactmoves from@v4to@v7inbuild.yml(matrix binaries),mutation.yml(gremlins report), andrelease.yml(per-platformdist/).actions/download-artifactinrelease.yml's publish job is bumped from@v4to@v7as well, avoiding a partial Dependabot-style upgrade that could breakmerge-multiplewhen aggregating release artifacts.No workflow logic, paths, or retention settings change—only the action version pins.
Reviewed by Cursor Bugbot for commit 47912d3. Bugbot is set up for automated code reviews on this repo. Configure here.