Skip to content

chore(deps): update actions/upload-artifact action to v7.0.1 - #85

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-upload-artifact-7.x
Open

chore(deps): update actions/upload-artifact action to v7.0.1#85
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/actions-upload-artifact-7.x

Conversation

@renovate

@renovate renovate Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
actions/upload-artifact action patch v7.0.0v7.0.1

Release Notes

actions/upload-artifact (actions/upload-artifact)

v7.0.1

Compare Source

What's Changed

Full Changelog: actions/upload-artifact@v7...v7.0.1


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/actions-upload-artifact-7.x branch from 1634c66 to 88f37d5 Compare August 6, 2026 06:38

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 DevSecOps Renovate sweep (TIM-117) — hard exclusion

This PR modifies .github/workflows/**, which the DevSecOps Renovate autopilot is hard-coded to never auto-merge. Workflow files are a privileged attack surface (supply-chain via pinned actions, permissions:, secrets:, with: injection).

Please review and merge manually if appropriate.

🤖 Automated by DevSecOps autopilot

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot (TIM-119) — flagged for human approval. This PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list for this sweep. Diff is a minor bump of actions/upload-artifact to v7.0.1, low risk in itself, but any change to GitHub Actions workflow files gets a human gate per DevSecOps policy. Please review and merge manually if accepted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagging for human approval — this PR touches .github/workflows/scorecard.yml (actions/upload-artifact v7.0.0 → v7.0.1). Renovate workflow files are on the hard-exclusion list for this autopilot; CI is green but I will not auto-merge changes under .github/workflows/**. Diff is a single-line uses: version bump. Please approve + squash after review.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate PR — DevSecOps sweep (2026-08-14).

Hard exclusion: PR diff touches .github/workflows/scorecard.yml. Per sweep policy, any change to GitHub Actions workflow files requires human review and is never auto-merged.

CI green otherwise. Please review and merge manually if appropriate.

@timoa

timoa commented Aug 15, 2026

Copy link
Copy Markdown
Owner

Renovate sweep — skipped, hard exclusion. Patch bump (actions/upload-artifact v7.0.0 → v7.0.1) but the diff touches .github/workflows/scorecard.yml — this is in the hard exclusion list (.github/workflows/**). CI is green but the autopilot policy never auto-merges workflow changes. Please review and merge manually, or close.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Autopilot: actions/upload-artifact v7.0.0 → v7.0.1 (patch bump). Touches .github/workflows/scorecard.yml. This is a hard exclusion for the autopilot (changes to .github/workflows/** require human review only). Please review and merge if happy.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge skipped (DevSecOps sweep): HARD EXCLUSION — this PR modifies .github/workflows/scorecard.yml. Workflow file changes are excluded from automatic merging per the sweep policy. Please review and merge when ready.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates actions/upload-artifact v7.0.0 → v7.0.1 (patch, readme/typespec only). However, the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). CI is fully green. Skipping auto-merge — please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep: skipping auto-merge. actions/upload-artifact v7.0.0 → v7.0.1 is a patch bump, but the diff touches .github/workflows/scorecard.yml — workflow-file changes are on the hard-exclusion list and require human approval. Please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), out of scope for autopilot auto-merge. Diff is actions/upload-artifact v7.0.0 → v7.0.1 patch bump; CI is green. Please review and merge manually if wanted.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Green CI and the change is only actions/upload-artifact v7.0.0 → v7.0.1 (patch), but my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.

@timoa

timoa commented Aug 22, 2026

Copy link
Copy Markdown
Owner

DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies .github/workflows/scorecard.yml (actions/upload-artifact 7.0.0 → 7.0.1), which is in the excluded paths for auto-merge. Skipping auto-merge; please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the patch (v7.0.0v7.0.1 for actions/upload-artifact) is low-risk, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is auto-flagged for human review — hard exclusion in scope.

PR #85 updates actions/upload-artifact from v7.0.0 to v7.0.1 and modifies .github/workflows/scorecard.yml. Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.

This is a routine patch release of the upload-artifact action. Please review the workflow diff and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot: flagged — hard exclusion. PR touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope; please review the actions/upload-artifact patch bump manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security. Not auto-merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):

Flagged for human approval — not auto-merged.

Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps actions/upload-artifact v7.0.0v7.0.1 (patch; readme + typespec bumps).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. The autopilot does not auto-merge workflow changes per policy.

Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps daily Renovate sweep — flagged for human review.

This PR (actions/upload-artifact v7.0.0 → v7.0.1 patch) modifies .github/workflows/scorecard.yml, a hard-excluded CI/CD workflow path. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green.

No auto-merge performed. Please review the workflow edit and merge manually if approved.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps autopilot (daily Renovate sweep). Not auto-merging — the diff touches .github/workflows/scorecard.yml (a patch bump of actions/upload-artifact from v7.0.0 to v7.0.1). Workflow files are on the hard-exclusion path list because CI modifications can change permissions, secrets handling, or execution paths. The release only contains readme and TypeSpec changes, so the merge itself is benign, but please review and merge manually.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Renovate autopilot flagged this PR for human approval.

Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk patch Renovate updates.

What this PR does: Patches actions/upload-artifact from v7.0.0v7.0.1 (readme and typespec updates only).

CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa

timoa commented Sep 3, 2026

Copy link
Copy Markdown
Owner

DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check (CodeQL-Build, Detect changes, Lint/Test/Build/Security, CodeQL). The change is an actions/upload-artifact patch bump (v7.0.0 → v7.0.1, readme/typespec updates only). Low-risk content but workflow edits always need a human review. — tldr: green CI but excluded from auto-merge.

@timoa

timoa commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check. The change is an actions/upload-artifact patch bump (v7.0.0 -> v7.0.1). Low-risk content but workflow edits always need a human review.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep — not auto-merged. Modifies .github/workflows/scorecard.yml — hard exclusion for automated merge. Please review the actions/upload-artifact v7.0.1 bump manually. Other checks are green.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update is the actions/upload-artifact action to v7.0.1, CI is green. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update is the actions/upload-artifact action to v7.0.1, CI is green. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a patch bump of actions/upload-artifact (v7.0.0 → v7.0.1, readme/typespec-only changes). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.

This PR updates actions/upload-artifact v7.0.0 → v7.0.1 (patch) in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge.

Not approving. Please review and merge manually if appropriate.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Awaiting human approval. This PR modifies .github/workflows/scorecard.yml, which falls under the DevSecOps autopilot's hard exclusion for workflow-file changes. The patch bump to actions/upload-artifact v7.0.1 should be reviewed by a maintainer with workflow-edit authority. (DevSecOps daily sweep)

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Flagging for human approval (devsecops sweep, 2026-09-11).

This PR updates actions/upload-artifact v7.0.0 → v7.0.1, but the diff touches .github/workflows/scorecard.yml. The daily sweep's hard-exclusion policy auto-skips any PR that modifies .github/workflows/**, even when the change is a trusted-action patch.

Please review and merge manually when ready.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Renovate sweep (TIM-298): flagged awaiting-human.

  • Touches .github/workflows/scorecard.ymlhard exclusion (workflow files).
  • CI is green.
  • No security/patch label is present.

This PR bumps actions/upload-artifact from v7.0.0 → v7.0.1 (docs-only and typespec bumps per upstream changelog). Low risk, but workflow-file changes require explicit human approval. Please approve before merge.

@timoa timoa left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion under the DevSecOps daily Renovate sweep policy — any PR that touches GitHub Actions workflows requires human review, regardless of label. The Lint, Test, Build & Security check was SKIPPED on the latest run. Please review the workflow diff (actions/upload-artifact patch bump) and merge manually if acceptable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant