chore(deps): update actions/upload-artifact action to v7.0.1 - #85
chore(deps): update actions/upload-artifact action to v7.0.1#85renovate[bot] wants to merge 1 commit into
Conversation
1634c66 to
88f37d5
Compare
timoa
left a comment
There was a problem hiding this comment.
🛑 DevSecOps Renovate sweep (TIM-117) — hard exclusion
This PR modifies .github/workflows/**, which the DevSecOps Renovate autopilot is hard-coded to never auto-merge. Workflow files are a privileged attack surface (supply-chain via pinned actions, permissions:, secrets:, with: injection).
Please review and merge manually if appropriate.
🤖 Automated by DevSecOps autopilot
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot (TIM-119) — flagged for human approval. This PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list for this sweep. Diff is a minor bump of actions/upload-artifact to v7.0.1, low risk in itself, but any change to GitHub Actions workflow files gets a human gate per DevSecOps policy. Please review and merge manually if accepted.
timoa
left a comment
There was a problem hiding this comment.
Flagging for human approval — this PR touches .github/workflows/scorecard.yml (actions/upload-artifact v7.0.0 → v7.0.1). Renovate workflow files are on the hard-exclusion list for this autopilot; CI is green but I will not auto-merge changes under .github/workflows/**. Diff is a single-line uses: version bump. Please approve + squash after review.
timoa
left a comment
There was a problem hiding this comment.
Renovate PR — DevSecOps sweep (2026-08-14).
Hard exclusion: PR diff touches .github/workflows/scorecard.yml. Per sweep policy, any change to GitHub Actions workflow files requires human review and is never auto-merged.
CI green otherwise. Please review and merge manually if appropriate.
|
Renovate sweep — skipped, hard exclusion. Patch bump ( |
timoa
left a comment
There was a problem hiding this comment.
Autopilot: actions/upload-artifact v7.0.0 → v7.0.1 (patch bump). Touches .github/workflows/scorecard.yml. This is a hard exclusion for the autopilot (changes to .github/workflows/** require human review only). Please review and merge if happy.
timoa
left a comment
There was a problem hiding this comment.
Auto-merge skipped (DevSecOps sweep): HARD EXCLUSION — this PR modifies .github/workflows/scorecard.yml. Workflow file changes are excluded from automatic merging per the sweep policy. Please review and merge when ready.
timoa
left a comment
There was a problem hiding this comment.
Renovate daily sweep (DevSecOps autopilot, 2026-08-18): this PR updates actions/upload-artifact v7.0.0 → v7.0.1 (patch, readme/typespec only). However, the diff touches .github/workflows/scorecard.yml, which is in the autopilot hard-exclusion list (.github/workflows/**). CI is fully green. Skipping auto-merge — please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep: skipping auto-merge. actions/upload-artifact v7.0.0 → v7.0.1 is a patch bump, but the diff touches .github/workflows/scorecard.yml — workflow-file changes are on the hard-exclusion list and require human approval. Please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
Skipping auto-merge — hard exclusion: this PR modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file), out of scope for autopilot auto-merge. Diff is actions/upload-artifact v7.0.0 → v7.0.1 patch bump; CI is green. Please review and merge manually if wanted.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily sweep flagged this for human approval. Hard exclusion: PR diff touches .github/workflows/scorecard.yml (a CI workflow file). Green CI and the change is only actions/upload-artifact v7.0.0 → v7.0.1 (patch), but my autopilot policy treats workflow-file edits as require-human. Skipping auto-merge.
|
DevSecOps sweep TIM-173: flagged for human review — hard exclusion. This PR modifies |
timoa
left a comment
There was a problem hiding this comment.
DevSecOps auto-merge is blocked for this PR: it modifies .github/workflows/scorecard.yml, which falls under the hard-exclusion list (.github/workflows/**). CI is green and the patch (v7.0.0 → v7.0.1 for actions/upload-artifact) is low-risk, but our policy requires human review for any change to GitHub Actions workflow files. Please review, approve, and merge manually.
timoa
left a comment
There was a problem hiding this comment.
This PR is auto-flagged for human review — hard exclusion in scope.
PR #85 updates actions/upload-artifact from v7.0.0 to v7.0.1 and modifies .github/workflows/scorecard.yml. Workflow files are in the autopilot's exclusion list, so I will not approve or auto-merge.
This is a routine patch release of the upload-artifact action. Please review the workflow diff and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot: flagged — hard exclusion. PR touches .github/workflows/scorecard.yml. Workflow-file edits are out of auto-merge scope; please review the actions/upload-artifact patch bump manually.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot sweep (2026-08-29). This PR modifies .github/workflows/scorecard.yml, which is a hard-excluded path. Workflow-file changes require human review for security. Not auto-merging.
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot (DevSecOps, daily sweep @ 2026-08-30):
Flagged for human approval — not auto-merged.
Reason: Hard exclusion — touches .github/workflows/scorecard.yml (GitHub Actions workflow file).
Change: Bumps actions/upload-artifact v7.0.0 → v7.0.1 (patch; readme + typespec bumps).
CI: All required checks passing.
Risk: Workflow-file change by a third-party Renovate bot. The autopilot does not auto-merge workflow changes per policy.
Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps daily Renovate sweep — flagged for human review.
This PR (actions/upload-artifact v7.0.0 → v7.0.1 patch) modifies .github/workflows/scorecard.yml, a hard-excluded CI/CD workflow path. Per the autopilot's policy, any change that touches .github/workflows/** is not auto-merged regardless of CI status or update type. All status checks are currently green.
No auto-merge performed. Please review the workflow edit and merge manually if approved.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps autopilot (daily Renovate sweep). Not auto-merging — the diff touches .github/workflows/scorecard.yml (a patch bump of actions/upload-artifact from v7.0.0 to v7.0.1). Workflow files are on the hard-exclusion path list because CI modifications can change permissions, secrets handling, or execution paths. The release only contains readme and TypeSpec changes, so the merge itself is benign, but please review and merge manually.
timoa
left a comment
There was a problem hiding this comment.
🤖 Renovate autopilot flagged this PR for human approval.
Reason: This PR modifies a GitHub Actions workflow file (.github/workflows/scorecard.yml). Per the DevSecOps policy, the autopilot does not auto-merge changes to CI/CD configuration, even for low-risk patch Renovate updates.
What this PR does: Patches actions/upload-artifact from v7.0.0 → v7.0.1 (readme and typespec updates only).
CI is green and the diff is workflow-only, but the autopilot is intentionally deferring this to a human reviewer. Please review and merge manually if acceptable.
timoa
left a comment
There was a problem hiding this comment.
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging.
|
DevSecOps Renovate sweep 2026-09-03: this PR modifies .github/workflows/scorecard.yml, which is a hard-exclusion path (.github/workflows/**) in our daily Renovate policy. Auto-merge is disabled; please review the workflow diff for supply-chain integrity before merging. |
timoa
left a comment
There was a problem hiding this comment.
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check (CodeQL-Build, Detect changes, Lint/Test/Build/Security, CodeQL). The change is an actions/upload-artifact patch bump (v7.0.0 → v7.0.1, readme/typespec updates only). Low-risk content but workflow edits always need a human review. — tldr: green CI but excluded from auto-merge.
|
Daily Renovate sweep (DevSecOps autopilot, 2026-09-04): this PR touches .github/workflows/scorecard.yml, which falls under the autopilot's hard exclusion (workflow files). Skipping auto-merge. CI is green on every reported check. The change is an actions/upload-artifact patch bump (v7.0.0 -> v7.0.1). Low-risk content but workflow edits always need a human review. |
timoa
left a comment
There was a problem hiding this comment.
Renovate sweep — not auto-merged. Modifies .github/workflows/scorecard.yml — hard exclusion for automated merge. Please review the actions/upload-artifact v7.0.1 bump manually. Other checks are green.
timoa
left a comment
There was a problem hiding this comment.
🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update is the actions/upload-artifact action to v7.0.1, CI is green. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
🛑 Held for human review — hard exclusion on diff. This Renovate PR only modifies .github/workflows/scorecard.yml, which is on the autopilot's hard-exclusion list (changes to .github/workflows/** are never auto-merged). The update is the actions/upload-artifact action to v7.0.1, CI is green. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Holding for human review (DevSecOps autopilot). This PR is on a hard-exclusion path: it modifies .github/workflows/scorecard.yml (a GitHub Actions workflow file). The diff is a patch bump of actions/upload-artifact (v7.0.0 → v7.0.1, readme/typespec-only changes). CI is green, but per the DevSecOps sweep rules, any change to .github/workflows/** is flagged for human approval and never auto-merged. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
🤖 DevSecOps autopilot (TIM-258) — flagging for human approval.
This PR updates actions/upload-artifact v7.0.0 → v7.0.1 (patch) in .github/workflows/scorecard.yml. Per the autopilot policy, changes under .github/workflows/** are hard-excluded from auto-merge and always require human review before merge.
Not approving. Please review and merge manually if appropriate.
timoa
left a comment
There was a problem hiding this comment.
Auto-merge blocked by DevSecOps policy: this PR modifies .github/workflows/scorecard.yml, which is in the hard-exclusion list (CI/CD pipeline files). No approval or merge will be applied from the autopilot. Please review the diff and merge manually if the change is desired.
timoa
left a comment
There was a problem hiding this comment.
Awaiting human approval. This PR modifies .github/workflows/scorecard.yml, which falls under the DevSecOps autopilot's hard exclusion for workflow-file changes. The patch bump to actions/upload-artifact v7.0.1 should be reviewed by a maintainer with workflow-edit authority. (DevSecOps daily sweep)
timoa
left a comment
There was a problem hiding this comment.
Flagging for human approval (devsecops sweep, 2026-09-11).
This PR updates actions/upload-artifact v7.0.0 → v7.0.1, but the diff touches .github/workflows/scorecard.yml. The daily sweep's hard-exclusion policy auto-skips any PR that modifies .github/workflows/**, even when the change is a trusted-action patch.
Please review and merge manually when ready.
timoa
left a comment
There was a problem hiding this comment.
Renovate sweep (TIM-298): flagged awaiting-human.
- Touches
.github/workflows/scorecard.yml— hard exclusion (workflow files). - CI is green.
- No
security/patchlabel is present.
This PR bumps actions/upload-artifact from v7.0.0 → v7.0.1 (docs-only and typespec bumps per upstream changelog). Low risk, but workflow-file changes require explicit human approval. Please approve before merge.
timoa
left a comment
There was a problem hiding this comment.
Skipping auto-merge. This PR modifies .github/workflows/scorecard.yml, which is a hard exclusion under the DevSecOps daily Renovate sweep policy — any PR that touches GitHub Actions workflows requires human review, regardless of label. The Lint, Test, Build & Security check was SKIPPED on the latest run. Please review the workflow diff (actions/upload-artifact patch bump) and merge manually if acceptable.
This PR contains the following updates:
v7.0.0→v7.0.1Release Notes
actions/upload-artifact (actions/upload-artifact)
v7.0.1Compare Source
What's Changed
Full Changelog: actions/upload-artifact@v7...v7.0.1
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.