Skip to content

Bump the github-actions group across 1 directory with 2 updates#2809

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/github-actions-77afac0109
Open

Bump the github-actions group across 1 directory with 2 updates#2809
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/github-actions-77afac0109

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 2, 2026

Bumps the github-actions group with 2 updates in the / directory: dart-lang/setup-dart and actions/cache.

Updates dart-lang/setup-dart from 1.7.1 to 1.7.2

Release notes

Sourced from dart-lang/setup-dart's releases.

v1.7.2

  • Update Node.js requirement to Node 24.
  • Fix open Dependabot alerts by bumping undici to >=6.24.0.
  • Update GitHub Action dependencies (@actions/core, @actions/exec, @actions/tool-cache, @actions/http-client).
  • Update workflow actions to their latest versions (actions/checkout v6, setup-flutter).
Changelog

Sourced from dart-lang/setup-dart's changelog.

v1.7.2

  • Update Node.js requirement to Node 24.
  • Fix open Dependabot alerts by bumping undici to >=6.24.0.
  • Update GitHub Action dependencies (@actions/core, @actions/exec, @actions/tool-cache, @actions/http-client).
  • Update workflow actions to their latest versions (actions/checkout v6, setup-flutter).

v1.7.1

  • Roll undici dependency to address CVE-2025-22150.
  • Update to the latest npm dependencies.
  • Recompile the action using the new Dart / JavaScript interop.

v1.7.0

v1.6.5

  • Fix zip path handling on Windows 11 (#118[])

#118: dart-lang/setup-dart#118

v1.6.4

  • Rebuild JS code.

v1.6.3

v1.6.2

v1.6.1

  • Updated the google storage url for main channel releases.

... (truncated)

Commits
  • 65eb853 chore: prepare v1.7.2 release (#175)
  • 6e0ff0b Node 24 (#174)
  • 03a180d Group npm dependency updates (#172)
  • 74195ec Bump @​actions/exec from 1.1.1 to 3.0.0 (#167)
  • 41705c9 Bump @​actions/core from 1.11.1 to 3.0.0 (#168)
  • dd42013 Bump @​actions/tool-cache from 2.0.2 to 4.0.0 (#169)
  • b36cb5e Bump @​actions/http-client from 3.0.0 to 4.0.0 (#170)
  • 21e68f4 Bump actions/checkout from 5 to 6 in the github-actions group (#162)
  • 0bdb602 Bump @​actions/http-client from 2.2.3 to 3.0.0 (#160)
  • daef289 Bump flutter-actions/setup-flutter in the github-actions group (#159)
  • Additional commits viewable in compare view

Updates actions/cache from 5.0.3 to 5.0.4

Release notes

Sourced from actions/cache's releases.

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE]
Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

  • Bump @actions/cache to v5.0.3 #1692

5.0.1

  • Update @azure/storage-blob to ^12.29.1 via @actions/cache@5.0.1 #1685

5.0.0

[!IMPORTANT] actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

... (truncated)

Commits

@dependabot dependabot bot added the autosubmit label Apr 2, 2026
@github-actions github-actions bot added the type-infra A repository infrastructure change or enhancement label Apr 2, 2026
@auto-submit
Copy link
Copy Markdown

auto-submit bot commented Apr 2, 2026

autosubmit label was removed for dart-lang/webdev/2809, because - The status or check suite unit_test; windows; Dart main; PKG: dwds; `dart test --total-shards 3 --shard-index 2 --exclude-t... has failed. Please fix the issues identified (or deflake) before re-applying this label.

@auto-submit auto-submit bot removed the autosubmit label Apr 2, 2026
Bumps the github-actions group with 2 updates: [dart-lang/setup-dart](https://github.com/dart-lang/setup-dart) and [actions/cache](https://github.com/actions/cache).


Updates `dart-lang/setup-dart` from 1.7.1 to 1.7.2
- [Release notes](https://github.com/dart-lang/setup-dart/releases)
- [Changelog](https://github.com/dart-lang/setup-dart/blob/main/CHANGELOG.md)
- [Commits](dart-lang/setup-dart@e51d8e5...65eb853)

Updates `actions/cache` from 5.0.3 to 5.0.4
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@cdf6c1f...6682284)

---
updated-dependencies:
- dependency-name: dart-lang/setup-dart
  dependency-version: 1.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: actions/cache
  dependency-version: 5.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the title Bump the github-actions group with 2 updates Bump the github-actions group across 1 directory with 2 updates Apr 8, 2026
@dependabot dependabot bot force-pushed the dependabot/github_actions/github-actions-77afac0109 branch from 9ef44fb to 4e5a84c Compare April 8, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-infra A repository infrastructure change or enhancement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant