Skip to content

[release/v7.6.7] Bump actions/upload-artifact from 7.0.0 to 7.0.1 - #28085

Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.6.7from
adityapatwardhan:backport/release/v7.6.7/27261-8359c1ba3
Sep 24, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.6.7from
adityapatwardhan:backport/release/v7.6.7/27261-8359c1ba3

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27261 to release/v7.6.7

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of @app/dependabot

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Required tooling update to keep release/v7.6.7 macOS CI, Windows packaging, security scorecard, and xUnit workflows on actions/upload-artifact v7.0.1.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

The original dependency update was validated on master. The backport cherry-picked cleanly. Targeted validation confirmed exactly the four expected GitHub workflow files changed, each replacing the actions/upload-artifact v7.0.0 pinned SHA with the v7.0.1 pinned SHA, and git diff --check upstream/release/v7.6.7...HEAD passed with no whitespace errors. Full workflow execution is deferred to required PR CI.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk because this updates a GitHub Action used by macOS CI, Windows packaging, security scorecards, and xUnit workflows on release builds. The change is narrowly scoped to the immutable actions/upload-artifact SHA and version comment, and the same update has already been validated on master and backported to other supported release branches.

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 24, 2026 05:12
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 24, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The updated action affects release, packaging, security, and CI workflows and warrants final human review.

Review effort: Lite
Findings: None

What changed in this PR

Updates actions/upload-artifact from v7.0.0 to v7.0.1 across four release workflows using immutable SHA pinning.

Changes:

  • Updated artifact upload references and version annotations.
  • Preserved existing workflow behavior and configurations.
File Description
.github/​workflows/​xunit-tests.yml Updates xUnit result uploads.
.github/​workflows/​windows-packaging-reusable.yml Updates Windows artifact uploads.
.github/​workflows/​scorecards.yml Updates SARIF artifact uploads.
.github/​workflows/​macos-ci.yml Updates macOS package uploads.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit 8cc67bb into PowerShell:release/v7.6.7 Sep 24, 2026
36 checks passed
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) deleted the backport/release/v7.6.7/27261-8359c1ba3 branch September 24, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants