Skip to content
This repository has been archived by the owner on Nov 5, 2024. It is now read-only.

Bump actions/cache from 2 to 3 #2543

Merged
merged 1 commit into from
Sep 3, 2023

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 3, 2023

Bumps actions/cache from 2 to 3.

Release notes

Sourced from actions/cache's releases.

v3.0.0

  • This change adds a minimum runner version(node12 -> node16), which can break users using an out-of-date/fork of the runner. This would be most commonly affecting users on GHES 3.3 or before, as those runners do not support node16 actions and they can use actions from github.com via github connect or manually copying the repo to their GHES instance.

  • Few dependencies and cache action usage examples have also been updated.

Updating actions/core to version 1.10.0

The ::save-state and ::set-output are deprecated. The newer version of actions/core >1.10.0 uses the new syntax for save and set output. After this change, customers using actions/cache@v2 won't see deprecation warning message.

v2.1.7

Support 10GB cache upload using the latest version 1.0.8 of @actions/cache

v2.1.6

  • Catch unhandled "bad file descriptor" errors that sometimes occurs when the cache server returns non-successful response (actions/cache#596)

v2.1.5

  • Fix permissions error seen when extracting caches with GNU tar that were previously created using BSD tar (actions/cache#527)

v2.1.4

  • Make caching more verbose #650
  • Use GNU tar on macOS if available #701

v2.1.3

  • Upgrades @actions/core to v1.2.6 for CVE-2020-15228. This action was not using the affected methods.
  • Fix error handling in uploadChunk where 400-level errors were not being detected and handled correctly

v2.1.2

  • Adds input to limit the chunk upload size, useful for self-hosted runners with slower upload speeds
  • No-op when executing on GHES

v2.1.1

  • Update @actions/cache package to v1.0.2 which allows cache action to use posix format when taring files.

v2.1.0

  • Replaces the http-client with the Azure Storage SDK for NodeJS when downloading cache content from Azure. This should help improve download performance and reliability as the SDK downloads files in 4 MB chunks, which can be parallelized and retried independently
  • Display download progress and speed
Changelog

Sourced from actions/cache's changelog.

Releases

3.0.0

  • Updated minimum runner version support from node 12 -> node 16

3.0.1

  • Added support for caching from GHES 3.5.
  • Fixed download issue for files > 2GB during restore.

3.0.2

  • Added support for dynamic cache size cap on GHES.

3.0.3

  • Fixed avoiding empty cache save when no files are available for caching. (issue)

3.0.4

  • Fixed tar creation error while trying to create tar with path as ~/ home folder on ubuntu-latest. (issue)

3.0.5

  • Removed error handling by consuming actions/cache 3.0 toolkit, Now cache server error handling will be done by toolkit. (PR)

3.0.6

  • Fixed #809 - zstd -d: no such file or directory error
  • Fixed #833 - cache doesn't work with github workspace directory

3.0.7

  • Fixed #810 - download stuck issue. A new timeout is introduced in the download process to abort the download if it gets stuck and doesn't finish within an hour.

3.0.8

  • Fix zstd not working for windows on gnu tar in issues #888 and #891.
  • Allowing users to provide a custom timeout as input for aborting download of a cache segment using an environment variable SEGMENT_DOWNLOAD_TIMEOUT_MINS. Default is 60 minutes.

3.0.9

  • Enhanced the warning message for cache unavailablity in case of GHES.

3.0.10

  • Fix a bug with sorting inputs.
  • Update definition for restore-keys in README.md

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested a review from ILIYANGERMANOV as a code owner September 3, 2023 09:01
@dependabot dependabot bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 3, 2023
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Sep 3, 2023

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/github_actions/actions/cache-3 branch September 3, 2023 09:55
@StefMa
Copy link
Contributor

StefMa commented Sep 3, 2023 via email

@ILIYANGERMANOV
Copy link
Collaborator

Why did you closed all of these? 🤔

On Sun, Sep 3, 2023, 11:55 AM dependabot[bot] @.> wrote: OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition https://docs.github.com/en/code-security/supply-chain-security/configuration-options-for-dependency-updates#ignore with the desired update_types to your config file. If you change your mind, just re-open this PR and I'll resolve any conflicts on it. — Reply to this email directly, view it on GitHub <#2543 (comment)>, or unsubscribe https://github.com/notifications/unsubscribe-auth/ACOBQ66XEFRFHARNQ62D6DDXYRHYRANCNFSM6AAAAAA4JFSJX4 . You are receiving this because you are subscribed to this thread.Message ID: @.>

Hey, I'm reconfiguring dependabot to group deps updates properly https://github.com/Ivy-Apps/ivy-wallet/blob/devexp/.github/dependabot.yml

I closed them because:

  • Each merged PR = message in https://t.me/+ETavgioAvWg4NThk = SPAM = we lose community members
  • If I merge for example the Kotlin update w/o Compose update = the app may crash runtime (Kotlin and Compose must go together)

@StefMa Would there be a way to ask dependabot to re-open them but following my rules that I'm configuring atm?

@StefMa
Copy link
Contributor

StefMa commented Sep 3, 2023

Okay, understood.
Maybe you want to excude the "message in telekom" in case the merged commit is from dependabot? 🤔

Would there be a way to ask dependabot to re-open them but following my rules that I'm configuring atm?

Sorry, I don't know.
But I guess as soon as you group them together, they will be re-opened in that group. In case they belong to a group now.
Otherwise, I guess its not possible..

@ILIYANGERMANOV
Copy link
Collaborator

@dependabot reopen

@dependabot dependabot bot reopened this Sep 3, 2023
@dependabot dependabot bot restored the dependabot/github_actions/actions/cache-3 branch September 3, 2023 21:17
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/cache-3 branch from d7712eb to 129feeb Compare September 3, 2023 21:17
@ILIYANGERMANOV
Copy link
Collaborator

@dependabot recreate

Bumps [actions/cache](https://github.com/actions/cache) from 2 to 3.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v2...v3)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/github_actions/actions/cache-3 branch from 129feeb to f26878c Compare September 3, 2023 21:22
@ILIYANGERMANOV ILIYANGERMANOV merged commit 64650f2 into main Sep 3, 2023
@dependabot dependabot bot deleted the dependabot/github_actions/actions/cache-3 branch September 3, 2023 21:43
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants