mirror of
https://github.com/gradle/actions.git
synced 2026-09-10 19:28:33 +08:00
Rolls the outstanding dependency updates into a single change, along with fixes for two breaking changes they brought with them. ## Gradle Wrapper 9.6.1 → 9.7.1 Updated in all five wrapped projects: `sources/test/init-scripts` and the `gradle-plugin`, `groovy-dsl`, `java-toolchain` and `kotlin-dsl` workflow samples. ## GitHub Actions - `actions/setup-java` v5.7.0 → v6.0.0 - `github/codeql-action/init` and `github/codeql-action/analyze` re-pinned to a newer v3.29.5 commit ## npm dependencies - `@typescript-eslint/eslint-plugin` 8.66.0 → 8.69.0 - `esbuild` 0.28.1 → 0.28.2 - `eslint` 10.8.0 → 10.9.1 - `globals` 17.9.0 → 17.11.0 `jest` stays at 30.4.2 and `@jest/globals` at 30.4.1 — see below. ## setup-java v6 needs signature verification disabled for EOL JDKs v6 enables `verify-signature` by default. Temurin 16 and 20 are EOL and publish no signatures, so the toolchain-detection job could no longer install them: ``` Java setup process failed due to: Input 'verify-signature' is enabled, but no signature URL was found for Temurin version 16.0.2+7. ``` Verification is disabled for those two steps only. The Java 17 and matrix steps still verify. ## jest is held at 30.4.x because 30.5.0 breaks nock jest 30.5.0 reworked the ESM module registry (ES modules keyed by full URL, modules shared across overlapping CommonJS/ESM graphs). nock ends up patching a different module instance than the one `@actions/http-client` reaches undici through, so it no longer intercepts anything: all five mocked tests in `short-lived-token.test.ts` silently hit the real network and resolve `null`. Two further tests in that file keep passing only vacuously — they assert `null`, which is also what an unintercepted request returns. Bisected on node 24.18.0, changing only the jest version: | jest | result | | --- | --- | | 30.5.0 | 5 failed, 38 passed | | 30.4.2 | 43 passed | nock 15.0.0 does not fix it, so this cannot be resolved by moving nock forward. The node version matters too: 24.3.0 masks the failure completely, which is why it reproduced only in CI. Because `jest` is an exactly-pinned direct devDependency, the pin by itself holds the entire test runtime at 30.4.x — `jest-cli`, `jest-runtime`, `jest-environment-node`, `@jest/core`, `@jest/transform`, `@jest/types`, `expect` and `jest-util` all resolve to 30.4.x with no `overrides` block. Nothing in the tree forces jest forward; only dependabot proposes it. So the constraint is expressed in `.github/dependabot.yml`, alongside the existing `typescript` and `@types/node` entries, ignoring `jest` and `@jest/globals` `>=30.5.0` with a comment recording when it can be lifted. `pretty-format` is left to float to 30.5.1 via the types-only `@types/jest`; it renders test output and has no bearing on nock or module resolution. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Signed-off-by: bot-githubaction <bot-githubaction@gradle.com> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: bot-githubaction <bot-githubaction@gradle.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
47 lines
1.0 KiB
YAML
47 lines
1.0 KiB
YAML
name: CI-codeql
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- 'main'
|
|
- 'release/**'
|
|
- 'dev/**' # Allow running Code QL on dev branches without a PR
|
|
pull_request:
|
|
branches:
|
|
- 'main'
|
|
schedule:
|
|
- cron: '25 23 * * 2'
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
analyze:
|
|
name: Analyze
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
actions: read
|
|
contents: read
|
|
security-events: write
|
|
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
language: [ 'javascript-typescript' ]
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
# Initializes the CodeQL tools for scanning.
|
|
- name: Initialize CodeQL
|
|
uses: github/codeql-action/init@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v3.29.5
|
|
with:
|
|
languages: ${{ matrix.language }}
|
|
config: |
|
|
paths:
|
|
- sources/src
|
|
|
|
- name: Perform CodeQL Analysis
|
|
uses: github/codeql-action/analyze@cdf488f595d80d6e07e03d4674febd5ab45fa938 # v3.29.5
|