Conversation
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| actions/download-artifact | action | major | v6.0.0 → v8.0.1 |
| actions/upload-artifact | action | major | v5.0.0 → v7.0.0 |
Release Notes
actions/download-artifact (actions/download-artifact)v8.0.1
What's Changed
- Support for CJK characters in the artifact name by @danwkennedy in #471
- Add a regression test for artifact name + content-type mismatches by @danwkennedy in #472
Full Changelog: actions/download-artifact@ v8...v8.0.1
v8.0.0
v8 - What's new
Direct downloads
To support direct uploads in actions/upload-artifact, the action will no longer attempt to unzip all downloaded files. Instead, the action checks the Content-Type header ahead of unzipping and skips non-zipped files. Callers wishing to download a zipped file as-is can also set the new skip-decompress parameter to false.
Enforced checks (breaking)
A previous release introduced digest checks on the download. If a download hash didn't match the expected hash from the server, the action would log a warning. Callers can now configure the behavior on mismatch with the digest-mismatch parameter. To be secure by default, we are now defaulting the behavior to error which will fail the workflow run.
ESM
To support new versions of the @actions/* packages, we've upgraded the package to ESM.
What's Changed
- Don't attempt to un-zip non-zipped downloads by @danwkennedy in #460
- Add a setting to specify what to do on hash mismatch and default it to
errorby @danwkennedy in #461
Full Changelog: actions/download-artifact@ v7...v8.0.0
v7.0.0
v7 - What's new
[!IMPORTANT]
actions/download-artifact@v7 now runs on Node.js 24 (runs.using: node24) and requires a minimum Actions Runner version of 2.327.1. If you are using self-hosted runners, ensure they are updated before upgrading.
Node.js 24
This release updates the runtime to Node.js 24. v6 had preliminary support for Node 24, however this action was by default still running on Node.js 20. Now this action by default will run on Node.js 24.
What's Changed
- Update GHES guidance to include reference to Node 20 version by @patrikpolyak in #440
- Download Artifact Node24 support by @salmanmkc in #415
- fix: update @actions/artifact to fix Node.js 24 punycode deprecation by @salmanmkc in #451
- prepare release v7.0.0 for Node.js 24 support by @salmanmkc in #452
New Contributors
- @patrikpolyak made their first contribution in #440
- @salmanmkc made their first contribution in #415
Full Changelog: actions/download-artifact@ v6.0.0...v7.0.0
actions/upload-artifact (actions/upload-artifact)v7.0.0
v7 What's new
Direct Uploads
Adds support for uploading single files directly (unzipped). Callers can set the new archive parameter to false to skip zipping the file during upload. Right now, we only support single files. The action will fail if the glob passed resolves to multiple files. The name parameter is also ignored with this setting. Instead, the name of the artifact will be the name of the uploaded file.
ESM
To support new versions of the @actions/* packages, we've upgraded the package to ESM.
What's Changed
- Add proxy integration test by @Link- in #754
- Upgrade the module to ESM and bump dependencies by @danwkennedy in #762
- Support direct file uploads by @danwkennedy in #764
New Contributors
Full Changelog: actions/upload-artifact@ v6...v7.0.0
v6.0.0
Configuration
📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, on day 1 of the month ( * 0-3 1 * * ) (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
- If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.
renovate Bot deleted the renovate/major-github-artifact-actions branch
March 16, 2026 07:45