ci: bump actions/setup-java from 5.7.0 to 6.0.0 - #2972
dependabot[bot] wants to merge 2 commits into
Conversation
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@v5.7.0...v6) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
jaime-jmebot
left a comment
There was a problem hiding this comment.
Thanks! Looked through the whole diff — this is a clean, consistent version bump.
- All 10
setup-javausages in the repo are updated together (.github/workflows/main.yml×8,j3o-scan.yml,android-screenshot.yml), and no@v5.7.0references are left behind. - The SHA-pinned occurrence now points at
dd06d9c, which I confirmed is exactly the commit that tagv6.0.0resolves to, so the# v6.0.0comment is accurate. - Only
distributionandjava-versioninputs are used at these call sites, so the v6 input renames (jdkFile→jdk-file, GPG settings) don't affect us. - No workflow runs are attached to the head commit yet — worth letting the PR-triggered build go green before merging, since this touches the workflow that runs our builds.
|
@jaime-jmebot CI is failing for this PR, create a new PR that supersedes this pr and does the same action upgrade with also the fix to make CI green again. |
|
I have opened #2979 (#2979) to supersede this pull request as requested by @riccardobl. Please see #2979 for details. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
* ci: bump actions/setup-java from 5.7.0 to 6.0.0 Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0. - [Release notes](https://github.com/actions/setup-java/releases) - [Commits](actions/setup-java@v5.7.0...v6) --- updated-dependencies: - dependency-name: actions/setup-java dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> * ci: bump actions/setup-java to v6, install gpg in screenshot container Supersedes #2972, which had the same bump but left CI red. setup-java v6 verifies the JDK signature with gpg. The ScreenshotTests container has no gpg, so both matrix legs failed. Install gnupg there. * ci: add gpg install step for ScreenshotTests, drop stray path file * ci: remove stray `path` file A file literally named `path`, containing the text .github/workflows/main.yml, was committed by mistake. Nothing references it; delete it. * ci: delete stray path file --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Riccardo Balbo <riccardo0blb@gmail.com>
Bumps actions/setup-java from 5.7.0 to 6.0.0.
Release notes
Sourced from actions/setup-java's releases.
... (truncated)
Commits
de7274fAvoid macOS GPG socket overflow on long runner paths (#1266)134912aFix import-safe checks when scripts are run from a path with symlinks (#1265)0781fc6Fix alpine failures by switching default back to only warn on verification fa...4889c4aFix Temurin EA E2E signature verification (#1260)8fd3240[WIP] Fix failing GitHub Actions job for temurin 17 (#1259)2732291chore(deps-dev): update eslint and globals (#1256)1a8f22bchore: streamline Dependabot updates (#1255)85030b7docs: complete v6 release highlights (#1254)dd06d9cPrepare documentation for v6 release (#1253)59b3450chore(deps): combine open Dependabot npm updates (#1252)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)