Skip to content

Bump actions/cache from 4.3.0 to 6.1.0 - #2

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/cache-6.1.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/actions/cache-6.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown

Bumps actions/cache from 4.3.0 to 6.1.0.

Release notes

Sourced from actions/cache's releases.

v6.1.0

What's Changed

Full Changelog: actions/cache@v6...v6.1.0

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 29, 2026
Bumps [actions/cache](https://github.com/actions/cache) from 4.3.0 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@0057852...55cc834)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/cache-6.1.0 branch from 8a84c49 to 0630043 Compare September 3, 2026 17:07
@dependabot @github

dependabot Bot commented on behalf of github Sep 4, 2026

Copy link
Copy Markdown
Author

Superseded by #15.

@dependabot dependabot Bot closed this Sep 4, 2026
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/cache-6.1.0 branch September 4, 2026 15:56
karthik1729 added a commit that referenced this pull request Sep 12, 2026
…team

The create, clone, restore and push gates charged a team workspace to the team, but the object
was stamped with the person who made it (`spec.owner`) plus `spec.team`, and `usage` summed
`spec.owner` alone — so a team's workspaces, disk and snapshots were counted against no one, and
a member could allocate past any limit. `usage` now reads the team label as well as the owner
label and charges each object by one rule: `spec.team` when set, else `spec.owner`; a snapshot
follows its volume, and only a snapshot whose volume is in no listing falls back to its own
owner. The admin owners page's fold uses the same rule and the same per-item accounting as the
gate (the hidden builder spends no environment slot; a service's own resources beat the unit),
so a grant made off that page is made off the number the gate enforces.

Review 2026-09-12, findings #1, #2, #12.
karthik1729 added a commit that referenced this pull request Sep 12, 2026
…lk has a ceiling

The `.git` guard knew five HFS-ignorable code points where git's own table has sixteen, so
`.g\u{200e}it` reached a checkout as `.git`; it compared `.`/`..` before trimming the trailing
dots and spaces NTFS drops, so `".. "` was the parent directory there; and it let `:` through,
which opens an alternate data stream (`.git::$DATA`). The table is git's, the trim comes first,
and `:` is refused.

A commit diff recursed once per tree level with no bound under `panic = "abort"`, and its 4 MiB
cap applied only while formatting, after every changed path was already in memory. The walk
stops at 512 levels with an error and at 20 000 paths with the truncation marker.

A fetch naming a `want` that was neither a tip nor a commit, or a `deepen-not` that was not an
ancestor, walked the whole history with nothing counting it. The commit walks carry a budget of
two million commits, the shallow walk is interruptible and counted like the others, a fetch may
name at most 64 wants that are not tips before the whole-repository closure is refused, and
`deepen-since` reads each parent's time once.

Review findings #2, #3, #120, #122, and the walk memo.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants