Skip to content

chore(deps): bump actions/cache from 5 to 6 - #1271

Merged
openshift-merge-bot[bot] merged 1 commit into
masterfrom
dependabot/github_actions/actions/cache-6
Jul 21, 2026
Merged

chore(deps): bump actions/cache from 5 to 6#1271
openshift-merge-bot[bot] merged 1 commit into
masterfrom
dependabot/github_actions/actions/cache-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 24, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/cache from 5 to 6.

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.1.0

What's Changed

Full Changelog: actions/cache@v5...v5.1.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits
  • 55cc834 Merge pull request #1768 from jasongin/readonly-cache
  • d8cd72f Bump @​actions/cache to v6.1.0 - handle cache write error due to RO token
  • 2c8a9bd Merge pull request #1760 from actions/samirat/esm_migration_and_package_update
  • e9b91fd Prettier fixes
  • e4884b8 Rebuild dist
  • 10baf01 Fixed licenses
  • e39b386 Fix test mock return order
  • b692820 PR feedback
  • 6074912 Rebuild dist bundles as ESM to match type:module
  • 5a912e8 Fix lint and jest issues
  • Additional commits viewable in compare view

Summary by CodeRabbit

  • Chores
    • Updated dependency caching in automated workflows to use the latest caching action version.
    • Preserved existing cache paths, keys, and restore behavior.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Jun 24, 2026
@openshift-ci

openshift-ci Bot commented Jun 24, 2026

Copy link
Copy Markdown

Hi @dependabot[bot]. Thanks for your PR.

I'm waiting for a codeready-toolchain member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work.

Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@coderabbitai

coderabbitai Bot commented Jun 24, 2026

Copy link
Copy Markdown

Walkthrough

Two GitHub Actions workflows update their dependency cache step from actions/cache@v5 to actions/cache@v6.

Changes

Workflow cache version bump

Layer / File(s) Summary
Update dependency cache action
.github/workflows/operator-cd.yml, .github/workflows/publish-components-for-e2e-tests.yml
Both workflows switch their dependency caching step from actions/cache@v5 to actions/cache@v6 while retaining the existing cache configuration.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: rajivnathan, alexeykazakov

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: upgrading actions/cache from v5 to v6.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/github_actions/actions/cache-6

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/operator-cd.yml (1)

29-34: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Isolate this cache from the PR-target workflow. .github/workflows/publish-components-for-e2e-tests.yml uses the same ~/go/pkg/mod key on pull_request_target with allow-unsafe-pr-checkout: true, so an untrusted PR can populate a cache that .github/workflows/operator-cd.yml may later restore. Use a workflow-specific key or drop the shared prefix fallback.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/operator-cd.yml around lines 29 - 34, Update the
actions/cache configuration in the operator-cd workflow to isolate its Go module
cache from the pull_request_target workflow: make the key workflow-specific and
remove or scope the shared `${{ runner.os }}-go-` restore prefix so caches
cannot be shared across workflows.

Source: Linters/SAST tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/operator-cd.yml:
- Around line 29-34: Update the actions/cache configuration in the operator-cd
workflow to isolate its Go module cache from the pull_request_target workflow:
make the key workflow-specific and remove or scope the shared `${{ runner.os
}}-go-` restore prefix so caches cannot be shared across workflows.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Enterprise

Run ID: 463bd400-559b-4d97-af20-7657eef6aeeb

📥 Commits

Reviewing files that changed from the base of the PR and between 27196c1 and 1c1e9a9.

📒 Files selected for processing (2)
  • .github/workflows/operator-cd.yml
  • .github/workflows/publish-components-for-e2e-tests.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/publish-components-for-e2e-tests.yml
📜 Review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: test
  • GitHub Check: govulncheck
  • GitHub Check: GolangCI Lint
  • GitHub Check: Build & push operator bundles & dashboard image for e2e tests
🧰 Additional context used
🪛 zizmor (1.26.1)
.github/workflows/operator-cd.yml

[error] 29-29: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default

(cache-poisoning)

🔀 Multi-repo context codeready-toolchain/registration-service, codeready-toolchain/member-operator, codeready-toolchain/toolchain-e2e, codeready-toolchain/api, codeready-toolchain/toolchain-common

Linked repositories findings

  • registration-service (inspected refs/pull/601/head): both .github/workflows/operator-cd.yml and .github/workflows/publish-components-for-e2e-tests.yml still use actions/cache@v5. [::codeready-toolchain/registration-service::]
  • member-operator (inspected refs/pull/748/head): the corresponding workflows still use actions/cache@v5. [::codeready-toolchain/member-operator::]
  • toolchain-e2e (inspected refs/pull/1289/head): .github/workflows/publish-components-for-e2e-tests.yml still uses actions/cache@v5. [::codeready-toolchain/toolchain-e2e::]
  • No related cache-action references were found in api or toolchain-common. [::codeready-toolchain/api::] [::codeready-toolchain/toolchain-common::]

These are independent workflow updates; no shared API or cross-repository contract is affected.

@openshift-ci

openshift-ci Bot commented Jul 21, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: alexeykazakov, dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@alexeykazakov

Copy link
Copy Markdown
Contributor

/ok-to-test

Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/cache-6 branch from 1c1e9a9 to 8f3b0ac Compare July 21, 2026 00:41
@sonarqubecloud

Copy link
Copy Markdown

@alexeykazakov

Copy link
Copy Markdown
Contributor

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label Jul 21, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit b43e766 into master Jul 21, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/actions/cache-6 branch July 21, 2026 03:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved ci Add or update CI/CD configuration dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code lgtm ok-to-test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant