Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump actions/download-artifact and actions/upload-artifact #3487

Closed

Conversation

zhassan-aws
Copy link
Contributor

@zhassan-aws zhassan-aws commented Sep 3, 2024

Upgrade the download-artifact and upload-artifact actions to the latest versions.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 and MIT licenses.

@zhassan-aws zhassan-aws requested a review from a team as a code owner September 3, 2024 23:20
@zhassan-aws zhassan-aws changed the title Bump actions/download-artifact Bump actions/download-artifact and actions/upload-artifact Sep 3, 2024
@zhassan-aws
Copy link
Contributor Author

zhassan-aws commented Sep 4, 2024

This PR was meant to address the following security advisory:

GHSA-cxww-7g56-2vh6

which was issued yesterday, but has since been updated, and no longer includes the version we're using (the affected versions are >= 4.0.0, < 4.1.7, and we're using v3).

However, the versions of those actions need to be upgraded ASAP since the current versions will be deprecated on Nov 30, 2024. I filed #3492 to track this, and I'm closing this PR.

@zhassan-aws zhassan-aws closed this Sep 4, 2024
@zhassan-aws zhassan-aws deleted the bump-download-artifact branch September 4, 2024 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant