-
Notifications
You must be signed in to change notification settings - Fork 351
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update @actions/cache to 4.0.0 #1328
Conversation
|
It's not clear why this is failing. I don't have access to the details:
|
8bfbbeb
to
c328799
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@MikeMcC399 Snyk is surfacing a medium security violation in this new package - I wonder if this is tracked anywhere in the actions/cache repo: https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
Introduced through: @actions/[email protected] › [email protected] › [email protected] › [email protected] › [email protected]
Thanks for passing on the vulnerability assessment from SNYK. I will check. |
We can leave this issue in draft until either the cut-off date Feb 2025 is reached or the vulnerability is resolved, which ever happens first. If this PR is merged without resolution, then every subsequent PR is going to get flagged by SNYK, which would be annoying. BTW: The Cypress binary is also distributing |
|
GitHub maintainers have acknowledged the issue (see actions/toolkit#1890 (reply in thread)) and have added it to their backlog to resolve in the next minor release of |
Issue
The new version is @actions/[email protected]
See also @actions/cache Package Deprecation Notice. Upgrade to the latest 4.0.0 or higher before February 1st 2025.
Change