Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update @actions/cache to 4.0.0 #1328

Closed

Conversation

MikeMcC399
Copy link
Collaborator

Issue

  • GitHub has released a new version of the npm module @actions/cache with the deprecation notice:

The new service will gradually roll out as of February 1st, 2025. The legacy service will also be sunset on the same date. Changes in this release are fully backward compatible.

All previous versions of this package will be deprecated. We recommend upgrading to version 4.0.0 as soon as possible before February 1st, 2025.

The new version is @actions/[email protected]

See also @actions/cache Package Deprecation Notice. Upgrade to the latest 4.0.0 or higher before February 1st 2025.

Change

@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 self-assigned this Dec 7, 2024
@MikeMcC399 MikeMcC399 marked this pull request as ready for review December 7, 2024 11:33
@MikeMcC399
Copy link
Collaborator Author

It's not clear why this is failing. I don't have access to the details:

security/snyk (Cypress Tools) — 1 test has failed

@MikeMcC399 MikeMcC399 force-pushed the update/at-actions/cache branch from 8bfbbeb to c328799 Compare December 9, 2024 11:18
Copy link
Member

@jennifer-shehane jennifer-shehane left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@MikeMcC399 Snyk is surfacing a medium security violation in this new package - I wonder if this is tracked anywhere in the actions/cache repo: https://security.snyk.io/vuln/SNYK-JS-INFLIGHT-6095116

Introduced through: @actions/[email protected][email protected][email protected][email protected][email protected]

@MikeMcC399
Copy link
Collaborator Author

@jennifer-shehane

Thanks for passing on the vulnerability assessment from SNYK. I will check.

@MikeMcC399 MikeMcC399 marked this pull request as draft December 9, 2024 16:38
@MikeMcC399
Copy link
Collaborator Author

@jennifer-shehane

We can leave this issue in draft until either the cut-off date Feb 2025 is reached or the vulnerability is resolved, which ever happens first.

If this PR is merged without resolution, then every subsequent PR is going to get flagged by SNYK, which would be annoying.

BTW: The Cypress binary is also distributing inflight through glob.

@MikeMcC399
Copy link
Collaborator Author

@MikeMcC399 MikeMcC399 closed this Dec 13, 2024
@MikeMcC399 MikeMcC399 deleted the update/at-actions/cache branch December 13, 2024 10:58
@MikeMcC399
Copy link
Collaborator Author

@jennifer-shehane

GitHub maintainers have acknowledged the issue (see actions/toolkit#1890 (reply in thread)) and have added it to their backlog to resolve in the next minor release of @actions/cache@4.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants