Skip to content

chore(deps): bump actions/cache from 5 to 6 - #63

Merged
thwbh merged 1 commit into
developfrom
dependabot/github_actions/develop/actions/cache-6
Jun 26, 2026
Merged

thwbh merged 1 commit into
developfrom
dependabot/github_actions/develop/actions/cache-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/cache from 5 to 6.

Release notes

Sourced from actions/cache's releases.

v6.0.0

What's Changed

Full Changelog: actions/cache@v5...v6.0.0

v5.0.5

What's Changed

Full Changelog: actions/cache@v5...v5.0.5

v5.0.4

What's Changed

New Contributors

Full Changelog: actions/cache@v5...v5.0.4

v5.0.3

What's Changed

Full Changelog: actions/cache@v5...v5.0.3

v.5.0.2

v5.0.2

What's Changed

When creating cache entries, 429s returned from the cache service will not be retried.

v5.0.1

[!IMPORTANT] actions/cache@v5 runs on the Node.js 24 runtime and requires a minimum Actions Runner version of 2.327.1.

... (truncated)

Changelog

Sourced from actions/cache's changelog.

Releases

How to prepare a release

[!NOTE] Relevant for maintainers with write access only.

  1. Switch to a new branch from main.
  2. Run npm test to ensure all tests are passing.
  3. Update the version in https://github.com/actions/cache/blob/main/package.json.
  4. Run npm run build to update the compiled files.
  5. Update this https://github.com/actions/cache/blob/main/RELEASES.md with the new version and changes in the ## Changelog section.
  6. Run licensed cache to update the license report.
  7. Run licensed status and resolve any warnings by updating the https://github.com/actions/cache/blob/main/.licensed.yml file with the exceptions.
  8. Commit your changes and push your branch upstream.
  9. Open a pull request against main and get it reviewed and merged.
  10. Draft a new release https://github.com/actions/cache/releases use the same version number used in package.json
    1. Create a new tag with the version number.
    2. Auto generate release notes and update them to match the changes you made in RELEASES.md.
    3. Toggle the set as the latest release option.
    4. Publish the release.
  11. Navigate to https://github.com/actions/cache/actions/workflows/release-new-action-version.yml
    1. There should be a workflow run queued with the same version number.
    2. Approve the run to publish the new version and update the major tags for this action.

Changelog

6.1.0

6.0.0

  • Updated @actions/cache to ^6.0.1, @actions/core to ^3.0.1, @actions/exec to ^3.0.0, @actions/io to ^3.0.2
  • Migrated to ESM module system
  • Upgraded Jest to v30 and test infrastructure to be ESM compatible

5.0.4

  • Bump minimatch to v3.1.5 (fixes ReDoS via globstar patterns)
  • Bump undici to v6.24.1 (WebSocket decompression bomb protection, header validation fixes)
  • Bump fast-xml-parser to v5.5.6

5.0.3

5.0.2

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the devops label Jun 26, 2026
@chrome-grid

chrome-grid Bot commented Jun 26, 2026

Copy link
Copy Markdown

🟪🔷 netrunner :: intrusion report

░▒▓ N E T R U N N E R ▓▒░
   🟪 GRID STATUS: JACKED IN   |   netrunner-review: pass

💉 CHROME · actions/cache ⏫ 5 → 6

Dependency bump to actions/cache@v6 looks clean. CI is green, and the upgrade is straightforward with no compatibility issues or CVEs noted.


📡 NETWATCH · gate checks

✅ Test Suite — success
✅ Code Coverage — success
✅ Validate Examples — success
✅ automerge — success

🟢 VERDICT // JACKED IN — deck's clean, netrunner-review gate open.

"Stay shiny, choom. Keep your cache hot and your decks cold."
— netrunner 🟪🔷

verdict: APPROVE · model: mistral-medium-2508

@thwbh
thwbh merged commit fb4498b into develop Jun 26, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot/github_actions/develop/actions/cache-6 branch June 26, 2026 12:38
thwbh added a commit that referenced this pull request Sep 17, 2026
* chore(deps): bump actions/cache from 5 to 6 (#63)

Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump actions/setup-node from 6 to 7 (#65)

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): update syn requirement from 2.0.106 to 3.0.2 (#66)

Updates the requirements on [syn](https://github.com/dtolnay/syn) to permit the latest version.
- [Release notes](https://github.com/dtolnay/syn/releases)
- [Commits](dtolnay/syn@2.0.106...3.0.2)

---
updated-dependencies:
- dependency-name: syn
  dependency-version: 3.0.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#69)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2 to 2.85.3
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2...v2.85.3)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#70)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.85.3 to 2.85.8
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.85.3...v2.85.8)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#71)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.85.8 to 2.85.11
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.85.8...v2.85.11)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.85.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#72)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.85.11 to 2.86.3
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.85.11...v2.86.3)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.86.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#75)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.86.3 to 2.86.7
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.86.3...v2.86.7)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.86.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#79)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.86.7 to 2.87.3
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.86.7...v2.87.3)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.87.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* chore(deps): bump taiki-e/install-action (#80)

Bumps the github-actions-updates group with 1 update: [taiki-e/install-action](https://github.com/taiki-e/install-action).


Updates `taiki-e/install-action` from 2.87.3 to 2.87.8
- [Release notes](https://github.com/taiki-e/install-action/releases)
- [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md)
- [Commits](taiki-e/install-action@v2.87.3...v2.87.8)

---
updated-dependencies:
- dependency-name: taiki-e/install-action
  dependency-version: 2.87.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* External type lookup (#78)

* chore(release): prevent dirty work tree on publication

* Add External crate type lookup and nix dev enviroment.

Extend the analysis module to search the Cargo registry for
type definitions in external crates, cache discovered paths, and parse
the
files. Add tests covering the external‑type lookup feature.

* Improving the logic for validating internal types that are part of a
type from an external crate

---------

Co-authored-by: Stefan Poindl <stefan@tohuwabohu.io>

* fix(analysis): discover external types with visibility, attributes, and generics (#82) (#83)

The external-crate lookup introduced in #78 used a raw substring match
(content.contains("struct X") / content.contains("enum X")), which produced
both false negatives and false positives:

- false negatives for multi-line declarations and any form a stricter
  keyword-anchored regex would miss
- false positives where a longer identifier (e.g. ExternalFooBar) matched a
  search for a shorter one (e.g. ExternalFoo)

Replace the substring heuristic with a syn-based AST match on the item
identifier. A cheap contains(type_name) pre-filter still skips the vast
majority of registry files before paying for a parse; candidate files are
then parsed with syn::parse_file and checked for a struct/enum item whose
ident exactly equals the requested type name. This transparently handles
pub, pub(crate), #[derive(...)] attributes, generics, and multi-line
declarations, and recurses into inline mod blocks.

Files that fail to parse (macro-heavy/generated registry sources) are
skipped instead of aborting the walk.

Adds 9 regression tests covering pub(crate) visibility, derive attributes,
generics, multi-line declarations, pub enum with attributes, nested
modules, prefix false-positive avoidance, missing types, and unparseable
files. Tests run #[serial] since they share the CARGO_HOME env var.

* fix(analysis): make unresolved external types observable; fix CARGO_HOME fallback (#84) (#88)

The external-crate lookup (#78, hardened in #82) silently returned None when a
referenced type could not be found, producing quietly-incomplete bindings
with no indication that anything was wrong (the original #77 symptom). The
registry-root resolution also used format!("{}/.cargo", h), which is wrong on
Windows.

Resolve_types_lazily now records every type name it could not resolve
(neither in-project nor via the Cargo registry) on the analyzer and exposes
them via CommandAnalyzer::unresolved_types(). analyze_project_with_verbose
prints a non-fatal warning to stderr listing the unresolved names and
pointing at #84, so CLI and build.rs users see it even without --verbose.
Generation continues as before to preserve backward-compatible output.

The CARGO_HOME fallback now uses PathBuf::join (not string formatting) and
additionally honors USERPROFILE when HOME is unset, fixing the Windows path.

Vendored-dependency (.cargo/config.toml source.*.replace-with) and
cargo-metadata-based discovery are intentionally out of scope here; they are
tracked separately in #84's suggested-direction list and depend on this
reportability groundwork.

Adds 5 tests: fresh-analyzer invariant, unresolved-with-empty-registry,
unresolved-with-absent-registry-dir, resolved-in-project-type-not-reported,
and USERPROFILE-fallback-locates-type. Tests are #[serial] (shared CARGO_HOME).

* perf(analysis): persist external-crate type lookups in .typecache (#87) (#89)

The external-crate registry walk (#78/#82) was invoked on every reference to a
type within a single analyze() pass, with no result caching, so missing types
re-walked the Cargo registry DFS from scratch each time (#87). The in-process
memo added in the first cut of this change only helped within one process
invocation — on the next cargo build / tauri-typegen generate, the walk ran
again from a cold cache, which defeats the point for warm builds.

Persist the lookup index in .typecache so it survives across runs, matching the
existing generation-cache mechanism (that's what .typecache was added for).

Changes:
- GenerationCache carries a new external_type_index: HashMap<String,
  Option<PathBuf>> (type name -> defining file, or None for known-missing).
  Bumped CURRENT_VERSION to 3; the field is #[serde(default)] so older cache
  files deserialize cleanly and are then invalidated by the version check.
- The index is derived data and is intentionally excluded from combined_hash,
  so registry churn does not force regeneration; invalidation rides the
  command/struct/event/config hashes as before.
- CommandAnalyzer exposes seed_external_type_cache() and
  external_type_lookup_cache() so the cache can be loaded into the analyzer
  before analysis and read back out after generation.
- Both consumers (CLI and build.rs) load the previous .typecache and seed the
  analyzer before analyze_project*, then save a fresh cache (including the
  index) after successful generation.
- find_external_type_path_cached remains the memoizing lookup the resolver
  uses; seeded entries short-circuit the walk, unseeded types fall back to it
  and are memoized in turn.

Correctness: the index is a hint, not authoritative — a stale positive entry
pointing at a file that no longer exists is handled by the downstream
parse_and_cache_file failing gracefully. A stale negative entry is an accepted
trade-off matching .typecache's existing source-stability assumption: when the
user's code changes such that new external types are referenced, the command
hash changes, .typecache is regenerated, and the index is rebuilt.

Tests: 3 new in generation_cache (index stored/exposed, excluded from
combined_hash, round-trips through save/load) and 3 new in analysis (seeded
positive skips walk, seeded negative skips walk, unseeded falls back to walk
and memoizes). All #[serial] (shared CARGO_HOME).

* 0.5.3

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: GarandPLG <89148639+GarandPLG@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant