Skip to content

chore(deps): bump actions/setup-node from 5.0.0 to 7.0.0 - #459

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/actions/setup-node-7
Open

chore(deps): bump actions/setup-node from 5.0.0 to 7.0.0#459
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/github_actions/develop/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-node from 5.0.0 to 7.0.0.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@dependabot
dependabot Bot requested a review from tomymaritano as a code owner August 1, 2026 19:55
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) August 1, 2026 19:56
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/actions/setup-node-7 branch 4 times, most recently from 7ec98c9 to 410e844 Compare August 20, 2026 18:23
tomymaritano added a commit that referenced this pull request Aug 22, 2026
<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
## Summary

Dependabot PRs fail the required `e2e` check in ~20s during `pnpm
install`, not during Playwright. Automerge is already enabled; it cannot
land while e2e is red.

**Exact failure** (PR #482 job
[96541625973](https://github.com/dripnex/app/actions/runs/32404870524/job/96541625973),
also #464 / #456 / #462 and `commitlint` on #464):

```
ERROR  Command failed with exit code 128: git clone git@github.com:electron/node-gyp.git ...
git@github.com: Permission denied (publickey).
```

This is not missing repo secrets. Dependabot-regenerated lockfiles
resolve `@electron/node-gyp` as a git dep whose `resolution.repo` is
SSH:

```
# PR #456 (shell-quote) lockfile
'@electron/node-gyp@git+https://git@github.com:electron/node-gyp.git#06b29aa...'
resolution: {commit: 06b29aa..., repo: git@github.com:electron/node-gyp.git, type: git}

# develop lockfile (e2e green after #541)
'@electron/node-gyp@https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...'
resolution: {tarball: https://codeload.github.com/electron/node-gyp/tar.gz/06b29aa...}
```

pnpm clones `resolution.repo` over SSH. GitHub-hosted runners have no
deploy key.

The `setup` job already rewrites SSH to HTTPS and therefore succeeds on
the same PRs. `e2e` and `commitlint` did a fresh `pnpm install` without
that rewrite.

`develop` itself is green after #541 — its lockfile uses the HTTPS
tarball, so e2e never hits the SSH clone.

## Type of Change

- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update

## Fix

Add the same `git config --global 'url.https://github.com/.insteadOf'
'git@github.com:'` step that `setup` / `release` / `build` / `docs`
already use:

- `.github/workflows/ci.yml` `e2e` job — unblocks the required e2e check
- `.github/workflows/pr-title.yml` — same SSH death on Dependabot
lockfiles

Existing Dependabot PRs (#482, #464, #462, #460, #459, #456, #451, #431,
#430, #248) should go green after rebase onto this `develop` change (the
merge commit picks up the workflow).

## Related Issues

Closes #544

## Checklist

- [x] I've read [CONTRIBUTING.md](../CONTRIBUTING.md)
- [ ] Tests pass locally (`pnpm test`) — workflow-only change; no
product code
- [ ] Build succeeds (`pnpm build`) — not applicable
- [x] PR targets `develop` branch (not `main`)

<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-65d9f024-2af5-4bbe-8318-35ae4db127d2?cursor_ref=pr_footer&cursor_cta=open_in_web"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-65d9f024-2af5-4bbe-8318-35ae4db127d2&cursor_ref=pr_footer&cursor_cta=open_in_cursor"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/actions/setup-node-7 branch 10 times, most recently from c7d1816 to 249dca5 Compare August 25, 2026 17:19
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 5.0.0 to 7.0.0.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v5...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump actions/setup-node from 5 to 7 chore(deps): bump actions/setup-node from 5.0.0 to 7.0.0 Aug 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/develop/actions/setup-node-7 branch from 249dca5 to 86e9101 Compare August 26, 2026 04:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code size/S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants