{"thread":{"id":"65475","subject":"[PATCH] codeql: bump actions/cache from 4 to 5","startedAt":"2026-04-13T16:24:21Z","lastAt":"2026-04-13T18:21:32Z","messageCount":3,"participants":["Johannes Schindelin via GitGitGadget","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"541482","messageId":"pull.2086.git.1776097457136.gitgitgadget@gmail.com","threadId":"65475","inReplyTo":null,"subject":"[PATCH] codeql: bump actions/cache from 4 to 5","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-13T16:24:17Z","receivedAt":"2026-04-13T16:24:21Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nBumps [actions/cache](https://github.com/actions/cache) from 4 to 5.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/v4...v5)\n\n---\n    codeql: bump actions/cache from 4 to 5\n    \n    Just a regular GitHub Actions bump\n\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2086%2Fgit-for-windows%2Fdependabot%2Fgithub_actions%2Factions%2Fcache-5-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2086/git-for-windows/dependabot/github_actions/actions/cache-5-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2086\n\nupdated-dependencies:\n- dependency-name: actions/cache\n  dependency-version: '5'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/coverity.yml | 4 ++--\n 1 file changed, 2 insertions(+), 2 deletions(-)\n\ndiff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\nindex cfa17d394a..3435baeca2 100644\n--- a/.github/workflows/coverity.yml\n+++ b/.github/workflows/coverity.yml\n@@ -98,7 +98,7 @@ jobs:\n       # A cache miss will add ~30s to create, but a cache hit will save minutes.\n       - name: restore the Coverity Build Tool\n         id: cache\n-        uses: actions/cache/restore@v4\n+        uses: actions/cache/restore@v5\n         with:\n           path: ${{ runner.temp }}/cov-analysis\n           key: cov-build-${{ env.COVERITY_LANGUAGE }}-${{ env.COVERITY_PLATFORM }}-${{ steps.lookup.outputs.hash }}\n@@ -141,7 +141,7 @@ jobs:\n           esac\n       - name: cache the Coverity Build Tool\n         if: steps.cache.outputs.cache-hit != 'true'\n-        uses: actions/cache/save@v4\n+        uses: actions/cache/save@v5\n         with:\n           path: ${{ runner.temp }}/cov-analysis\n           key: cov-build-${{ env.COVERITY_LANGUAGE }}-${{ env.COVERITY_PLATFORM }}-${{ steps.lookup.outputs.hash }}\n\nbase-commit: 67ad42147a7acc2af6074753ebd03d904476118f\n-- \ngitgitgadget\n"},{"id":"541493","messageId":"xmqq7bqaiwm3.fsf@gitster.g","threadId":"65475","inReplyTo":"pull.2086.git.1776097457136.gitgitgadget@gmail.com","subject":"Re: [PATCH] codeql: bump actions/cache from 4 to 5","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-13T17:44:04Z","receivedAt":"2026-04-13T17:44:07Z","isPatch":true,"body":"\"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> From: Johannes Schindelin <johannes.schindelin@gmx.de>\n>\n> Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5.\n> - [Release notes](https://github.com/actions/cache/releases)\n> - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n> - [Commits](https://github.com/actions/cache/compare/v4...v5)\n>\n> ---\n>     codeql: bump actions/cache from 4 to 5\n>     \n>     Just a regular GitHub Actions bump\n>\n> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2086%2Fgit-for-windows%2Fdependabot%2Fgithub_actions%2Factions%2Fcache-5-v1\n> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2086/git-for-windows/dependabot/github_actions/actions/cache-5-v1\n> Pull-Request: https://github.com/gitgitgadget/git/pull/2086\n>\n> updated-dependencies:\n> - dependency-name: actions/cache\n>   dependency-version: '5'\n>   dependency-type: direct:production\n>   update-type: version-update:semver-major\n> ...\n>\n> Originally-authored-by: dependabot[bot] <support@github.com>\n> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n> ---\n\nYou should not need to be reminded on how our log messages should\nlook like.  Also your sign-off must come before the three-dash line.\n\nThanks.\n\n>  .github/workflows/coverity.yml | 4 ++--\n>  1 file changed, 2 insertions(+), 2 deletions(-)\n>\n> diff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\n> index cfa17d394a..3435baeca2 100644\n> --- a/.github/workflows/coverity.yml\n> +++ b/.github/workflows/coverity.yml\n> @@ -98,7 +98,7 @@ jobs:\n>        # A cache miss will add ~30s to create, but a cache hit will save minutes.\n>        - name: restore the Coverity Build Tool\n>          id: cache\n> -        uses: actions/cache/restore@v4\n> +        uses: actions/cache/restore@v5\n>          with:\n>            path: ${{ runner.temp }}/cov-analysis\n>            key: cov-build-${{ env.COVERITY_LANGUAGE }}-${{ env.COVERITY_PLATFORM }}-${{ steps.lookup.outputs.hash }}\n> @@ -141,7 +141,7 @@ jobs:\n>            esac\n>        - name: cache the Coverity Build Tool\n>          if: steps.cache.outputs.cache-hit != 'true'\n> -        uses: actions/cache/save@v4\n> +        uses: actions/cache/save@v5\n>          with:\n>            path: ${{ runner.temp }}/cov-analysis\n>            key: cov-build-${{ env.COVERITY_LANGUAGE }}-${{ env.COVERITY_PLATFORM }}-${{ steps.lookup.outputs.hash }}\n>\n> base-commit: 67ad42147a7acc2af6074753ebd03d904476118f\n"},{"id":"541495","messageId":"xmqqpl42hgba.fsf@gitster.g","threadId":"65475","inReplyTo":"xmqq7bqaiwm3.fsf@gitster.g","subject":"Re: [PATCH] codeql: bump actions/cache from 4 to 5","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2026-04-13T18:21:29Z","receivedAt":"2026-04-13T18:21:32Z","isPatch":true,"body":"Junio C Hamano <gitster@pobox.com> writes:\n\n> \"Johannes Schindelin via GitGitGadget\" <gitgitgadget@gmail.com>\n> writes:\n>\n>> From: Johannes Schindelin <johannes.schindelin@gmx.de>\n>>\n>> Bumps [actions/cache](https://github.com/actions/cache) from 4 to 5.\n>> - [Release notes](https://github.com/actions/cache/releases)\n>> - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n>> - [Commits](https://github.com/actions/cache/compare/v4...v5)\n>>\n>> ---\n>>     codeql: bump actions/cache from 4 to 5\n>>     \n>>     Just a regular GitHub Actions bump\n>>\n>> Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2086%2Fgit-for-windows%2Fdependabot%2Fgithub_actions%2Factions%2Fcache-5-v1\n>> Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2086/git-for-windows/dependabot/github_actions/actions/cache-5-v1\n>> Pull-Request: https://github.com/gitgitgadget/git/pull/2086\n>>\n>> updated-dependencies:\n>> - dependency-name: actions/cache\n>>   dependency-version: '5'\n>>   dependency-type: direct:production\n>>   update-type: version-update:semver-major\n>> ...\n>>\n>> Originally-authored-by: dependabot[bot] <support@github.com>\n>> Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n>> ---\n>\n> You should not need to be reminded on how our log messages should\n> look like.  Also your sign-off must come before the three-dash line.\n>\n> Thanks.\n\nA tangent, but I probably should mention that I didn't even notice\nthe last time we got identically malformatted patch submission in\nOctober,\n\n<2443e519f0ff6160e058d391495dd51256595a48.1760629692.git.gitgitgadget@gmail.com>\n\nwhich resulted in 63541ed9 (build(deps): bump actions/checkout from\n4 to 5, 2025-10-16) that you meant to sign off but ended up\ncommitted without one due to the premature three-dash line.\n\n\n\nIt seems that GitHub Actions started complaining about use of\nNode.js 20 and I was wondering why only one job uses\nactions/checkout@v4, and it turns out that it is a semantic mismerge\nbetween e75cd059 (ci: check formatting of our Rust code, 2025-10-15)\nthat added a new use of actions/checkout@v4 that happened very close\nto another change 63541ed9 (build(deps): bump actions/checkout from\n4 to 5, 2025-10-16) that updated all uses of actions/checkout@v4 to\nuse actions/checkout@v5.\n\n\n"}]}