{"thread":{"id":"65530","subject":"[PATCH 0/4] ci: GitHub Actions updates (brought to you by Dependabot)","startedAt":"2026-04-21T12:42:04Z","lastAt":"2026-04-30T07:35:16Z","messageCount":18,"participants":["Johannes Schindelin via GitGitGadget"],"isPatch":true,"patchVersion":1,"patchTotal":4},"messages":[{"id":"542037","messageId":"pull.2097.git.1776775319.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":null,"subject":"[PATCH 0/4] ci: GitHub Actions updates (brought to you by Dependabot)","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-21T12:41:55Z","receivedAt":"2026-04-21T12:42:04Z","isPatch":true,"body":"Dependabot (which my voice-typing software frequently mis-translates to \"the\npanda bot\" 😉) is enabled in Git for Windows' fork of the git/git repository\nto lighten the maintenance burden a little bit. Frequently, the updates are\nnot actually for Git for Windows' patches on top of git/git, but apply\ndirectly to git/git.\n\nHere is the latest batch of those updates, with heavily augmented commit\nmessages.\n\nJohannes Schindelin (4):\n  ci: bump microsoft/setup-msbuild from v2 to v3\n  ci: bump actions/{upload,download}-artifact to v7 and v8\n  ci: bump actions/github-script from v8 to v9\n  ci: bump actions/checkout from v5 to v6\n\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  2 +-\n .github/workflows/main.yml             | 50 +++++++++++++-------------\n 4 files changed, 28 insertions(+), 28 deletions(-)\n\n\nbase-commit: 94f057755b7941b321fd11fec1b2e3ca5313a4e0\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2097%2Fdscho%2Fdependabot-updates-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2097/dscho/dependabot-updates-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/2097\n-- \ngitgitgadget\n"},{"id":"542038","messageId":"0d2fdc1cf4c5d7273addedc442a222f0c3485efd.1776775319.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.git.1776775319.gitgitgadget@gmail.com","subject":"[PATCH 1/4] ci: bump microsoft/setup-msbuild from v2 to v3","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-21T12:41:56Z","receivedAt":"2026-04-21T12:42:06Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe v2 of `microsoft/setup-msbuild` runs on Node.js 20, which GitHub\nis phasing out of the Actions runners. v3 is a minimal release whose\nonly substantive change is moving the action's runtime to Node.js 24,\nso that our Visual Studio build jobs keep working once Node.js 20 is\nremoved from the runners.\n\nThe risk of this bump is very low: v3 contains no functional changes\nto the action itself -- it merely adds `msbuild.exe` to `PATH`, with\nno change to command-line flags, inputs, outputs, or default tool\nresolution. The only precondition is a recent-enough Actions Runner,\nwhich the github.com-hosted runners already satisfy.\n\nSee also:\n\n- Release notes: https://github.com/microsoft/setup-msbuild/releases\n- Compare: https://github.com/microsoft/setup-msbuild/compare/v2...v3\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6f3d94e3a6..0d3e0e42a4 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -186,7 +186,7 @@ jobs:\n         repository: git/git\n         definitionId: 9\n     - name: add msbuild to PATH\n-      uses: microsoft/setup-msbuild@v2\n+      uses: microsoft/setup-msbuild@v3\n     - name: copy dlls to root\n       shell: cmd\n       run: compat\\vcbuild\\vcpkg_copy_dlls.bat release\n-- \ngitgitgadget\n\n"},{"id":"542039","messageId":"5d719b3729e39d63ec0a1a474b0c1ff57570133e.1776775319.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.git.1776775319.gitgitgadget@gmail.com","subject":"[PATCH 2/4] ci: bump actions/{upload,download}-artifact to v7 and v8","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-21T12:41:57Z","receivedAt":"2026-04-21T12:42:09Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\n`actions/upload-artifact` and `actions/download-artifact` are tightly\ncoupled: the upload action writes artifact archives in a format that\nthe download action then reads. Because of this coupling, the two\nactions should always be bumped together so that the artifact format\ncontract between them is satisfied.\n\nAll of our `actions/upload-artifact` uses are still on v5, with one\nstray v4 occurrence. Keeping them on these versions would leave the\nartifact-upload steps running on Node.js 20, which GitHub is phasing\nout, and would eventually cause all upload steps to fail.\n\nGoing from v5 directly to v7 folds in two release bumps:\n\n- v6 switches the action's default runtime from Node.js 20 to\n  Node.js 24 (v5 had preliminary Node 24 support but still defaulted\n  to Node 20). This is the main motivation for bumping now: it gets\n  us off the deprecated runtime.\n- v7 adds two opt-in features: direct (unzipped) single-file uploads\n  via a new `archive: false` parameter, and an internal conversion of\n  the action to ESM to match the updated `@actions/*` packages.\n\nRisk analysis: we never pass `archive`, so the zip-as-usual behavior\nis unchanged. We also do not `require('@actions/*')` from any calling\nworkflow, so the ESM migration cannot affect us. The upload steps we\ncare about -- tracked files/build artifacts and failing-test\ndirectories -- keep the same inputs (`name`, `path`) and outputs, so\nthe diff is purely the `@vN` identifier. The main precondition is a\nrecent Actions Runner (>= 2.327.1), which the github.com-hosted\nrunners used by our CI already satisfy.\n\nWhile at it, align the one remaining `@v4` occurrence with the rest\nso that every `upload-artifact` step uses the same version.\n\nSee also:\n\n- Release notes: https://github.com/actions/upload-artifact/releases\n- Compare: https://github.com/actions/upload-artifact/compare/v5...v7\n\nWe use `actions/download-artifact` to pass build artifacts between\nthe \"windows-build\" / \"vs-build\" / \"windows-meson-build\" jobs and\ntheir corresponding test jobs. All callers are currently on v6;\nbumping to v8 keeps this action in lockstep with the `upload-artifact`\nbump above.\n\nWhat v7 and v8 change:\n\n- v7 switches the default runtime from Node.js 20 to Node.js 24 (v6\n  had preliminary Node 24 support but still defaulted to Node 20).\n  This is the main motivation: it gets us off the deprecated runtime.\n- v8 makes three further changes:\n  * The package is converted to ESM (invisible to workflow authors).\n  * The action now checks the `Content-Type` header before\n    attempting to unzip a download, so that directly-uploaded\n    (unzipped) artifacts from `upload-artifact` v7 are downloaded\n    correctly.\n  * The `digest-mismatch` behaviour is changed from warn-and-\n    continue to a hard failure by default.\n\nRisk analysis: defaulting hash-mismatch to a hard failure is\nstrictly safer than the previous warn-and-continue behaviour -- a\nmismatch points to real corruption or tampering and should stop the\nrun. We download archives that the same workflow just uploaded, on\nthe same runner fleet, so false positives are not expected. Our\nusage is limited to the `name` and `path` inputs, which are\nunchanged between v6 and v8, so the diff is purely the `@vN`\nidentifier.\n\nSee also:\n\n- Release notes: https://github.com/actions/download-artifact/releases\n- Compare: https://github.com/actions/download-artifact/compare/v6...v8\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 22 +++++++++++-----------\n 1 file changed, 11 insertions(+), 11 deletions(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 0d3e0e42a4..da31b10c79 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -123,7 +123,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-artifacts\n         path: artifacts\n@@ -140,7 +140,7 @@ jobs:\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-artifacts\n         path: ${{github.workspace}}\n@@ -157,7 +157,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -208,7 +208,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: vs-artifacts\n         path: artifacts\n@@ -226,7 +226,7 @@ jobs:\n     steps:\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: vs-artifacts\n         path: ${{github.workspace}}\n@@ -244,7 +244,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-vs-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -270,7 +270,7 @@ jobs:\n       shell: pwsh\n       run: meson compile -C build\n     - name: Upload build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -292,7 +292,7 @@ jobs:\n       shell: pwsh\n       run: pip install meson ninja\n     - name: Download build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -305,7 +305,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v4\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-meson-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -349,7 +349,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -449,7 +449,7 @@ jobs:\n       run: sudo --preserve-env --set-home --user=builder ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n-- \ngitgitgadget\n\n"},{"id":"542040","messageId":"bfbe0db67f5a0454378bd5fd71e2cbc1493bcb59.1776775319.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.git.1776775319.gitgitgadget@gmail.com","subject":"[PATCH 3/4] ci: bump actions/github-script from v8 to v9","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-21T12:41:58Z","receivedAt":"2026-04-21T12:42:11Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe only use we have of `actions/github-script` is the \"skip if the\ncommit or tree was already tested\" step in `main.yml`, which checks\nwhether an identical tree-SHA was already built successfully. It\ncurrently pins v8; v9 is the latest release.\n\nWhat v9 changes:\n\n- The `ACTIONS_ORCHESTRATION_ID` environment variable is now\n  appended to the HTTP user-agent string. This is transparent to\n  our script.\n- A new injected `getOctokit` factory lets scripts create\n  additional authenticated clients in the same step without\n  importing `@actions/github`. We do not use it.\n- Two breaking changes affect scripts that either call\n  `require('@actions/github')` (fails at runtime, because\n  `@actions/github` v9 is now ESM-only) or that shadow the\n  implicit `getOctokit` parameter via `const`/`let` (syntax\n  error). Our script does neither -- it only uses the pre-supplied\n  `github` REST client and `core` helpers -- so the upgrade is\n  safe.\n\nRisk analysis: the step is advisory. It sets `enabled=' but skip'`\nas an optimization to avoid re-running CI on a tree that was already\ntested successfully. Even if the v9 upgrade broke the script, the\nsurrounding `try { ... } catch (e) { core.warning(e); }` block would\ndegrade it to a warning and CI would still run normally. In practice\nthe script continues to work identically on v9.\n\nSee also:\n\n- Release notes: https://github.com/actions/github-script/releases\n- Compare: https://github.com/actions/github-script/compare/v8...v9\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex da31b10c79..6d7f26e71e 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -63,7 +63,7 @@ jobs:\n           echo \"skip_concurrent=$skip_concurrent\" >>$GITHUB_OUTPUT\n       - name: skip if the commit or tree was already tested\n         id: skip-if-redundant\n-        uses: actions/github-script@v8\n+        uses: actions/github-script@v9\n         if: steps.check-ref.outputs.enabled == 'yes'\n         with:\n           github-token: ${{secrets.GITHUB_TOKEN}}\n-- \ngitgitgadget\n\n"},{"id":"542041","messageId":"5694ca10167f683c55151672a1e5bcf6482b2a43.1776775319.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.git.1776775319.gitgitgadget@gmail.com","subject":"[PATCH 4/4] ci: bump actions/checkout from v5 to v6","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-21T12:41:59Z","receivedAt":"2026-04-21T12:42:14Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nEvery workflow currently pins `actions/checkout` to v5, which was\nintroduced primarily to move to the Node.js 24 runtime. v6 is the\nnext release and worth picking up so we stay on a maintained version\nof the action.\n\nThe one behaviorally interesting change in v6:\n\n  `persist-credentials` now stores the helper credentials under\n  `$RUNNER_TEMP` instead of writing them directly into the local\n  `.git/config`. Two implications follow:\n\n  1. In the normal case this is an unambiguous improvement -- the\n     token no longer lands in `.git/config`, reducing the risk of\n     inadvertently leaking it through workspace archiving\n     (`upload-artifact` snapshots, cache entries, core dumps, ...).\n\n  2. Docker container actions require an Actions Runner of at least\n     v2.329.0 to find the credentials in their new location. The\n     github.com-hosted runners our CI uses are already past that\n     version, so this does not affect us. Downstream users running\n     self-hosted runners may need to update them before adopting\n     this version of the action.\n\nRisk analysis: our checkout steps either check out the default\nrepository (no special credential requirements) or, in the `vs-build`\njob, explicitly set `repository: microsoft/vcpkg` and\n`path: compat/vcbuild/vcpkg`. Neither case relies on the precise\nlocation of the persisted credentials -- subsequent steps interact\nwith the API via the runner-provided `GITHUB_TOKEN` directly -- so\nthe v6 credential-storage change is transparent to our workflows.\nThe diff is purely the `@vN` identifier; there are no input or\noutput changes.\n\nSee also:\n\n- Release notes: https://github.com/actions/checkout/releases\n- Changelog: https://github.com/actions/checkout/blob/main/CHANGELOG.md\n- Compare: https://github.com/actions/checkout/compare/v5...v6\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  2 +-\n .github/workflows/main.yml             | 24 ++++++++++++------------\n 4 files changed, 15 insertions(+), 15 deletions(-)\n\ndiff --git a/.github/workflows/check-style.yml b/.github/workflows/check-style.yml\nindex 19a145d4ad..108a2de903 100644\n--- a/.github/workflows/check-style.yml\n+++ b/.github/workflows/check-style.yml\n@@ -20,7 +20,7 @@ jobs:\n       jobname: ClangFormat\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/check-whitespace.yml b/.github/workflows/check-whitespace.yml\nindex 928fd4cfe2..ea6f49f742 100644\n--- a/.github/workflows/check-whitespace.yml\n+++ b/.github/workflows/check-whitespace.yml\n@@ -19,7 +19,7 @@ jobs:\n   check-whitespace:\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\nindex 3435baeca2..89bef26727 100644\n--- a/.github/workflows/coverity.yml\n+++ b/.github/workflows/coverity.yml\n@@ -38,7 +38,7 @@ jobs:\n       COVERITY_LANGUAGE: cxx\n       COVERITY_PLATFORM: overridden-below\n     steps:\n-      - uses: actions/checkout@v5\n+      - uses: actions/checkout@v6\n       - name: install minimal Git for Windows SDK\n         if: contains(matrix.os, 'windows')\n         uses: git-for-windows/setup-git-for-windows-sdk@v1\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6d7f26e71e..0ea266f27c 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -112,7 +112,7 @@ jobs:\n       group: windows-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: build\n       shell: bash\n@@ -173,10 +173,10 @@ jobs:\n       group: vs-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: initialize vcpkg\n-      uses: actions/checkout@v5\n+      uses: actions/checkout@v6\n       with:\n         repository: 'microsoft/vcpkg'\n         path: 'compat/vcbuild/vcpkg'\n@@ -258,7 +258,7 @@ jobs:\n       group: windows-meson-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -286,7 +286,7 @@ jobs:\n       group: windows-meson-test-${{ matrix.nr }}-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -341,7 +341,7 @@ jobs:\n       TEST_OUTPUT_DIRECTORY: ${{github.workspace}}/t\n     runs-on: ${{matrix.vector.pool}}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-tests.sh\n     - name: print test failures\n@@ -362,7 +362,7 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-minimal-fuzzers.sh\n   dockerized:\n@@ -439,7 +439,7 @@ jobs:\n         else\n           apt-get -q update && apt-get -q -y install git\n         fi\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: useradd builder --create-home\n     - run: chown -R builder .\n@@ -464,7 +464,7 @@ jobs:\n       group: static-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-static-analysis.sh\n     - run: ci/check-directional-formatting.bash\n@@ -480,7 +480,7 @@ jobs:\n       group: rust-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-rust-checks.sh\n   sparse:\n@@ -494,7 +494,7 @@ jobs:\n       group: sparse-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - name: Install other dependencies\n       run: ci/install-dependencies.sh\n     - run: make sparse\n@@ -510,6 +510,6 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/test-documentation.sh\n-- \ngitgitgadget\n"},{"id":"542290","messageId":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.git.1776775319.gitgitgadget@gmail.com","subject":"[PATCH v2 0/5] ci: GitHub Actions updates (brought to you by Dependabot)","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:35Z","receivedAt":"2026-04-25T10:58:43Z","isPatch":true,"body":"Dependabot (which my voice-typing software frequently mis-translates to \"the\npanda bot\" 😉) is enabled in Git for Windows' fork of the git/git repository\nto lighten the maintenance burden a little bit. Frequently, the updates are\nnot actually for Git for Windows' patches on top of git/git, but apply\ndirectly to git/git.\n\nHere is the latest batch of those updates, with heavily augmented commit\nmessages.\n\nChanges since v1:\n\n * Also bump mshick/add-pr-comment to the newest major version.\n\nJohannes Schindelin (5):\n  ci: bump microsoft/setup-msbuild from v2 to v3\n  ci: bump actions/{upload,download}-artifact to v7 and v8\n  ci: bump actions/github-script from v8 to v9\n  ci: bump actions/checkout from v5 to v6\n  l10n: bump mshick/add-pr-comment from v2 to v3\n\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  2 +-\n .github/workflows/l10n.yml             |  2 +-\n .github/workflows/main.yml             | 50 +++++++++++++-------------\n 5 files changed, 29 insertions(+), 29 deletions(-)\n\n\nbase-commit: 94f057755b7941b321fd11fec1b2e3ca5313a4e0\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2097%2Fdscho%2Fdependabot-updates-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2097/dscho/dependabot-updates-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/2097\n\nRange-diff vs v1:\n\n 1:  0d2fdc1cf4 = 1:  0d2fdc1cf4 ci: bump microsoft/setup-msbuild from v2 to v3\n 2:  5d719b3729 = 2:  5d719b3729 ci: bump actions/{upload,download}-artifact to v7 and v8\n 3:  bfbe0db67f = 3:  bfbe0db67f ci: bump actions/github-script from v8 to v9\n 4:  5694ca1016 = 4:  5694ca1016 ci: bump actions/checkout from v5 to v6\n -:  ---------- > 5:  faa83723f4 l10n: bump mshick/add-pr-comment from v2 to v3\n\n-- \ngitgitgadget\n"},{"id":"542291","messageId":"0d2fdc1cf4c5d7273addedc442a222f0c3485efd.1777114720.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v2 1/5] ci: bump microsoft/setup-msbuild from v2 to v3","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:36Z","receivedAt":"2026-04-25T10:58:45Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe v2 of `microsoft/setup-msbuild` runs on Node.js 20, which GitHub\nis phasing out of the Actions runners. v3 is a minimal release whose\nonly substantive change is moving the action's runtime to Node.js 24,\nso that our Visual Studio build jobs keep working once Node.js 20 is\nremoved from the runners.\n\nThe risk of this bump is very low: v3 contains no functional changes\nto the action itself -- it merely adds `msbuild.exe` to `PATH`, with\nno change to command-line flags, inputs, outputs, or default tool\nresolution. The only precondition is a recent-enough Actions Runner,\nwhich the github.com-hosted runners already satisfy.\n\nSee also:\n\n- Release notes: https://github.com/microsoft/setup-msbuild/releases\n- Compare: https://github.com/microsoft/setup-msbuild/compare/v2...v3\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6f3d94e3a6..0d3e0e42a4 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -186,7 +186,7 @@ jobs:\n         repository: git/git\n         definitionId: 9\n     - name: add msbuild to PATH\n-      uses: microsoft/setup-msbuild@v2\n+      uses: microsoft/setup-msbuild@v3\n     - name: copy dlls to root\n       shell: cmd\n       run: compat\\vcbuild\\vcpkg_copy_dlls.bat release\n-- \ngitgitgadget\n\n"},{"id":"542292","messageId":"5d719b3729e39d63ec0a1a474b0c1ff57570133e.1777114720.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v2 2/5] ci: bump actions/{upload,download}-artifact to v7 and v8","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:37Z","receivedAt":"2026-04-25T10:58:46Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\n`actions/upload-artifact` and `actions/download-artifact` are tightly\ncoupled: the upload action writes artifact archives in a format that\nthe download action then reads. Because of this coupling, the two\nactions should always be bumped together so that the artifact format\ncontract between them is satisfied.\n\nAll of our `actions/upload-artifact` uses are still on v5, with one\nstray v4 occurrence. Keeping them on these versions would leave the\nartifact-upload steps running on Node.js 20, which GitHub is phasing\nout, and would eventually cause all upload steps to fail.\n\nGoing from v5 directly to v7 folds in two release bumps:\n\n- v6 switches the action's default runtime from Node.js 20 to\n  Node.js 24 (v5 had preliminary Node 24 support but still defaulted\n  to Node 20). This is the main motivation for bumping now: it gets\n  us off the deprecated runtime.\n- v7 adds two opt-in features: direct (unzipped) single-file uploads\n  via a new `archive: false` parameter, and an internal conversion of\n  the action to ESM to match the updated `@actions/*` packages.\n\nRisk analysis: we never pass `archive`, so the zip-as-usual behavior\nis unchanged. We also do not `require('@actions/*')` from any calling\nworkflow, so the ESM migration cannot affect us. The upload steps we\ncare about -- tracked files/build artifacts and failing-test\ndirectories -- keep the same inputs (`name`, `path`) and outputs, so\nthe diff is purely the `@vN` identifier. The main precondition is a\nrecent Actions Runner (>= 2.327.1), which the github.com-hosted\nrunners used by our CI already satisfy.\n\nWhile at it, align the one remaining `@v4` occurrence with the rest\nso that every `upload-artifact` step uses the same version.\n\nSee also:\n\n- Release notes: https://github.com/actions/upload-artifact/releases\n- Compare: https://github.com/actions/upload-artifact/compare/v5...v7\n\nWe use `actions/download-artifact` to pass build artifacts between\nthe \"windows-build\" / \"vs-build\" / \"windows-meson-build\" jobs and\ntheir corresponding test jobs. All callers are currently on v6;\nbumping to v8 keeps this action in lockstep with the `upload-artifact`\nbump above.\n\nWhat v7 and v8 change:\n\n- v7 switches the default runtime from Node.js 20 to Node.js 24 (v6\n  had preliminary Node 24 support but still defaulted to Node 20).\n  This is the main motivation: it gets us off the deprecated runtime.\n- v8 makes three further changes:\n  * The package is converted to ESM (invisible to workflow authors).\n  * The action now checks the `Content-Type` header before\n    attempting to unzip a download, so that directly-uploaded\n    (unzipped) artifacts from `upload-artifact` v7 are downloaded\n    correctly.\n  * The `digest-mismatch` behaviour is changed from warn-and-\n    continue to a hard failure by default.\n\nRisk analysis: defaulting hash-mismatch to a hard failure is\nstrictly safer than the previous warn-and-continue behaviour -- a\nmismatch points to real corruption or tampering and should stop the\nrun. We download archives that the same workflow just uploaded, on\nthe same runner fleet, so false positives are not expected. Our\nusage is limited to the `name` and `path` inputs, which are\nunchanged between v6 and v8, so the diff is purely the `@vN`\nidentifier.\n\nSee also:\n\n- Release notes: https://github.com/actions/download-artifact/releases\n- Compare: https://github.com/actions/download-artifact/compare/v6...v8\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 22 +++++++++++-----------\n 1 file changed, 11 insertions(+), 11 deletions(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 0d3e0e42a4..da31b10c79 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -123,7 +123,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-artifacts\n         path: artifacts\n@@ -140,7 +140,7 @@ jobs:\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-artifacts\n         path: ${{github.workspace}}\n@@ -157,7 +157,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -208,7 +208,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: vs-artifacts\n         path: artifacts\n@@ -226,7 +226,7 @@ jobs:\n     steps:\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: vs-artifacts\n         path: ${{github.workspace}}\n@@ -244,7 +244,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-vs-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -270,7 +270,7 @@ jobs:\n       shell: pwsh\n       run: meson compile -C build\n     - name: Upload build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -292,7 +292,7 @@ jobs:\n       shell: pwsh\n       run: pip install meson ninja\n     - name: Download build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -305,7 +305,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v4\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-meson-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -349,7 +349,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -449,7 +449,7 @@ jobs:\n       run: sudo --preserve-env --set-home --user=builder ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n-- \ngitgitgadget\n\n"},{"id":"542293","messageId":"bfbe0db67f5a0454378bd5fd71e2cbc1493bcb59.1777114720.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v2 3/5] ci: bump actions/github-script from v8 to v9","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:38Z","receivedAt":"2026-04-25T10:58:47Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe only use we have of `actions/github-script` is the \"skip if the\ncommit or tree was already tested\" step in `main.yml`, which checks\nwhether an identical tree-SHA was already built successfully. It\ncurrently pins v8; v9 is the latest release.\n\nWhat v9 changes:\n\n- The `ACTIONS_ORCHESTRATION_ID` environment variable is now\n  appended to the HTTP user-agent string. This is transparent to\n  our script.\n- A new injected `getOctokit` factory lets scripts create\n  additional authenticated clients in the same step without\n  importing `@actions/github`. We do not use it.\n- Two breaking changes affect scripts that either call\n  `require('@actions/github')` (fails at runtime, because\n  `@actions/github` v9 is now ESM-only) or that shadow the\n  implicit `getOctokit` parameter via `const`/`let` (syntax\n  error). Our script does neither -- it only uses the pre-supplied\n  `github` REST client and `core` helpers -- so the upgrade is\n  safe.\n\nRisk analysis: the step is advisory. It sets `enabled=' but skip'`\nas an optimization to avoid re-running CI on a tree that was already\ntested successfully. Even if the v9 upgrade broke the script, the\nsurrounding `try { ... } catch (e) { core.warning(e); }` block would\ndegrade it to a warning and CI would still run normally. In practice\nthe script continues to work identically on v9.\n\nSee also:\n\n- Release notes: https://github.com/actions/github-script/releases\n- Compare: https://github.com/actions/github-script/compare/v8...v9\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex da31b10c79..6d7f26e71e 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -63,7 +63,7 @@ jobs:\n           echo \"skip_concurrent=$skip_concurrent\" >>$GITHUB_OUTPUT\n       - name: skip if the commit or tree was already tested\n         id: skip-if-redundant\n-        uses: actions/github-script@v8\n+        uses: actions/github-script@v9\n         if: steps.check-ref.outputs.enabled == 'yes'\n         with:\n           github-token: ${{secrets.GITHUB_TOKEN}}\n-- \ngitgitgadget\n\n"},{"id":"542294","messageId":"5694ca10167f683c55151672a1e5bcf6482b2a43.1777114720.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v2 4/5] ci: bump actions/checkout from v5 to v6","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:39Z","receivedAt":"2026-04-25T10:58:49Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nEvery workflow currently pins `actions/checkout` to v5, which was\nintroduced primarily to move to the Node.js 24 runtime. v6 is the\nnext release and worth picking up so we stay on a maintained version\nof the action.\n\nThe one behaviorally interesting change in v6:\n\n  `persist-credentials` now stores the helper credentials under\n  `$RUNNER_TEMP` instead of writing them directly into the local\n  `.git/config`. Two implications follow:\n\n  1. In the normal case this is an unambiguous improvement -- the\n     token no longer lands in `.git/config`, reducing the risk of\n     inadvertently leaking it through workspace archiving\n     (`upload-artifact` snapshots, cache entries, core dumps, ...).\n\n  2. Docker container actions require an Actions Runner of at least\n     v2.329.0 to find the credentials in their new location. The\n     github.com-hosted runners our CI uses are already past that\n     version, so this does not affect us. Downstream users running\n     self-hosted runners may need to update them before adopting\n     this version of the action.\n\nRisk analysis: our checkout steps either check out the default\nrepository (no special credential requirements) or, in the `vs-build`\njob, explicitly set `repository: microsoft/vcpkg` and\n`path: compat/vcbuild/vcpkg`. Neither case relies on the precise\nlocation of the persisted credentials -- subsequent steps interact\nwith the API via the runner-provided `GITHUB_TOKEN` directly -- so\nthe v6 credential-storage change is transparent to our workflows.\nThe diff is purely the `@vN` identifier; there are no input or\noutput changes.\n\nSee also:\n\n- Release notes: https://github.com/actions/checkout/releases\n- Changelog: https://github.com/actions/checkout/blob/main/CHANGELOG.md\n- Compare: https://github.com/actions/checkout/compare/v5...v6\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  2 +-\n .github/workflows/main.yml             | 24 ++++++++++++------------\n 4 files changed, 15 insertions(+), 15 deletions(-)\n\ndiff --git a/.github/workflows/check-style.yml b/.github/workflows/check-style.yml\nindex 19a145d4ad..108a2de903 100644\n--- a/.github/workflows/check-style.yml\n+++ b/.github/workflows/check-style.yml\n@@ -20,7 +20,7 @@ jobs:\n       jobname: ClangFormat\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/check-whitespace.yml b/.github/workflows/check-whitespace.yml\nindex 928fd4cfe2..ea6f49f742 100644\n--- a/.github/workflows/check-whitespace.yml\n+++ b/.github/workflows/check-whitespace.yml\n@@ -19,7 +19,7 @@ jobs:\n   check-whitespace:\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\nindex 3435baeca2..89bef26727 100644\n--- a/.github/workflows/coverity.yml\n+++ b/.github/workflows/coverity.yml\n@@ -38,7 +38,7 @@ jobs:\n       COVERITY_LANGUAGE: cxx\n       COVERITY_PLATFORM: overridden-below\n     steps:\n-      - uses: actions/checkout@v5\n+      - uses: actions/checkout@v6\n       - name: install minimal Git for Windows SDK\n         if: contains(matrix.os, 'windows')\n         uses: git-for-windows/setup-git-for-windows-sdk@v1\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6d7f26e71e..0ea266f27c 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -112,7 +112,7 @@ jobs:\n       group: windows-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: build\n       shell: bash\n@@ -173,10 +173,10 @@ jobs:\n       group: vs-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: initialize vcpkg\n-      uses: actions/checkout@v5\n+      uses: actions/checkout@v6\n       with:\n         repository: 'microsoft/vcpkg'\n         path: 'compat/vcbuild/vcpkg'\n@@ -258,7 +258,7 @@ jobs:\n       group: windows-meson-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -286,7 +286,7 @@ jobs:\n       group: windows-meson-test-${{ matrix.nr }}-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -341,7 +341,7 @@ jobs:\n       TEST_OUTPUT_DIRECTORY: ${{github.workspace}}/t\n     runs-on: ${{matrix.vector.pool}}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-tests.sh\n     - name: print test failures\n@@ -362,7 +362,7 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-minimal-fuzzers.sh\n   dockerized:\n@@ -439,7 +439,7 @@ jobs:\n         else\n           apt-get -q update && apt-get -q -y install git\n         fi\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: useradd builder --create-home\n     - run: chown -R builder .\n@@ -464,7 +464,7 @@ jobs:\n       group: static-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-static-analysis.sh\n     - run: ci/check-directional-formatting.bash\n@@ -480,7 +480,7 @@ jobs:\n       group: rust-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-rust-checks.sh\n   sparse:\n@@ -494,7 +494,7 @@ jobs:\n       group: sparse-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - name: Install other dependencies\n       run: ci/install-dependencies.sh\n     - run: make sparse\n@@ -510,6 +510,6 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/test-documentation.sh\n-- \ngitgitgadget\n\n"},{"id":"542295","messageId":"faa83723f4d09616f4bf18b9e040dbea351d2eb1.1777114720.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v2 5/5] l10n: bump mshick/add-pr-comment from v2 to v3","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-25T10:58:40Z","receivedAt":"2026-04-25T10:58:50Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe l10n workflow uses `mshick/add-pr-comment` to post git-po-helper\nreports as comments on translation pull requests. It was still pinned\nto v2, which runs on Node.js 20. GitHub is phasing out the Node.js 20\nruntime on Actions runners, so staying on v2 will eventually cause the\n\"Create comment in pull request for report\" step to fail.\n\nThe sole breaking change in v3 is the switch from Node.js 20 to\nNode.js 24 (https://github.com/mshick/add-pr-comment/releases/tag/v3.0.0).\nThe action's inputs and outputs are unchanged, so the upgrade is a\ndrop-in replacement. Subsequent v3.x releases added new opt-in\nfeatures (message truncation, retry with exponential backoff, file\nattachments, commit comment support, \"delete on status\") but none of\nthem affect existing callers that do not opt in.\n\nSee also:\n\n- Changelog: https://github.com/mshick/add-pr-comment/blob/main/CHANGELOG.md\n- Compare: https://github.com/mshick/add-pr-comment/compare/v2...v3\n\nPointed-out-by: Christoph Grüninger <foss@grueninger.de>\nAssisted-by: Claude Opus 4.6\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/l10n.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/l10n.yml b/.github/workflows/l10n.yml\nindex 95e55134bd..114a12a9e5 100644\n--- a/.github/workflows/l10n.yml\n+++ b/.github/workflows/l10n.yml\n@@ -92,7 +92,7 @@ jobs:\n           cat git-po-helper.out\n           exit $exit_code\n       - name: Create comment in pull request for report\n-        uses: mshick/add-pr-comment@v2\n+        uses: mshick/add-pr-comment@v3\n         if: >-\n           always() &&\n           github.event_name == 'pull_request_target' &&\n-- \ngitgitgadget\n"},{"id":"542513","messageId":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v2.git.1777114720.gitgitgadget@gmail.com","subject":"[PATCH v3 0/6] ci: GitHub Actions updates (brought to you by Dependabot)","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:54Z","receivedAt":"2026-04-30T07:35:07Z","isPatch":true,"body":"Dependabot (which my voice-typing software frequently mis-translates to \"the\npanda bot\" 😉) is enabled in Git for Windows' fork of the git/git repository\nto lighten the maintenance burden a little bit. Frequently, the updates are\nnot actually for Git for Windows' patches on top of git/git, but apply\ndirectly to git/git.\n\nHere is the latest batch of those updates, with heavily augmented commit\nmessages.\n\nChanges since v2:\n\n * Included the version bump for the freshly-updated\n   setup-git-for-windows-sdk GitHub Action (which now also requires Node.JS\n   24, at long last).\n\nChanges since v1:\n\n * Also bump mshick/add-pr-comment to the newest major version.\n\nJohannes Schindelin (6):\n  ci: bump microsoft/setup-msbuild from v2 to v3\n  ci: bump actions/{upload,download}-artifact to v7 and v8\n  ci: bump actions/github-script from v8 to v9\n  ci: bump actions/checkout from v5 to v6\n  ci: bump git-for-windows/setup-git-for-windows-sdk from v1 to v2\n  l10n: bump mshick/add-pr-comment from v2 to v3\n\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  4 +-\n .github/workflows/l10n.yml             |  2 +-\n .github/workflows/main.yml             | 58 +++++++++++++-------------\n 5 files changed, 34 insertions(+), 34 deletions(-)\n\n\nbase-commit: 94f057755b7941b321fd11fec1b2e3ca5313a4e0\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-2097%2Fdscho%2Fdependabot-updates-v3\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2097/dscho/dependabot-updates-v3\nPull-Request: https://github.com/gitgitgadget/git/pull/2097\n\nRange-diff vs v2:\n\n 1:  0d2fdc1cf4 = 1:  0d2fdc1cf4 ci: bump microsoft/setup-msbuild from v2 to v3\n 2:  5d719b3729 = 2:  5d719b3729 ci: bump actions/{upload,download}-artifact to v7 and v8\n 3:  bfbe0db67f = 3:  bfbe0db67f ci: bump actions/github-script from v8 to v9\n 4:  5694ca1016 = 4:  5694ca1016 ci: bump actions/checkout from v5 to v6\n -:  ---------- > 5:  c6e8df1eff ci: bump git-for-windows/setup-git-for-windows-sdk from v1 to v2\n 5:  faa83723f4 = 6:  b9ccb66405 l10n: bump mshick/add-pr-comment from v2 to v3\n\n-- \ngitgitgadget\n"},{"id":"542514","messageId":"0d2fdc1cf4c5d7273addedc442a222f0c3485efd.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 1/6] ci: bump microsoft/setup-msbuild from v2 to v3","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:55Z","receivedAt":"2026-04-30T07:35:07Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe v2 of `microsoft/setup-msbuild` runs on Node.js 20, which GitHub\nis phasing out of the Actions runners. v3 is a minimal release whose\nonly substantive change is moving the action's runtime to Node.js 24,\nso that our Visual Studio build jobs keep working once Node.js 20 is\nremoved from the runners.\n\nThe risk of this bump is very low: v3 contains no functional changes\nto the action itself -- it merely adds `msbuild.exe` to `PATH`, with\nno change to command-line flags, inputs, outputs, or default tool\nresolution. The only precondition is a recent-enough Actions Runner,\nwhich the github.com-hosted runners already satisfy.\n\nSee also:\n\n- Release notes: https://github.com/microsoft/setup-msbuild/releases\n- Compare: https://github.com/microsoft/setup-msbuild/compare/v2...v3\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6f3d94e3a6..0d3e0e42a4 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -186,7 +186,7 @@ jobs:\n         repository: git/git\n         definitionId: 9\n     - name: add msbuild to PATH\n-      uses: microsoft/setup-msbuild@v2\n+      uses: microsoft/setup-msbuild@v3\n     - name: copy dlls to root\n       shell: cmd\n       run: compat\\vcbuild\\vcpkg_copy_dlls.bat release\n-- \ngitgitgadget\n\n"},{"id":"542511","messageId":"bfbe0db67f5a0454378bd5fd71e2cbc1493bcb59.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 3/6] ci: bump actions/github-script from v8 to v9","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:57Z","receivedAt":"2026-04-30T07:35:10Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe only use we have of `actions/github-script` is the \"skip if the\ncommit or tree was already tested\" step in `main.yml`, which checks\nwhether an identical tree-SHA was already built successfully. It\ncurrently pins v8; v9 is the latest release.\n\nWhat v9 changes:\n\n- The `ACTIONS_ORCHESTRATION_ID` environment variable is now\n  appended to the HTTP user-agent string. This is transparent to\n  our script.\n- A new injected `getOctokit` factory lets scripts create\n  additional authenticated clients in the same step without\n  importing `@actions/github`. We do not use it.\n- Two breaking changes affect scripts that either call\n  `require('@actions/github')` (fails at runtime, because\n  `@actions/github` v9 is now ESM-only) or that shadow the\n  implicit `getOctokit` parameter via `const`/`let` (syntax\n  error). Our script does neither -- it only uses the pre-supplied\n  `github` REST client and `core` helpers -- so the upgrade is\n  safe.\n\nRisk analysis: the step is advisory. It sets `enabled=' but skip'`\nas an optimization to avoid re-running CI on a tree that was already\ntested successfully. Even if the v9 upgrade broke the script, the\nsurrounding `try { ... } catch (e) { core.warning(e); }` block would\ndegrade it to a warning and CI would still run normally. In practice\nthe script continues to work identically on v9.\n\nSee also:\n\n- Release notes: https://github.com/actions/github-script/releases\n- Compare: https://github.com/actions/github-script/compare/v8...v9\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex da31b10c79..6d7f26e71e 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -63,7 +63,7 @@ jobs:\n           echo \"skip_concurrent=$skip_concurrent\" >>$GITHUB_OUTPUT\n       - name: skip if the commit or tree was already tested\n         id: skip-if-redundant\n-        uses: actions/github-script@v8\n+        uses: actions/github-script@v9\n         if: steps.check-ref.outputs.enabled == 'yes'\n         with:\n           github-token: ${{secrets.GITHUB_TOKEN}}\n-- \ngitgitgadget\n\n"},{"id":"542515","messageId":"5d719b3729e39d63ec0a1a474b0c1ff57570133e.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 2/6] ci: bump actions/{upload,download}-artifact to v7 and v8","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:56Z","receivedAt":"2026-04-30T07:35:10Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\n`actions/upload-artifact` and `actions/download-artifact` are tightly\ncoupled: the upload action writes artifact archives in a format that\nthe download action then reads. Because of this coupling, the two\nactions should always be bumped together so that the artifact format\ncontract between them is satisfied.\n\nAll of our `actions/upload-artifact` uses are still on v5, with one\nstray v4 occurrence. Keeping them on these versions would leave the\nartifact-upload steps running on Node.js 20, which GitHub is phasing\nout, and would eventually cause all upload steps to fail.\n\nGoing from v5 directly to v7 folds in two release bumps:\n\n- v6 switches the action's default runtime from Node.js 20 to\n  Node.js 24 (v5 had preliminary Node 24 support but still defaulted\n  to Node 20). This is the main motivation for bumping now: it gets\n  us off the deprecated runtime.\n- v7 adds two opt-in features: direct (unzipped) single-file uploads\n  via a new `archive: false` parameter, and an internal conversion of\n  the action to ESM to match the updated `@actions/*` packages.\n\nRisk analysis: we never pass `archive`, so the zip-as-usual behavior\nis unchanged. We also do not `require('@actions/*')` from any calling\nworkflow, so the ESM migration cannot affect us. The upload steps we\ncare about -- tracked files/build artifacts and failing-test\ndirectories -- keep the same inputs (`name`, `path`) and outputs, so\nthe diff is purely the `@vN` identifier. The main precondition is a\nrecent Actions Runner (>= 2.327.1), which the github.com-hosted\nrunners used by our CI already satisfy.\n\nWhile at it, align the one remaining `@v4` occurrence with the rest\nso that every `upload-artifact` step uses the same version.\n\nSee also:\n\n- Release notes: https://github.com/actions/upload-artifact/releases\n- Compare: https://github.com/actions/upload-artifact/compare/v5...v7\n\nWe use `actions/download-artifact` to pass build artifacts between\nthe \"windows-build\" / \"vs-build\" / \"windows-meson-build\" jobs and\ntheir corresponding test jobs. All callers are currently on v6;\nbumping to v8 keeps this action in lockstep with the `upload-artifact`\nbump above.\n\nWhat v7 and v8 change:\n\n- v7 switches the default runtime from Node.js 20 to Node.js 24 (v6\n  had preliminary Node 24 support but still defaulted to Node 20).\n  This is the main motivation: it gets us off the deprecated runtime.\n- v8 makes three further changes:\n  * The package is converted to ESM (invisible to workflow authors).\n  * The action now checks the `Content-Type` header before\n    attempting to unzip a download, so that directly-uploaded\n    (unzipped) artifacts from `upload-artifact` v7 are downloaded\n    correctly.\n  * The `digest-mismatch` behaviour is changed from warn-and-\n    continue to a hard failure by default.\n\nRisk analysis: defaulting hash-mismatch to a hard failure is\nstrictly safer than the previous warn-and-continue behaviour -- a\nmismatch points to real corruption or tampering and should stop the\nrun. We download archives that the same workflow just uploaded, on\nthe same runner fleet, so false positives are not expected. Our\nusage is limited to the `name` and `path` inputs, which are\nunchanged between v6 and v8, so the diff is purely the `@vN`\nidentifier.\n\nSee also:\n\n- Release notes: https://github.com/actions/download-artifact/releases\n- Compare: https://github.com/actions/download-artifact/compare/v6...v8\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/main.yml | 22 +++++++++++-----------\n 1 file changed, 11 insertions(+), 11 deletions(-)\n\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 0d3e0e42a4..da31b10c79 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -123,7 +123,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-artifacts\n         path: artifacts\n@@ -140,7 +140,7 @@ jobs:\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-artifacts\n         path: ${{github.workspace}}\n@@ -157,7 +157,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -208,7 +208,7 @@ jobs:\n     - name: zip up tracked files\n       run: git archive -o artifacts/tracked.tar.gz HEAD\n     - name: upload tracked files and build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: vs-artifacts\n         path: artifacts\n@@ -226,7 +226,7 @@ jobs:\n     steps:\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: download tracked files and build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: vs-artifacts\n         path: ${{github.workspace}}\n@@ -244,7 +244,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-vs-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -270,7 +270,7 @@ jobs:\n       shell: pwsh\n       run: meson compile -C build\n     - name: Upload build artifacts\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -292,7 +292,7 @@ jobs:\n       shell: pwsh\n       run: pip install meson ninja\n     - name: Download build artifacts\n-      uses: actions/download-artifact@v6\n+      uses: actions/download-artifact@v8\n       with:\n         name: windows-meson-artifacts\n         path: build\n@@ -305,7 +305,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v4\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-windows-meson-${{ matrix.nr }}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -349,7 +349,7 @@ jobs:\n       run: ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n@@ -449,7 +449,7 @@ jobs:\n       run: sudo --preserve-env --set-home --user=builder ci/print-test-failures.sh\n     - name: Upload failed tests' directories\n       if: failure() && env.FAILED_TEST_ARTIFACTS != ''\n-      uses: actions/upload-artifact@v5\n+      uses: actions/upload-artifact@v7\n       with:\n         name: failed-tests-${{matrix.vector.jobname}}\n         path: ${{env.FAILED_TEST_ARTIFACTS}}\n-- \ngitgitgadget\n\n"},{"id":"542512","messageId":"5694ca10167f683c55151672a1e5bcf6482b2a43.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 4/6] ci: bump actions/checkout from v5 to v6","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:58Z","receivedAt":"2026-04-30T07:35:12Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nEvery workflow currently pins `actions/checkout` to v5, which was\nintroduced primarily to move to the Node.js 24 runtime. v6 is the\nnext release and worth picking up so we stay on a maintained version\nof the action.\n\nThe one behaviorally interesting change in v6:\n\n  `persist-credentials` now stores the helper credentials under\n  `$RUNNER_TEMP` instead of writing them directly into the local\n  `.git/config`. Two implications follow:\n\n  1. In the normal case this is an unambiguous improvement -- the\n     token no longer lands in `.git/config`, reducing the risk of\n     inadvertently leaking it through workspace archiving\n     (`upload-artifact` snapshots, cache entries, core dumps, ...).\n\n  2. Docker container actions require an Actions Runner of at least\n     v2.329.0 to find the credentials in their new location. The\n     github.com-hosted runners our CI uses are already past that\n     version, so this does not affect us. Downstream users running\n     self-hosted runners may need to update them before adopting\n     this version of the action.\n\nRisk analysis: our checkout steps either check out the default\nrepository (no special credential requirements) or, in the `vs-build`\njob, explicitly set `repository: microsoft/vcpkg` and\n`path: compat/vcbuild/vcpkg`. Neither case relies on the precise\nlocation of the persisted credentials -- subsequent steps interact\nwith the API via the runner-provided `GITHUB_TOKEN` directly -- so\nthe v6 credential-storage change is transparent to our workflows.\nThe diff is purely the `@vN` identifier; there are no input or\noutput changes.\n\nSee also:\n\n- Release notes: https://github.com/actions/checkout/releases\n- Changelog: https://github.com/actions/checkout/blob/main/CHANGELOG.md\n- Compare: https://github.com/actions/checkout/compare/v5...v6\n\nOriginally-authored-by: dependabot[bot] <support@github.com>\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/check-style.yml      |  2 +-\n .github/workflows/check-whitespace.yml |  2 +-\n .github/workflows/coverity.yml         |  2 +-\n .github/workflows/main.yml             | 24 ++++++++++++------------\n 4 files changed, 15 insertions(+), 15 deletions(-)\n\ndiff --git a/.github/workflows/check-style.yml b/.github/workflows/check-style.yml\nindex 19a145d4ad..108a2de903 100644\n--- a/.github/workflows/check-style.yml\n+++ b/.github/workflows/check-style.yml\n@@ -20,7 +20,7 @@ jobs:\n       jobname: ClangFormat\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/check-whitespace.yml b/.github/workflows/check-whitespace.yml\nindex 928fd4cfe2..ea6f49f742 100644\n--- a/.github/workflows/check-whitespace.yml\n+++ b/.github/workflows/check-whitespace.yml\n@@ -19,7 +19,7 @@ jobs:\n   check-whitespace:\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n       with:\n         fetch-depth: 0\n \ndiff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\nindex 3435baeca2..89bef26727 100644\n--- a/.github/workflows/coverity.yml\n+++ b/.github/workflows/coverity.yml\n@@ -38,7 +38,7 @@ jobs:\n       COVERITY_LANGUAGE: cxx\n       COVERITY_PLATFORM: overridden-below\n     steps:\n-      - uses: actions/checkout@v5\n+      - uses: actions/checkout@v6\n       - name: install minimal Git for Windows SDK\n         if: contains(matrix.os, 'windows')\n         uses: git-for-windows/setup-git-for-windows-sdk@v1\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 6d7f26e71e..0ea266f27c 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -112,7 +112,7 @@ jobs:\n       group: windows-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: build\n       shell: bash\n@@ -173,10 +173,10 @@ jobs:\n       group: vs-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: git-for-windows/setup-git-for-windows-sdk@v1\n     - name: initialize vcpkg\n-      uses: actions/checkout@v5\n+      uses: actions/checkout@v6\n       with:\n         repository: 'microsoft/vcpkg'\n         path: 'compat/vcbuild/vcpkg'\n@@ -258,7 +258,7 @@ jobs:\n       group: windows-meson-build-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -286,7 +286,7 @@ jobs:\n       group: windows-meson-test-${{ matrix.nr }}-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - uses: actions/setup-python@v6\n     - name: Set up dependencies\n       shell: pwsh\n@@ -341,7 +341,7 @@ jobs:\n       TEST_OUTPUT_DIRECTORY: ${{github.workspace}}/t\n     runs-on: ${{matrix.vector.pool}}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-tests.sh\n     - name: print test failures\n@@ -362,7 +362,7 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-build-and-minimal-fuzzers.sh\n   dockerized:\n@@ -439,7 +439,7 @@ jobs:\n         else\n           apt-get -q update && apt-get -q -y install git\n         fi\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: useradd builder --create-home\n     - run: chown -R builder .\n@@ -464,7 +464,7 @@ jobs:\n       group: static-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-static-analysis.sh\n     - run: ci/check-directional-formatting.bash\n@@ -480,7 +480,7 @@ jobs:\n       group: rust-analysis-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/run-rust-checks.sh\n   sparse:\n@@ -494,7 +494,7 @@ jobs:\n       group: sparse-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - name: Install other dependencies\n       run: ci/install-dependencies.sh\n     - run: make sparse\n@@ -510,6 +510,6 @@ jobs:\n       CI_JOB_IMAGE: ubuntu-latest\n     runs-on: ubuntu-latest\n     steps:\n-    - uses: actions/checkout@v5\n+    - uses: actions/checkout@v6\n     - run: ci/install-dependencies.sh\n     - run: ci/test-documentation.sh\n-- \ngitgitgadget\n\n"},{"id":"542516","messageId":"c6e8df1eff329302ac080f70d4db6d9fdd1ae8ae.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 5/6] ci: bump git-for-windows/setup-git-for-windows-sdk from v1 to v2","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:34:59Z","receivedAt":"2026-04-30T07:35:15Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe v1 of `git-for-windows/setup-git-for-windows-sdk` runs on\nNode.js 20, which GitHub is phasing out of the Actions runners.\nv2 moves the action to Node.js 24 so that the CI jobs relying on\na Git for Windows SDK keep working once Node.js 20 is removed.\n\nThe risk is very low: v2 contains no functional changes to the\nSDK setup itself, only the runtime upgrade. The action still\nprovisions the same minimal SDK and exposes the same outputs.\nThe sole precondition is a recent Actions Runner (>= 2.327.1),\nwhich the github.com-hosted runners already satisfy.\n\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/coverity.yml | 2 +-\n .github/workflows/main.yml     | 8 ++++----\n 2 files changed, 5 insertions(+), 5 deletions(-)\n\ndiff --git a/.github/workflows/coverity.yml b/.github/workflows/coverity.yml\nindex 89bef26727..58a78f1eb3 100644\n--- a/.github/workflows/coverity.yml\n+++ b/.github/workflows/coverity.yml\n@@ -41,7 +41,7 @@ jobs:\n       - uses: actions/checkout@v6\n       - name: install minimal Git for Windows SDK\n         if: contains(matrix.os, 'windows')\n-        uses: git-for-windows/setup-git-for-windows-sdk@v1\n+        uses: git-for-windows/setup-git-for-windows-sdk@v2\n       - run: ci/install-dependencies.sh\n         if: contains(matrix.os, 'ubuntu') || contains(matrix.os, 'macos')\n         env:\ndiff --git a/.github/workflows/main.yml b/.github/workflows/main.yml\nindex 0ea266f27c..3da5326f0b 100644\n--- a/.github/workflows/main.yml\n+++ b/.github/workflows/main.yml\n@@ -113,7 +113,7 @@ jobs:\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n     - uses: actions/checkout@v6\n-    - uses: git-for-windows/setup-git-for-windows-sdk@v1\n+    - uses: git-for-windows/setup-git-for-windows-sdk@v2\n     - name: build\n       shell: bash\n       env:\n@@ -147,7 +147,7 @@ jobs:\n     - name: extract tracked files and build artifacts\n       shell: bash\n       run: tar xf artifacts.tar.gz && tar xf tracked.tar.gz\n-    - uses: git-for-windows/setup-git-for-windows-sdk@v1\n+    - uses: git-for-windows/setup-git-for-windows-sdk@v2\n     - name: test\n       shell: bash\n       run: . /etc/profile && ci/run-test-slice.sh $((${{matrix.nr}} + 1)) 10\n@@ -174,7 +174,7 @@ jobs:\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n     - uses: actions/checkout@v6\n-    - uses: git-for-windows/setup-git-for-windows-sdk@v1\n+    - uses: git-for-windows/setup-git-for-windows-sdk@v2\n     - name: initialize vcpkg\n       uses: actions/checkout@v6\n       with:\n@@ -224,7 +224,7 @@ jobs:\n       group: vs-test-${{ matrix.nr }}-${{ github.ref }}\n       cancel-in-progress: ${{ needs.ci-config.outputs.skip_concurrent == 'yes' }}\n     steps:\n-    - uses: git-for-windows/setup-git-for-windows-sdk@v1\n+    - uses: git-for-windows/setup-git-for-windows-sdk@v2\n     - name: download tracked files and build artifacts\n       uses: actions/download-artifact@v8\n       with:\n-- \ngitgitgadget\n\n"},{"id":"542517","messageId":"b9ccb66405c887812a3dd5791b343aed6c15a15f.1777534500.git.gitgitgadget@gmail.com","threadId":"65530","inReplyTo":"pull.2097.v3.git.1777534500.gitgitgadget@gmail.com","subject":"[PATCH v3 6/6] l10n: bump mshick/add-pr-comment from v2 to v3","fromName":"Johannes Schindelin via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2026-04-30T07:35:00Z","receivedAt":"2026-04-30T07:35:16Z","isPatch":true,"body":"From: Johannes Schindelin <johannes.schindelin@gmx.de>\n\nThe l10n workflow uses `mshick/add-pr-comment` to post git-po-helper\nreports as comments on translation pull requests. It was still pinned\nto v2, which runs on Node.js 20. GitHub is phasing out the Node.js 20\nruntime on Actions runners, so staying on v2 will eventually cause the\n\"Create comment in pull request for report\" step to fail.\n\nThe sole breaking change in v3 is the switch from Node.js 20 to\nNode.js 24 (https://github.com/mshick/add-pr-comment/releases/tag/v3.0.0).\nThe action's inputs and outputs are unchanged, so the upgrade is a\ndrop-in replacement. Subsequent v3.x releases added new opt-in\nfeatures (message truncation, retry with exponential backoff, file\nattachments, commit comment support, \"delete on status\") but none of\nthem affect existing callers that do not opt in.\n\nSee also:\n\n- Changelog: https://github.com/mshick/add-pr-comment/blob/main/CHANGELOG.md\n- Compare: https://github.com/mshick/add-pr-comment/compare/v2...v3\n\nPointed-out-by: Christoph Grüninger <foss@grueninger.de>\nAssisted-by: Claude Opus 4.6\nSigned-off-by: Johannes Schindelin <johannes.schindelin@gmx.de>\n---\n .github/workflows/l10n.yml | 2 +-\n 1 file changed, 1 insertion(+), 1 deletion(-)\n\ndiff --git a/.github/workflows/l10n.yml b/.github/workflows/l10n.yml\nindex 95e55134bd..114a12a9e5 100644\n--- a/.github/workflows/l10n.yml\n+++ b/.github/workflows/l10n.yml\n@@ -92,7 +92,7 @@ jobs:\n           cat git-po-helper.out\n           exit $exit_code\n       - name: Create comment in pull request for report\n-        uses: mshick/add-pr-comment@v2\n+        uses: mshick/add-pr-comment@v3\n         if: >-\n           always() &&\n           github.event_name == 'pull_request_target' &&\n-- \ngitgitgadget\n"}]}