Skip to content

chore(deps): bump actions/setup-node from 4 to 7 - #854

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/setup-node-7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown

Bumps actions/setup-node from 4 to 7.

Release notes

Sourced from actions/setup-node's releases.

v7.0.0

What's Changed

Enhancements:

Bug fixes:

Documentation updates:

Dependency update:

New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

v6.5.0

What's Changed

Full Changelog: actions/setup-node@v6.4.0...v6.5.0

v6.4.0

What's Changed

Dependency updates:

New Contributors

Full Changelog: actions/setup-node@v6...v6.4.0

v6.3.0

What's Changed

Enhancements:

... (truncated)

Commits
  • 8207627 Migrate to ESM and upgrade dependencies (#1574)
  • 04be95c Add cache-primary-key and cache-matched-key as outputs (#1577)
  • 7c2c68d docs: Update caching recommendations to mitigate cache poisoning risks (#1567)
  • 6a61c03 Merge pull request #1569 from jasongin/update-actions-cache-5.1.0
  • 30eb73b Resolve high-severity audit issues
  • 4e1a87a Update dist
  • 360237f Strict equality
  • 4f8aac5 Bump @​actions/cache to 5.1.0, log cache write denied
  • f4a67bb Only use mirrorToken in getManifest if it's provided (#1548)
  • 0355742 Remove dummy NODE_AUTH_TOKEN export (#1558)
  • Additional commits viewable in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1269 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](actions/setup-node@v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions/setup-node-7 branch from 3591a70 to d7028e3 Compare October 4, 2026 12:29
@dependabot
dependabot Bot deployed to staging October 4, 2026 12:29 Active
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🛡️ Frontend Security Scan

npm audit
# npm audit report

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
# npm audit report

@vitest/mocker  2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix --force`
Will install storybook@10.6.1, which is a breaking change
node_modules/@vitest/mocker
  storybook  9.1.0-alpha.0 - 10.1.0-beta.6
  Depends on vulnerable versions of @vitest/mocker
  node_modules/storybook
    @storybook/addon-docs  <=0.0.0-pr-35259-sha-153697da || 9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/csf-plugin
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-docs
    @storybook/addon-links  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-links
    @storybook/builder-webpack5  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of fork-ts-checker-webpack-plugin
    Depends on vulnerable versions of storybook
    Depends on vulnerable versions of webpack-dev-middleware
    node_modules/@storybook/builder-webpack5
      @storybook/nextjs  *
      Depends on vulnerable versions of @storybook/builder-webpack5
      Depends on vulnerable versions of @storybook/preset-react-webpack
      Depends on vulnerable versions of @storybook/react
      Depends on vulnerable versions of node-polyfill-webpack-plugin
      Depends on vulnerable versions of storybook
      node_modules/@storybook/nextjs
    @storybook/core-webpack  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/core-webpack
    @storybook/csf-plugin  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/csf-plugin
    @storybook/preset-react-webpack  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of @storybook/react-docgen-typescript-plugin
    Depends on vulnerable versions of storybook
    node_modules/@storybook/preset-react-webpack
    @storybook/react  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react
    @storybook/react-dom-shim  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react-dom-shim

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/braces
  chokidar  2.0.0 - 3.6.0
  Depends on vulnerable versions of braces
  node_modules/chokidar
    fork-ts-checker-webpack-plugin  0.4.7 - 4.0.0-beta.5 || 6.0.0-alpha.1 - 9.0.3
    Depends on vulnerable versions of chokidar
    node_modules/fork-ts-checker-webpack-plugin
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    @storybook/react-docgen-typescript-plugin  *
    Depends on vulnerable versions of micromatch
    node_modules/@storybook/react-docgen-typescript-plugin
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/@shadcn/registry/node_modules/fast-glob
    node_modules/@ts-morph/common/node_modules/fast-glob
    node_modules/fast-glob
    node_modules/shadcn/node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
      @shadcn/registry  0.0.0-beta-20261001093212 || >=0.1.0
      Depends on vulnerable versions of fast-glob
      Depends on vulnerable versions of ts-morph
      node_modules/@shadcn/registry
        shadcn  <=0.0.0-beta-20261001093212 || >=2.0.0
        Depends on vulnerable versions of @shadcn/registry
        Depends on vulnerable versions of fast-glob
        Depends on vulnerable versions of ts-morph
        node_modules/shadcn
      @ts-morph/common  0.2.0 - 0.24.0 || 0.26.0 - 0.27.0
      Depends on vulnerable versions of fast-glob
      node_modules/@ts-morph/common
        ts-morph  6.0.1 - 23.0.0 || 25.0.0 - 26.0.0
        Depends on vulnerable versions of @ts-morph/common
        node_modules/ts-morph

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/elliptic
  browserify-sign  >=2.4.0
  Depends on vulnerable versions of elliptic
  node_modules/browserify-sign
    crypto-browserify  >=3.4.0
    Depends on vulnerable versions of browserify-sign
    Depends on vulnerable versions of create-ecdh
    node_modules/crypto-browserify
      node-polyfill-webpack-plugin  <=4.0.0
      Depends on vulnerable versions of crypto-browserify
      node_modules/node-polyfill-webpack-plugin
  create-ecdh  *
  Depends on vulnerable versions of elliptic
  node_modules/create-ecdh

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

webpack-dev-middleware  <7.4.5
Severity: high
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath - https://github.com/advisories/GHSA-g84c-rxfj-3j2c
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/webpack-dev-middleware

31 vulnerabilities (5 low, 11 moderate, 15 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force
ESLint
> flowstar@0.1.0 lint
> eslint .


/home/runner/work/FlowStar/FlowStar/next.config.mjs
  15:5  warning  Unexpected console statement  no-console

/home/runner/work/FlowStar/FlowStar/scripts/check-secrets.mjs
  28:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
  31:16  warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  47:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  52:9   warning  Unexpected console statement                                               no-console
  60:3   warning  Unexpected console statement                                               no-console
  63:3   warning  Unexpected console statement                                               no-console

/home/runner/work/FlowStar/FlowStar/scripts/soroban-security-check.mjs
   14:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
   16:9   warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  135:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  142:7   warning  Unexpected console statement                                               no-console
  150:3   warning  Unexpected console statement                                               no-console
  154:3   warning  Unexpected console statement                                               no-console
  159:3   warning  Unexpected console statement                                               no-console

✖ 14 problems (0 errors, 14 warnings)
Hardcoded secrets check
✅ No hardcoded secrets found.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1290 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

This branch was successfully deployed

1 active deployment
staging — d7028e39 Deployed Oct 4, 2026 by dependabot[bot] via deploy-staging #305
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants