Skip to content

BUILD-10765 Important: Update SonarSource/gh-action_release to v6#102

Merged
mikolaj-matuszny-ext-sonarsource merged 1 commit into
masterfrom
feat/BUILD-10765/update-gh-action_release-and-releasability
Apr 17, 2026
Merged

BUILD-10765 Important: Update SonarSource/gh-action_release to v6#102
mikolaj-matuszny-ext-sonarsource merged 1 commit into
masterfrom
feat/BUILD-10765/update-gh-action_release-and-releasability

Conversation

@SonarTech
Copy link
Copy Markdown
Contributor

Important: Update GitHub Actions to compliant versions.

  • .github/workflows/release.yml: release c52861bb0e5dd564187f3fd74e048f20aef0f761v6

See: https://discuss.sonarsource.com/t/action-required-update-your-github-actions-cache-release-and-releasability-before-31-04-2026/23899

@SonarTech SonarTech requested a review from a team April 17, 2026 08:32
@hashicorp-vault-sonar-prod
Copy link
Copy Markdown

hashicorp-vault-sonar-prod Bot commented Apr 17, 2026

BUILD-10765

@sonar-review-alpha
Copy link
Copy Markdown

sonar-review-alpha Bot commented Apr 17, 2026

Summary

This PR updates the SonarSource gh-action_release action from a pinned commit (c52861bb0e5dd564187f3fd74e048f20aef0f761, tagged as v6.5.0) to the semantic version tag v6 in the release workflow.

Why: This is a compliance requirement from SonarSource with a deadline of April 31, 2026 (see discussion). Pinned commits must be updated to semantic version tags.

Impact: The workflow will now use the latest v6.x release of the action instead of a fixed patch version. This is a forward-looking change that may include bug fixes and improvements within the v6 series.

What reviewers should know

What to review:

  • Single-line change in .github/workflows/release.yml
  • Confirm v6 is a stable tag and compatible with the project's release process

Context for reviewers:

  • This is a required compliance update, not an optional upgrade
  • Moving from pinned commit to semantic versioning follows GitHub Actions best practices
  • The change is minimal and low-risk; the workflow structure and all with: parameters remain unchanged
  • If the v6 tag ever introduces breaking changes, the project will need to update to the next major version (v7, etc.)

  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown

@sonar-review-alpha sonar-review-alpha Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

Clean, minimal compliance update — no issues found.

🗣️ Give feedback

@mikolaj-matuszny-ext-sonarsource mikolaj-matuszny-ext-sonarsource merged commit 384fda5 into master Apr 17, 2026
10 checks passed
@mikolaj-matuszny-ext-sonarsource mikolaj-matuszny-ext-sonarsource deleted the feat/BUILD-10765/update-gh-action_release-and-releasability branch April 17, 2026 08:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants