This is an automated email from the ASF dual-hosted git repository.

paleolimbot pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-nanoarrow.git


The following commit(s) were added to refs/heads/main by this push:
     new a5d7011f chore: bump actions/cache from 5 to 6 (#897)
a5d7011f is described below

commit a5d7011ff4838bd4cbf70c6f72b7078ea8842cd4
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Fri Jun 26 11:27:00 2026 -0500

    chore: bump actions/cache from 5 to 6 (#897)
    
    Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/cache/releases";>actions/cache's
    releases</a>.</em></p>
    <blockquote>
    <h2>v6.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update packages, migrate to ESM by <a
    href="https://github.com/Samirat";><code>@​Samirat</code></a> in <a
    
href="https://redirect.github.com/actions/cache/pull/1760";>actions/cache#1760</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/actions/cache/compare/v5...v6.0.0";>https://github.com/actions/cache/compare/v5...v6.0.0</a></p>
    <h2>v5.0.5</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update ts-http-runtime dependency by <a
    href="https://github.com/yacaovsnc";><code>@​yacaovsnc</code></a> in <a
    
href="https://redirect.github.com/actions/cache/pull/1747";>actions/cache#1747</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/actions/cache/compare/v5...v5.0.5";>https://github.com/actions/cache/compare/v5...v5.0.5</a></p>
    <h2>v5.0.4</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Add release instructions and update maintainer docs by <a
    href="https://github.com/Link";><code>@​Link</code></a>- in <a
    
href="https://redirect.github.com/actions/cache/pull/1696";>actions/cache#1696</a></li>
    <li>Potential fix for code scanning alert no. 52: Workflow does not
    contain permissions by <a
    href="https://github.com/Link";><code>@​Link</code></a>- in <a
    
href="https://redirect.github.com/actions/cache/pull/1697";>actions/cache#1697</a></li>
    <li>Fix workflow permissions and cleanup workflow names / formatting by
    <a href="https://github.com/Link";><code>@​Link</code></a>- in <a
    
href="https://redirect.github.com/actions/cache/pull/1699";>actions/cache#1699</a></li>
    <li>docs: Update examples to use the latest version by <a
    href="https://github.com/XZTDean";><code>@​XZTDean</code></a> in <a
    
href="https://redirect.github.com/actions/cache/pull/1690";>actions/cache#1690</a></li>
    <li>Fix proxy integration tests by <a
    href="https://github.com/Link";><code>@​Link</code></a>- in <a
    
href="https://redirect.github.com/actions/cache/pull/1701";>actions/cache#1701</a></li>
    <li>Fix cache key in examples.md for bun.lock by <a
    href="https://github.com/RyPeck";><code>@​RyPeck</code></a> in <a
    
href="https://redirect.github.com/actions/cache/pull/1722";>actions/cache#1722</a></li>
    <li>Update dependencies &amp; patch security vulnerabilities by <a
    href="https://github.com/Link";><code>@​Link</code></a>- in <a
    
href="https://redirect.github.com/actions/cache/pull/1738";>actions/cache#1738</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/XZTDean";><code>@​XZTDean</code></a> made
    their first contribution in <a
    
href="https://redirect.github.com/actions/cache/pull/1690";>actions/cache#1690</a></li>
    <li><a href="https://github.com/RyPeck";><code>@​RyPeck</code></a> made
    their first contribution in <a
    
href="https://redirect.github.com/actions/cache/pull/1722";>actions/cache#1722</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/actions/cache/compare/v5...v5.0.4";>https://github.com/actions/cache/compare/v5...v5.0.4</a></p>
    <h2>v5.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
    
href="https://github.com/actions/cache/security/dependabot/33";>https://github.com/actions/cache/security/dependabot/33</a>)</li>
    <li>Bump <code>@actions/core</code> to v2.0.3</li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/actions/cache/compare/v5...v5.0.3";>https://github.com/actions/cache/compare/v5...v5.0.3</a></p>
    <h2>v.5.0.2</h2>
    <h1>v5.0.2</h1>
    <h2>What's Changed</h2>
    <p>When creating cache entries, 429s returned from the cache service
    will not be retried.</p>
    <h2>v5.0.1</h2>
    <blockquote>
    <p>[!IMPORTANT]
    <strong><code>actions/cache@v5</code> runs on the Node.js 24 runtime and
    requires a minimum Actions Runner version of
    <code>2.327.1</code>.</strong></p>
    </blockquote>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    
href="https://github.com/actions/cache/blob/main/RELEASES.md";>actions/cache's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Releases</h1>
    <h2>How to prepare a release</h2>
    <blockquote>
    <p>[!NOTE]
    Relevant for maintainers with write access only.</p>
    </blockquote>
    <ol>
    <li>Switch to a new branch from <code>main</code>.</li>
    <li>Run <code>npm test</code> to ensure all tests are passing.</li>
    <li>Update the version in <a
    
href="https://github.com/actions/cache/blob/main/package.json";><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
    <li>Run <code>npm run build</code> to update the compiled files.</li>
    <li>Update this <a
    
href="https://github.com/actions/cache/blob/main/RELEASES.md";><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
    with the new version and changes in the <code>## Changelog</code>
    section.</li>
    <li>Run <code>licensed cache</code> to update the license report.</li>
    <li>Run <code>licensed status</code> and resolve any warnings by
    updating the <a
    
href="https://github.com/actions/cache/blob/main/.licensed.yml";><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
    file with the exceptions.</li>
    <li>Commit your changes and push your branch upstream.</li>
    <li>Open a pull request against <code>main</code> and get it reviewed
    and merged.</li>
    <li>Draft a new release <a
    
href="https://github.com/actions/cache/releases";>https://github.com/actions/cache/releases</a>
    use the same version number used in <code>package.json</code>
    <ol>
    <li>Create a new tag with the version number.</li>
    <li>Auto generate release notes and update them to match the changes you
    made in <code>RELEASES.md</code>.</li>
    <li>Toggle the set as the latest release option.</li>
    <li>Publish the release.</li>
    </ol>
    </li>
    <li>Navigate to <a
    
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml";>https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
    <ol>
    <li>There should be a workflow run queued with the same version
    number.</li>
    <li>Approve the run to publish the new version and update the major tags
    for this action.</li>
    </ol>
    </li>
    </ol>
    <h2>Changelog</h2>
    <h3>6.1.0</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v6.1.0 to pick up <a
    
href="https://redirect.github.com/actions/toolkit/pull/2435";>actions/toolkit#2435
    Handle cache write error due to read-only token</a></li>
    <li>Switch redundant &quot;Cache save failed&quot; warning to debug log
    in save-only</li>
    </ul>
    <h3>6.0.0</h3>
    <ul>
    <li>Updated <code>@actions/cache</code> to ^6.0.1,
    <code>@actions/core</code> to ^3.0.1, <code>@actions/exec</code> to
    ^3.0.0, <code>@actions/io</code> to ^3.0.2</li>
    <li>Migrated to ESM module system</li>
    <li>Upgraded Jest to v30 and test infrastructure to be ESM
    compatible</li>
    </ul>
    <h3>5.0.4</h3>
    <ul>
    <li>Bump <code>minimatch</code> to v3.1.5 (fixes ReDoS via globstar
    patterns)</li>
    <li>Bump <code>undici</code> to v6.24.1 (WebSocket decompression bomb
    protection, header validation fixes)</li>
    <li>Bump <code>fast-xml-parser</code> to v5.5.6</li>
    </ul>
    <h3>5.0.3</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
    
href="https://github.com/actions/cache/security/dependabot/33";>https://github.com/actions/cache/security/dependabot/33</a>)</li>
    <li>Bump <code>@actions/core</code> to v2.0.3</li>
    </ul>
    <h3>5.0.2</h3>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/actions/cache/commit/2c8a9bd7457de244a408f35966fab2fb45fda9c8";><code>2c8a9bd</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/cache/issues/1760";>#1760</a>
    from actions/samirat/esm_migration_and_package_update</li>
    <li><a
    
href="https://github.com/actions/cache/commit/e9b91fdc3fea7d79165fceb79042ef45c2d51023";><code>e9b91fd</code></a>
    Prettier fixes</li>
    <li><a
    
href="https://github.com/actions/cache/commit/e4884b8ff7f92ef6b52c79eda480bbc86e685adb";><code>e4884b8</code></a>
    Rebuild dist</li>
    <li><a
    
href="https://github.com/actions/cache/commit/10baf0191a3c426ea0fa4a3253a5c04233b6e18f";><code>10baf01</code></a>
    Fixed licenses</li>
    <li><a
    
href="https://github.com/actions/cache/commit/e39b386c9004d72a15d864ade8c0b3a702d47a37";><code>e39b386</code></a>
    Fix test mock return order</li>
    <li><a
    
href="https://github.com/actions/cache/commit/b6928203372a8571ff984c0c883ef3a1adfb0c06";><code>b692820</code></a>
    PR feedback</li>
    <li><a
    
href="https://github.com/actions/cache/commit/60749128a44d25d3c520a489e576380cf00ff3f1";><code>6074912</code></a>
    Rebuild dist bundles as ESM to match type:module</li>
    <li><a
    
href="https://github.com/actions/cache/commit/5a912e8b4af820fa082a0e75cfd2c782f8fbfe0e";><code>5a912e8</code></a>
    Fix lint and jest issues</li>
    <li><a
    
href="https://github.com/actions/cache/commit/b9bf592b98b6a5d0cad9929c76247de1cac78abe";><code>b9bf592</code></a>
    Update documentation for v6 release</li>
    <li><a
    
href="https://github.com/actions/cache/commit/80f777761d0990932f64ed2740522d7226a49062";><code>80f7777</code></a>
    Update packages, migrate to ESM</li>
    <li>See full diff in <a
    href="https://github.com/actions/cache/compare/v5...v6";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/cache&package-manager=github_actions&previous-version=5&new-version=6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .github/workflows/build-and-test-device.yaml | 2 +-
 .github/workflows/build-and-test-ipc.yaml    | 2 +-
 .github/workflows/build-and-test.yaml        | 4 ++--
 .github/workflows/clang-tidy.yaml            | 2 +-
 .github/workflows/dev.yaml                   | 2 +-
 .github/workflows/verify.yaml                | 2 +-
 6 files changed, 7 insertions(+), 7 deletions(-)

diff --git a/.github/workflows/build-and-test-device.yaml 
b/.github/workflows/build-and-test-device.yaml
index b2088d3d..9c2205ff 100644
--- a/.github/workflows/build-and-test-device.yaml
+++ b/.github/workflows/build-and-test-device.yaml
@@ -94,7 +94,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build
diff --git a/.github/workflows/build-and-test-ipc.yaml 
b/.github/workflows/build-and-test-ipc.yaml
index 9396674f..e34d9a27 100644
--- a/.github/workflows/build-and-test-ipc.yaml
+++ b/.github/workflows/build-and-test-ipc.yaml
@@ -69,7 +69,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build
diff --git a/.github/workflows/build-and-test.yaml 
b/.github/workflows/build-and-test.yaml
index 13188489..e57dd757 100644
--- a/.github/workflows/build-and-test.yaml
+++ b/.github/workflows/build-and-test.yaml
@@ -61,7 +61,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build
@@ -150,7 +150,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build
diff --git a/.github/workflows/clang-tidy.yaml 
b/.github/workflows/clang-tidy.yaml
index 821ae823..d65004c0 100644
--- a/.github/workflows/clang-tidy.yaml
+++ b/.github/workflows/clang-tidy.yaml
@@ -44,7 +44,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build
diff --git a/.github/workflows/dev.yaml b/.github/workflows/dev.yaml
index cfb28c7a..2f3f93f5 100644
--- a/.github/workflows/dev.yaml
+++ b/.github/workflows/dev.yaml
@@ -41,7 +41,7 @@ jobs:
         with:
           python-version: '3.13'
       - name: pre-commit (cache)
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: ~/.cache/pre-commit
           key: pre-commit-${{ hashFiles('.pre-commit-config.yaml') }}
diff --git a/.github/workflows/verify.yaml b/.github/workflows/verify.yaml
index 05c1c692..2652dca2 100644
--- a/.github/workflows/verify.yaml
+++ b/.github/workflows/verify.yaml
@@ -86,7 +86,7 @@ jobs:
 
       - name: Cache Arrow C++ Build
         id: cache-arrow-build
-        uses: actions/cache@v5
+        uses: actions/cache@v6
         with:
           path: arrow
           # Bump the number at the end of this line to force a new Arrow C++ 
build

Reply via email to