Skip to content

chore(ci): bump gradle/actions from 4 to 6 - #296

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/gradle/actions-6
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/github_actions/gradle/actions-6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps gradle/actions from 4 to 6.

Release notes

Sourced from gradle/actions's releases.

v6.0.0

[!IMPORTANT] The release of gradle/actions@v6 contains important changes to the license terms. More details in this blog post. TL;DR: By upgrading to v6, you accept the Terms of Use for the gradle-actions-caching component.

Summary

  • Caching functionality of 'gradle-actions' has been extracted into a separate gradle-actions-caching library, and is no longer open-source. See this blog post for more context.
  • Existing, rudimentary, configuration-cache support has been removed, pending a fully functional implementation in gradle-actions-caching.
  • Dependencies updated to address security vulnerabilities

[!IMPORTANT]

Licensing notice

The caching functionality in `gradle-actions` has been extracted into `gradle-actions-caching`, a proprietary commercial component that is not covered by the MIT License. The bundled `gradle-actions-caching` component is licensed and governed by a separate license, available at https://gradle.com/legal/terms-of-use/.

The `gradle-actions-caching` component is used only when caching is enabled and is not loaded or used when caching is disabled.

Use of the `gradle-actions-caching` component is subject to a separate license, available at https://gradle.com/legal/terms-of-use/. If you do not agree to these license terms, do not use the `gradle-actions-caching` component.

What's Changed

Full Changelog: gradle/actions@v5.0.2...v6.0.0

v5.0.2

Summary

This release contains no functional changes. It updates dependencies and known Gradle wrapper checksums.

What's Changed

... (truncated)

Commits
  • 3f5f9ad Document the new Gradle signing key for dependency verification (#1071)
  • b031f6d [bot] Update dist directory
  • 5bc4175 Bump dependency-graph-gradle-plugin to 1.5.0 (#1069)
  • f3ff59b Combined automated updates: wrapper checksums, npm dependencies, setup-java (...
  • 7927085 Update .tool-versions: node 24.18.0, gradle 9.7.1, java 17 (#1068)
  • c3897a4 [bot] Update dist directory
  • 6b92be1 Update dependencies (#1065)
  • 0d208da [bot] Update dist directory
  • e49d0a3 Report EOL and maintenance status for Gradle versions (#1057)
  • 575435b Use the root-qualified :wrapper task (#1064)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [gradle/actions](https://github.com/gradle/actions) from 4 to 6.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](gradle/actions@v4...v6)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Dependency security scan

Scanned 24 resolved dependencies, failing on HIGH and above.

No known vulnerabilities in 24 resolved dependencies.

Result: passed

Full run log

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Unit Test Results 🚀

611 tests  ±0   611 ✅ +1   2m 6s ⏱️ -1s
 54 suites ±0     0 💤 ±0 
 54 files   ±0     0 ❌  - 1 

Results for commit 0201bce. ± Comparison against base commit 02187b7.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Code coverage

module lines branches
sdk-java 90.4% (5092/5634) 81.1% (2122/2617)
sdk-java-ui 70.5% (968/1374) 63.2% (499/790)
Least covered classes (10 shown)
class module lines covered uncovered
ly.count.sdk.java.ui.JavaFxContentDisplay sdk-java-ui 10.6% (23/216) 193
ly.count.sdk.java.ui.FxSurfaces sdk-java-ui 74.8% (172/230) 58
ly.count.sdk.java.ui.ExternalBrowser sdk-java-ui 55.0% (66/120) 54
ly.count.sdk.java.ui.JavaFxWidgetHost sdk-java-ui 81.2% (190/234) 44
ly.count.sdk.java.internal.SDKCore sdk-java 87.9% (304/346) 42
ly.count.sdk.java.internal.ModuleContent sdk-java 86.8% (210/242) 32
ly.count.sdk.java.internal.TimedEvents sdk-java 60.8% (48/79) 31
ly.count.sdk.java.internal.SessionImpl sdk-java 89.4% (262/293) 31
ly.count.sdk.java.internal.SDKStorage sdk-java 84.3% (150/178) 28
ly.count.sdk.java.internal.ModuleFeedback sdk-java 86.7% (176/203) 27

Full run log

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants