Files
PaperClipAI/.github/workflows
dependabot[bot] da679f113a build(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 (#12964)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The repository runs a weekly full-stack end-to-end campaign for the
runner, and that workflow publishes its merged dashboard to GitHub Pages
> - The publish step pins `actions/upload-pages-artifact` to a version 4
commit
> - Version 4 of that action embeds `actions/upload-artifact` at
`v4.6.2`, so the publish step keeps an old upload path
> - An old pinned action falls behind upstream fixes, and the gap grows
with each upstream release
> - This pull request moves the pin to the commit that upstream tags as
`v5.0.0`
> - The benefit is that the Pages publish step uses the current upload
path, and the pin stays a commit SHA

## Linked Issues or Issue Description

No public issue exists for this change. Refs #12963 and Refs #12962 —
two other pinned GitHub Action updates for the same repository. They are
related, and they are not duplicates. The description below follows the
enhancement template.

**What existing behavior does this improve?**

The weekly runner end-to-end workflow publishes its merged dashboard to
GitHub Pages. This change updates the action that packages that
dashboard.

**Subsystem affected**

CI and release automation —
`.github/workflows/runner-full-stack-e2e.yml`.

**Current behavior**

The publish step uses `actions/upload-pages-artifact` at the commit that
upstream tags as version 4. That version embeds
`actions/upload-artifact` at `v4.6.2`.

**Proposed behavior**

The publish step uses `actions/upload-pages-artifact` at commit
`fc324d3547104276b827a68afc52ff2a11cc49c9`, which upstream tags as
`v5.0.0`. That version embeds `actions/upload-artifact` at `v7.0.0`.

**Breaking changes**

None for this repository. Version 5 keeps the `name`, `path` and
`retention-days` inputs with the same defaults. Version 5 adds one
optional input, `include-hidden-files`, which defaults to `false`. The
step in this workflow passes `name` and `path` only. With the default
value of the new input, version 5 excludes hidden files, and that
matches version 4.

## What Changed

- Change the pinned commit of `actions/upload-pages-artifact` in
`.github/workflows/runner-full-stack-e2e.yml` from the version 4 commit
to `fc324d3547104276b827a68afc52ff2a11cc49c9`, which upstream tags as
`v5.0.0`.

## Verification

- The pinned commit matches the upstream tag. `gh api
repos/actions/upload-pages-artifact/git/ref/tags/v5.0.0 --jq
.object.sha` returns `fc324d3547104276b827a68afc52ff2a11cc49c9`.
- The input contract stays compatible. A comparison of `action.yml` at
the old pin and at the new pin shows the same `name`, `path` and
`retention-days` inputs with the same defaults, plus one new optional
input.
- The repository CI suite passes on this branch after a rebase onto the
current base branch.
- One limit applies. The changed step runs only in the `Runner
Full-Stack E2E` workflow. That workflow starts on a weekly schedule and
on a manual dispatch, so no pull-request run exercises the step. A
maintainer can exercise it with a manual dispatch of that workflow, or
the next scheduled run exercises it.

## Risks

- Low risk, with one limit. The changed step does not run on a pull
request, so the pull-request checks do not prove the new action version
in this workflow.
- Version 5 of the outer action embeds a newer `actions/upload-artifact`
version. A behaviour change in that inner action appears first in the
weekly campaign, and not in the pull-request checks.
- The rollback is one commit. Restore the previous pinned commit of
`actions/upload-pages-artifact`.

## Model Used

Dependabot generated this dependency update automatically, so no AI
model produced the code change. A maintainer wrote this description with
Claude Opus 5 (Anthropic, model id `claude-opus-5`, extended thinking,
tool use).

## Checklist

Three boxes stay unticked on purpose. This change pins one GitHub Action
version in one workflow file. No local test covers a pinned action
version, no new test applies, and no document refers to this pin.

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [ ] I have run tests locally and they pass
- [ ] I have added or updated tests where applicable
- [ ] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-10-06 13:53:05 -07:00
..