Skip to content

chore(deps): update dependency @actions/tool-cache to v4#97

Open
renovate[bot] wants to merge 1 commit intotrunkfrom
renovate/actions-tool-cache-4.x
Open

chore(deps): update dependency @actions/tool-cache to v4#97
renovate[bot] wants to merge 1 commit intotrunkfrom
renovate/actions-tool-cache-4.x

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Feb 9, 2026

This PR contains the following updates:

Package Change Age Confidence
@actions/tool-cache (source) 2.0.24.0.0 age confidence

Release Notes

actions/toolkit (@​actions/tool-cache)

v4.0.0

  • Breaking change: Package is now ESM-only
    • CommonJS consumers must use dynamic import() instead of require()
3.0.1
  • Bump @actions/http-client to 3.0.2
3.0.0
  • Update to v2.0.1 of @actions/core
  • Update to v2.0.0 of @actions/exec
  • Update to v3.0.1 of @actions/http-client
  • Update to v2.0.0 of @actions/io
2.0.2
2.0.1
  • Update to v2.0.1 of @actions/http-client #​1087
2.0.0
  • Update to v2.0.0 of @actions/http-client
  • The type of the headers parameter in the exported function downloadTool has been narrowed from { [header: string]: any } to { [header: string]: number | string | string[] | undefined; } (that is, http.OutgoingHttpHeaders).
    This is strictly a compile-time change for TypeScript consumers. Previous attempts to use a header value of a type other than those now accepted would have resulted in an error at run time.
1.7.2
  • Update lockfileVersion to v2 in package-lock.json #​1025
1.7.1
1.7.0
1.6.1
1.6.0
1.3.5
1.3.4

Here is the security issue that was fixed in the http-client 1.0.8 release

1.3.3
1.3.2
1.3.1
1.3.0
1.2.0
1.1.2
1.0.0
  • Initial release

v3.0.1

  • Bump @actions/http-client to 3.0.2

v3.0.0

  • Update to v2.0.1 of @actions/core
  • Update to v2.0.0 of @actions/exec
  • Update to v3.0.1 of @actions/http-client
  • Update to v2.0.0 of @actions/io

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

@renovate renovate bot added the dependencies label Feb 9, 2026
@socket-security
Copy link

socket-security bot commented Feb 9, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​actions/​tool-cache@​2.0.2 ⏵ 4.0.099 +11009794 +5100

View full report

@renovate renovate bot force-pushed the renovate/actions-tool-cache-4.x branch from ef652a0 to e331d5f Compare February 10, 2026 23:26
@renovate renovate bot force-pushed the renovate/actions-tool-cache-4.x branch 4 times, most recently from 716c012 to bf18967 Compare February 20, 2026 05:53
@renovate renovate bot force-pushed the renovate/actions-tool-cache-4.x branch 2 times, most recently from 30c24fa to 61b13d4 Compare March 5, 2026 22:38
@renovate renovate bot force-pushed the renovate/actions-tool-cache-4.x branch from 61b13d4 to d558a48 Compare March 7, 2026 08:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

0 participants