Skip to content

BUILD-10765 Important: Update SonarSource/gh-action_release to 6.5.0#101

Merged
mikolaj-matuszny-ext-sonarsource merged 1 commit into
masterfrom
feat/BUILD-10765/update-gh-action_release
Apr 13, 2026
Merged

BUILD-10765 Important: Update SonarSource/gh-action_release to 6.5.0#101
mikolaj-matuszny-ext-sonarsource merged 1 commit into
masterfrom
feat/BUILD-10765/update-gh-action_release

Conversation

@mikolaj-matuszny-ext-sonarsource

Copy link
Copy Markdown
Contributor

Important: Update SonarSource/gh-action_release to c52861bb0e5dd564187f3fd74e048f20aef0f761 (6.5.0) for compliance with allowed versions.

See: https://discuss.sonarsource.com/t/action-required-update-your-github-actions-cache-release-and-releasability-before-10-04/23899/5

@mikolaj-matuszny-ext-sonarsource mikolaj-matuszny-ext-sonarsource requested a review from a team April 2, 2026 10:07
@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Apr 2, 2026

Copy link
Copy Markdown

BUILD-10765

@sonar-review-alpha

sonar-review-alpha Bot commented Apr 2, 2026

Copy link
Copy Markdown

Summary

Single-line update to .github/workflows/release.yml that upgrades the SonarSource/gh-action_release action from 6.4.0 to 6.5.0 (commit hash change). This is a compliance update per the SonarSource guidance requiring projects to use only approved versions of this action.

What reviewers should know

What to review:

  • Verify the commit hash c52861bb0e5dd564187f3fd74e048f20aef0f761 corresponds to the published 6.5.0 release of SonarSource/gh-action_release
  • Check if 6.5.0 introduces any breaking changes or new requirements (especially around the id-token and contents permissions already specified)
  • Confirm this is the specific version mandated by the SonarSource compliance requirement mentioned in the author's description

Non-obvious notes:

  • This is a required compliance update, not an optional feature upgrade
  • The change only affects release workflows, not CI/build pipelines
  • The permissions block is unchanged, which is good — verify that 6.5.0 doesn't require additional permissions

  • Generate Walkthrough
  • Generate Diagram

🗣️ Give feedback

@sonarqubecloud

sonarqubecloud Bot commented Apr 2, 2026

Copy link
Copy Markdown

@sonar-review-alpha sonar-review-alpha Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! ✅

Clean, minimal compliance update — safe to merge.

🗣️ Give feedback

@mikolaj-matuszny-ext-sonarsource mikolaj-matuszny-ext-sonarsource merged commit b4f2824 into master Apr 13, 2026
10 checks passed
@mikolaj-matuszny-ext-sonarsource mikolaj-matuszny-ext-sonarsource deleted the feat/BUILD-10765/update-gh-action_release branch April 13, 2026 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants