This is an automated email from the ASF dual-hosted git repository.

curth pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-dotnet.git


The following commit(s) were added to refs/heads/main by this push:
     new 3d5daa0  chore: Bump actions/cache from 5.0.2 to 5.0.3 (#252)
3d5daa0 is described below

commit 3d5daa06da147b2cf925f3ee5fb6584ae69ee2c7
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Mon Feb 2 07:11:58 2026 -0800

    chore: Bump actions/cache from 5.0.2 to 5.0.3 (#252)
    
    Bumps [actions/cache](https://github.com/actions/cache) from 5.0.2 to
    5.0.3.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/cache/releases";>actions/cache's
    releases</a>.</em></p>
    <blockquote>
    <h2>v5.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
    
href="https://github.com/actions/cache/security/dependabot/33";>https://github.com/actions/cache/security/dependabot/33</a>)</li>
    <li>Bump <code>@actions/core</code> to v2.0.3</li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    
href="https://github.com/actions/cache/compare/v5...v5.0.3";>https://github.com/actions/cache/compare/v5...v5.0.3</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    
href="https://github.com/actions/cache/blob/main/RELEASES.md";>actions/cache's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Releases</h1>
    <h2>How to prepare a release</h2>
    <blockquote>
    <p>[!NOTE]<br />
    Relevant for maintainers with write access only.</p>
    </blockquote>
    <ol>
    <li>Switch to a new branch from <code>main</code>.</li>
    <li>Run <code>npm test</code> to ensure all tests are passing.</li>
    <li>Update the version in <a
    
href="https://github.com/actions/cache/blob/main/package.json";><code>https://github.com/actions/cache/blob/main/package.json</code></a>.</li>
    <li>Run <code>npm run build</code> to update the compiled files.</li>
    <li>Update this <a
    
href="https://github.com/actions/cache/blob/main/RELEASES.md";><code>https://github.com/actions/cache/blob/main/RELEASES.md</code></a>
    with the new version and changes in the <code>## Changelog</code>
    section.</li>
    <li>Run <code>licensed cache</code> to update the license report.</li>
    <li>Run <code>licensed status</code> and resolve any warnings by
    updating the <a
    
href="https://github.com/actions/cache/blob/main/.licensed.yml";><code>https://github.com/actions/cache/blob/main/.licensed.yml</code></a>
    file with the exceptions.</li>
    <li>Commit your changes and push your branch upstream.</li>
    <li>Open a pull request against <code>main</code> and get it reviewed
    and merged.</li>
    <li>Draft a new release <a
    
href="https://github.com/actions/cache/releases";>https://github.com/actions/cache/releases</a>
    use the same version number used in <code>package.json</code>
    <ol>
    <li>Create a new tag with the version number.</li>
    <li>Auto generate release notes and update them to match the changes you
    made in <code>RELEASES.md</code>.</li>
    <li>Toggle the set as the latest release option.</li>
    <li>Publish the release.</li>
    </ol>
    </li>
    <li>Navigate to <a
    
href="https://github.com/actions/cache/actions/workflows/release-new-action-version.yml";>https://github.com/actions/cache/actions/workflows/release-new-action-version.yml</a>
    <ol>
    <li>There should be a workflow run queued with the same version
    number.</li>
    <li>Approve the run to publish the new version and update the major tags
    for this action.</li>
    </ol>
    </li>
    </ol>
    <h2>Changelog</h2>
    <h3>5.0.3</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.5 (Resolves: <a
    
href="https://github.com/actions/cache/security/dependabot/33";>https://github.com/actions/cache/security/dependabot/33</a>)</li>
    <li>Bump <code>@actions/core</code> to v2.0.3</li>
    </ul>
    <h3>5.0.2</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to v5.0.3 <a
    href="https://redirect.github.com/actions/cache/pull/1692";>#1692</a></li>
    </ul>
    <h3>5.0.1</h3>
    <ul>
    <li>Update <code>@azure/storage-blob</code> to <code>^12.29.1</code> via
    <code>@actions/[email protected]</code> <a
    href="https://redirect.github.com/actions/cache/pull/1685";>#1685</a></li>
    </ul>
    <h3>5.0.0</h3>
    <blockquote>
    <p>[!IMPORTANT]
    <code>actions/cache@v5</code> runs on the Node.js 24 runtime and
    requires a minimum Actions Runner version of <code>2.327.1</code>.
    If you are using self-hosted runners, ensure they are updated before
    upgrading.</p>
    </blockquote>
    <h3>4.3.0</h3>
    <ul>
    <li>Bump <code>@actions/cache</code> to <a
    href="https://redirect.github.com/actions/toolkit/pull/2132";>v4.1.0</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/actions/cache/commit/cdf6c1fa76f9f475f3d7449005a359c84ca0f306";><code>cdf6c1f</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/cache/issues/1695";>#1695</a>
    from actions/Link-/prepare-5.0.3</li>
    <li><a
    
href="https://github.com/actions/cache/commit/a1bee22673bee4afb9ce4e0a1dc3da1c44060b7d";><code>a1bee22</code></a>
    Add review for the <code>@​actions/http-client</code> license</li>
    <li><a
    
href="https://github.com/actions/cache/commit/46957638dc5c5ff0c34c0143f443c07d3a7c769f";><code>4695763</code></a>
    Add licensed output</li>
    <li><a
    
href="https://github.com/actions/cache/commit/dc73bb9f7bf74a733c05ccd2edfd1f2ac9e5f502";><code>dc73bb9</code></a>
    Upgrade dependencies and address security warnings</li>
    <li><a
    
href="https://github.com/actions/cache/commit/345d5c2f761565bace4b6da356737147e9041e3a";><code>345d5c2</code></a>
    Add 5.0.3 builds</li>
    <li>See full diff in <a
    
href="https://github.com/actions/cache/compare/8b402f58fbc84540c8b491a91e594a4576fec3d7...cdf6c1fa76f9f475f3d7449005a359c84ca0f306";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/cache&package-manager=github_actions&previous-version=5.0.2&new-version=5.0.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot merge` will merge this PR after your CI passes on it
    - `@dependabot squash and merge` will squash and merge this PR after
    your CI passes on it
    - `@dependabot cancel merge` will cancel a previously requested merge
    and block automerging
    - `@dependabot reopen` will reopen this PR if it is closed
    - `@dependabot close` will close this PR and stop Dependabot recreating
    it. You can achieve the same result by closing it manually
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .github/workflows/test.yaml | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/.github/workflows/test.yaml b/.github/workflows/test.yaml
index 149e8ee..6921588 100644
--- a/.github/workflows/test.yaml
+++ b/.github/workflows/test.yaml
@@ -45,7 +45,7 @@ jobs:
         run: |
           python -m pip install pre-commit
       - name: Cache pre-commit
-        uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2
+        uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
         with:
           path: ~/.cache/pre-commit
           key: pre-commit-${{ hashFiles('.pre-commit-config.yaml') }}
@@ -128,7 +128,7 @@ jobs:
         run: |
           ci/scripts/util_free_space.sh
       - name: Cache Docker Volumes
-        uses: actions/cache@8b402f58fbc84540c8b491a91e594a4576fec3d7 # v5.0.2
+        uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3
         with:
           path: .docker
           key: integration-conda-${{ hashFiles('cpp/**') }}

Reply via email to