Skip to content

chore(deps): Bump actions/setup-java from 5 to 5.6.0 - #127

Merged
bbaarriiss merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-java-5.6.0
Aug 11, 2026
Merged

chore(deps): Bump actions/setup-java from 5 to 5.6.0#127
bbaarriiss merged 1 commit into
mainfrom
dependabot/github_actions/actions/setup-java-5.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps actions/setup-java from 5 to 5.6.0.

Release notes

Sourced from actions/setup-java's releases.

v5.6.0

What's Changed

Full Changelog: actions/setup-java@v5...v5.6.0

v5.5.0

What's Changed

New Contributors

Full Changelog: actions/setup-java@v5...v5.5.0

v5.4.0

What's Changed

... (truncated)

Commits
  • c5f2f2e Bump github/codeql-action from 3 to 4 (#1069)
  • 623c707 chore: enforce pre-PR validation (aggregate scripts, git hooks, PR checklist)...
  • 1bcf9fb dist: Address Copilot review suggestions from PR #1042 (GraalVM Community) (#...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 5.6.0.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](actions/setup-java@v5...v5.6.0)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: 5.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 1, 2026 20:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Aug 1, 2026
steps:
- uses: actions/checkout@v7
- uses: actions/setup-java@v5
- uses: actions/setup-java@v5.6.0

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:

GitHub Actions step uses a mutable tag (v5.6.0) that can be repointed by the action owner to inject malicious code into your workflow. Pin to a full commit SHA instead to prevent supply-chain attacks.

More details about this

The actions/setup-java@v5.6.0 step uses a mutable version tag (v5.6.0) instead of pinning to a specific commit SHA. Even though this looks like a precise version, GitHub Actions tags can be moved or retagged by the action owner after you've written your workflow.

Here's how an attacker could exploit this:

  1. Compromise the action repository: An attacker gains control of the actions/setup-java repository (through account compromise, supply-chain attack, etc.)
  2. Retag the version: The attacker moves the v5.6.0 tag to point to their malicious commit
  3. Inject malicious code: Your workflow runs their compromised version of setup-java without any indication that something changed
  4. Exfiltrate secrets or modify build artifacts: The malicious setup-java step now has access to your workflow's environment variables, secrets, and can modify what gets built or published

This exact scenario happened with real GitHub Actions: the trivy-action and kics-github-action were compromised when maintainers' accounts were taken over, and mutable tag references meant workflows silently pulled compromised versions without any notification.

Pinning to a full 40-character commit SHA (like actions/setup-java@8ade135a41bc03ea155e62e844d188df1ea18608) prevents the tag from being moved and ensures your workflow always uses the exact code you verified.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
- uses: actions/setup-java@v5.6.0
# TODO: Replace the placeholder SHA below with the official 40-character commit SHA for actions/setup-java v5.6.0
# from the upstream release/tag page before merging. GitHub Actions should be pinned to a full commit SHA.
- uses: actions/setup-java@<40-character-commit-sha-for-v5.6.0>
with:
distribution: 'zulu'
java-version: '21'
View step-by-step instructions
  1. Replace the mutable action reference with a full 40-character commit SHA for the same actions/setup-java release.
    Change uses: actions/setup-java@v5.6.0 to uses: actions/setup-java@<40-character-commit-sha-for-v5.6.0>.

  2. Keep the rest of the step unchanged, including the with: block for distribution and java-version.
    Pinning to a commit SHA prevents the action owner from silently changing what runs for that reference.

  3. Verify the SHA from the official actions/setup-java repository release or tag page before updating the workflow, so the pinned commit matches the version you intended to use.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by github-actions-mutable-action-tag.

You can view more details about this finding in the Semgrep AppSec Platform.

@bbaarriiss
bbaarriiss merged commit 8184f9e into main Aug 11, 2026
7 checks passed
@bbaarriiss
bbaarriiss deleted the dependabot/github_actions/actions/setup-java-5.6.0 branch August 11, 2026 06:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant