Skip to content

ci: bump GitHub Actions off the deprecated Node 20 runtime - #167

Open
fullstackjam wants to merge 1 commit into
mainfrom
ci/bump-actions
Open

fullstackjam wants to merge 1 commit into
mainfrom
ci/bump-actions

Conversation

@fullstackjam

Copy link
Copy Markdown
Member

What does this PR do?

Moves every GitHub Action in .github/workflows/ to its current major version. Each new version runs on Node 24.

Action From To
actions/checkout v4 v7
actions/setup-go v5 v7
actions/upload-artifact v4 v7
actions/download-artifact v4 v8
actions/github-script v7 v9
actions/labeler v5 v7
codecov/codecov-action v4 v7 (composite)
golangci/golangci-lint-action v7 v9
softprops/action-gh-release v2 v3

Why?

main CI currently emits this warning:

Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-go@v5, golangci/golangci-lint-action@v7.

Testing

I read each skipped major's breaking changes against how we use the action. None require workflow edits:

Breaking change Our usage
checkout v7 refuses fork-PR checkout under pull_request_target / workflow_run drift-to-issue (workflow_run) checks out the default ref. labeler (pull_request_target) does not check out code.
checkout v6 stores persisted creds under $RUNNER_TEMP The upstream README says git push needs no change. Affected steps: the auto-release tag push and the homebrew-tap push.
github-script v9: require('@actions/github') fails issue-greeting uses neither require nor getOctokit.
download-artifact v5: by-ID single-artifact path change. v8: digest mismatch now errors. release.yml downloads all artifacts by name. The by-ID change doesn't apply.
codecov v5 deprecates file We already pass files.
  • Every with: input we pass (25 of them) exists in the new version's action.yml
  • actionlint: clean
  • All new versions confirmed runs.using: node24 (codecov is composite)
  • Relevant tests added or updated: n/a, CI config only

Cross-repo checklist

  • Does this need a docs/content update in openboot.dev? No
  • Does this change the CLI ↔ server API contract? No

Notes for reviewer

This PR's CI can't verify these workflows, because they only run on their own triggers:

  • release.yml: upload/download artifacts, gh-release, and the homebrew-tap push
  • auto-release.yml: tag push
  • labeler.yml, issue-greeting.yml, drift-to-issue.yml, validate-catalog.yml
  • claude.yml

The first real release after merge is where to watch. A manual workflow_dispatch of release.yml would exercise it earlier, but it publishes a real release.

This PR is independent of #166 (the Go 1.26.8 bump).

main CI already warns that checkout@v4, setup-go@v5 and
golangci-lint-action@v7 target Node 20 and are being forced onto
Node 24. Move every action to its current major, all of which run on
node24 (codecov is a composite action):

  checkout v4->v7, setup-go v5->v7, upload-artifact v4->v7,
  download-artifact v4->v8, github-script v7->v9, labeler v5->v7,
  codecov-action v4->v7, golangci-lint-action v7->v9,
  action-gh-release v2->v3

Breaking changes reviewed against our usage, none require edits:
- checkout v7 refuses fork-PR checkout under pull_request_target /
  workflow_run: drift-to-issue checks out the default ref; labeler
  does not check out.
- checkout v6 moves persisted creds to $RUNNER_TEMP: the upstream
  README says git push needs no change (auto-release tag push,
  homebrew-tap push).
- github-script v9 breaks require('@actions/github'): issue-greeting
  does not use it.
- download-artifact v5 changes by-ID single downloads; v8 errors on
  digest mismatch: release.yml downloads all artifacts by name.
- codecov v5 deprecates `file`: we already use `files`.

Every `with:` input we pass exists in the new action.yml; actionlint
is clean.
@github-actions github-actions Bot added the ci CI/CD changes label Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI/CD changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant