Fix Node.js version in action.yml - #691
Merged
Merged
Conversation
It looks like the Node.js version specified in action.yml was left behind when we upgraded the project to Node.js 24. This commit updates action.yml to reflect the correct Node.js version.
There was a problem hiding this comment.
Pull request overview
This PR fixes an oversight where the action.yml file was not updated during the project-wide upgrade to Node.js 24. The change aligns the GitHub Action runtime specification with the rest of the codebase, which already uses Node.js 24 throughout.
Key Changes
- Updated the
usingfield inaction.ymlfrom'node20'to'node24'to match the project's Node.js 24 upgrade
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
v-priyagupta108
approved these changes
Dec 10, 2025
v-aparnajyothi-y
approved these changes
Dec 11, 2025
v-HarithaVattikuti
approved these changes
Jan 7, 2026
7 of 16 tasks
This was referenced Mar 11, 2026
hoodnoah
added a commit
to hoodnoah/certmanager-porkbun-webhook
that referenced
this pull request
Jun 10, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://github.com/actions/setup-go) | action | major | `v5` → `v6` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v6.4.0`](https://github.com/actions/setup-go/releases/tag/v6.4.0) [Compare Source](actions/setup-go@v6.3.0...v6.4.0) ##### What's Changed ##### Enhancement - Add go-download-base-url input for custom Go distributions by [@​gdams](https://github.com/gdams) in [#​721](actions/setup-go#721) ##### Dependency update - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​727](actions/setup-go#727) ##### Documentation update - Rearrange README.md, add advanced-usage.md by [@​priyagupta108](https://github.com/priyagupta108) in [#​724](actions/setup-go#724) - Fix Microsoft build of Go link by [@​gdams](https://github.com/gdams) in [#​734](actions/setup-go#734) ##### New Contributors - [@​gdams](https://github.com/gdams) made their first contribution in [#​721](actions/setup-go#721) **Full Changelog**: <actions/setup-go@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-go/releases/tag/v6.3.0) [Compare Source](actions/setup-go@v6.2.0...v6.3.0) ##### What's Changed - Update default Go module caching to use go.mod by [@​priyagupta108](https://github.com/priyagupta108) in [#​705](actions/setup-go#705) - Fix golang download url to go.dev by [@​178inaba](https://github.com/178inaba) in [#​469](actions/setup-go#469) **Full Changelog**: <actions/setup-go@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-go/releases/tag/v6.2.0) [Compare Source](actions/setup-go@v6.1.0...v6.2.0) ##### What's Changed ##### Enhancements - Example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​696](actions/setup-go#696) - Update Node.js version in action.yml by [@​ccoVeille](https://github.com/ccoVeille) in [#​691](actions/setup-go#691) - Documentation update of actions/checkout by [@​deining](https://github.com/deining) in [#​683](actions/setup-go#683) ##### Dependency updates - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot) in [#​682](actions/setup-go#682) - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5 by [@​salmanmkc](https://github.com/salmanmkc) in [#​695](actions/setup-go#695) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot) in [#​686](actions/setup-go#686) - Upgrade qs from 6.14.0 to 6.14.1 by [@​dependabot](https://github.com/dependabot) in [#​703](actions/setup-go#703) ##### New Contributors - [@​ccoVeille](https://github.com/ccoVeille) made their first contribution in [#​691](actions/setup-go#691) - [@​deining](https://github.com/deining) made their first contribution in [#​683](actions/setup-go#683) **Full Changelog**: <actions/setup-go@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-go/releases/tag/v6.1.0) [Compare Source](actions/setup-go@v6...v6.1.0) ##### What's Changed ##### Enhancements - Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by [@​nicholasngai](https://github.com/nicholasngai) in [#​665](actions/setup-go#665) - Add support for .tool-versions file and update workflow by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​673](actions/setup-go#673) - Add comprehensive breaking changes documentation for v6 by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​674](actions/setup-go#674) ##### Dependency updates - Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by [@​dependabot](https://github.com/dependabot) in [#​617](actions/setup-go#617) - Upgrade actions/publish-action from 0.3.0 to 0.4.0 by [@​dependabot](https://github.com/dependabot) in [#​641](actions/setup-go#641) - Upgrade semver and [@​types/semver](https://github.com/types/semver) by [@​dependabot](https://github.com/dependabot) in [#​652](actions/setup-go#652) ##### New Contributors - [@​nicholasngai](https://github.com/nicholasngai) made their first contribution in [#​665](actions/setup-go#665) - [@​priya-kinthali](https://github.com/priya-kinthali) made their first contribution in [#​673](actions/setup-go#673) - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​674](actions/setup-go#674) **Full Changelog**: <actions/setup-go@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/setup-go/releases/tag/v6.0.0) [Compare Source](actions/setup-go@v6...v6) ##### What's Changed ##### Breaking Changes - Improve toolchain handling to ensure more reliable and consistent toolchain selection and management by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​460](actions/setup-go#460) - Upgrade Nodejs runtime from node20 to node 24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​624](actions/setup-go#624) Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. [See Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1) ##### Dependency Upgrades - Upgrade [@​types/jest](https://github.com/types/jest) from 29.5.12 to 29.5.14 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​589](actions/setup-go#589) - Upgrade [@​actions/tool-cache](https://github.com/actions/tool-cache) from 2.0.1 to 2.0.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​591](actions/setup-go#591) - Upgrade [@​typescript-eslint/parser](https://github.com/typescript-eslint/parser) from 8.31.1 to 8.35.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​590](actions/setup-go#590) - Upgrade undici from 5.28.5 to 5.29.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​594](actions/setup-go#594) - Upgrade typescript from 5.4.2 to 5.8.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​538](actions/setup-go#538) - Upgrade eslint-plugin-jest from 28.11.0 to 29.0.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​603](actions/setup-go#603) - Upgrade `form-data` to bring in fix for critical vulnerability by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​618](actions/setup-go#618) - Upgrade actions/checkout from 4 to 5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​631](actions/setup-go#631) ##### New Contributors - [@​matthewhughes934](https://github.com/matthewhughes934) made their first contribution in [#​618](actions/setup-go#618) - [@​salmanmkc](https://github.com/salmanmkc) made their first contribution in [#​624](actions/setup-go#624) **Full Changelog**: <actions/setup-go@v5...v6.0.0> ### [`v6`](actions/setup-go@v5.6.0...v6) [Compare Source](actions/setup-go@v5.6.0...v6) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMTcuMSIsInVwZGF0ZWRJblZlciI6IjQzLjIxNy4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: hoodn <hood.noah@gmail.com> Reviewed-on: https://gitea.k3s.noah-hood.io/hoodn/certmanager-porkbun-webhook/pulls/7 Co-authored-by: renovate-bot <renovate-bot@example.local> Co-committed-by: renovate-bot <renovate-bot@example.local>
mergify Bot
added a commit
to ArcadeData/arcadedb
that referenced
this pull request
Jul 5, 2026
Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.5.0 to 6.5.0. Release notes *Sourced from [actions/setup-go's releases](https://github.com/actions/setup-go/releases).* > v6.5.0 > ------ > > What's Changed > -------------- > > ### Dependency update > > * Upgrade actions dependencies by [`@priyagupta108`](https://github.com/priyagupta108) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-go#744](https://redirect.github.com/actions/setup-go/pull/744) > * Upgrade `@types/node` and typescript-eslint dependencies to resolve npm audit findings by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-go#755](https://redirect.github.com/actions/setup-go/pull/755) > * Upgrade `@actions/cache` to 5.1.0, log cache write denied by [`@jasongin`](https://github.com/jasongin) in [actions/setup-go#758](https://redirect.github.com/actions/setup-go/pull/758) > * Upgrade version to 6.5.0 in package.json and package-lock.json by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-go#762](https://redirect.github.com/actions/setup-go/pull/762) > > New Contributors > ---------------- > > * [`@priyagupta108`](https://github.com/priyagupta108) with [`@Copilot`](https://github.com/Copilot) made their first contribution in [actions/setup-go#744](https://redirect.github.com/actions/setup-go/pull/744) > * [`@jasongin`](https://github.com/jasongin) made their first contribution in [actions/setup-go#758](https://redirect.github.com/actions/setup-go/pull/758) > > **Full Changelog**: <actions/setup-go@v6...v6.5.0> > > v6.4.0 > ------ > > What's Changed > -------------- > > ### Enhancement > > * Add go-download-base-url input for custom Go distributions by [`@gdams`](https://github.com/gdams) in [actions/setup-go#721](https://redirect.github.com/actions/setup-go/pull/721) > > ### Dependency update > > * Upgrade minimatch from 3.1.2 to 3.1.5 by [`@dependabot`](https://github.com/dependabot) in [actions/setup-go#727](https://redirect.github.com/actions/setup-go/pull/727) > > ### Documentation update > > * Rearrange README.md, add advanced-usage.md by [`@priyagupta108`](https://github.com/priyagupta108) in [actions/setup-go#724](https://redirect.github.com/actions/setup-go/pull/724) > * Fix Microsoft build of Go link by [`@gdams`](https://github.com/gdams) in [actions/setup-go#734](https://redirect.github.com/actions/setup-go/pull/734) > > New Contributors > ---------------- > > * [`@gdams`](https://github.com/gdams) made their first contribution in [actions/setup-go#721](https://redirect.github.com/actions/setup-go/pull/721) > > **Full Changelog**: <actions/setup-go@v6...v6.4.0> > > v6.3.0 > ------ > > What's Changed > -------------- > > * Update default Go module caching to use go.mod by [`@priyagupta108`](https://github.com/priyagupta108) in [actions/setup-go#705](https://redirect.github.com/actions/setup-go/pull/705) > * Fix golang download url to go.dev by [`@178inaba`](https://github.com/178inaba) in [actions/setup-go#469](https://redirect.github.com/actions/setup-go/pull/469) > > **Full Changelog**: <actions/setup-go@v6...v6.3.0> > > v6.2.0 > ------ > > What's Changed > -------------- > > ### Enhancements > > * Example for restore-only cache in documentation by [`@aparnajyothi-y`](https://github.com/aparnajyothi-y) in [actions/setup-go#696](https://redirect.github.com/actions/setup-go/pull/696) > * Update Node.js version in action.yml by [`@ccoVeille`](https://github.com/ccoVeille) in [actions/setup-go#691](https://redirect.github.com/actions/setup-go/pull/691) > * Documentation update of actions/checkout by [`@deining`](https://github.com/deining) in [actions/setup-go#683](https://redirect.github.com/actions/setup-go/pull/683) > > ### Dependency updates > > * Upgrade js-yaml from 3.14.1 to 3.14.2 by [`@dependabot`](https://github.com/dependabot) in [actions/setup-go#682](https://redirect.github.com/actions/setup-go/pull/682) > * Upgrade `@actions/cache` to v5 by [`@salmanmkc`](https://github.com/salmanmkc) in [actions/setup-go#695](https://redirect.github.com/actions/setup-go/pull/695) > * Upgrade actions/checkout from 5 to 6 by [`@dependabot`](https://github.com/dependabot) in [actions/setup-go#686](https://redirect.github.com/actions/setup-go/pull/686) > * Upgrade qs from 6.14.0 to 6.14.1 by [`@dependabot`](https://github.com/dependabot) in [actions/setup-go#703](https://redirect.github.com/actions/setup-go/pull/703) ... (truncated) Commits * [`924ae3a`](actions/setup-go@924ae3a) chore: bump version to 6.5.0 in package.json and package-lock.json ([#762](https://redirect.github.com/actions/setup-go/issues/762)) * [`e91cc3b`](actions/setup-go@e91cc3b) Bump `@actions/cache` to 5.1.0, log cache write denied ([#758](https://redirect.github.com/actions/setup-go/issues/758)) * [`4a2405e`](actions/setup-go@4a2405e) chore: update `@types/node` and [`@typescript-eslint`](https://github.com/typescript-eslint) dependencies to latest versi... * [`78961f6`](actions/setup-go@78961f6) chore: update [`@actions`](https://github.com/actions) dependencies and refresh license cache ([#744](https://redirect.github.com/actions/setup-go/issues/744)) * [`4a36011`](actions/setup-go@4a36011) docs: fix Microsoft build of Go link ([#734](https://redirect.github.com/actions/setup-go/issues/734)) * [`8f19afc`](actions/setup-go@8f19afc) feat: add go-download-base-url input for custom Go distributions ([#721](https://redirect.github.com/actions/setup-go/issues/721)) * [`27fdb26`](actions/setup-go@27fdb26) Bump minimatch from 3.1.2 to 3.1.5 ([#727](https://redirect.github.com/actions/setup-go/issues/727)) * [`def8c39`](actions/setup-go@def8c39) Rearrange README.md, add advanced-usage.md ([#724](https://redirect.github.com/actions/setup-go/issues/724)) * [`4b73464`](actions/setup-go@4b73464) Fix golang download url to go.dev ([#469](https://redirect.github.com/actions/setup-go/issues/469)) * [`a5f9b05`](actions/setup-go@a5f9b05) Update default Go module caching to use go.mod ([#705](https://redirect.github.com/actions/setup-go/issues/705)) * Additional commits viewable in [compare view](actions/setup-go@d35c59a...924ae3a) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
wu
pushed a commit
to wu/keyop-messenger
that referenced
this pull request
Jul 18, 2026
This PR contains the following updates: | Package | Type | Update | Change | Pending | |---|---|---|---|---| | [actions/setup-go](https://github.com/actions/setup-go) | action | major | `v5` → `v6` | `v7.0.0` (+1) | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v6.5.0`](https://github.com/actions/setup-go/releases/tag/v6.5.0) [Compare Source](actions/setup-go@v6.4.0...v6.5.0) #### What's Changed ##### Dependency update - Upgrade actions dependencies by [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) in [#​744](actions/setup-go#744) - Upgrade [@​types/node](https://github.com/types/node) and typescript-eslint dependencies to resolve npm audit findings by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​755](actions/setup-go#755) - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​758](actions/setup-go#758) - Upgrade version to 6.5.0 in package.json and package-lock.json by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​762](actions/setup-go#762) #### New Contributors - [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) made their first contribution in [#​744](actions/setup-go#744) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​758](actions/setup-go#758) **Full Changelog**: <actions/setup-go@v6...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-go/releases/tag/v6.4.0) [Compare Source](actions/setup-go@v6.3.0...v6.4.0) #### What's Changed ##### Enhancement - Add go-download-base-url input for custom Go distributions by [@​gdams](https://github.com/gdams) in [#​721](actions/setup-go#721) ##### Dependency update - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​727](actions/setup-go#727) ##### Documentation update - Rearrange README.md, add advanced-usage.md by [@​priyagupta108](https://github.com/priyagupta108) in [#​724](actions/setup-go#724) - Fix Microsoft build of Go link by [@​gdams](https://github.com/gdams) in [#​734](actions/setup-go#734) #### New Contributors - [@​gdams](https://github.com/gdams) made their first contribution in [#​721](actions/setup-go#721) **Full Changelog**: <actions/setup-go@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-go/releases/tag/v6.3.0) [Compare Source](actions/setup-go@v6.2.0...v6.3.0) #### What's Changed - Update default Go module caching to use go.mod by [@​priyagupta108](https://github.com/priyagupta108) in [#​705](actions/setup-go#705) - Fix golang download url to go.dev by [@​178inaba](https://github.com/178inaba) in [#​469](actions/setup-go#469) **Full Changelog**: <actions/setup-go@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-go/releases/tag/v6.2.0) [Compare Source](actions/setup-go@v6.1.0...v6.2.0) #### What's Changed ##### Enhancements - Example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​696](actions/setup-go#696) - Update Node.js version in action.yml by [@​ccoVeille](https://github.com/ccoVeille) in [#​691](actions/setup-go#691) - Documentation update of actions/checkout by [@​deining](https://github.com/deining) in [#​683](actions/setup-go#683) ##### Dependency updates - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot) in [#​682](actions/setup-go#682) - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5 by [@​salmanmkc](https://github.com/salmanmkc) in [#​695](actions/setup-go#695) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot) in [#​686](actions/setup-go#686) - Upgrade qs from 6.14.0 to 6.14.1 by [@​dependabot](https://github.com/dependabot) in [#​703](actions/setup-go#703) #### New Contributors - [@​ccoVeille](https://github.com/ccoVeille) made their first contribution in [#​691](actions/setup-go#691) - [@​deining](https://github.com/deining) made their first contribution in [#​683](actions/setup-go#683) **Full Changelog**: <actions/setup-go@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-go/releases/tag/v6.1.0) [Compare Source](actions/setup-go@v6...v6.1.0) #### What's Changed ##### Enhancements - Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by [@​nicholasngai](https://github.com/nicholasngai) in [#​665](actions/setup-go#665) - Add support for .tool-versions file and update workflow by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​673](actions/setup-go#673) - Add comprehensive breaking changes documentation for v6 by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​674](actions/setup-go#674) ##### Dependency updates - Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by [@​dependabot](https://github.com/dependabot) in [#​617](actions/setup-go#617) - Upgrade actions/publish-action from 0.3.0 to 0.4.0 by [@​dependabot](https://github.com/dependabot) in [#​641](actions/setup-go#641) - Upgrade semver and [@​types/semver](https://github.com/types/semver) by [@​dependabot](https://github.com/dependabot) in [#​652](actions/setup-go#652) #### New Contributors - [@​nicholasngai](https://github.com/nicholasngai) made their first contribution in [#​665](actions/setup-go#665) - [@​priya-kinthali](https://github.com/priya-kinthali) made their first contribution in [#​673](actions/setup-go#673) - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​674](actions/setup-go#674) **Full Changelog**: <actions/setup-go@v6...v6.1.0> ### [`v6.0.0`](https://github.com/actions/setup-go/releases/tag/v6.0.0) [Compare Source](actions/setup-go@v6...v6) #### What's Changed ##### Breaking Changes - Improve toolchain handling to ensure more reliable and consistent toolchain selection and management by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​460](actions/setup-go#460) - Upgrade Nodejs runtime from node20 to node 24 by [@​salmanmkc](https://github.com/salmanmkc) in [#​624](actions/setup-go#624) Make sure your runner is on version v2.327.1 or later to ensure compatibility with this release. [See Release Notes](https://github.com/actions/runner/releases/tag/v2.327.1) ##### Dependency Upgrades - Upgrade [@​types/jest](https://github.com/types/jest) from 29.5.12 to 29.5.14 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​589](actions/setup-go#589) - Upgrade [@​actions/tool-cache](https://github.com/actions/tool-cache) from 2.0.1 to 2.0.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​591](actions/setup-go#591) - Upgrade [@​typescript-eslint/parser](https://github.com/typescript-eslint/parser) from 8.31.1 to 8.35.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​590](actions/setup-go#590) - Upgrade undici from 5.28.5 to 5.29.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​594](actions/setup-go#594) - Upgrade typescript from 5.4.2 to 5.8.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​538](actions/setup-go#538) - Upgrade eslint-plugin-jest from 28.11.0 to 29.0.1 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​603](actions/setup-go#603) - Upgrade `form-data` to bring in fix for critical vulnerability by [@​matthewhughes934](https://github.com/matthewhughes934) in [#​618](actions/setup-go#618) - Upgrade actions/checkout from 4 to 5 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​631](actions/setup-go#631) #### New Contributors - [@​matthewhughes934](https://github.com/matthewhughes934) made their first contribution in [#​618](actions/setup-go#618) - [@​salmanmkc](https://github.com/salmanmkc) made their first contribution in [#​624](actions/setup-go#624) **Full Changelog**: <actions/setup-go@v5...v6.0.0> ### [`v6`](actions/setup-go@v5.6.0...v6) [Compare Source](actions/setup-go@v5.6.0...v6) </details> --- ### Configuration 📅 **Schedule**: (in timezone America/Los_Angeles) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI3MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Co-authored-by: Renovate Bot <renovate-bot@geekfarm.org> Reviewed-on: https://git.geekfarm.org/wu/keyop-messenger/pulls/10
GiteaBot
pushed a commit
to go-gitea/terraform-provider-gitea
that referenced
this pull request
Jul 23, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://github.com/actions/setup-go) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v7.0.0`](https://github.com/actions/setup-go/releases/tag/v7.0.0) [Compare Source](actions/setup-go@v7.0.0...v7.0.0) ##### What's Changed - Migrate to ESM and upgrade dependencies by [@​priyagupta108](https://github.com/priyagupta108) in [#​763](actions/setup-go#763) - chore(deps): bump [@​actions/cache](https://github.com/actions/cache) to 6.2.0 by [@​philip-gai](https://github.com/philip-gai) in [#​771](actions/setup-go#771) ##### New Contributors - [@​philip-gai](https://github.com/philip-gai) made their first contribution in [#​771](actions/setup-go#771) **Full Changelog**: <actions/setup-go@v6...v7.0.0> ### [`v7`](actions/setup-go@v6.5.0...v7.0.0) [Compare Source](actions/setup-go@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-go/releases/tag/v6.5.0) [Compare Source](actions/setup-go@v6.4.0...v6.5.0) #### What's Changed ##### Dependency update - Upgrade actions dependencies by [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) in [#​744](actions/setup-go#744) - Upgrade [@​types/node](https://github.com/types/node) and typescript-eslint dependencies to resolve npm audit findings by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​755](actions/setup-go#755) - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​758](actions/setup-go#758) - Upgrade version to 6.5.0 in package.json and package-lock.json by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​762](actions/setup-go#762) #### New Contributors - [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) made their first contribution in [#​744](actions/setup-go#744) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​758](actions/setup-go#758) **Full Changelog**: <actions/setup-go@v6...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-go/releases/tag/v6.4.0) [Compare Source](actions/setup-go@v6.3.0...v6.4.0) ##### What's Changed ##### Enhancement - Add go-download-base-url input for custom Go distributions by [@​gdams](https://github.com/gdams) in [#​721](actions/setup-go#721) ##### Dependency update - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​727](actions/setup-go#727) ##### Documentation update - Rearrange README.md, add advanced-usage.md by [@​priyagupta108](https://github.com/priyagupta108) in [#​724](actions/setup-go#724) - Fix Microsoft build of Go link by [@​gdams](https://github.com/gdams) in [#​734](actions/setup-go#734) ##### New Contributors - [@​gdams](https://github.com/gdams) made their first contribution in [#​721](actions/setup-go#721) **Full Changelog**: <actions/setup-go@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-go/releases/tag/v6.3.0) [Compare Source](actions/setup-go@v6.2.0...v6.3.0) ##### What's Changed - Update default Go module caching to use go.mod by [@​priyagupta108](https://github.com/priyagupta108) in [#​705](actions/setup-go#705) - Fix golang download url to go.dev by [@​178inaba](https://github.com/178inaba) in [#​469](actions/setup-go#469) **Full Changelog**: <actions/setup-go@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-go/releases/tag/v6.2.0) [Compare Source](actions/setup-go@v6.1.0...v6.2.0) ##### What's Changed ##### Enhancements - Example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​696](actions/setup-go#696) - Update Node.js version in action.yml by [@​ccoVeille](https://github.com/ccoVeille) in [#​691](actions/setup-go#691) - Documentation update of actions/checkout by [@​deining](https://github.com/deining) in [#​683](actions/setup-go#683) ##### Dependency updates - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot) in [#​682](actions/setup-go#682) - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5 by [@​salmanmkc](https://github.com/salmanmkc) in [#​695](actions/setup-go#695) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot) in [#​686](actions/setup-go#686) - Upgrade qs from 6.14.0 to 6.14.1 by [@​dependabot](https://github.com/dependabot) in [#​703](actions/setup-go#703) ##### New Contributors - [@​ccoVeille](https://github.com/ccoVeille) made their first contribution in [#​691](actions/setup-go#691) - [@​deining](https://github.com/deining) made their first contribution in [#​683](actions/setup-go#683) **Full Changelog**: <actions/setup-go@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-go/releases/tag/v6.1.0) [Compare Source](actions/setup-go@v6...v6.1.0) ##### What's Changed ##### Enhancements - Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by [@​nicholasngai](https://github.com/nicholasngai) in [#​665](actions/setup-go#665) - Add support for .tool-versions file and update workflow by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​673](actions/setup-go#673) - Add comprehensive breaking changes documentation for v6 by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​674](actions/setup-go#674) ##### Dependency updates - Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by [@​dependabot](https://github.com/dependabot) in [#​617](actions/setup-go#617) - Upgrade actions/publish-action from 0.3.0 to 0.4.0 by [@​dependabot](https://github.com/dependabot) in [#​641](actions/setup-go#641) - Upgrade semver and [@​types/semver](https://github.com/types/semver) by [@​dependabot](https://github.com/dependabot) in [#​652](actions/setup-go#652) ##### New Contributors - [@​nicholasngai](https://github.com/nicholasngai) made their first contribution in [#​665](actions/setup-go#665) - [@​priya-kinthali](https://github.com/priya-kinthali) made their first contribution in [#​673](actions/setup-go#673) - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​674](actions/setup-go#674) **Full Changelog**: <actions/setup-go@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Reviewed-on: https://gitea.com/gitea/terraform-provider-gitea/pulls/181 Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
chhe
pushed a commit
to chhe/act_runner
that referenced
this pull request
Jul 23, 2026
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/setup-go](https://github.com/actions/setup-go) | action | major | `v6` → `v7` | --- ### Release Notes <details> <summary>actions/setup-go (actions/setup-go)</summary> ### [`v7.0.0`](https://github.com/actions/setup-go/releases/tag/v7.0.0) [Compare Source](actions/setup-go@v7.0.0...v7.0.0) ##### What's Changed - Migrate to ESM and upgrade dependencies by [@​priyagupta108](https://github.com/priyagupta108) in [#​763](actions/setup-go#763) - chore(deps): bump [@​actions/cache](https://github.com/actions/cache) to 6.2.0 by [@​philip-gai](https://github.com/philip-gai) in [#​771](actions/setup-go#771) ##### New Contributors - [@​philip-gai](https://github.com/philip-gai) made their first contribution in [#​771](actions/setup-go#771) **Full Changelog**: <actions/setup-go@v6...v7.0.0> ### [`v7`](actions/setup-go@v6.5.0...v7.0.0) [Compare Source](actions/setup-go@v6.5.0...v7.0.0) ### [`v6.5.0`](https://github.com/actions/setup-go/releases/tag/v6.5.0) [Compare Source](actions/setup-go@v6.4.0...v6.5.0) ##### What's Changed ##### Dependency update - Upgrade actions dependencies by [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) in [#​744](actions/setup-go#744) - Upgrade [@​types/node](https://github.com/types/node) and typescript-eslint dependencies to resolve npm audit findings by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​755](actions/setup-go#755) - Upgrade [@​actions/cache](https://github.com/actions/cache) to 5.1.0, log cache write denied by [@​jasongin](https://github.com/jasongin) in [#​758](actions/setup-go#758) - Upgrade version to 6.5.0 in package.json and package-lock.json by [@​HarithaVattikuti](https://github.com/HarithaVattikuti) in [#​762](actions/setup-go#762) ##### New Contributors - [@​priyagupta108](https://github.com/priyagupta108) with [@​Copilot](https://github.com/Copilot) made their first contribution in [#​744](actions/setup-go#744) - [@​jasongin](https://github.com/jasongin) made their first contribution in [#​758](actions/setup-go#758) **Full Changelog**: <actions/setup-go@v6...v6.5.0> ### [`v6.4.0`](https://github.com/actions/setup-go/releases/tag/v6.4.0) [Compare Source](actions/setup-go@v6.3.0...v6.4.0) ##### What's Changed ##### Enhancement - Add go-download-base-url input for custom Go distributions by [@​gdams](https://github.com/gdams) in [#​721](actions/setup-go#721) ##### Dependency update - Upgrade minimatch from 3.1.2 to 3.1.5 by [@​dependabot](https://github.com/dependabot) in [#​727](actions/setup-go#727) ##### Documentation update - Rearrange README.md, add advanced-usage.md by [@​priyagupta108](https://github.com/priyagupta108) in [#​724](actions/setup-go#724) - Fix Microsoft build of Go link by [@​gdams](https://github.com/gdams) in [#​734](actions/setup-go#734) ##### New Contributors - [@​gdams](https://github.com/gdams) made their first contribution in [#​721](actions/setup-go#721) **Full Changelog**: <actions/setup-go@v6...v6.4.0> ### [`v6.3.0`](https://github.com/actions/setup-go/releases/tag/v6.3.0) [Compare Source](actions/setup-go@v6.2.0...v6.3.0) ##### What's Changed - Update default Go module caching to use go.mod by [@​priyagupta108](https://github.com/priyagupta108) in [#​705](actions/setup-go#705) - Fix golang download url to go.dev by [@​178inaba](https://github.com/178inaba) in [#​469](actions/setup-go#469) **Full Changelog**: <actions/setup-go@v6...v6.3.0> ### [`v6.2.0`](https://github.com/actions/setup-go/releases/tag/v6.2.0) [Compare Source](actions/setup-go@v6.1.0...v6.2.0) ##### What's Changed ##### Enhancements - Example for restore-only cache in documentation by [@​aparnajyothi-y](https://github.com/aparnajyothi-y) in [#​696](actions/setup-go#696) - Update Node.js version in action.yml by [@​ccoVeille](https://github.com/ccoVeille) in [#​691](actions/setup-go#691) - Documentation update of actions/checkout by [@​deining](https://github.com/deining) in [#​683](actions/setup-go#683) ##### Dependency updates - Upgrade js-yaml from 3.14.1 to 3.14.2 by [@​dependabot](https://github.com/dependabot) in [#​682](actions/setup-go#682) - Upgrade [@​actions/cache](https://github.com/actions/cache) to v5 by [@​salmanmkc](https://github.com/salmanmkc) in [#​695](actions/setup-go#695) - Upgrade actions/checkout from 5 to 6 by [@​dependabot](https://github.com/dependabot) in [#​686](actions/setup-go#686) - Upgrade qs from 6.14.0 to 6.14.1 by [@​dependabot](https://github.com/dependabot) in [#​703](actions/setup-go#703) ##### New Contributors - [@​ccoVeille](https://github.com/ccoVeille) made their first contribution in [#​691](actions/setup-go#691) - [@​deining](https://github.com/deining) made their first contribution in [#​683](actions/setup-go#683) **Full Changelog**: <actions/setup-go@v6...v6.2.0> ### [`v6.1.0`](https://github.com/actions/setup-go/releases/tag/v6.1.0) [Compare Source](actions/setup-go@v6...v6.1.0) ##### What's Changed ##### Enhancements - Fall back to downloading from go.dev/dl instead of storage.googleapis.com/golang by [@​nicholasngai](https://github.com/nicholasngai) in [#​665](actions/setup-go#665) - Add support for .tool-versions file and update workflow by [@​priya-kinthali](https://github.com/priya-kinthali) in [#​673](actions/setup-go#673) - Add comprehensive breaking changes documentation for v6 by [@​mahabaleshwars](https://github.com/mahabaleshwars) in [#​674](actions/setup-go#674) ##### Dependency updates - Upgrade eslint-config-prettier from 10.0.1 to 10.1.8 and document breaking changes in v6 by [@​dependabot](https://github.com/dependabot) in [#​617](actions/setup-go#617) - Upgrade actions/publish-action from 0.3.0 to 0.4.0 by [@​dependabot](https://github.com/dependabot) in [#​641](actions/setup-go#641) - Upgrade semver and [@​types/semver](https://github.com/types/semver) by [@​dependabot](https://github.com/dependabot) in [#​652](actions/setup-go#652) ##### New Contributors - [@​nicholasngai](https://github.com/nicholasngai) made their first contribution in [#​665](actions/setup-go#665) - [@​priya-kinthali](https://github.com/priya-kinthali) made their first contribution in [#​673](actions/setup-go#673) - [@​mahabaleshwars](https://github.com/mahabaleshwars) made their first contribution in [#​674](actions/setup-go#674) **Full Changelog**: <actions/setup-go@v6...v6.1.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xOTEuMiIsInVwZGF0ZWRJblZlciI6IjQzLjE5MS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Reviewed-on: https://gitea.com/gitea/runner/pulls/1102 Reviewed-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Renovate Bot <renovate-bot@gitea.com>
3 of 5 tasks
slchris
added a commit
to slchris/qubes-air
that referenced
this pull request
Oct 1, 2026
GitHub is retiring the Node 20 action runtime on its hosted runners: according to the gitleaks-action v3.0.0 release notes (a vendor statement, not verified here), Node 24 became the default on 2026-06-02 and Node 20 is removed on 2026-09-16. Every JS action this repo used was still on a node20 release, so each workflow depended on a runtime the runner is dropping. This moves each one to a release whose action.yml declares `runs.using: node24`. Behavior change: none intended. Same inputs, same steps, same gates; only the action releases (and, for trivy-action, the Trivy default it downloads) change. SHA-pinned actions stay SHA-pinned. Version choice: the lowest Node 24 major that has shipped a release in the last six months (since 2026-03-26). Where the lowest node24 major was left behind, the next one is used: - actions/checkout v4 -> v5 (v5.1.0, 2026-07-20). v5 is the first node24 major. Its v5.1.0 backports allow-unsafe-pr-checkout (blocks fork-PR checkout under pull_request_target/workflow_run); this repo uses neither trigger. Input used: fetch-depth (present, same meaning). - actions/setup-go v5 -> v6 (v6.5.0, 2026-06-24). The floating v6 tag is what makes this a Node 24 upgrade: action.yml at v6.0.0 and v6.1.0 still declares node20 (despite the v6.0.0 notes); node24 since v6.2.0 (actions/setup-go#691). v6 "toolchain handling" change only matters with a `toolchain` directive; go.mod has none (`go 1.26.0`). Inputs used: go-version, go-version-file, cache-dependency-path (all present). v7 is ESM + @actions/cache 6.2.0, no input change, not required. - actions/setup-node v4 -> v6, not v5: v5 had a single release (5.0.0, 2025-09-04) and did not receive the @actions/cache / undici security updates that v6.5.0 shipped on 2026-07-14. v6 limits automatic caching to npm; every step here already sets `cache: npm` explicitly or has no package.json at its root. Inputs used: node-version, cache, cache-dependency-path (present). - actions/upload-artifact v4 -> v7, not v6: v5 still runs node20, and v6 had one release (6.0.0, 2025-12-12) with nothing since v7 shipped. v7 adds opt-in `archive: false` (default unchanged) and moves to ESM. Inputs used: name, path, retention-days (present). - golangci/golangci-lint-action v8 -> v9 (v9.3.0). Only change in v9.0.0 is the runtime plus two opt-in features (install-only, module plugins). Inputs used: version, working-directory, args (present). - github/codeql-action init/analyze v3 -> v4, matching the upload-sarif@v4 already in security.yml. v3 is deprecated from December 2026 per the action's CHANGELOG. Inputs used: languages, build-mode, category (present; add-snippets was removed but is not used here). - softprops/action-gh-release v2 -> v3 (v3.0.3). v3.0.0 notes: runtime move only. Inputs used: tag_name, name, generate_release_notes, files, body (present). - gitleaks/gitleaks-action v2.3.9 (ff98106) -> v3.0.0 (e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e; lightweight tag, verified with git ls-remote). Notes: "No changes to inputs, outputs, or behavior". dist/index.js at both SHAs defaults GITLEAKS_VERSION to 8.24.3, so the scanner binary and the .gitleaks.toml [allowlist] semantics are unchanged. - aquasecurity/trivy-action 0.35.0 (57a97c7) -> v0.36.0 (ed142fd0673e97e23eac54620cfb913e5ce36c25, the peeled commit of the annotated v0.36.0 tag). The action is composite; 0.35.0 nested actions/cache v4.2.4 (node20), 0.36.0 nests actions/cache v5.0.5 and setup-trivy v0.2.6 (node24 cache/checkout). It also moves the default Trivy from v0.69.3 to v0.70.0. Inputs used: scan-type, scan-ref, format, output, severity (present). exit-code is left unset as before: whether Trivy should gate is an owner decision and is not changed here. Every action.yml above was read at the chosen tag/SHA from raw.githubusercontent.com and every release note from the GitHub releases API. ludeeus/action-shellcheck and ibiqlik/action-yamllint are composite actions with no Node runtime; later commits replace them. Trust boundary: third-party code that runs with the workflow token. The pinning style of each action is unchanged: those on major tags (actions/*, github/codeql-action, golangci-lint-action, action-gh-release) stay on major tags, and the two pinned to full commit SHAs (gitleaks-action, trivy-action) stay SHA-pinned with the release named in a comment. Failure modes: an input that changed meaning would show as a failed or behaviorally different step on the PR run; the inputs were compared against each action.yml to rule that out. Acceptance: actionlint 1.7.12 reports 0 findings on all workflows; scripts/check-workflow-gates.mjs passes; make BASE_REV=2d409fd pre-commit exits 0. The CI run on this branch must show no Node 20 deprecation annotation (not verifiable locally). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
slchris
added a commit
to slchris/qubes-air
that referenced
this pull request
Oct 1, 2026
The previous commit moved every action to a release that runs on Node 24.
Nothing stopped that from being undone: a revert, a copy-pasted step or a
Dependabot-style downgrade to a Node 20 release would pass every local and
CI check and only show up as a broken job once hosted runners stop
offering Node 20 (2026-09-16 according to the gitleaks-action v3.0.0
release notes; a vendor statement, not verified here).
Behavior change: scripts/check-workflow-gates.mjs gains a fifth rule. A
`uses:` line is rejected when it names a release older than the first
release of that action whose action.yml declares `runs.using: node24`:
actions/checkout v5.0.0 (v4.4.0: node20)
actions/setup-go v6.2.0 (v6.0.0 and v6.1.0: node20)
actions/setup-node v5.0.0 (v4.4.0: node20)
actions/setup-python v6.0.0 (v5.6.0: node20)
actions/upload-artifact v6.0.0 (v5.0.0: node20)
github/codeql-action v4.30.7 (v3.38.2: node20; init, analyze,
upload-sarif)
golangci/golangci-lint-action v9.0.0 (v8.0.0: node20)
softprops/action-gh-release v3.0.0 (v2.6.2: node20)
gitleaks/gitleaks-action v3.0.0 (v2.3.9: node20)
aquasecurity/trivy-action v0.36.0 (v0.35.0 nests actions/cache
v4.2.4: node20)
Each runtime was read from action.yml on raw.githubusercontent.com, at the
first node24 tag and at the release before it. setup-go is the trap: the
v6.0.0 release notes say "Upgrade Nodejs runtime from node20 to node 24",
but action.yml at v6.0.0 and v6.1.0 still declares node20; it changed in
v6.2.0 (actions/setup-go#691, released 2026-01-13). trivy-action is
composite; at v0.36.0 it nests actions/cache v5.0.5 and setup-trivy
v0.2.6, whose nested actions/cache v5.0.1 and actions/checkout v6.0.1 are
node24 too. v4.30.7 is the first v4 tag of codeql-action (v4 kept v3's
minor numbering).
How a ref is judged:
- a full version tag (`@v6.1.0`) against the exact first node24 release;
- a partial tag (`@v6`, `@v6.1`) only on the parts it names, since it is
the floating tag for the newest release in that line: `setup-go@v6`
passes (it resolves past v6.2.0), `setup-go@v6.1` does not;
- a commit SHA by its `# vX.Y.Z` release comment. The commit is fixed, so
a partial comment is read as the lowest release it could name (`# v6`
as v6.0.0), which fails closed;
- the two Node 20 commits this repo actually pinned (gitleaks v2.3.9,
trivy 0.35.0) by SHA, even with the comment removed.
The table holds first node24 releases, not the releases the workflows
choose: the rule is about the runtime, not about which supported release
to prefer.
The script also now fails when the directory it reads has no workflow
files; before, a moved .github/workflows would have printed the green
summary having checked nothing. It takes an optional directory argument so
it can be run against fixtures; with no argument it reads the repo's
workflows exactly as before.
Trust boundary: the checker is the only thing that notices a weakened
workflow, so its failure path is now tested.
scripts/check-workflow-gates.test.mjs runs the real script as a child
process against fixture workflows and asserts on the exit status:
- every action at its last node20 release is rejected and at its first
node24 release accepted, so moving any table entry by one release
fails a test; setup-go@v6.0.0 and @v6.1 are rejected as well;
- floating majors: the node20 major of every action but trivy (which has
no major tag) is rejected, also quoted; setup-go@v6, codeql-action@v4
and action-gh-release@v3 are accepted;
- SHAs: setup-go at its real v6.0.0 and v6.1.0 commits with their release
comment is rejected, its v6.2.0 commit with a bare `# v6` is rejected
and with `# v6.2.0` accepted; the known gitleaks/trivy node20 SHAs are
rejected with and without comment; an unknown SHA with an old comment is
rejected;
- comment lines and actions without a baseline are ignored;
- `|| true` and a floating `@main` still fail (regression for the
restructuring), and so does a directory with no workflow files;
- the repository's own workflows pass.
docs.yml runs the test before the gate check itself.
Failure modes: the rule is a line heuristic. A SHA-pinned action with no
release comment and an unknown SHA is not judged; actions outside the
table are not judged. Both are stated in the script.
Acceptance: node --test scripts/check-workflow-gates.test.mjs passes
51/51. Mutation-checked locally, each of these fails at least one test:
moving any table entry to the adjacent release on either side (and to a
version between the two); comparing a major-only tag on all three parts;
dropping the partial-comment padding for SHAs; removing the known-SHA
denylist, the rule itself or the empty-directory check. actionlint 0
findings; make BASE_REV=2d409fd pre-commit exits 0. `make docs-check`
does not run the new test yet (the Makefile is owned by another change).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description:
It looks like the Node.js version specified in action.yml was left behind when we upgraded the project to Node.js 24. This commit updates action.yml to reflect the correct Node.js version.
Related issue:
Check list: