MOBILE-121: Bump GitHub Actions to supported Node runtimes - #184
Merged
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
This PR modernizes the repository’s GitHub Actions setup to align with currently supported Node runtimes and hardens the supply chain by upgrading actions to current major versions pinned by commit SHA. It also improves workflow correctness (e.g., output handling) and adds automation to keep action versions up to date.
Changes:
- Upgraded GitHub Actions to newer major versions and pinned them by SHA; added minimal
permissionsdefaults across workflows. - Replaced deprecated
::set-outputusage with$GITHUB_OUTPUTand fixed prerelease detection wiring. - Added Dependabot configuration for weekly grouped
github-actionsupdates; adjusted release tooling scripts and gitignore to allow committingyarn.lock.
Reviewed changes
Copilot reviewed 13 out of 15 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
git-release-branch.sh |
Improves shell robustness (env bash, set -euo pipefail) and quoting in the release branch helper script. |
.gitignore |
Stops ignoring yarn.lock to allow reproducible installs. |
.github/workflows/release-version-check.yml |
Pins actions by SHA, tightens branch prefix checks, and uses safer env handling for GitHub env exports. |
.github/workflows/publish-reusable.yml |
Pins actions by SHA, modernizes outputs via $GITHUB_OUTPUT, adds required secret definition, and scopes permissions per job. |
.github/workflows/publish-common-trigger.yml |
Adds default read permissions and passes required secrets explicitly to the reusable workflow. |
.github/workflows/pr-description-validate.yml |
Pins actions by SHA, removes broken issue_comment trigger, and introduces explicit permissions for PR validation/commenting. |
.github/workflows/manual-prepare_release_branch.yml |
Pins actions by SHA, improves input/branch validation, switches to $GITHUB_OUTPUT, and tightens quoting/env handling. |
.github/workflows/lint_and_test.yml |
Pins actions by SHA and updates CI Node version to 24. |
.github/workflows/gitleaks-secrets-validate.yml |
Pins actions by SHA and upgrades gitleaks action major version. |
.github/workflows/distribute-reusable.yml |
Pins checkout by SHA and improves multiline env handling via randomized delimiter. |
.github/workflows/distribute-release-support-mission.yml |
Adds default read permissions and passes required secrets explicitly. |
.github/workflows/distribute-manual.yml |
Adds default read permissions and passes required secrets explicitly. |
.github/workflows/distribute-develop-mission.yml |
Adds default read permissions and passes required secrets explicitly. |
.github/dependabot.yml |
Adds weekly grouped Dependabot updates for GitHub Actions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
justSmK
approved these changes
Jun 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
https://tracker.yandex.ru/MOBILE-121
What changed
setup-node v6, github-script v9, read-file-action v1.1.8, find-comment v4,
create-or-update-comment v5, gitleaks-action v3.
::set-outputwith$GITHUB_OUTPUT(and fixed a pre-releasedetection step that was missing its
id, so it never worked)..github/dependabot.yml(github-actions, weekly, grouped) to keep actionversions current automatically.
yarn.lockfor reproducible installs (stopped gitignoring it; notpublished to npm). Release flow unchanged — stays
yarn release.lts/*.issue_commenttrigger inpr-description-validate.yml(re-validation is already handled by
pull_request: edited).