Skip to content

ci: move actions to Node 24 runtimes and add dependabot - #2

Merged
heysanil merged 1 commit into
mainfrom
ci/node24-action-bumps
Jul 26, 2026
Merged

heysanil merged 1 commit into
mainfrom
ci/node24-action-bumps

Conversation

@heysanil

Copy link
Copy Markdown
Member

Why

GitHub is force-running two of our pinned actions on Node 24 already, ahead of Node 20's
removal from the runners:

Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on
Node.js 24: actions/checkout@v4, actions/github-script@v7.

This repo also had no Dependabot config, which is why the pins drifted in the first place.

Changes

Pin Before Runtime After Runtime
actions/checkout v4 node20 ⚠️ v7 node24
actions/github-script v7 node20 ⚠️ v9 node24
peter-evans/create-pull-request 5f6978f (v8.1.1) node24 ✅ unchanged —
rhysd/actionlint (docker) 1.7.12 n/a unchanged (latest) —

Also:

  • .github/dependabot.yml (new) — weekly github-actions ecosystem, grouped into a single
    PR, ci commit prefix to match this repo's scope-less conventional commits. Mirrors
    slingshot/reputation's config.
  • claude-code-version default 2.1.209 → 2.1.220 (npm latest), with the README input
    table synced.

actions/checkout 4 → 7 matches what Dependabot proposed in slingshot/reputation#4.

Breaking-change review

  • checkout v5 was the Node 24 bump; v6 moved credential persistence out of .git/config
    into a separate file; v7 blocks fork checkouts under pull_request_target / workflow_run.
    None affect us — audit-pr pushes from the same persisted-credential worktree, and the gate
    already rejects fork PRs and only runs under pull_request / push.
  • github-script v9 breaks require('@actions/github') (now ESM-only) and makes getOctokit
    an injected parameter. Both script: blocks use only require('fs'), github.rest.*,
    github.paginate, and context — so v9 is a drop-in with no script changes.

Verification

Ran the full CI matrix locally against the edited workflows:

  • actionlint 1.7.12 — exit 0
  • shellcheck engine/*.sh — clean
  • bats tests — 24/24 pass
  • @anthropic-ai/claude-code@2.1.220 confirmed on the npm registry

Follow-up (not in this PR)

Consumers pin audit.yml@v1, so this reaches them only once v1 is re-pointed — needs a
v1.4.0 tag plus a v1 move after merge.

GitHub is already force-running actions/checkout@v4 and actions/github-script@v7 on
Node 24 ahead of Node 20's removal from the runners. Bump both to their current
majors so the runtime is the pinned one rather than a fallback.

- audit.yml / ci.yml: actions/checkout v4 -> v7, actions/github-script v7 -> v9; both
  declare node24. github-script v9 breaks require('@actions/github') and makes
  getOctokit an injected param -- neither script block uses either, so no script edits.
- dependabot.yml: weekly grouped github-actions PRs (ci prefix) so these pins stop
  drifting silently. The actionlint step's docker:// ref is outside Dependabot's
  github-actions ecosystem; noted inline as a hand-bump.
- audit.yml / README: bump the pinned @anthropic-ai/claude-code default from 2.1.209
  to 2.1.220 (npm latest).

peter-evans/create-pull-request (v8.1.1) and rhysd/actionlint (1.7.12) are already
current, and create-pull-request is already node24.
@heysanil
heysanil merged commit b110847 into main Jul 26, 2026
3 checks passed
@heysanil
heysanil deleted the ci/node24-action-bumps branch July 26, 2026 19:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant