From 34538f793930c9693504e68d3a9dc1c0a7872c17 Mon Sep 17 00:00:00 2001 From: Sanil Chawla Date: Sun, 26 Jul 2026 12:58:15 -0700 Subject: [PATCH] ci: move actions to Node 24 runtimes and add dependabot GitHub is already force-running actions/checkout@v4 and actions/github-script@v7 on Node 24 ahead of Node 20's removal from the runners. Bump both to their current majors so the runtime is the pinned one rather than a fallback. - audit.yml / ci.yml: actions/checkout v4 -> v7, actions/github-script v7 -> v9; both declare node24. github-script v9 breaks require('@actions/github') and makes getOctokit an injected param -- neither script block uses either, so no script edits. - dependabot.yml: weekly grouped github-actions PRs (ci prefix) so these pins stop drifting silently. The actionlint step's docker:// ref is outside Dependabot's github-actions ecosystem; noted inline as a hand-bump. - audit.yml / README: bump the pinned @anthropic-ai/claude-code default from 2.1.209 to 2.1.220 (npm latest). peter-evans/create-pull-request (v8.1.1) and rhysd/actionlint (1.7.12) are already current, and create-pull-request is already node24. --- .github/dependabot.yml | 20 ++++++++++++++++++++ .github/workflows/audit.yml | 12 ++++++------ .github/workflows/ci.yml | 2 +- README.md | 2 +- 4 files changed, 28 insertions(+), 8 deletions(-) create mode 100644 .github/dependabot.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..433ba2e --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,20 @@ +version: 2 +updates: + # Keep GitHub Actions current so SHA-pinned actions don't rot and floating major tags get + # reviewed bumps rather than implicit ones. Runner deprecations (e.g. the Node 20 -> 24 + # migration) land here first, so this is the early-warning channel for CI breakage. + # + # Caveat: the github-actions ecosystem only tracks `uses: owner/repo@ref`. The actionlint + # step in ci.yml uses a `docker://` reference, which Dependabot does not update — bump + # rhysd/actionlint by hand. + - package-ecosystem: github-actions + directory: / + schedule: + interval: weekly + groups: + github-actions: + patterns: + - "*" + commit-message: + # This repo's history uses bare conventional-commit types (no scopes) -> "ci: bump …". + prefix: ci diff --git a/.github/workflows/audit.yml b/.github/workflows/audit.yml index 42349ed..e36c894 100644 --- a/.github/workflows/audit.yml +++ b/.github/workflows/audit.yml @@ -60,7 +60,7 @@ on: claude-code-version: description: Pinned @anthropic-ai/claude-code npm version type: string - default: '2.1.209' + default: '2.1.220' anthropic-base-url: description: Gateway base URL (empty = Anthropic default endpoint) type: string @@ -103,7 +103,7 @@ jobs: # not_configured | skip_marker | no_source_changes | '' (empty when run=true) skip_reason: ${{ steps.decide.outputs.skip_reason }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 @@ -188,7 +188,7 @@ jobs: group: docs-sentinel-pr-${{ github.event.pull_request.number }} cancel-in-progress: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: ${{ github.head_ref }} # PR branch tip so we can push back fetch-depth: 0 # default GITHUB_TOKEN creds -> push does NOT re-trigger CI @@ -336,7 +336,7 @@ jobs: # Always leave a single, sticky status comment — drift or not — so every PR shows the # docs-sentinel result instead of going silent when there's nothing to fix. - name: Post docs-sentinel status comment (sticky) - uses: actions/github-script@v7 + uses: actions/github-script@v9 env: CHANGED: ${{ steps.guard.outputs.changed }} BODY_PATH: ${{ steps.compose.outputs.body_path }} @@ -391,7 +391,7 @@ jobs: cancel-in-progress: true steps: - name: Post docs-sentinel status comment (sticky) - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const marker = ''; @@ -427,7 +427,7 @@ jobs: group: docs-sentinel-main cancel-in-progress: false # never cancel a half-opened PR steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8d95d1f..6f9107b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,7 +12,7 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Install bats + shellcheck run: sudo apt-get update -q && sudo apt-get install -y -q bats shellcheck - name: Shellcheck engine scripts diff --git a/README.md b/README.md index 687ab6f..40e28fe 100644 --- a/README.md +++ b/README.md @@ -107,7 +107,7 @@ All inputs are optional. | `diff-exclude` | common lockfiles | File patterns excluded from the diff text shown to the auditor | | `sync-branch` | `docs/sync` | Fixed branch for the rolling docs-sync PR | | `runner` | `ubuntu-latest` | Runner label for all jobs | -| `claude-code-version` | `2.1.209` | Pinned `@anthropic-ai/claude-code` npm version | +| `claude-code-version` | `2.1.220` | Pinned `@anthropic-ai/claude-code` npm version | | `anthropic-base-url` | `https://openrouter.ai/api` | Model gateway base URL | | `model` | `z-ai/glm-5.2` | Main auditor model | | `small-model` | `deepseek/deepseek-v4-flash` | Background/summarization model |