Repository navigation
ci: move every pinned action to a Node 24 release - #128
Merged
Merged
Conversation
The runners now warn that actions/checkout, actions/setup-node and nick-fields/retry target the deprecated Node 20 runtime and are being forced onto Node 24. Every pinned action moves to its newest release, each of which runs on Node 24 natively. setup-node v7 dropped the dummy NODE_AUTH_TOKEN fallback; the publish job authenticates through OIDC and never set one, so the only change there is turning off the automatic npm cache, as the trusted publishing docs recommend. github-script v9 stops supporting require of @actions/github inside scripts; neither script here does that.
Owner
Author
|
Publish dry run from this branch: https://github.com/JeanExtreme002/FlightRadarAPI/actions/runs/37978908688
|
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Recent runs warn that
actions/checkout,actions/setup-nodeandnick-fields/retrytarget the deprecated Node 20 runtime and are being forced onto Node 24. This moves every pinned action to its newest release, all of which run on Node 24 natively, so the warnings go away before GitHub turns them into failures.What
actions/upload-pages-artifactandpypa/gh-action-pypi-publishwere already on their latest release. All SHAs resolved from the release tags via the GitHub API and pinned with the full version in the comment.Breaking changes checked
NODE_AUTH_TOKENfallback. The publish job authenticates via OIDC trusted publishing and never set a token, so nothing changes there. Following the setup-node trusted publishing docs, the publish step now setspackage-manager-cache: false.require('@actions/github')inside scripts. Neither the labeler nor the branch-cleanup script does that; both use the injectedgithub,contextandcore.pull_request_target. The twopull_request_targetworkflows here do not check out code.pip-installinput, which is not used.Verification
workflow_dispatchdry run from this branch (see the comment below): PyPI side green end to end, npm side green up tonpm publish --dry-run, which the registry refuses because 1.6.3 is already published. That limitation predates this PR.deploy-docs(cache v6, deploy-pages v5.0.1) only runs on push tomain; it will run on merge since its own file is in the path filter.