Skip to content

chore(ci): clear Actions deprecation warnings across all workflows - #271

Merged
ralyodio merged 1 commit into
masterfrom
ci/action-deprecations
Sep 24, 2026
Merged

ralyodio merged 1 commit into
masterfrom
ci/action-deprecations

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

The CodeQL run was throwing three annotations on every build:

  • warning — Node.js 20 is deprecated; actions/checkout@v4 and github/codeql-action/{init,autobuild,analyze}@v3 are being forced onto Node 24.
  • warning — CodeQL Action v3 will be deprecated in December 2026.
  • notice — ubuntu-latest migrates to Ubuntu 26 beginning October 19, 2026.

The first two applied to every workflow in the repo, not just codeql.yml, so all five are bumped together.

action before after
actions/checkout v4 v7
actions/setup-node v4 v7
actions/upload-artifact v4 v7
actions/github-script v7 v9
github/codeql-action/* v3 v4
runs-on ubuntu-latest ubuntu-24.04

Pinning the runner to ubuntu-24.04 keeps the October 19 image migration from landing on us mid-week; it can be unpinned deliberately later.

Breaking changes checked against this repo

  • checkout@v7 blocks fork checkouts under pull_request_target / workflow_run — neither event is used here (threatcrush-scan.yml documents that it deliberately stays on pull_request).
  • setup-node@v6 limits automatic caching to npm — ci.yml already sets cache: npm explicitly.
  • github-script@v9 drops require('@actions/github') and reserves the getOctokit identifier — the one script here requires fs and calls github.rest.issues, so it is unaffected.

All five workflows parse clean.

Note separately, not changed here: node-version: 20 in ci.yml, security.yml and threatcrush-scan.yml is the test runtime, unrelated to these annotations, but Node 20 is past EOL and worth its own bump.

Replaces #270, which was accidentally branched off an in-progress mcp-autoblog commit.

🤖 Generated with Claude Code

GitHub is forcing Node 20 actions onto the Node 24 runtime, CodeQL
Action v3 is deprecated in December 2026, and ubuntu-latest migrates to
Ubuntu 26 on October 19, 2026. Bump every action to its current major
and pin the runner so none of that lands on us unannounced.

- actions/checkout v4 -> v7
- actions/setup-node v4 -> v7
- actions/upload-artifact v4 -> v7
- actions/github-script v7 -> v9
- github/codeql-action/{init,autobuild,analyze,upload-sarif} v3 -> v4
- runs-on: ubuntu-latest -> ubuntu-24.04

Checked the majors for breaking changes that apply here:
- checkout v7 blocks fork checkouts under pull_request_target and
  workflow_run; neither event is used in this repo.
- setup-node v6 limits automatic caching to npm; ci.yml already sets
  cache: npm explicitly.
- github-script v9 drops require('@actions/github') and reserves the
  getOctokit identifier; the only script here requires 'fs' and uses
  github.rest.issues, so it is unaffected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

48 finding(s)

HIGH/CRITICAL: 2 | MEDIUM: 31 | LOW: 15

Severity Rule Location
HIGH tls-verification-disabled lib/onion.ts:48
HIGH secret-generic-credential lib/sp/platforms/facebook.ts:32
MEDIUM js-unescaped-html-sink app/(app)/dashboard/admin/email-broadcast/EmailBroadcastForm.tsx:125
MEDIUM js-unescaped-html-sink app/(app)/dashboard/projects/[id]/autoblog/articles/[articleId]/page.tsx:214
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:67
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:97
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:104
MEDIUM js-unescaped-html-sink app/(marketing)/blog/[slug]/page.tsx:110
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:186
MEDIUM js-unescaped-html-sink app/(marketing)/recent/page.tsx:190
MEDIUM js-unescaped-html-sink app/c/[project]/[slug]/page.tsx:77
MEDIUM js-unescaped-html-sink app/c/[project]/page.tsx:57
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:228
MEDIUM js-unescaped-html-sink app/careers.js/route.ts:285
MEDIUM js-unescaped-html-sink app/layout.tsx:129
MEDIUM js-open-redirect app/login/form.tsx:39
MEDIUM js-unescaped-html-sink app/r/[token]/page.tsx:176
MEDIUM js-open-redirect app/signup/form.tsx:43
MEDIUM js-open-redirect components/billing/buy-credits-modal.tsx:98
MEDIUM js-unescaped-html-sink components/json-ld.tsx:8
MEDIUM js-unescaped-html-sink components/report/markdown-view.tsx:15
MEDIUM js-unescaped-html-sink lib/careers/page-templates.ts:198
MEDIUM js-dynamic-code-execution lib/crawl-limits.ts:67
MEDIUM redos-nested-quantifier lib/emailMarkdown.ts:41
MEDIUM redos-nested-quantifier lib/emailMarkdown.ts:324
MEDIUM redos-nested-quantifier lib/lx/articleGen.ts:99
MEDIUM redos-nested-quantifier lib/tracker/agent-gate.ts:61
MEDIUM sh-remote-script-execution prober/deploy/provision.sh:30
MEDIUM sql-template-interpolation scripts/detect-slot-themes.ts:31
MEDIUM sql-template-interpolation scripts/purge-constructed-keywords.ts:163
MEDIUM sql-template-interpolation scripts/purge-offniche-keywords.ts:124
MEDIUM js-dynamic-code-execution scripts/test-crawl-limits.mjs:14
MEDIUM js-dynamic-code-execution scripts/test-crawl-limits.mjs:24
LOW secret-generic-credential app/(marketing)/docs/autoblog-webhook/page.tsx:145
LOW secret-generic-credential lib/sp/platforms/linkedin.ts:25
LOW js-dynamic-code-execution tests/careers-page-templates.test.ts:21
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:19
LOW js-dynamic-code-execution tests/careers-widget-script.test.ts:69
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:51
LOW js-dynamic-code-execution tests/contract/ad-visitor-id.test.ts:52
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:20
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:24
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:25
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:26
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:31
LOW js-dynamic-code-execution tests/contract/ads-click-cooldown-redis.test.ts:35
LOW secret-generic-credential tests/contract/posthog-integration.test.ts:13
LOW secret-generic-credential tests/lead-campaign.test.ts:16

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit ff28d0e into master Sep 24, 2026
10 checks passed
@ralyodio
ralyodio deleted the ci/action-deprecations branch September 24, 2026 07:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant