From f5a47a185b4478ed246b47ab145147e920dc1854 Mon Sep 17 00:00:00 2001 From: Anthony Ettinger Date: Thu, 24 Sep 2026 06:48:52 +0000 Subject: [PATCH] chore(ci): clear Actions deprecation warnings across all workflows GitHub is forcing Node 20 actions onto the Node 24 runtime, CodeQL Action v3 is deprecated in December 2026, and ubuntu-latest migrates to Ubuntu 26 on October 19, 2026. Bump every action to its current major and pin the runner so none of that lands on us unannounced. - actions/checkout v4 -> v7 - actions/setup-node v4 -> v7 - actions/upload-artifact v4 -> v7 - actions/github-script v7 -> v9 - github/codeql-action/{init,autobuild,analyze,upload-sarif} v3 -> v4 - runs-on: ubuntu-latest -> ubuntu-24.04 Checked the majors for breaking changes that apply here: - checkout v7 blocks fork checkouts under pull_request_target and workflow_run; neither event is used in this repo. - setup-node v6 limits automatic caching to npm; ci.yml already sets cache: npm explicitly. - github-script v9 drops require('@actions/github') and reserves the getOctokit identifier; the only script here requires 'fs' and uses github.rest.issues, so it is unaffected. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/ci.yml | 6 +++--- .github/workflows/codeql.yml | 10 +++++----- .github/workflows/deploy-prober.yml | 4 ++-- .github/workflows/security.yml | 14 +++++++------- .github/workflows/threatcrush-scan.yml | 12 ++++++------ 5 files changed, 23 insertions(+), 23 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6ce8ebc0..8b34db27 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,10 +9,10 @@ on: jobs: test: name: test + typecheck - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: 20 cache: npm diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index a8fddeeb..6d5aa7a6 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -26,7 +26,7 @@ jobs: name: analyze (${{ matrix.language }}) # Auto-skips on private repos; CodeQL is free on public ones. if: ${{ github.event.repository.visibility == 'public' }} - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 permissions: actions: read contents: read @@ -39,10 +39,10 @@ jobs: language: [javascript-typescript] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Initialize CodeQL - uses: github/codeql-action/init@v3 + uses: github/codeql-action/init@v4 with: languages: ${{ matrix.language }} # 'security-and-quality' is the broadest preset — includes both @@ -51,9 +51,9 @@ jobs: queries: security-and-quality - name: Build (autobuild for JS/TS — no-op compile) - uses: github/codeql-action/autobuild@v3 + uses: github/codeql-action/autobuild@v4 - name: Perform CodeQL analysis - uses: github/codeql-action/analyze@v3 + uses: github/codeql-action/analyze@v4 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/deploy-prober.yml b/.github/workflows/deploy-prober.yml index 95979c98..5d4bb3f2 100644 --- a/.github/workflows/deploy-prober.yml +++ b/.github/workflows/deploy-prober.yml @@ -37,9 +37,9 @@ env: jobs: deploy: name: provision + deploy prober - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Configure SSH env: diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 4989e1b4..535a4ad2 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -11,14 +11,14 @@ on: jobs: semgrep: name: semgrep - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 continue-on-error: true # Skip on cross-repo fork PRs — they can't write annotations. if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository container: image: semgrep/semgrep steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 # OSS scan only (no SaaS upload, no token). Block only on ERROR-severity # findings — anything WARNING / INFO is logged but doesn't fail the build. - run: | @@ -34,11 +34,11 @@ jobs: npm-audit: name: npm audit - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 continue-on-error: true steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-node@v7 with: node-version: 20 - name: Audit (skip when no package.json) @@ -55,10 +55,10 @@ jobs: gitleaks: name: gitleaks - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 continue-on-error: true steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 # OSS binary — no license shakedown for org-owned repos. diff --git a/.github/workflows/threatcrush-scan.yml b/.github/workflows/threatcrush-scan.yml index d9190b62..bb51acd6 100644 --- a/.github/workflows/threatcrush-scan.yml +++ b/.github/workflows/threatcrush-scan.yml @@ -15,13 +15,13 @@ permissions: jobs: scan: name: Scan for credentials and vulnerable patterns - runs-on: ubuntu-latest + runs-on: ubuntu-24.04 timeout-minutes: 15 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - - uses: actions/setup-node@v4 + - uses: actions/setup-node@v7 with: node-version: "20" @@ -151,7 +151,7 @@ jobs: - name: Upload to the Security tab if: always() && 'true' == 'true' continue-on-error: true - uses: github/codeql-action/upload-sarif@v3 + uses: github/codeql-action/upload-sarif@v4 with: sarif_file: threatcrush.sarif category: threatcrush @@ -236,7 +236,7 @@ jobs: - name: Upload SARIF artifact if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@v7 with: name: threatcrush-sarif path: threatcrush.sarif @@ -251,7 +251,7 @@ jobs: - name: Comment on PR if: always() && github.event.pull_request.head.repo.full_name == github.repository && github.actor != 'dependabot[bot]' continue-on-error: true - uses: actions/github-script@v7 + uses: actions/github-script@v9 with: script: | const fs = require('fs');