chore: upgrade actions to Node 24 runtime (SHA-pinned) - #60
Merged
John C. Bland II (johncblandii) merged 1 commit intoAug 13, 2026
Merged
Conversation
Combines the pending Renovate bumps (checkout v7, github-script v9, release-drafter v7) with SHA pins and precise version comments. Passes token explicitly to release-drafter per its v7 interface.
Copilot started reviewing on behalf of
John C. Bland II (johncblandii)
August 13, 2026 16:06
View session
There was a problem hiding this comment.
Pull request overview
Upgrades this repository’s composite GitHub Action to use SHA-pinned upstream actions that run on the Node 24 runtime, reducing deprecation warnings for downstream consumers and aligning with supply-chain pinning practices.
Changes:
- Replace
actions/checkout,actions/github-script(x2), andrelease-drafter/release-drafterversion tags with specific commit SHAs (with version comments). - Add an explicit
token: ${{ inputs.token }}input to therelease-drafterstep to ensure the intended token is used.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Erik Osterman (Cloud Posse) (osterman)
approved these changes
Aug 13, 2026
John C. Bland II (johncblandii)
deleted the
chore/node24-runtime-upgrade
branch
August 13, 2026 16:12
|
These changes were released in v4.0.1. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
what
with precise version comments:
actions/checkout@v4→@3d3c42e5...# v7.0.1actions/github-script@v7→@3a2844b7...# v9.0.0(×2)release-drafter/release-drafter@v6→@34d80673...# v7.7.0token: ${{ inputs.token }}explicitly to the release-drafter step — v7 introduces atokeninput (defaulting togithub.token); passing it explicitly guarantees the bot token isused regardless of how future versions weigh the input vs. the
GITHUB_TOKENenv (the env iskept for back-compat)
why
warning for every consumer of this action (232 repos reference it)
chore(deps): update release-drafter/release-drafter action to v7 - autoclosed #56 release-drafter) in one reviewable change, upgraded to SHA pinning per the org's
supply-chain direction (chore: upgrade actions to Node 24 runtime and enforce SHA pinning .github#261)
runs.using: node24confirmed at eachpinned ref
disable-releaser/disable-autolabelerinputs are not used here, and the org's
auto-release*.ymlconfigs use none of the droppedconfig keys (
include-pre-releases,references)references