chore: upgrade actions to Node 24 runtime (SHA-pinned) - #48
John C. Bland II (johncblandii) wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Updates this repository’s composite action and CI workflows to use SHA-pinned GitHub Actions that are compatible with GitHub’s Node 24 runtime migration, aligning with the stated supply-chain pinning approach.
Changes:
- Pin
actions/checkoutin all test workflows to a specific SHA (v7.0.1). - Pin
nick-fields/assert-actionin test workflows to a specific SHA (v4.0.1). - Pin
cloudposse/github-action-yaml-config-queryinaction.ymlto a specific SHA (v1.0.1).
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| action.yml | Pins cloudposse/github-action-yaml-config-query by SHA within the composite action steps. |
| .github/workflows/test-to-no-metadata.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
| .github/workflows/test-positive.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
| .github/workflows/test-negative.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
| .github/workflows/test-auto-to.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
| .github/workflows/test-auto-to-no-metadata.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
| .github/workflows/test-auto-from.yml | Pins actions/checkout and nick-fields/assert-action by SHA. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| with: | ||
| expected: true | ||
| actual: ${{ ( inputs.use_metadata == 'true' ) || ( inputs.to != '' ) }} | ||
|
|
||
| - uses: cloudposse/github-action-yaml-config-query@v1 | ||
| - uses: cloudposse/github-action-yaml-config-query@8178e0c0d186f53de40f6bcf8e039f1e6a9aefc5 # v1.0.1 |
Erik Osterman (Cloud Posse) (osterman)
left a comment
There was a problem hiding this comment.
Approving. All three SHAs verified against upstream tag refs, diff matches the description, no permissions/secrets/Dockerfile/release-config changes.
The only consumer-facing change is yaml-config-query@v1 → v1.0.1 inside action.yml — same major, low blast radius. The two test jobs reporting failure are the intentional negative paths (test-negative.yml, test-auto-to-no-metadata.yml); their asserts pass and the umbrella checks are green.
what
action.yml) to versions running on theNode 24 runtime, SHA-pinned with precise version comments:
actions/checkout@v6→@3d3c42e5...# v7.0.1nick-fields/assert-action@v2→@0efd6166...# v4.0.1cloudposse/github-action-yaml-config-query@v1→@8178e0c0...# v1.0.1why
are already being force-migrated to Node 24
matching the org's direction in chore: upgrade actions to Node 24 runtime and enforce SHA pinning .github#261
references
Supersedes #46
Supersedes #45
Supersedes #44