From 36f377b9f2885b0c070d7ffae116b39ab33c3f30 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:03:20 +0100 Subject: [PATCH 01/10] Bump `@types/node` to `v24` for `pr-checks` All scripts in `pr-checks` are run with Node24 --- package-lock.json | 19 ++++++++++++++++++- pr-checks/package.json | 2 +- 2 files changed, 19 insertions(+), 2 deletions(-) diff --git a/package-lock.json b/package-lock.json index 27bf393bfd..167f0801b3 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10508,9 +10508,26 @@ "yaml": "^2.9.1" }, "devDependencies": { - "@types/node": "^20.19.43", + "@types/node": "^24.19.0", "tsx": "^4.23.15" } + }, + "pr-checks/node_modules/@types/node": { + "version": "24.19.0", + "resolved": "https://registry.npmjs.org/@types/node/-/node-24.19.0.tgz", + "integrity": "sha512-zY+5tKxXdhGh1PYI0ac+7juvEu4OI6vWtVVoj5i2m42jxAY1U+zHGt6QCyOFwykdP62sM3MJ9stoYYUw5aCWew==", + "dev": true, + "license": "MIT", + "dependencies": { + "undici-types": ">=7.24.0 <7.24.7" + } + }, + "pr-checks/node_modules/undici-types": { + "version": "7.24.6", + "resolved": "https://registry.npmjs.org/undici-types/-/undici-types-7.24.6.tgz", + "integrity": "sha512-WRNW+sJgj5OBN4/0JpHFqtqzhpbnV0GuB+OozA9gCL7a993SmU+1JBZCzLNxYsbMfIeDL+lTsphD5jN5N+n0zg==", + "dev": true, + "license": "MIT" } } } diff --git a/pr-checks/package.json b/pr-checks/package.json index d758d3200d..c86dc29896 100644 --- a/pr-checks/package.json +++ b/pr-checks/package.json @@ -13,7 +13,7 @@ "yaml": "^2.9.1" }, "devDependencies": { - "@types/node": "^20.19.43", + "@types/node": "^24.19.0", "tsx": "^4.23.15" } } From 4c98a0bfb7a4e670afccf65d0279f62414253c5d Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:03:52 +0100 Subject: [PATCH 02/10] Add `nvmrc` for `pr-checks` --- pr-checks/.nvmrc | 1 + 1 file changed, 1 insertion(+) create mode 100644 pr-checks/.nvmrc diff --git a/pr-checks/.nvmrc b/pr-checks/.nvmrc new file mode 100644 index 0000000000..a45fd52cc5 --- /dev/null +++ b/pr-checks/.nvmrc @@ -0,0 +1 @@ +24 From b813f919534e7f8bcf8daa008c2947bb39cdc069 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:16:25 +0100 Subject: [PATCH 03/10] Add compatibility definitions to `config.ts` --- pr-checks/config.ts | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pr-checks/config.ts b/pr-checks/config.ts index 05bcbfe3ce..876654a1cc 100644 --- a/pr-checks/config.ts +++ b/pr-checks/config.ts @@ -1,4 +1,9 @@ import path from "path"; +import { fileURLToPath } from "url"; + +// For backwards-compatibility. +const __filename = fileURLToPath(import.meta.url); +const __dirname = path.dirname(__filename); /** The oldest supported major version of the CodeQL Action. */ export const OLDEST_SUPPORTED_MAJOR_VERSION = 3; From f5b4c32a4e177acbda6f9b8e6c1f75505630b67f Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:19:20 +0100 Subject: [PATCH 04/10] Replace `require` check with `import.meta.main` --- pr-checks/bundle-changelog.ts | 2 +- pr-checks/bundle-metadata.ts | 2 +- pr-checks/check-repo-size.ts | 2 +- pr-checks/prepare-changelog.ts | 2 +- pr-checks/release-branches.ts | 2 +- pr-checks/rollback-changelog.ts | 2 +- pr-checks/sync-back.ts | 2 +- pr-checks/sync-checks.ts | 2 +- pr-checks/update-ghes-versions.ts | 2 +- pr-checks/update-release-branch.ts | 2 +- 10 files changed, 10 insertions(+), 10 deletions(-) diff --git a/pr-checks/bundle-changelog.ts b/pr-checks/bundle-changelog.ts index 557a8556c1..230b80fb86 100755 --- a/pr-checks/bundle-changelog.ts +++ b/pr-checks/bundle-changelog.ts @@ -122,6 +122,6 @@ function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { process.exit(main()); } diff --git a/pr-checks/bundle-metadata.ts b/pr-checks/bundle-metadata.ts index 25c282e9ae..f06b7104d3 100755 --- a/pr-checks/bundle-metadata.ts +++ b/pr-checks/bundle-metadata.ts @@ -43,6 +43,6 @@ async function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { void main(); } diff --git a/pr-checks/check-repo-size.ts b/pr-checks/check-repo-size.ts index e38b19cce0..b15a85c1b3 100644 --- a/pr-checks/check-repo-size.ts +++ b/pr-checks/check-repo-size.ts @@ -218,6 +218,6 @@ async function run(): Promise { } } -if (require.main === module) { +if (import.meta.main) { void run(); } diff --git a/pr-checks/prepare-changelog.ts b/pr-checks/prepare-changelog.ts index 0c89699fc8..7ddf185202 100755 --- a/pr-checks/prepare-changelog.ts +++ b/pr-checks/prepare-changelog.ts @@ -77,6 +77,6 @@ function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { process.exit(main()); } diff --git a/pr-checks/release-branches.ts b/pr-checks/release-branches.ts index d0b4702018..04ea087334 100755 --- a/pr-checks/release-branches.ts +++ b/pr-checks/release-branches.ts @@ -116,6 +116,6 @@ async function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { void main(); } diff --git a/pr-checks/rollback-changelog.ts b/pr-checks/rollback-changelog.ts index 15a37b1b7c..9a744dc9fc 100755 --- a/pr-checks/rollback-changelog.ts +++ b/pr-checks/rollback-changelog.ts @@ -79,6 +79,6 @@ function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { process.exit(main()); } diff --git a/pr-checks/sync-back.ts b/pr-checks/sync-back.ts index bb442b2fe1..3a860eae42 100755 --- a/pr-checks/sync-back.ts +++ b/pr-checks/sync-back.ts @@ -232,6 +232,6 @@ function main(): number { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { process.exit(main()); } diff --git a/pr-checks/sync-checks.ts b/pr-checks/sync-checks.ts index afebc5831e..435b3a29e8 100755 --- a/pr-checks/sync-checks.ts +++ b/pr-checks/sync-checks.ts @@ -342,6 +342,6 @@ async function main(): Promise { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { void main(); } diff --git a/pr-checks/update-ghes-versions.ts b/pr-checks/update-ghes-versions.ts index 055424dff1..03b53c5dee 100755 --- a/pr-checks/update-ghes-versions.ts +++ b/pr-checks/update-ghes-versions.ts @@ -238,6 +238,6 @@ function main() { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { main(); } diff --git a/pr-checks/update-release-branch.ts b/pr-checks/update-release-branch.ts index 088da59281..93e50f7ad2 100755 --- a/pr-checks/update-release-branch.ts +++ b/pr-checks/update-release-branch.ts @@ -835,6 +835,6 @@ async function main(): Promise { } // Only call `main` if this script was run directly. -if (require.main === module) { +if (import.meta.main) { void main(); } From 1b38bb12c6cdc5749063bae7168b06e8bd405b4d Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:19:33 +0100 Subject: [PATCH 05/10] Set `type: module` for `pr-checks` --- pr-checks/package.json | 1 + 1 file changed, 1 insertion(+) diff --git a/pr-checks/package.json b/pr-checks/package.json index c86dc29896..3d6b3d07e6 100644 --- a/pr-checks/package.json +++ b/pr-checks/package.json @@ -1,6 +1,7 @@ { "private": true, "description": "Dependencies for codeql-action scripts", + "type": "module", "dependencies": { "@actions/core": "^2.0.3", "@actions/github": "^8.0.1", From 4c932d994880a3d0e83fbef1c5f9b8d5b80fc908 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:21:35 +0100 Subject: [PATCH 06/10] Replace `.mts` extensions --- pr-checks/changelog/{validate.test.mts => validate.test.ts} | 2 +- pr-checks/changelog/{validate.mts => validate.ts} | 0 pr-checks/{changenotes.mts => changenotes.ts} | 2 +- 3 files changed, 2 insertions(+), 2 deletions(-) rename pr-checks/changelog/{validate.test.mts => validate.test.ts} (99%) rename pr-checks/changelog/{validate.mts => validate.ts} (100%) rename pr-checks/{changenotes.mts => changenotes.ts} (98%) diff --git a/pr-checks/changelog/validate.test.mts b/pr-checks/changelog/validate.test.ts similarity index 99% rename from pr-checks/changelog/validate.test.mts rename to pr-checks/changelog/validate.test.ts index b8b1e33bb0..379b5737a8 100644 --- a/pr-checks/changelog/validate.test.mts +++ b/pr-checks/changelog/validate.test.ts @@ -9,7 +9,7 @@ import { isValidChangenoteFile, isValidChangenoteFilename, VALID_CHANGE_NOTE_CATEGORIES, -} from "./validate.mjs"; +} from "./validate"; await describe("isValidChangenoteContent", async () => { await it("recognizes an unordered Markdown list", () => { diff --git a/pr-checks/changelog/validate.mts b/pr-checks/changelog/validate.ts similarity index 100% rename from pr-checks/changelog/validate.mts rename to pr-checks/changelog/validate.ts diff --git a/pr-checks/changenotes.mts b/pr-checks/changenotes.ts similarity index 98% rename from pr-checks/changenotes.mts rename to pr-checks/changenotes.ts index 980d103a28..58d4cefa1e 100755 --- a/pr-checks/changenotes.mts +++ b/pr-checks/changenotes.ts @@ -14,7 +14,7 @@ import { renderChangelog, withChangelog, } from "./changelog"; -import { isValidChangenoteFile } from "./changelog/validate.mjs"; +import { isValidChangenoteFile } from "./changelog/validate"; import { CHANGENOTES_DIR } from "./config"; /** From a2374c3d1c10bcb924c3152d4c79870b809e80a1 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:23:42 +0100 Subject: [PATCH 07/10] Replace `__dirname` in `sync-back.ts` --- pr-checks/sync-back.ts | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/pr-checks/sync-back.ts b/pr-checks/sync-back.ts index 3a860eae42..233621ea74 100755 --- a/pr-checks/sync-back.ts +++ b/pr-checks/sync-back.ts @@ -21,10 +21,11 @@ import * as fs from "fs"; import { parseArgs } from "node:util"; import * as path from "path"; -const THIS_DIR = __dirname; -const CHECKS_DIR = path.join(THIS_DIR, "checks"); -const WORKFLOW_DIR = path.join(THIS_DIR, "..", ".github", "workflows"); -const SYNC_TS_PATH = path.join(THIS_DIR, "sync.ts"); +import { PR_CHECKS_DIR, REPO_ROOT } from "./config"; + +const CHECKS_DIR = path.join(PR_CHECKS_DIR, "checks"); +const WORKFLOW_DIR = path.join(REPO_ROOT, ".github", "workflows"); +const SYNC_TS_PATH = path.join(PR_CHECKS_DIR, "sync.ts"); /** * Scan generated workflow files to extract the latest action versions. From 0f3412f83270fbe793fe6631dc9b52de27f28cd8 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:28:05 +0100 Subject: [PATCH 08/10] Replace `.mts` with `.ts` in comments and workflows --- .github/workflows/pr-checks.yml | 4 ++-- pr-checks/changenotes.ts | 6 +++--- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/pr-checks.yml b/.github/workflows/pr-checks.yml index b2ce0a614e..2ae0594407 100644 --- a/.github/workflows/pr-checks.yml +++ b/.github/workflows/pr-checks.yml @@ -128,9 +128,9 @@ jobs: working-directory: pr-checks run: npx tsx --test - - name: Run `pr-checks/changenotes.mts` to ensure that all unreleased change notes are valid + - name: Run `pr-checks/changenotes.ts` to ensure that all unreleased change notes are valid if: ${{ !cancelled() && steps.install-deps.outcome == 'success' }} - run: npx tsx pr-checks/changenotes.mts validate + run: npx tsx pr-checks/changenotes.ts validate - name: Verify all Actions use the same Node version id: head-version diff --git a/pr-checks/changenotes.ts b/pr-checks/changenotes.ts index 58d4cefa1e..933d255cd5 100755 --- a/pr-checks/changenotes.ts +++ b/pr-checks/changenotes.ts @@ -82,9 +82,9 @@ function main(): ExitCode { function usage(): ExitCode { const message = - "Usage: changenotes.mts assemble\n" + - " changenotes.mts validate\n" + - " changenotes.mts help"; + "Usage: changenotes.ts assemble\n" + + " changenotes.ts validate\n" + + " changenotes.ts help"; console.log(message); return ExitCode.Success; } From 0a44f18dc21310091c51a5bebe1582d4bff8d894 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:28:44 +0100 Subject: [PATCH 09/10] Remove `.mts` patterns from configurations --- eslint.config.mjs | 4 ++-- pr-checks/tsconfig.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/eslint.config.mjs b/eslint.config.mjs index 115da235c7..34fe49a9df 100644 --- a/eslint.config.mjs +++ b/eslint.config.mjs @@ -158,7 +158,7 @@ export default [ }, }, { - files: ["**/*.ts", "**/*.js", "**/*.mts"], + files: ["**/*.ts", "**/*.js"], rules: { "@typescript-eslint/no-explicit-any": "off", @@ -180,7 +180,7 @@ export default [ }, }, { - files: ["pr-checks/**/*.ts", "pr-checks/**/*.mts"], + files: ["pr-checks/**/*.ts"], languageOptions: { parserOptions: { diff --git a/pr-checks/tsconfig.json b/pr-checks/tsconfig.json index 67f31d2cdb..e0a6c856c9 100644 --- a/pr-checks/tsconfig.json +++ b/pr-checks/tsconfig.json @@ -8,6 +8,6 @@ "sourceMap": false, "noEmit": true }, - "include": ["./**/*.ts", "./**/*.mts", "../src/**/*.ts"], + "include": ["./**/*.ts", "../src/**/*.ts"], "exclude": ["node_modules"] } From a71b0c6684dea6ca627a472a11bf5b80bd47c845 Mon Sep 17 00:00:00 2001 From: "Michael B. Gale" Date: Tue, 6 Oct 2026 18:29:58 +0100 Subject: [PATCH 10/10] Replace `__dirname` in `sync.ts` --- pr-checks/sync.ts | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pr-checks/sync.ts b/pr-checks/sync.ts index 23ff6fc234..9b40c2e411 100755 --- a/pr-checks/sync.ts +++ b/pr-checks/sync.ts @@ -7,6 +7,8 @@ import * as yaml from "yaml"; import { BuiltInLanguage } from "../src/languages"; +import { PR_CHECKS_DIR, REPO_ROOT } from "./config"; + /** * Returns a `uses` value for `action` pinned to a commit SHA, with the * human-readable version recorded in a trailing comment. @@ -312,9 +314,8 @@ const languageSetups: LanguageSetups = { // See https://github.com/github/codeql-action/pull/3423 const YQ_VERSION = "v4.50.1"; -const THIS_DIR = __dirname; -const CHECKS_DIR = path.join(THIS_DIR, "checks"); -const OUTPUT_DIR = path.join(THIS_DIR, "..", ".github", "workflows"); +const CHECKS_DIR = path.join(PR_CHECKS_DIR, "checks"); +const OUTPUT_DIR = path.join(REPO_ROOT, ".github", "workflows"); /** * Loads and parses a YAML file.