Skip to content

Move the workflow actions to the Node 24 runtime - #48

Merged
micheltlutz merged 1 commit into
mainfrom
chore/node-24-actions
Sep 21, 2026
Merged

micheltlutz merged 1 commit into
mainfrom
chore/node-24-actions

Conversation

@micheltlutz

Copy link
Copy Markdown
Owner

Every run was printing the same deprecation notice and being forced onto Node 24 anyway,
so the old pins bought nothing but the warning.

Action From To
actions/checkout v4 v7
actions/setup-python v5 v7
softprops/action-gh-release v2 v3
codecov/codecov-action v5 v7

pypa/gh-action-pypi-publish@release/v1 is a Docker action and never had the problem.

What the new majors dropped

Worth checking rather than assuming, since release.yml is the one workflow that breaks
at the moment you need it most:

  • checkout v7 restricts checking out a forked PR under pull_request_target and
    workflow_run. Neither trigger appears here.
  • setup-python v7 removed the pip-install input. Nothing used it; cache: pip is
    unchanged.
  • action-gh-release v3 is the Node 24 move itself. body_path and files unchanged.
  • codecov-action v6 carried the Node 24 switch, v7 a signing-key rotation. token,
    files and fail_ci_if_error unchanged.

Also

Restores the ## [Unreleased] header that folding the 1.0.0 release removed. AGENTS.md
tells every change to write its entry under it, and it was not there to write under.

./scripts/verify.sh passes.

🤖 Generated with Claude Code

Every run printed the same deprecation notice and was forced onto Node 24 regardless, so
the pins were buying nothing but the warning. checkout v4 to v7, setup-python v5 to v7,
action-gh-release v2 to v3, codecov-action v5 to v7 -- the latest major of each, which is
where dependabot would have landed anyway.

Checked what the new majors dropped before jumping, because a major bump taken on faith is
how a release workflow breaks at the one moment you need it: checkout v7 only restricts
checking out a forked PR under `pull_request_target` and `workflow_run`, neither of which
appears here, and setup-python v7 removed the `pip-install` input, which nothing used.
`cache: pip`, `body_path`, `files`, `token` and `fail_ci_if_error` are all unchanged.

Also restores the `## [Unreleased]` header that folding 1.0.0 removed. AGENTS.md tells
every change to write its entry under it, and it was not there to write under.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@micheltlutz
micheltlutz merged commit da2c971 into main Sep 21, 2026
16 checks passed
@codecov

codecov Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.27%. Comparing base (5da8902) to head (158b94f).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #48   +/-   ##
=======================================
  Coverage   92.27%   92.27%           
=======================================
  Files          19       19           
  Lines        1048     1048           
  Branches      119      119           
=======================================
  Hits          967      967           
  Misses         65       65           
  Partials       16       16           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@micheltlutz
micheltlutz deleted the chore/node-24-actions branch September 21, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant