Skip to content

[sc-208568] Move GitHub Actions off Node 20 - #47

Merged
Mallear merged 1 commit into
masterfrom
chore/sc-208568-node24-github-actions
Sep 29, 2026
Merged

Mallear merged 1 commit into
masterfrom
chore/sc-208568-node24-github-actions

Conversation

@Mallear

@Mallear Mallear commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Why

GitHub is retiring Node 20 on Actions runners, and every JavaScript action has to run on Node 24 (epic sc-208536). This PR moves every node12/node20 action used by this repo's workflows to a Node 24 release. Story: https://app.shortcut.com/agorapulse/story/208568. Audit and migration notes: https://agorapulse.slite.com/app/docs/9IsAaizelUFHVV.

Actions changed

Action From To
actions/checkout v4 (node20) v7 (node24)
actions/setup-java v4 (node20) v6 (node24)
gradle/actions/setup-gradle v4 (node20) v6 (node24)
timheuer/base64-to-file v1 (node20) v2 (node24)
peter-evans/repository-dispatch v1 (node12) v4 (node24)

The repo's major-tag pinning style is kept (for example @v7, not a SHA).

Behaviour changes for reviewers

  • checkout v7: the new refusal to check out fork PRs only applies under pull_request_target/workflow_run. This repo doesn't use either trigger, so it has no effect here. Since v6, persisted credentials live in a file under $RUNNER_TEMP instead of .git/config. Nothing in this repo's release job reads the token from .git/config. gitPublishPush gets its credentials from GIT_PUBLISH_USERNAME/GIT_PUBLISH_PASSWORD.
  • setup-java v6: distribution is already set everywhere, and no workflow uses the cache input, so the new "cache the JDK too" behaviour doesn't apply.
  • setup-gradle v4 → v6 (org standard, already used in platform-github-actions): no inputs to migrate. v6's default caching (cache-provider: enhanced) is the proprietary gradle-actions-caching component, and using it counts as accepting the Gradle Terms of Use. It's free for public repos like this one. The cache protocol changed in v6.3.0, so the first run after merge will miss the cache. v6.4.0+ also adds EOL-Gradle warning annotations.
  • repository-dispatch v4 / base64-to-file v2: runtime-only bumps. Inputs and outputs (filePath) are unchanged, and dispatch still sends the same JSON.parse(client-payload) to createDispatchEvent.
  • Node 24 actions need runner >= v2.327.1. The GitHub-hosted ubuntu-latest runners used here meet that.

Not exercised by this PR

  • release.yml runs only on release: published. PGP decoding (base64-to-file), the Maven Central publish and the upstream repository-dispatch jobs are not exercised here. They will first run on the next release.
  • gradle.yml (Check) is exercised by this PR (push and pull_request).

🤖 Generated with Claude Code

Bump actions/checkout v4 -> v7, actions/setup-java v4 -> v6,
gradle/actions/setup-gradle v4 -> v6, timheuer/base64-to-file v1 -> v2
and peter-evans/repository-dispatch v1 -> v4.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Mallear
Mallear marked this pull request as ready for review September 29, 2026 14:40
@Mallear
Mallear requested a review from musketyr September 29, 2026 14:40
@Mallear
Mallear merged commit 41ea149 into master Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants