Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
# actionlint validates `runs-on:` against a runner-label list baked into its
# binary. Ubuntu 26.04 went GA 2026-09-17, after the latest actionlint release
# (v1.7.12, 2026-03-30), so every ubuntu-26.04 label in this repo is reported
# as unknown. Declaring the labels here is the escape hatch actionlint's own
# error message points to.
#
# Remove this file once actionlint ships ubuntu-26.04 in rule_runner_label.go;
# keeping it after that only costs the version-compatibility checks actionlint
# does for known images.
self-hosted-runner:
labels:
- ubuntu-26.04
- ubuntu-26.04-arm
26 changes: 18 additions & 8 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ jobs:
# add it to the filter's `if:` so `image` is never left empty (empty ==
# silent skip, the very failure mode this job exists to prevent).
changes:
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
outputs:
image: ${{ steps.filter.outputs.image || steps.force.outputs.image }}
steps:
Expand Down Expand Up @@ -98,16 +98,26 @@ jobs:
# compile, which dominated wall-clock under the old single-job
# multi-platform build. amd64 builds on the standard x86 runner, arm64 on
# GitHub's free public-repo arm runner, and both legs run in parallel.
#
# Renovate's built-in github-actions manager does NOT see the `runner:`
# labels below: it extracts runner labels from literal `runs-on:` values
# only and does not traverse strategy.matrix.include[] (confirmed in
# doc-scanner #209). Left unmanaged, a runner-image bump would update
# every other job in this repo and leave these two behind -- a
# split-brain build that still passes CI, since both images work. The
# `ubuntu` customManager in the shared preset (owine/renovate-config)
# covers these two lines so they bump in the same PR. Keep the
# `runner: ubuntu-<major>.<minor>` shape: that manager matches on it.
runs-on: ${{ matrix.runner }}
strategy:
fail-fast: false
matrix:
include:
- platform: linux/amd64
runner: ubuntu-24.04
runner: ubuntu-26.04
arch: amd64
- platform: linux/arm64
runner: ubuntu-24.04-arm
runner: ubuntu-26.04-arm
arch: arm64
permissions:
contents: read
Expand Down Expand Up @@ -183,7 +193,7 @@ jobs:
# PRs never push, so there is nothing to merge.
needs: build
if: github.event_name != 'pull_request'
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
permissions:
contents: read
packages: write
Expand Down Expand Up @@ -250,7 +260,7 @@ jobs:

test:
name: Functional Testing
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
permissions:
contents: read
packages: read
Expand Down Expand Up @@ -422,7 +432,7 @@ jobs:

scan:
name: Security Scan
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
needs: merge
if: github.event_name != 'pull_request'
permissions:
Expand Down Expand Up @@ -472,7 +482,7 @@ jobs:

promote:
name: Tag and Promote Image
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
needs: [merge, test, scan]
if: |
github.event_name != 'pull_request' &&
Expand Down Expand Up @@ -563,7 +573,7 @@ jobs:
ci-pass:
needs: [changes, build, merge, test, scan, promote]
if: always()
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: All required jobs passed or were appropriately skipped
env:
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ permissions:
jobs:
hadolint:
name: Dockerfile Linting
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -44,7 +44,7 @@ jobs:

shellcheck:
name: Shell Script Linting
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -56,7 +56,7 @@ jobs:

yaml-lint:
name: YAML Linting
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand All @@ -68,7 +68,7 @@ jobs:

action-lint:
name: GitHub Actions Linting
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ permissions:
jobs:
release:
name: Release Please
runs-on: ubuntu-24.04
runs-on: ubuntu-26.04
steps:
- name: Generate GitHub App token
id: app-token
Expand Down