Summary
Every GitHub Action used in this repository is one major version behind current. #622 aligned
the two laggard workflows to the repository's existing standard, but that standard is itself
out of date.
| Action |
Repository uses |
Latest |
actions/checkout |
v6 |
v7.0.1 |
actions/cache |
v5 |
v6.1.0 |
actions/setup-node |
v6 |
v7.0.0 |
actions/upload-artifact |
v6 |
v7.0.1 |
actions/setup-python |
v5 |
v7.0.0 |
Third-party actions are also worth reviewing: EndBug/add-and-commit@v10,
softprops/action-gh-release@v3, github/codeql-action/*@v4.
Why this is a separate piece of work
Action major bumps carry breaking changes — upload-artifact v3 → v4 being the well-known
example, where artifact behaviour changed in ways that silently broke workflows. The bumps
here touch:
main.yml, which commits build artifacts back to master
publish.yml, which publishes to npm on a tag
codeql.yml, which gates security scanning
None of those fail in a way that is cheap to discover. publish.yml in particular only runs
on a tag push, so a break is found after the tag exists — the same failure shape as #619.
Suggested approach
Notes
publish.yml also pins node-version: 22.15.1 while .nvmrc specifies 24.15.0 — tracked
separately.
Follow-up to #622.
Summary
Every GitHub Action used in this repository is one major version behind current. #622 aligned
the two laggard workflows to the repository's existing standard, but that standard is itself
out of date.
actions/checkoutactions/cacheactions/setup-nodeactions/upload-artifactactions/setup-pythonThird-party actions are also worth reviewing:
EndBug/add-and-commit@v10,softprops/action-gh-release@v3,github/codeql-action/*@v4.Why this is a separate piece of work
Action major bumps carry breaking changes —
upload-artifactv3 → v4 being the well-knownexample, where artifact behaviour changed in ways that silently broke workflows. The bumps
here touch:
main.yml, which commits build artifacts back tomasterpublish.yml, which publishes to npm on a tagcodeql.yml, which gates security scanningNone of those fail in a way that is cheap to discover.
publish.ymlin particular only runson a tag push, so a break is found after the tag exists — the same failure shape as #619.
Suggested approach
bumping and seeing what happens.
CI.ymlandcodeql.ymlfirst — they run on every push, so breakage surfacesimmediately and costs nothing.
build-python.yml.main.yml, checking that the artifact commit step still behaves.publish.ymllast, and consider exercising it on a throwaway prerelease tag ratherthan a real release.
Notes
publish.ymlalso pinsnode-version: 22.15.1while.nvmrcspecifies24.15.0— trackedseparately.
Follow-up to #622.