Skip to content

fix(ci): run setup-node on Node 24 action runtime - #340

Draft
seonghobae wants to merge 2 commits into
developfrom
fix/foundation-setup-node-node24
Draft

seonghobae wants to merge 2 commits into
developfrom
fix/foundation-setup-node-node24

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Finding

Fresh Foundation logs on active Orgmetra heads emitted GitHub's Node 20 action-runtime deprecation warning while executing actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 (v4.4.0), followed by the Node punycode deprecation warning. The workflow already requested Node 24 for the project toolchain, so suppression or a compatibility override would leave the action runtime debt in place.

Repair

This dedicated repository-workflow owner lane pins immutable upstream actions/setup-node v7.0.0 at exact commit 820762786026740c76f36085b0efc47a31fe5020. The pinned upstream action.yml declares runs.using: node24. node-version: "24", the explicit Ubuntu 24.04 runner, exact-candidate proof, Foundation commands, coverage gates, PostgreSQL isolation and all other workflow behavior remain unchanged.

The initial workflow-only head de85a49a28ca9211b0f9e57157d398cd0dc1c612 intentionally left manifest.json on protected predecessor bytes so the repository validator could expose the exact seal mismatch rather than hiding it. Current exact head 28f2bd28414e217f7e848ba86c0cfdbe97fd518f reseals only .github/workflows/foundation-ci.yml to SHA-256 1c84b084884679eaf631d1cab49d42a0c5b3852170402fced3dfd9fee9cafd47, 6651 bytes, 125 lines; no unrelated manifest entry changed.

Current exact-head evidence — 2026-09-20

Protected base remains develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Fresh compare is 2 ahead / 0 behind with merge base exactly the protected base. The PR remains open · Draft · mergeable=true.

Exact-head hosted results are now terminal rather than queued:

  • Foundation CI 34862980322: success. Repository quality job 104039660737 passed exact checkout proof, Foundation validation, dependency hygiene, unit/service contracts, isolated PostgreSQL contracts and read-only validation.
  • SAST Semgrep 34862980157: success.
  • Security Scan 34862980301: success. Changed-scope classification skipped dependency-review/OSV for this workflow-only delta, so that skip is not promoted to dependency-review evidence.
  • CodeQL PR 34862980179: failure in the central current-head verdict compatibility path. Detect-language succeeded; compatibility jobs 104173892965 (python) and 104173892991 (actions) failed at Release runner or enforce current-head CodeQL verdict after reading a non-terminal/missing dispatch verdict, while later dispatch job 104234458389 succeeded. This is routed to ContextualWisdomLab/.github#1929; no leaf shim or manual status is authorized.

No PR review has been submitted on this head. Live organization ruleset 18156473 still requires one approval, resolved review threads, and the central required workflows. Keep Draft while the required CodeQL path is red and approval is absent.

Issue #339 remains the owner finding. Do not suppress warnings, use mutable action tags, create no-op rerun churn, transfer predecessor evidence, force-push/destructively rebase, self/model approve, weaken a gate, or use routine administrator bypass.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant