ci: upgrade actions/checkout from v3.7.0 to v7.0.1 in release.yml - #105
Merged
Merged
Conversation
The step has no with: block, and the v4-v7 majors change only the runtime and internals (Node 20/24, credential file location, ESM, fork-PR restriction on pull_request_target/workflow_run), none of which this tag-push/dispatch workflow touches. v3.7.0 runs on Node 16, which is past deprecation. SHA resolved from the tag ref and verified to carry both v7.0.1 and v7; it matches the pin already used in dp-grpc, dp-service, dp-desktop-app and dp-python-lib. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012nsCzraPATf4LCKVyUStfd
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #94.
Upgrades the single
actions/checkoutreference inrelease.ymlfrom v3.7.0 (Node 16, past deprecation) to v7.0.1. This was the last laggingcheckoutpin in the org; dp-grpc, dp-service, dp-desktop-app and dp-python-lib already pin this exact SHA.This PR changes only
checkout.softprops/action-gh-releasev2.6.2 → v3 stays separate: a dry run skips the publish step, so this rehearsal cannot exercise it, and keeping it out means a problem at the next release points at one change.Why it is low-risk
The step has no
with:block. The v4–v7 majors change only the runtime and internals (Node 20/24, credentials in a separate file, ESM, a fork-PR block onpull_request_target/workflow_run). This workflow triggers only onrel-*tag push andworkflow_dispatch, runs onubuntu-latest, and passes an explicittoken:to everyrelease-downloaderstep. None of those changes reach it.Verification
git/ref/tags/v7.0.1→ lightweight tag → commit3d3c42e…)["v7.0.1", "v7"]for itgrep -rnE 'uses: *[^ ]+@' .github/workflows/ | grep -vE '@[0-9a-f]{40} # v'returns nothingversion=1.16.0,dry_run=true: run 36786322390, successdoc/release-notes/rel-1.16.0.md(no warning), so the notes step was fully exercisedNot caused by this change, noted for later:
release-downloadersteps logs a NodeDEP0169(url.parse()) deprecation warning.ubuntu-latestmoves to Ubuntu 26 starting 2026-10-19.🤖 Generated with Claude Code
https://claude.ai/code/session_012nsCzraPATf4LCKVyUStfd