Skip to content

ci: upgrade actions/checkout from v3.7.0 to v7.0.1 in release.yml - #105

Merged
craigmcchesney merged 1 commit into
mainfrom
ci-94-checkout-v7
Sep 30, 2026
Merged

craigmcchesney merged 1 commit into
mainfrom
ci-94-checkout-v7

Conversation

@craigmcchesney

Copy link
Copy Markdown
Collaborator

Closes #94.

Upgrades the single actions/checkout reference in release.yml from v3.7.0 (Node 16, past deprecation) to v7.0.1. This was the last lagging checkout pin in the org; dp-grpc, dp-service, dp-desktop-app and dp-python-lib already pin this exact SHA.

-        uses: actions/checkout@a37ce9120846195fa4ece8f58b268e6043cb2f26 # v3.7.0
+        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

This PR changes only checkout. softprops/action-gh-release v2.6.2 → v3 stays separate: a dry run skips the publish step, so this rehearsal cannot exercise it, and keeping it out means a problem at the next release points at one change.

Why it is low-risk

The step has no with: block. The v4–v7 majors change only the runtime and internals (Node 20/24, credentials in a separate file, ESM, a fork-PR block on pull_request_target/workflow_run). This workflow triggers only on rel-* tag push and workflow_dispatch, runs on ubuntu-latest, and passes an explicit token: to every release-downloader step. None of those changes reach it.

Verification

  • SHA resolved from the tag ref (git/ref/tags/v7.0.1 → lightweight tag → commit 3d3c42e…)
  • SHA re-verified: the tags API returns ["v7.0.1", "v7"] for it
  • Grep gate clean: grep -rnE 'uses: *[^ ]+@' .github/workflows/ | grep -vE '@[0-9a-f]{40} # v' returns nothing
  • Dry-run dispatch from this branch, version=1.16.0, dry_run=true: run 36786322390, success
    • Checkout ran at the new SHA and synced the repo
    • Release notes found at doc/release-notes/rel-1.16.0.md (no warning), so the notes step was fully exercised
    • All three sibling 1.16.0 JARs were downloaded; the tarball and checksum were built
    • Publish was skipped, as expected

Not caused by this change, noted for later:

  • Each of the three release-downloader steps logs a Node DEP0169 (url.parse()) deprecation warning.
  • The run carries a notice that ubuntu-latest moves to Ubuntu 26 starting 2026-10-19.

🤖 Generated with Claude Code

https://claude.ai/code/session_012nsCzraPATf4LCKVyUStfd

The step has no with: block, and the v4-v7 majors change only the runtime
and internals (Node 20/24, credential file location, ESM, fork-PR restriction
on pull_request_target/workflow_run), none of which this tag-push/dispatch
workflow touches.  v3.7.0 runs on Node 16, which is past deprecation.

SHA resolved from the tag ref and verified to carry both v7.0.1 and v7; it
matches the pin already used in dp-grpc, dp-service, dp-desktop-app and
dp-python-lib.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012nsCzraPATf4LCKVyUStfd
@craigmcchesney
craigmcchesney merged commit 6b463aa into main Sep 30, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

upgrade actions/checkout from v3.7.0 to v7.x in release.yml

1 participant