Sitelet https://github.com/thinkvp/Syncitol/pull/1
Skip to content

Bump GitHub Actions off the Node 20 runtime - #1

Merged
thinkvp merged 2 commits into
mainfrom
ci/bump-actions
Sep 19, 2026
Merged

thinkvp merged 2 commits into
mainfrom
ci/bump-actions

Conversation

@thinkvp

@thinkvp thinkvp commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Every workflow run has been warning that actions/checkout, actions/setup-node, actions/cache and actions/upload-artifact target Node 20 and are being force-run on Node 24. Pinned to current majors:

action was now
actions/checkout v4 v7
actions/setup-node v4 v7
actions/cache v4 v6
actions/upload-artifact v4 v7
actions/download-artifact v4 v8

Build logic, the tag-matches-manifest gate and the CI Node matrix (20/22/24) are untouched.

Breaking changes checked, not assumed

  • setup-node v5 began caching package managers automatically. There is no lockfile and there are no dependencies here, so the auto-cache would only fail looking for one — package-manager-cache: false is now set explicitly in both workflows.
  • download-artifact v5's path change applies to downloads by ID (artifact-ids); this repo downloads by name, so it is unaffected. v8 makes a digest mismatch a hard error rather than a warning, which is what we want for a package that carries a native binary.
  • upload-artifact v5→v7 does not change path handling. The common-ancestor stripping that uxp-release.yml relies on still applies; v7's archive: false is opt-in and unused.
  • checkout v7 blocks checking out fork PRs for pull_request_target/workflow_run; this repo uses neither.
  • All jobs run on GitHub-hosted runners, so the 2.327.1 minimum runner version is met.

Verification

uxp-release.yml only runs on a v* tag, so a PR cannot exercise it. tmp-artifact-check.yml mirrors its upload/download path handling exactly — same path: block, same path: uxp/mac restore, same defaults.run.working-directory — and asserts the layout build-ccx.js expects. That temp workflow is deleted before merge; it exists only so the artifact round-trip is proven rather than reasoned about.

🤖 Generated with Claude Code

thinkvp and others added 2 commits September 19, 2026 19:02
Every run warned that checkout/setup-node/cache/upload-artifact target
Node 20 and are being forced onto Node 24. Pinned to current majors:
checkout v7, setup-node v7, cache v6, upload-artifact v7,
download-artifact v8.

setup-node started caching package managers automatically in v5, so
package-manager-cache is explicitly off — there are no dependencies and
no lockfile here, and the auto-cache would only fail looking for one.

The release workflow only runs on a v* tag, so tmp-artifact-check.yml
mirrors its upload/download path handling to prove the artifact
round-trip under the new versions. It is deleted in the next commit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
It did its job: under upload-artifact@v7 + download-artifact@v8 the
artifact still lands as uxp/mac/{x64,arm64}/syncitol.uxpaddon, which is
the layout build-ccx.js expects.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@thinkvp
thinkvp merged commit 6baf781 into main Sep 19, 2026
3 checks passed
@thinkvp
thinkvp deleted the ci/bump-actions branch September 19, 2026 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant